Potted Dedicated secure element FIDO Certified Secrets encrypted against the PIN Upgradable firmware Open-source firmware
Solo 2
Potted Upgradable firmware Open-source firmware Secrets encrypted against the PIN Dedicated secure element Solo 2 certification pending
Nitrokey 3
Upgradable firmware Dedicated secure element Open-source firmware Partial encryption against the PIN Only Nitrokey 3A Mini is FIDO Certified Potted
OnlyKey
Potted Secrets encrypted against the PIN Upgradable firmware Open-source firmware FIDO2 Certified Dedicated secure element
Important notes:
Yubico claiming that non-upgradable firmware is necessary “for security” is like pissing on you and telling you it’s raining. Don’t buy into it. Titan M2 is arguably the most secure element available for consumers. It came out with the Pixel 6 almost five years ago, was built using OpenTitan, and, guess what, it supports firmware updates. Cellebrite, GrayKey, and other companies have been trying to exploit it for years and have so far failed miserably.
Nitrokey plans to introduce potting and certify more models.
OnlyKey’s software situation is awful. No updates since 2022, there are no ARM builds for the GUI applications, and the Linux version is distributed only as a .deb package.
Overall, I would recommend OnlyKey, provided you can tolerate its software situation.
Edit: forgot to mention that OnlyKey allows its secrets to be exported, which might be either a feature or a bug to you.
If you’d have any thoughts on this, I am also looking into recommending Ledger devices as security keys, largely for the convenience of being able to have unlimited security keys, while only needing to set up one of them with the website in question:
Ledger makes a number of cryptocurrency hardware wallet products and an optional, FIDO certified Security Key app for those wallets which enables FIDO2 security key functionality. If you need a cryptocurrency wallet anyway, this could be an option to consider for security key functionality as well.
Even if you don’t need a cryptocurrency wallet, using Ledger devices as security keys has three key advantages over YubiKey you may wish to consider:
Secure PIN authentication.
A 4-8 digit PIN is always required to operate Ledger devices. Additionally, that PIN is entered via the display on the device itself. YubiKey PIN authentication, in contrast, is a software prompt where you enter your PIN on the computer/phone you’re using.
Firmware updates.
Both the operating system firmware and the Security Key app software can be updated via the Ledger Wallet app if new security improvements are released.
Backups and sync.
When setting up your Ledger device you will create a 24-word “seed phrase.” Your security key credentials are tied to this seed phrase, meaning that if you lose/break your Ledger device, you can use the same 24-word phrase to set up a new Ledger device, and it will work with your existing accounts.
You can also use the same 24-word phrase to set up multiple Ledger devices simultaneously, and all of them will work with your accounts in a “synced” fashion, instead of needing to register each security key individually.
Some may consider the last two features to be downsides. Firmware updates can add additional attack surface and introduce new bugs at a later time. However, it is worth noting that many non-updatable security keys from various vendors have been recalled due to discovered security flaws which could not be patched. Backups can also be dangerous if your seed phrase is not properly secured, because it could be used by an attacker to create a duplicate security key if it is leaked.
Ledger devices are decent, but I prefer Trezor, especially the Trezor Safe 7 for a few reasons:
It supports discoverable credentials.
Has fully open-source firmware.
Has two dedicated secure elements.
Their TROPIC1 secure element has open and auditable architecture.
The second secure element is proprietary, but is publicly documented.
Edit: One more consideration is PIN length. With Ledger, 8 digits is the strongest PIN you can choose, while Trezor supports up to 50 digits. So, if an attacker bypasses the rate limiting, an 8 digit PIN provides only ~26.6 bits of entropy.
I am unhappy with Trezor’s attitude that just because their devices can be transparent/inspectable by anyone, they feel no obligation themselves to get their devices independently tested. For one example, they are not even considering seeking out FIDO Alliance certification for their security key app.
I also question their three-chip design, in comparison to Ledger’s approach to run everything inside its secure enclave. I don’t really see why their design would be a problem to be fair, but added complexity often causes trouble as a general rule.
In my draft I currently intend to recommend only Ledger as security keys, and recommend both Ledger and Trezor as crypto wallets in a new hardware wallet section.
That’s a weird move from them, but it was in 2021, maybe they would be willing to seek certification now.
With Ledger, the only thing protecting the secrets is its secure element; the measly 4–8 digit PIN is only used for authentication. If the secrets can be extracted from the secure element, it’s over. Since the secure element is proprietary and kinda opaque, I wouldn’t really rely on it. I also highly doubt that it’s anywhere close to being as secure as Titan M2 or Apple’s Secure Enclave, which are the two secure elements that I trust because of how battle-tested they are.
Meanwhile, with Trezor, not only is one of the secure elements open and auditable, but the second one is also publicly documented. The seed from which the FIDO keys are derived is protected by a decryption key dependent on the PIN and hardware secrets.
So, because Trezor supports PINs of up to 50 digits, you could theoretically use a random 27 digit PIN, which provides roughly the same entropy as a 7 word passphrase from EFF’s long list.
The Tropic01 has had serious unpatchable hardware vulnerabilities discovered, yet Trezor is comfortable continuing to sell affected products without any sort of notice for would-be customers. It’s not something I feel comfortable recommending.
Yubico also does an exceptional job at keeping up with standards and are afaik the only security keys with support for the latest CTAP 2.3 standard. Not supporting firmware updates for ‘security reasons’ is absurd, but it’s not unique to Yubico, and they are the superior option in many other ways.
Because it wouldn’t really make much sense to stop selling the Trezor Safe 7.
With this vulnerability, an attacker with physical access, an expert skill level, and more than €30,000 worth of specialized equipment could extract TROPIC01’s secret contribution.
The attacker would still have to compromise the second secure element.
They would also have to compromise the STM32U5 protection layer and somehow obtain or brute-force the user’s PIN, which can be up to 50 digits.
So, I don’t see how scrapping these devices just because one layer of defense can be compromised in a laboratory setting makes any sense.
TROPIC01, or Trezor? If the latter, could you elaborate at Trezor Safe 3/5/7 (hardware cold wallets)? My line of thinking is that TROPIC01 was included as some neat additional defense-in-depth, but its compromise doesn’t compromise the security of the product below what anything else provides.
One very important thing that is really easy to miss is that Trezor Safe 3 doesn’t have a touchscreen. So good luck typing a long PIN using those two physical buttons.
You can set up the backup key mode to “Locked” to prevent the backup password from being changed, and then “throw away” the password. Since the export is encrypted with the password, without it, the export is useless.
Onlykey is barely supported, including the said software situation. Only supports up to 12 passkeys.
Since I can’t edit my original post, I will write some very important information here:
Since OnlyKey doesn’t have a secure element, the longest possible PIN combination is only 10 digits, which is not enough entropy for secure encryption. Combined with the horrific software situation, it’s not something that I could personally recommend anymore.
While Nitrokey 3 has a secure element and encrypts some secrets against the PIN, passkeys and FIDO2 credentials are not stored in that secure element and aren’t encrypted against the PIN either. Combined with no potting, this is not good.
It looks like YubiKeys are still the best option for most people and for those who don’t want to spend too much.
If you’re someone who can spare €129 for an authenticator/crypto wallet, then the Trezor Safe 5 looks like the best option, beating even the YubiKeys.
Potted Dedicated secure element FIDO Certified Secrets encrypted against the PIN Upgradable firmware Open-source firmware
Solo 2
Potted Upgradable firmware Open-source firmware Solo 2 certification pending Secrets encrypted against the PIN Dedicated secure element
Nitrokey 3
Upgradable firmware Open-source firmware Dedicated secure element, but it is not used to store or protect FIDO2 credentials and passkeys Partial encryption against the PIN: some applications are PIN-encrypted, but FIDO2 credentials and passkeys are not Only the Nitrokey 3A Mini is FIDO Certified Potted
OnlyKey
Potted Upgradable firmware Open-source firmware FIDO2 Certified Secrets encrypted against the PIN, but the maximum 10-digit PIN does not provide enough entropy for proper encryption Dedicated secure element
Trezor Safe 3
Secrets encrypted against the PIN: the seed-derived key material is protected by the PIN and a hardware secret Dedicated secure element Upgradable firmware Open-source firmware No touchscreen PIN entry, which makes entering a strong PIN considerably less practical FIDO Certified
Trezor Safe 5
Secrets encrypted against the PIN: the seed-derived key material is protected by the PIN and a hardware secret Dedicated secure element Touchscreen PIN entry Upgradable firmware Open-source firmware FIDO Certified
Trezor Safe 7
Secrets encrypted against the PIN: the seed-derived key material is protected by the PIN and secrets contributed by both secure elements Two dedicated secure elements One independently auditable secure element Touchscreen PIN entry Upgradable firmware Open-source firmware TROPIC01 has a known laser-fault-injection hardware vulnerability, although exploiting it requires physical access, expert skills, and specialized equipment and does not compromise the entire device by itself FIDO Certified
Touchscreen PIN entry is important if you want to use a strong PIN. Although all Trezor Safe models support PINs of up to 50 digits, entering a strong PIN is a lot more sane on the Safe 5 and Safe 7 than on the Safe 3, which relies on two physical buttons.