Security Key Comparison

I’m not sure entropy is necessarily relevant here — data gets erased after 10 wrong attempts. Try brute-forcing even a 5-digit PIN in 10 attempts.

The whole comparison also misses some key features around HMAC — both YubiKey 5 and OnlyKey have it and can be used for offline encryption (like with KeePass family apps). Trezor doesn’t seem to have that.

The idea is to have enough entropy to still be secure if the rate limiting is bypassed?

From what I’ve read, the rate limit on current devices (EAL5+, not the old, already-hacked Trezors) is guaranteed by the same hardware secure element that stores the secret. So if it’s bypassed, the device is already compromised anyway

The whole point of this category of devices is to avoid making people use high-entropy secrets manually. I’m not sure these devices still make sense if we do not trust hardware SE and come back to the old model of high entropy managed by a human being

1 Like

Sadly I confused OnlyKey with OneKey. OnlyKey doesn’t use a SE. In that case, lack of entropy is indeed an issue for OnlyKey, but not the only one.

How about the Foundation Passport Prime? It’s open source, has secure element, encrypted storage, FIDO support etc. Not sure about FIDO certification though.

1 Like

Seems interesting, I was unaware it had Monero support but looks like it does. You should open a Site Development > Tool Suggestions thread.

Edit 1: I’m unsure why it would be worth double the price though.

Edit 2: Docs say FIDO2 support is coming, which probably means it is U2F.

Not that we can recommend this, but this looks sweet and I’m gonna get one next week lol