# SoloKey (Security Key)

**URL:** https://discuss.privacyguides.net/t/solokey-security-key/11585
**Category:** Tool Suggestions
**Tags:** waiting
**Created:** 2023-01-22T19:13:01Z
**Posts:** 23

## Post 1 by @ConsecutiveSpectacles — 2023-01-22T19:13:01Z

I’d like to bring up the suggestion of SoloKeys again for [Hardware Security Keys](https://www.privacyguides.org/multi-factor-authentication/#hardware-security-keys), which was on the GH Discuss forum [before](https://github.com/orgs/privacyguides/discussions/192) the move here to Discourse:

> I’d like to suggest [SoloKeys](https://solokeys.com/) for the MFA page as another option under the “Hardware Security Keys” section.
> 
> SoloKey devices use open source software (on [GitHub](https://github.com/solokeys)) and hardware, though I don’t know too much about the hardware part or how it compares to Nitrokey.
> 
> I haven’t seen any mention of it on [Pull Request 862](https://github.com/privacyguides/privacyguides.org/pull/862) yet. Also, SoloKeys was mentioned in [the discussions](https://github.com/orgs/privacyguides/discussions/311) a while back, but this seems to have fallen to the wayside.
> 
> ## Some background (so others don’t have to start research from scratch)
> 
> SoloKeys devices from the older but currently available [Solo 1 line](https://solokeys.com/collections/all) seem to be most similar to the older but currently available [Nitrokey FIDO2](https://shop.nitrokey.com/shop/product/nkfi2-nitrokey-fido2-55) hardware security devices.
> 
> Upcoming SoloKeys devices in the [Solo V2/Solo 2 line](https://www.indiegogo.com/projects/solo-v2-safety-net-against-phishing#/) (unless you already knew about SoloKeys) seem to be most similar to the [Nitrokey 3 line](https://www.nitrokey.com/news/2021/new-nitrokey-3-nfc-usb-c-rust-common-criteria-eal-6). Currently, the Nitrokey 3 products are in pre-order status (for the [USB-A](https://shop.nitrokey.com/shop/product/nk3an-nitrokey-3a-nfc-147) and [USB-C](https://shop.nitrokey.com/shop/product/nk3cn-nitrokey-3c-nfc-148) variants).
> 
> As stated in a SoloKeys [announcement](https://solokeys.com/blogs/news/trussed-announcement) from February 2021, SoloKeys and Nitrokey are competitor-collaborators because both companies use Trussed, the same open source cryptography framework.
> 
> SoloKeys doesn’t seem to get a lot of attention, because SoloKeys only makes hardware security keys (so far). On the other hand, Nitrokey is more well known because it sells other products, such as the Qubes Certified NitroPad [X230](https://shop.nitrokey.com/shop/product/nitropad-x230-67) and [T430](https://shop.nitrokey.com/shop/product/nitropad-t430-119) and the NitroPhone [1](https://shop.nitrokey.com/shop/product/nitrophone-1-199) and [2](https://shop.nitrokey.com/shop/product/nitrophone-2-244)/[2 Pro](https://shop.nitrokey.com/shop/product/nitrophone-2-pro-245) (which are preinstalled GrapheneOS devices on the Pixel 4a and Pixel 6/6 Pro, respectively, with various options for removing the microphones, sensors, and cameras).
> 
> ### Other consideration: shipping availability
> 
> I originally wanted the Nitrokey FIDO2 but accidentally bought the Nitrokey Pro 2 (which can be used for unlocking the computer upon boot, like in the [Insurgo PrivacyBeast X230](https://insurgo.ca/produit/qubesos-certified-privacybeast_x230-reasonably-secured-laptop/)) in late summer 2021. However, long story short I remembered in a [video](https://www.youtube.com/watch?v=ze2i9V1_aIc) about passwordless account logins (it’s a bit idealistic) that SoloKeys is a good alternative to Nitrokey devices (since shipping was €50 or more via only UPS due to German COVID mail restrictions in early fall 2021).
> 
> Basically, if you’re in the U.S. or close to North America, then SoloKeys is more sensible regarding shipping - while those in the EU should consider Nitrokey for similar reasoning. However, both SoloKeys and Nitrokey will ultimately ship internationally. Having 1 more recommendation for hardware-based MFA alongside YubiKey and Nitrokey could help readers regarding availability.

I’m wondering if there’s any progress on suggesting SoloKeys since then.

---

## Post 2 by @jonah — 2023-02-14T16:35:55Z

SoloKey 2 isn’t generally available yet, and SoloKey 1 is USB-A only, and doesn’t have the best build quality IMHO. I don’t think we should be recommending products that are pre-order only, so I’m going to mark this as waiting and we can revisit it when SK2 is available in stores.

---

## Post 3 by @anon66890361 — 2023-02-19T11:56:04Z

A note relating to **build quality and availabilit** y , i had been looking into buying a Nitrokey as recommended on privacyguides website. But after some research into their support and forums i found that a lot of users are complaining about nfc not working on their 3A models with pixel and samsung phones (refer their forum thread issues [1](https://support.nitrokey.com/t/nitrokey-3a-nfc-funktioniert-nicht/3765) , [2](https://support.nitrokey.com/t/nitrokey-3a-nfc/4645) (infact their support themselves say it won’t work with samsung SE models).  
Some even complained of their keys being bricked and had to replace them.  
Even a gui application for updating firmware and otp handling is not ready (only wip till now).  
nitrokey 3c is on pre-order ( since nfc working with the 3A is not a guarantee , then buying 3c would be the only practical thing.)  
My request is to atleast consider adding these drawbacks to the recommendation on website to the current list of drawbacks as it may affect buying decision.

---

## Post 4 by @jonah — 2023-02-24T17:58:05Z

Based on the responses to the first forum thread linked, it sounds like their support is replacing models with defective NFC.

---

## Post 5 by @TheDoc — 2023-11-03T19:05:22Z

Correct me if I’m wrong, but after taking a quick glance at their online store, [it looks like they’re now available](https://solokeys.com/collections/all).

---

## Post 6 by @ConsecutiveSpectacles — 2024-01-22T18:02:37Z

SoloKeys 2 started to be sold in summer of 2023 in its store - but at first the only options were the “Limited Edition” SoloKey 2 devices with glitter in the epoxy covering the microcontroller used ([USB-A](https://solokeys.com/collections/all/products/limited-edition-solo-2a-nfc-security-key-built-with-trussed%C2%AE) and [USB-C](https://solokeys.com/collections/all/products/limited-edition-solo-2c-nfc-security-key-built-with-trussed%C2%AE), the latter is now sold out).

However, by fall 2023, the “normal” non-glitter SoloKey devices also publicly became widely available through the official site IIRC ([USB-A](https://solokeys.com/collections/all/products/solo-2a-nfc-security-key) and [USB-C](https://solokeys.com/collections/all/products/solo-2a-nfc-security-key-built-with-trussed%C2%AE)).

---

## Post 7 by @jonah — 2024-05-30T02:19:39Z

These do seem to be widely available again, but they’re kind of ridiculously expensive IMO…

> **[Solo 2C+ NFC Security Key (Built with Trussed®)](https://solokeys.com/products/solo-2a-nfc-security-key-built-with-trussed%C2%AE?variant=42482273910977)**
>
>   Solo 2C+ :  NFC Security Key, Two-Factor Authentication, U2F and FIDO2 - USB-C, Built with Trussed® Secure your logins with two-factor authentication and stay protected against phishing and other online attacks. Works with Google,...

We’d have to remove our price criteria to include these, **but** I think they are our only open-source option if we merge [PR 2592](https://github.com/privacyguides/privacyguides.org/pull/2592). Worth another look for sure.

---

## Post 8 by @anon48875053 — 2024-05-30T08:05:51Z

> [@Remove Nitrokey](https://discuss.privacyguides.net/t/remove-nitrokey/18567/17):
>
> I think we should just recommend SoloKey as an open-source FIDO2 key.

Open-source doesn’t matter that much in here because good keys need to have a secure element, which will always be proprietary.

What matters is for the firmware to be upgradable, YubiKey’s non-upgradable firmware is an absolute joke.

1. Make sure that you receive the key with the latest firmware. I checked YubiKeys that are selling in my country and couldn’t find a clue on what version of firmware they have.

2. Pray that a new security vulnerability isn’t discovered in your YubiKey, if it’s, then pray that YubiKey will replace them for free. After that, go through all of your accounts and register the new keys.

3. If new features that you really need or want come out in a newer firmware, then be ready to pay up again.

---

## Post 9 by @ph00lt0 — 2024-05-30T08:23:54Z

I don’t agree this is an “absolute joke”. Adding options to update the firmware adds an attack factor that needs defence. The entire idea of the key is that it remains untouched and cannot be altered. It also is far cheaper to replace keys than the risk and security needed to fix firmware issues at least on larger scale. Most users will not be capable of doing an upgrade anyway.

When freitan’ key were pwned ([A Side Journey to Titan - NinjaLab](https://ninjalab.io/a-side-journey-to-titan/)) I also had to replace the hardware in the past. There is no reason they should allow you to do replace it for free, unless it was recently sold I guess. You buy tech to the latest standards, with the best effort. Not a lifetime guarantee.

---

## Post 10 by @pinkandwhite — 2024-05-30T08:26:04Z

> [@ph00lt0](#):
>
> Adding options to update the firmware adds an attack factor that needs defence

Yep, that is the exact reason I got told by Yubico themselves.

---

## Post 11 by @jonah — 2024-05-30T08:37:52Z

As @jans23 pointed out elsewhere, their latest keys aren’t FIDO Certified either. I hadn’t had a chance to look yet, but that’s a shame :frowning:

I’ll mark as #waiting again to see if that ever changes.

---

## Post 12 by @pika — 2024-05-30T08:56:20Z

> [@ph00lt0](#):
>
> Adding options to update the firmware adds an attack factor that needs defence.

It does add a security risk but its also a matter of your threat model and convenience. If keys are for your grandma sure you don’t want her to bother about upgrades.

But for example you are in a corporate setup and you want your keys to be supported for considerable time like 3-5 yrs atleast without needing to replace them due to a security vulnerability found , then they would prefer an upgradable key.  
I am not sure if its very “cheap” to replace keys you bought a year ago.  
A modern smart phone (on which most store sensitive data) has support for 2-3 yrs of security patches and it uses a secure boot process for ensuring signed firmware is loaded , the same way a security key also has a secure boot process which is used to verify signed firmware.  
Supply chain attacks can happen in both situations but you have to asses your threat model and make a decision.  
i feel mobile OS security has gotten much bigger and mainstream to deal with real life scenarios/threats

---

## Post 13 by @anon48875053 — 2024-05-30T08:57:12Z

Ledger, Trezor, and probably other crypto wallets have upgradable firmware. It requires multi-signature keys, which are stored in different locations and could be stored in HSMs. These devices store loads of cryptocurrency and are the best target for criminals.

Yubico’s excuse for not using the same strategy as Ledger and Trezor is:

> We have government and defense organizations using our keys which makes for a much more complex threat model.

Then why not make a separate kind of YubiKey for governments and defense organizations? Or keep everything the same and let people choose between YubiKeys with upgradable and non upgradable firmware.

Governments and defense agencies can afford to replace their keys when they need or want to, let’s assume that the average consumer can too :money_mouth_face:

---

## Post 14 by @anon48875053 — 2024-05-30T09:02:33Z

> [@pika](#):
>
> It does add a security risk but its also a matter of your threat model and convenience. If keys are for your grandma sure you don’t want her to bother about upgrades.

Would you rather upgrade the firmware for your grandma’s key or buy them a new one and then register it for all of his accounts? I would rather do the first one.

> [@pika](#):
>
> A modern smart phone (on which most store sensitive data) has support for 2-3 yrs of security patches and it uses a secure boot process for ensuring signed firmware is loaded , the same way a security key also has a secure boot process which is used to verify signed firmware.  
> Supply chain attacks can happen in both situations but you have to asses your threat model and make a decision.  
> i feel mobile OS security has gotten much bigger and mainstream to deal with real life scenarios/threats

If we are talking about phones, then let’s not forget that the firmware of the Titan M2 is upgradeable.

---

## Post 15 by @jonah — 2024-05-30T09:38:38Z

> [@anon48875053](#):
>
> Ledger, Trezor, and probably other crypto wallets have upgradable firmware.

You’re using two famously insecure devices as an example here.

> [@ph00lt0](#):
>
> When freitan’ key were pwned ([A Side Journey to Titan - NinjaLab](https://ninjalab.io/a-side-journey-to-titan/)) I also had to replace the hardware in the past. There is no reason they should allow you to do replace it for free,

I got free replacements for my Google Titan security keys directly from Feitian actually, to give them some credit.

> [@anon48875053](#):
>
> let’s not forget that the firmware of the Titan M2 is upgradeable.

It’s like @ph00lt0 said, it adds attack surface that needs defense. For a mobile chip that can be easily updated through a standard upgrade process that already exists (in Android), the trade-off of having to create and maintain that secure update mechanism makes sense. For a product that is already feature-complete like a Yubikey 5, probably less so.

* * *

Note that despite Solokey and Nitrokey having upgradable firmware, new features are still added to new products. They didn’t (and probably couldn’t) add Nitrokey 3 features to the Nitrokey 2.

I think both options are valid, but the tamper-proof nature of Yubikeys is a feature, not a bug.

---

## Post 16 by @ph00lt0 — 2024-05-30T09:53:06Z

> [@jonah](#):
>
> I got free replacements for my Google Titan security keys directly from Feitian actually, to give them some credit.

Actually now you mentioned I believe I have received the offer too, but switched to YubiKeys.

---

## Post 17 by @ph00lt0 — 2024-05-30T09:55:34Z

> [@pika](#):
>
> But for example you are in a corporate setup and you want your keys to be supported for considerable time like 3-5 yrs atleast without needing to replace them due to a security vulnerability found , then they would prefer an upgradable key.

it’s a minor expense for a corporate to replace them and still a great offering against phishing success.

---

## Post 18 by @pika — 2024-05-30T10:42:46Z

> [@ph00lt0](#):
>
> it’s a minor expense for a corporate to replace them and still a great offering against phishing success

Sure for your organisation it would be minor expense depending upon what organisation you work in and how many employees are mandated to use a security key.  
In my scenario it could be faster and easier to ask employees to upgrade the exisiting ones than first removing all the old ones and disrupting the workflow for days and weeks .  
Also the security key could be treated as more of ease of use utility product (by not memorising weak passwords) and not necessarily need a government level security.

---

## Post 19 by @ph00lt0 — 2024-05-30T14:05:04Z

You might forget about the cost increase of the keys when needed support for that. They will need significant defences. Also, you need to provision tooling for the upgrades, let alone that that tooling also needs to be build and maintained. Shipping and a few pieces of hardware do not cost more than that. There is an argument to be made for sustainability perhaps, not for cost nor security.

---

## Post 21 by @lriesebos — 2024-09-23T21:43:21Z

Hi, just wondering, the SoloKeys website [https://solokeys.com/](https://solokeys.com/) states that their Solo 2 key is FIDO certified (L1). Does that make a change in this discussion?

---

## Post 22 by @TrashPanda — 2025-03-10T16:19:13Z

I’d like to follow up on this one - what do you think about SoloKeys, considering they are now FIDO certified?

---

## Post 23 by @anon55464882 — 2025-03-10T17:08:21Z

> [@jonah](#):
>
> SoloKey 2 isn’t generally available yet, and SoloKey 1 is USB-A only, and doesn’t have the best build quality IMHO.

Does anyone have recent, firsthand experience with the Solo 2’s build quality?

I believe it would be beneficial to have an alternative recommendation in addition to YubiKey and Nitrokey. However, one significant drawback of the Solo 1 was its poor build quality and limited availability. It would be interesting to know if this has improved with the introduction of the Solo 2.

That being said, if I understand correctly, the Solo 2 should meet all the other minimum criteria after being FIDO certified.
