- Notifications
You must be signed in to change notification settings - Fork201
U2F USB token optimized for physical security, affordability, and style
License
conorpp/u2f-zero
Folders and files
| Name | Name | Last commit message | Last commit date | |
|---|---|---|---|---|
Repository files navigation
This project is superseded by theopen source FIDO2 token, Solo. It is stillin development, but offers:
- FIDO2 + U2F + more secure
- Easier to build & customize
U2F Zero is no longer maintained.
U2F Zero is an open source U2F token for 2 factor authentication. It is implemented securely. It works with Google accounts, Github, Duo, and anything else supporting U2F. The latest version uses key derivation and has no limit on registrations.
You can easilybuild your own. You just need to order the8 SMT parts,$1.13-$3.5 per PCB, andprogrammer.It ends up being $35 for programmer and ~$5/board. The token should be durable enough to survive on a key chain for years, even after going through the wash.
Check outthe wiki for more on how tobuild your own.
FIDO 2 protocol is replacing U2F. It has more flexibility and support for password-less login. A new open source FIDO 2 token is being planned (with support for USB, Bluetooth, and NFC). Discussion for hardware design and usageis happening here, feel free to chip in.
The security level is about the same as a modern car key. Any secret information cannot be read or duplicated. A true random number generator is used to create unpredictable keys.
However, side channel leakage is an unsolved problem in industry and academia. So for well equipped adversaries that can make targetted attacks and get physical access, secret information leakage is possible. Any other hardware token that claims it's "impenetrable" or otherwise totally secure isstill vulnerable to physical side channels and it's important to acknowledge. However, most people don't worry about targeted attacks from well equipped adversaries.
For more information about U2F Zero's secure implementation and the problem of side channels, check outthe wiki.
Support this project by purchasing or sharingU2F Zero on Amazon.
Everything is open source and licensed under theSimplified BSD License.
About
U2F USB token optimized for physical security, affordability, and style
Topics
Resources
License
Uh oh!
There was an error while loading.Please reload this page.
Stars
Watchers
Forks
Packages0
Uh oh!
There was an error while loading.Please reload this page.
Contributors11
Uh oh!
There was an error while loading.Please reload this page.
