Token2 is an open-source Swiss FIDO2 security key that brings innovative features at a cheaper price (www.token2.ch)
from GadgeteerZA@beehaw.org to technology@beehaw.org on 26 May 2024 19:32
https://beehaw.org/post/14054023

Token2 is a cybersecurity company specialized in the area of multifactor authentication. Founded by a team of researchers from the University of Geneva with years of experience in the field of strong security and multifactor authentication. Token2 has invented, designed and developed various hardware and software solutions for user-friendly and secure authentication. Token2 is headquartered in Geneva, Switzerland.

Don’t believe what AI tells you, as they tend to generalise around past statements. Token2 is a good example of how newer challengers to the incumbents, like YubiKey, bring lots of innovation. For example, Token2 has the ability to store up to 300 passkeys, dual port USB-A and USB-C on a single device, FIDO2.1 with additional PIN, opens-source, etc.

I also like the fact the device’s firmware and management is in Switzerland and not within one of the Five Eyes countries.

There are quite a few options, but their FIDO2 Keys page also has a selection wizard to help out.

Whilst prices may be cheaper, depending on your country, shipping may cost a bit more.

UPDATE: Token2 sent this clarification after posting: only the management software is open-source for the time being. The firmware (Java applet) is planned to be made available as open source for public security audit purposes, but the timeline is not yet clear.

See www.token2.ch

#technology #security #Token2 #authentication

#technology

threaded - newest

adespoton@lemmy.ca on 26 May 2024 19:57 next collapse

Dual PIN is a great idea; I’d also love an emergency PIN that invalidates the token silently (so you can enter it under duress).

stealth_cookies@lemmy.ca on 26 May 2024 20:37 next collapse

They actually have the dual USB-A and USB-C key product that is inexplicably missing from the main security key vendors! While I’m not going to replace my perfectly good keys, I was so pissed off when I bought mine and the obvious product was missing from Yubico’s offerings.

boatswain@infosec.pub on 26 May 2024 21:17 next collapse

I don’t see a good way to put it on a keychain; the only hole looks tiny, and right on an edge where it’s likely to snap after a year or so of wear.

GadgeteerZA@beehaw.org on 27 May 2024 11:53 collapse

Seems it fits on a lanyard string from what I see of the other photos. A keyring is thicker and would put twisting force on it, yes. So, seems the lanyard type connector may be better for long term use.

Zworf@beehaw.org on 27 May 2024 14:42 next collapse

Too bad they don’t do OpenPGP like Yubikeys do. I still need that even more (much more!) than Fido2. Sites are so slow adopting Fido2.

I don’t use it for email but I use it for SSH and my password manager (“pass”). And yes I know SSH can use Fido2 natively as well but there’s many embedded SSH daemons that don’t support that yet.

Luckily Yubico is still around but I’m betting on them going down the drain (subscription models etc) soon because they were taken over by a venture capital firm :(

GadgeteerZA@beehaw.org on 27 May 2024 20:55 collapse

Good point on OpenPGP. I suppose I already do my mails with OpenPGP in Proton Mail (using my own key that is already uploaded). But something to keep in mind yes.

tuhriel@infosec.pub on 27 May 2024 15:07 collapse

Found them when I was looking for a fido key, and was really happy sonce it allowed me to get a handfull of them (mostly usb mini) Their service is also quite good

Only sad thing is, that the duo (with usb-a and usb-c) is quite big, so i usually just carry the usb-a & nfc with me. Works for everthing except my mbp