Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there a clear path to a yubikey device supporting 1000+ resident keys and doing so well in the near future?

What does the cost look like? Are we talking $50 or $500?



$25. The solokey 2 already used a STM chip that could support at least 20X the storage (in USB mode), but didn't activate it in their initial firmware..

Additional flash that is just as secure would be expensive mostly because other Smart Card uses don't need it, but it doesn't really have to be secure because storing resident keys could be done in a similar opaque style as a server and only really brought in to the secure context when needed.

Edit- misremembered NXP->STM and added USB as difficulty getting significant flash within the NFC powered chip is an important consideration.


Presumably Yubico's upgrade path is to tweak the form factor slightly so they can fit more than a few kb of memory into the thing. I know that it's possible, I can buy 50GB flash drives in the micro yubikey form factor, the ones that are just a rectangle of plastic that fits in under a USB-A port's tongue, and they only cost like $10. So it's probably just something that Yubikey needs to design into the next gen of keys, and I suspect it won't make them cost much more than $5 more than the last gen.


They don't need to do that. Look at a teardown, most of a Yubikey is already bare circuit board encased in plastic. The active ICs are tiny.


I'm not sure why current keys cost so much...


My hunch is low volume and an enterprise-leaning customer base. Engineers aren't cheap, and those who can build security-sensitive products even less so.

When I bought a (single) Yubikey from their website late last year, it was Fedexed to me directly from their Palo Alto downtown office, not some distribution center in the middle of nowhere. That can't be cheap.


If you order a key and it comes from an Amazon warehouse, are you going to be worried about a supply chain attack? Maybe that's a benefit of sending by direct FedEx?


When I bought mine they (current owners) were actively advising against buying from Amazon. But who knows. Probably very unlikely




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: