Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've been looking into purchasing an OpenPGP card/stick for a while. Haven't yet pulled the plug.

Here are some fully open Yubikey alternatives.

https://www.sigilance.com/

https://www.nitrokey.com/

http://www.seeedstudio.com/wiki/FST-01



I actually ended up building my own OpenPGP stick a while ago using Gnuk: https://www.makomk.com/2016/01/23/openpgp-crypto-token-using... Should probably write it up properly sometime and maybe ask about getting support for my custom hardware merged upstream. (The official hardware's also open, but the case it's designed for was only available from the US and I'm not set up to solder QFN and 0402 parts. Not that fine-pitch TQFP is much fun either...)


This is extremely cool, I think you should submit this as a Show HN.


I have used nitrokeys and FST-01, the FST-01 beats the nitrokey in speed and in freedom, i currently use two of them, one with rsa 4096 and one with 25519 (for decryption you need libgcrypt 1.7). The nitrokey beats the FST-01 in the case, it's by default more weareable without need to make your own one.

It seems there is a big plus when you use a board made by the person who makes gnuk which is the same person who makes the smartcard gnupg code.


Nitrokey Start uses GNUK 1.0 firmware and its hardware is very similar to FST-01. The microprocessor should be identical so that its performance should be identical too. This applies to Nitrokey Start only, the other models differ.


Sigilance requires a card reader FST01 doesn't seem to have a Secure Element, which kind of makes it not a yubikey alternative. I am not sure about the nitro.

For too many applications, yubikey is still king


Sigilance and NitroKey both advertise 2048-bit keys; do you know if they support 4096 bits?


nitrokey supports rsa4096, just be aware that it can take time on processing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: