Nitrokey 3C NFC support - would be a compelling european sovereignity story

I would love to be able to use my Nitrokey security token with the JP26, now that we have NFC. @Jolla did you consider teaming up with Nitrokey already? It seems like an obvious match.

  • Both are European privacy first companies
  • Both serve users who actively reject Big Tech
  • Both are invested in open source software (Nitrokey even open source their hardware)
3 Likes

What is it and why should we care?
Yes that can be googled, but it is common courtesy to have in a post.

Does it not run on a standard protocol - and is standard protocol support not more important than some specific vendor?

3 Likes

Nitrokeys are Security Tokens like the well-known Yubikeys. Just from Germany instead of from US. I have one Nitrokey and a Token2 with NFC.

Edit: There’s a nice native app for Yubikeys, but unfortunately this does not work with Token2 (my Nitrokey does not NFC, so I could not test).

1 Like

You’re right, i should have explained. @madomac is spot on.

Does it not run on a standard protocol - and is standard protocol support not more important than some specific vendor?

The base protocols and algorithms (Passkey, WebAuthn, FIDO2, OTP, OpenPGP, etc), yes, but I’m not sure about the complete implementation and integration. (Device or vendor implementation quirks?)

Its all a matter of someone writing an app the same way someone wrote an app for yubikeys. Right?

I read someone used a USB YubiKey with the built-in browser at some point. I think also i read/saw something about that being an active objective to resurrect/maintain. For me it lights up my YubiKey, but does not sign in.

It depends on what capacity you are after. For management - yes, probably.
The parts that could sensibly be os-integrated should be the parts that works across all vendors.

1 Like

It would be amazing if I could use my Yubikey with websites, as SfOS is the blocker to me removing other less secure methods of authentication from some key accounts (like Proton).

I had no idea you could abbreviate Uppsala, Sweden as US. The more you know.

1 Like

:face_with_monocle: I didn’t check but was absolutely sure Yubico was US American. It may be because Nitrokey upped my expectations from security products. It requires immense confidence in the implementation to completely open source it and this model creates the most trust with me - in fact security by obscurity creates distrust and that may be why I lumped Yubico in with US Corporations.

It’s not unfair to. They are incorporated in both Sweden and the US, but they did start and are still headquartered in Sweden (Stockholm, I was just trying to be funny). It’s good that there’s competition and I’m glad you brought it up here or I might not have heard about Nitrokey :slight_smile:

3 Likes

Sorry, I somehow had a move of Yubikey from Europe to US of A in the back of my head. Should have checked the facts first. So we have a couple of European solutions at hand:

  • Yubico - Sweden
  • Nitrokey - Germany
  • Token2 - Switzerland

I liked the Token2 quite a lot, until I found a bug when switching from WebAuthn / Passkey and GPG (I use my security keys for ssh a lot). Unfortunately the bug will only be resolved with a new version of the Token2 key - need to re-purchase to “update”. That’s a clear advantage of the Nitrokey. On the other hand, Fedora messes up key usage anyhow after sleeping… :confused:

Edit: Just to add, Yubico are the most expensive keys, but probably also the most robust ones. And the best-known keys. Nitrokeys can be updated, but, well, look&feel is a mile of from Yubikeys. Token2 are well-made and the cheapest of the 3.