This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| SoloKeys | |
|---|---|
| Name | SoloKeys |
| Type | Security key |
| Manufacturer | SoloKeys (company) |
| Introduced | 2018 |
| Connectivity | USB-A, USB-C, NFC (varies) |
| Standards | FIDO2, U2F, WebAuthn |
SoloKeys
SoloKeys are open-source hardware authentication tokens implementing FIDO2 and U2F standards for passwordless login and two-factor authentication. They aim to provide interoperable, affordable security keys compatible with major platforms and services, integrating with browsers, enterprise identity systems, and cryptographic libraries. SoloKeys devices are designed to work with platforms such as Google, Microsoft, Apple Inc., Mozilla, and services including GitHub, GitLab, Dropbox, and AWS.
SoloKeys function as USB and NFC authentication devices that enable strong, phishing-resistant authentication through public-key cryptography. They interoperate with standards defined by the FIDO Alliance, W3C, and implementions in OpenSSH, GnuPG, and OpenSSL-based systems. Major browsers like Google Chrome, Mozilla Firefox, Microsoft Edge, and Apple Safari include built-in support for WebAuthn, facilitating integration with SoloKeys. Enterprises using Okta, Ping Identity, OneLogin, Azure Active Directory, or Google Workspace can adopt SoloKeys for hardware-backed multi-factor authentication.
Development began in the wake of standards work by the FIDO Alliance and the World Wide Web Consortium to replace passwords with public-key methods. SoloKeys creators drew on contributions from open-source projects such as TrueCrypt-era communities and OpenPGP implementations, collaborating with hardware makers like STMicroelectronics and firmware teams influenced by Yubico's early U2F products. Early prototypes were discussed at conferences including USENIX, DEF CON, Black Hat, and RSA Conference where researchers from Google Project Zero, EFF, and university labs presented on authentication weaknesses. Community testing occurred on platforms like GitHub and Hackaday, with manufacturing partners in Shenzhen and supply chain audits referencing firms such as Flextronics and Jabil.
SoloKeys hardware typically uses microcontrollers from vendors like STMicroelectronics, NXP Semiconductors, or Microchip Technology with USB controllers compliant with USB Implementers Forum specifications. The physical form factors include USB-A and USB-C connectors and occasionally NFC chips compliant with ISO/IEC 14443 for mobile use with devices from Samsung, Google Pixel, and Apple iPhone. The devices include tamper-evident enclosures manufactured in facilities similar to those used by Yubico, with firmware flashing and testing performed using tools from Segger and JTAG vendors. Cryptographic operations rely on hardware-accelerated primitives compatible with TPM concepts and algorithms standardized by NIST and implemented in libraries like libsodium and BoringSSL.
SoloKeys firmware is open-source and developed using toolchains such as GCC, Clang, and build systems like CMake and Makefile workflows hosted on GitHub and reviewed on platforms like GitLab and Gerrit. Security features include resident keys, PIN protection, attestation, and unique key generation per origin following FIDO2 and WebAuthn protocols. Threat modeling references findings by OWASP and security advisories from research groups at CISCO Talos, Kaspersky Lab, and academic teams at MIT and Stanford University. Audits have been commissioned from firms including Cure53, Trail of Bits, and NCC Group to validate implementation against standards from ISO and recommendations by NIST's Cryptographic Module Validation Program.
SoloKeys implement FIDO2 and U2F protocols enabling compatibility with identity providers like Okta and cloud platforms such as AWS Identity and Access Management, Google Cloud Platform, and Microsoft Azure. Integration extends to developer tooling like OpenSSH, ssh-agent, and CI/CD services including Travis CI and CircleCI where hardware-backed keys are used for deployment authentication. Mobile compatibility leverages Android's keystore and iOS integration through supported browsers and services. Standards bodies including the FIDO Alliance, W3C, and IETF provide the protocol specifications SoloKeys adheres to.
SoloKeys gained attention from privacy and security communities including the Electronic Frontier Foundation and adoption by open-source projects hosted on GitHub and integrations with platforms such as Red Hat and Canonical. Security reviewers from outlets like Ars Technica, The Register, and Wired have compared SoloKeys to competitors including Yubico and Google Titan Security Key, discussing trade-offs in cost, openness, and attestation practices. Universities and research institutions, such as University of California, Berkeley, Carnegie Mellon University, and Harvard University, have piloted hardware-backed authentication programs referencing SoloKeys alternatives. Large technology firms including Facebook, Twitter, and LinkedIn recommend FIDO hardware keys for privileged account protection and policy enforcement.
Product variants include USB-A and USB-C form factors and versions with or without NFC to match devices from Apple Inc., Samsung, and Google. Models are marketed for consumer and enterprise use, supporting administrative features for deployment in environments using Microsoft Intune, Jamf, and Google Admin Console. Hardware revisions reflect component sourcing improvements similar to those seen in products from Yubico and firmware updates aligned with specifications from the FIDO Alliance and the W3C.
Category:Computer security