Gentoo Archives: gentoo-nfp

From: Aaron Bauman <bman@g.o>
To: gentoo-nfp@l.g.o
Subject: [gentoo-nfp] Developer Crypto Hardware (AGM)
Date: Sun, 19 Aug 2018 18:42:29
Message-Id: 20180819184223.GA23587@monkey
1 Gentoo-bug: https://bugs.gentoo.org/659620
2
3 All, this email will serve as a comparison between the two vendors which
4 have provided quotes to the Foundation. This does not include Alice's
5 proposal as U2FZero is currently out of stock in the United States and
6 does not seem to offer any availability in Asia. Alice did suggest that
7 we split vendors across geographical markets, but I find this will make
8 the situation become very difficult to handle. It would also put the
9 burden on individuals to receive and disperse the tokens and increase
10 shipping costs, burden the treasurer for reimbursements to be processed,
11 and possibly cause delays.
12
13 Yubikey:
14
15 Quote received for (150) Yubikey FIPS tokens.
16
17 Unit Price: $44.16 USD
18 Total: $6,624 USD
19 Discount: 4% (already available to anyone ordering in bulk)
20
21 Shipping costs can be found at [1] and the lowest cost projections
22 given. They do not offer any standard costs for shipping and cannot
23 discount it.
24
25 Open source: Several products are no longer open sourced and tracking
26 which is/is not can be difficult [4].
27
28 Nitrokey:
29
30 Quote received based on (150) Nitrokey Pro tokens.
31
32 Unit Price: 27,59 € ($31.58 USD at the time of this email)
33 Total: 4,138.50 € ($4737.06 USD at the time of this email)
34 Discount: 33% (With sponsorship agreement on gentoo.org)
35
36 All prices are already inclusive of VAT.
37
38 Shipping times can be found here [2]. Shipping costs can be found here
39 [3]. The most expensive shipping is worldwide starting at 7,40 €
40 ($8.47 USD at the the time of this email).
41
42 Nitrokey has also offered several unique options for Gentoo. They will
43 provide a custom portal which allows each developer to request their
44 security token. This is done via a Foundation (infra really) provided
45 list of valid gentoo.org email addresses. Additionally, they will
46 provide monthly billing of all purchased devices and the Foundation is
47 not obligated to purchase all (150) tokens. This can be a standing
48 agreement until the Foundation decides to remove financial support.
49
50 Considering both vendors, we can estimate shipping at the highest cost
51 in order to best prepare for potential expenses.
52
53 Open source: All products are considered open [4].
54
55 -----
56
57 Motion: I move that the board vote to accept the offer from Yubico or
58 Nitrokey and begin our agreement with the accepted vendor beginning 1
59 September 2018. This motion will provide security tokens to all current
60 developers listed in Gentoo's LDAP infrastructure as of 31 August 2018.
61
62 Motion: I move that the board vote to maintain the aforementioned
63 agreement in order to support future Gentoo developers with security
64 tokens. This motion includes the right to terminate future purchases
65 based on the Foundation's financials.
66
67 [1]: https://www.yubico.com/support/shipping-and-buying-information/
68 [2]: https://www.nitrokey.com/documentation/frequently-asked-questions#how-long-does-the-shipping-take
69 [3]: https://shop.nitrokey.com/shop/product/nitrokey-pro-2-3
70 [4]: https://old.lwn.net/Articles/736231/
71
72 --
73 Cheers,
74 Aaron

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) Andrew Savchenko <bircoph@g.o>
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) "Michał Górny" <mgorny@g.o>
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) "Robin H. Johnson" <robbat2@g.o>
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) Alec Warner <antarus@g.o>