1 |
Hi! |
2 |
|
3 |
On Sun, 19 Aug 2018 14:42:23 -0400 Aaron Bauman wrote: |
4 |
> Gentoo-bug: https://bugs.gentoo.org/659620 |
5 |
> |
6 |
> All, this email will serve as a comparison between the two vendors which |
7 |
> have provided quotes to the Foundation. This does not include Alice's |
8 |
> proposal as U2FZero is currently out of stock in the United States and |
9 |
> does not seem to offer any availability in Asia. Alice did suggest that |
10 |
> we split vendors across geographical markets, but I find this will make |
11 |
> the situation become very difficult to handle. It would also put the |
12 |
> burden on individuals to receive and disperse the tokens and increase |
13 |
> shipping costs, burden the treasurer for reimbursements to be processed, |
14 |
> and possibly cause delays. |
15 |
> |
16 |
> Yubikey: |
17 |
> |
18 |
> Quote received for (150) Yubikey FIPS tokens. |
19 |
> |
20 |
> Unit Price: $44.16 USD |
21 |
> Total: $6,624 USD |
22 |
> Discount: 4% (already available to anyone ordering in bulk) |
23 |
> |
24 |
> Shipping costs can be found at [1] and the lowest cost projections |
25 |
> given. They do not offer any standard costs for shipping and cannot |
26 |
> discount it. |
27 |
> |
28 |
> Open source: Several products are no longer open sourced and tracking |
29 |
> which is/is not can be difficult [4]. |
30 |
> |
31 |
> Nitrokey: |
32 |
> |
33 |
> Quote received based on (150) Nitrokey Pro tokens. |
34 |
> |
35 |
> Unit Price: 27,59 € ($31.58 USD at the time of this email) |
36 |
> Total: 4,138.50 € ($4737.06 USD at the time of this email) |
37 |
> Discount: 33% (With sponsorship agreement on gentoo.org) |
38 |
> |
39 |
> All prices are already inclusive of VAT. |
40 |
> |
41 |
> Shipping times can be found here [2]. Shipping costs can be found here |
42 |
> [3]. The most expensive shipping is worldwide starting at 7,40 € |
43 |
> ($8.47 USD at the the time of this email). |
44 |
> |
45 |
> Nitrokey has also offered several unique options for Gentoo. They will |
46 |
> provide a custom portal which allows each developer to request their |
47 |
> security token. This is done via a Foundation (infra really) provided |
48 |
> list of valid gentoo.org email addresses. Additionally, they will |
49 |
> provide monthly billing of all purchased devices and the Foundation is |
50 |
> not obligated to purchase all (150) tokens. This can be a standing |
51 |
> agreement until the Foundation decides to remove financial support. |
52 |
> |
53 |
> Considering both vendors, we can estimate shipping at the highest cost |
54 |
> in order to best prepare for potential expenses. |
55 |
> |
56 |
> Open source: All products are considered open [4]. |
57 |
|
58 |
1. Are they open hardware? At the very least chip and board |
59 |
schematics should be available. At best they should be reproducible |
60 |
by third parties. |
61 |
|
62 |
2. How token integrity is protected during shipment? |
63 |
|
64 |
Otherwise all this security enhancement will be marginal at best if |
65 |
not fake, since if device is tampered with physically or on design |
66 |
level, it provides no additional security, only a dangerous false |
67 |
sense of such security enhancement. |
68 |
|
69 |
Best regards, |
70 |
Andrew Savchenko |