Gentoo Archives: gentoo-nfp

From: Andrew Savchenko <bircoph@g.o>
To: gentoo-nfp@l.g.o
Subject: Re: [gentoo-nfp] Developer Crypto Hardware (AGM)
Date: Sun, 19 Aug 2018 18:57:40
Message-Id: 20180819215716.94a4fe2cd1859dcb599f4d09@gentoo.org
In Reply to: [gentoo-nfp] Developer Crypto Hardware (AGM) by Aaron Bauman
1 Hi!
2
3 On Sun, 19 Aug 2018 14:42:23 -0400 Aaron Bauman wrote:
4 > Gentoo-bug: https://bugs.gentoo.org/659620
5 >
6 > All, this email will serve as a comparison between the two vendors which
7 > have provided quotes to the Foundation. This does not include Alice's
8 > proposal as U2FZero is currently out of stock in the United States and
9 > does not seem to offer any availability in Asia. Alice did suggest that
10 > we split vendors across geographical markets, but I find this will make
11 > the situation become very difficult to handle. It would also put the
12 > burden on individuals to receive and disperse the tokens and increase
13 > shipping costs, burden the treasurer for reimbursements to be processed,
14 > and possibly cause delays.
15 >
16 > Yubikey:
17 >
18 > Quote received for (150) Yubikey FIPS tokens.
19 >
20 > Unit Price: $44.16 USD
21 > Total: $6,624 USD
22 > Discount: 4% (already available to anyone ordering in bulk)
23 >
24 > Shipping costs can be found at [1] and the lowest cost projections
25 > given. They do not offer any standard costs for shipping and cannot
26 > discount it.
27 >
28 > Open source: Several products are no longer open sourced and tracking
29 > which is/is not can be difficult [4].
30 >
31 > Nitrokey:
32 >
33 > Quote received based on (150) Nitrokey Pro tokens.
34 >
35 > Unit Price: 27,59 € ($31.58 USD at the time of this email)
36 > Total: 4,138.50 € ($4737.06 USD at the time of this email)
37 > Discount: 33% (With sponsorship agreement on gentoo.org)
38 >
39 > All prices are already inclusive of VAT.
40 >
41 > Shipping times can be found here [2]. Shipping costs can be found here
42 > [3]. The most expensive shipping is worldwide starting at 7,40 €
43 > ($8.47 USD at the the time of this email).
44 >
45 > Nitrokey has also offered several unique options for Gentoo. They will
46 > provide a custom portal which allows each developer to request their
47 > security token. This is done via a Foundation (infra really) provided
48 > list of valid gentoo.org email addresses. Additionally, they will
49 > provide monthly billing of all purchased devices and the Foundation is
50 > not obligated to purchase all (150) tokens. This can be a standing
51 > agreement until the Foundation decides to remove financial support.
52 >
53 > Considering both vendors, we can estimate shipping at the highest cost
54 > in order to best prepare for potential expenses.
55 >
56 > Open source: All products are considered open [4].
57
58 1. Are they open hardware? At the very least chip and board
59 schematics should be available. At best they should be reproducible
60 by third parties.
61
62 2. How token integrity is protected during shipment?
63
64 Otherwise all this security enhancement will be marginal at best if
65 not fake, since if device is tampered with physically or on design
66 level, it provides no additional security, only a dangerous false
67 sense of such security enhancement.
68
69 Best regards,
70 Andrew Savchenko

Replies

Subject Author
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) Aaron Bauman <bman@g.o>