<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=33&amp;t=1537" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-03-19T15:51:33+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=33&amp;t=1537</id>
<entry>
<author><name><![CDATA[henrik]]></name></author>
<updated>2015-03-19T15:51:33+01:00</updated>
<published>2015-03-19T15:51:33+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=7074#p7074</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=7074#p7074"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=7074#p7074"><![CDATA[
<div class="quotetitle">squidbox wrote:</div><div class="quotecontent"><br />I bought my Yubikey Neo (fw 3.2) with the understanding that: <em>&quot;When we do release new firmware, we ensure the new YubiKey will function the same as with older versions, so there is no need to purchase new YubiKeys to ensure compatibility.&quot;</em>, which is a direct quote from this <a href="https://www.yubico.com/faq/upgrade-yubikey-firmware/" class="postlink">Yubico FAQ article</a>.<br /></div><br />What you're quoting is correct: We ensure that new YubiKeys will function the same as older versions. That is, new YubiKeys are backwards compatible. So if you've deployed a solution including YubiKeys with firmware 3.1, you can rest assured that for example firmware 3.3 will also work with your solution.<br /><br />This is a different thing from YubiKeys being upgradable (&quot;forwards compatible&quot;).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2968">henrik</a> — Thu Mar 19, 2015 3:51 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[squidbox]]></name></author>
<updated>2015-03-19T09:11:05+01:00</updated>
<published>2015-03-19T09:11:05+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=7068#p7068</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=7068#p7068"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=7068#p7068"><![CDATA[
<div class="quotetitle">darco wrote:</div><div class="quotecontent"><br />Where did they say they could update older keys?<br /><br />I don't think they have the physical capability to do what you are asking. Being upset about it won't help.<br /><br />You bought keys that did not advertise U2F. You got keys that didn't have U2F. Just because a later product was released with this feature doesn't mean you are entitled to have that feature added to your older device.<br /></div><br /><br />I bought my Yubikey Neo (fw 3.2) with the understanding that: <em>&quot;When we do release new firmware, we ensure the new YubiKey will function the same as with older versions, so there is no need to purchase new YubiKeys to ensure compatibility.&quot;</em>, which is a direct quote from this <a href="https://www.yubico.com/faq/upgrade-yubikey-firmware/" class="postlink">Yubico FAQ article</a>.<br /><br />While my main usage of the Yubikey is as a physical PGP key, I was very interested to try out U2F. Now, I'll most likely look to other U2F solutions instead.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3606">squidbox</a> — Thu Mar 19, 2015 9:11 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2015-01-15T23:42:31+01:00</updated>
<published>2015-01-15T23:42:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6730#p6730</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6730#p6730"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6730#p6730"><![CDATA[
<div class="quotetitle">techstud wrote:</div><div class="quotecontent"><br />What if we mailed in our current/existing Yubikey for a discount? Yubico, the company, can either re-sell them at discounted prices to those that do not want/need updated hardware or destroy them, and we get a discount towards the updated hardware we need? Fair?<br /></div><br /><br />The administrative costs of such a scheme would wipe out the value of any credit, and Yubico would have to pay disposal costs for the mailed in keys. I cannot see any way they could be resold, as each mailed in NEO would have to be wiped of customer data in the apps and tested before resale, which isn't cost-effective.<br /><br />I know a NEO isn't free but, as I said in my earlier reply, these are relatively inexpensive devices with a high level of functionality, even in 3.2.0 guise.<br /><br /><br />If you want to upgrade and offset some of the cost, why not put your existing NEO on eBay?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Thu Jan 15, 2015 11:42 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[techstud]]></name></author>
<updated>2015-01-14T21:54:02+01:00</updated>
<published>2015-01-14T21:54:02+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6718#p6718</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6718#p6718"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6718#p6718"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />Unfortunately there is no method for updating the firmware on pre-3.3 NEOs, and no discounts offered at this time. The cheapest way for an existing NEO owner to add U2F functionality is to purchase a Security Key ($18 with no shipping costs on orders over $35 on Amazon), or $23 with standard US shipping from the Yubico Webstore ($18 + $5 for standard shipping).<br /></div><br /><br />What if we mailed in our current/existing Yubikey for a discount? Yubico, the company, can either re-sell them at discounted prices to those that do not want/need updated hardware or destroy them, and we get a discount towards the updated hardware we need? Fair?<br /><br />~TechStud<br />Ontario, Canada<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=840">techstud</a> — Wed Jan 14, 2015 9:54 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2014-12-19T21:33:28+01:00</updated>
<published>2014-12-19T21:33:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6589#p6589</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6589#p6589"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6589#p6589"><![CDATA[
Public release of an updater creates a denial of service attack vector against deployed NEOs if, as I expect, it wipes the user data on the NEO.<br /><br />U2F requires the device to have an attestation certificate attesting to its provenance. Yubico would dilute the value of their attestations if they distributed an update that attests a device outside their physical control.<br /><br />Public release of an updater might assist with the creation of fake NEOs.<br /><br /><br />It is possible that my three concerns above could be overcome, especially if publicly distributed new firmware will only install on a device that authenticates itself as a NEO with existing firmware. Even so, distributing an updater has costs for Yubico that they cannot recoup, especially in terms of technical support.<br /><br />I know the norm these days is for firmware updates to be distributed freely, but security devices require a different way of thinking. If you buy a device and an advertised feature does not work correctly, you have a case for replacement or refund. However, you do not buy any sort of entitlement to future enhancements.<br /><br /><br />The NEO is an inexpensive device for the functionality it now has.<br /><br />An OpenPGP smartcard 2.0 is EUR16.40 from Kernel Concepts, or EUR17 if you want a card with an ID-000 size breakout (&quot;mini SIM&quot; size). A USB ID-000 reader is EUR18, so that's EUR35 for a USB device that only supports OpenPGP, has no contactless functionality and is less physically robust than a NEO. This device does support 4096 bit RSA keys, unlike the NEO, but 4096 bit RSA keys have relatively little additional entropy over a 2048 bit RSA key.<br /><br />A Gemalto IDPrime PIV card is available in dual interface format from Gemalto's web store for EUR37.34. Unlike the NEO, these cards are approved for US Government and NATO use, but this is of little value to the average NEO purchaser. As a dual interface card, it supports contactless but cannot be cut down from credit card size.<br /><br /><br />On the day I'm writing this, Yubico are selling NEOs for US$50, which is around EUR41 depending on the exact exchange rate you use. Even an older NEO with 3.2 firmware would give you OpenPGP and PIV functionality, as well as the OATH applet and the Yubikey OTP slots with a pre-personalised YubiCloud OTP credential in Slot 1.<br /><br />If you buy now, you get a device with 3.3 firmware which also offers U2F functionality on USB.<br /><br />The NEO is more robust and easier to carry than either of the comparison devices I've given. It needs no expensive proprietary middleware for full functionality (a drawback of the Aladdin eToken devices I used to use) and merely needs a USB port or suitable contactless reader to use.<br /><br /><br />At the moment, U2F is of limited value - it works with Chrome against Google via the USB interface only. The standards for U2F over a contactless interface have yet to be finalised, so it is unclear whether whatever support exists in the 3.3 NEO firmware will comply with the final standard.<br /><br /><br />When browser and site support for U2F has grown, the U2F over contactless standard is ratified and the NEO firmware has had chance to mature further, there is more of an argument for buying a new device.<br /><br />In time, I expect the OpenPGP applet to support elliptic curve keys. Elliptic curve support has finally been released in GnuPG 2.1, though I'm not sure there is a version of the OpenPGP smartcard standard with elliptic curve key support yet. I realise it will be many years before elliptic curve PGP keys are usable outside small closed groups, as users are typically rather slow to update to new security software versions.<br /><br />The NEO might migrate to a newer hardware platform that fully supports 4096 bit RSA keys and SHA512 (the latter is needed for a Bitcoin wallet app).<br /><br />One feature I miss from the eToken is the ability to carry intermediate certificates on the device, which is a feature I didn't find in my reading of the PIV standards, so the public CA issued certificates I have in the PIV applet don't chain to a public root via plug and play.<br /><br /><br />There will undoubtedly be further enhancements from Yubico and I will have to decide when to replace my NEO 3.3 with the latest version and make my current NEO a backup device. However, unless I lose or destroy my NEO, I expect it to provide the feature set it has today for years to come. It isn't perfect, but it is an inexpensive investment in high grade security offering a wide range of functions in a single device.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Fri Dec 19, 2014 9:33 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dreamss]]></name></author>
<updated>2014-12-19T17:07:50+01:00</updated>
<published>2014-12-19T17:07:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6588#p6588</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6588#p6588"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6588#p6588"><![CDATA[
ur right, u dont think... u dont see an issue with having to purvhase a 4th key? also this was from their blog<br /><br />With regards to the YubiKey NEO and DFU…<br />– The YubiKey NEO technically does support DFU, but requires the new firmware image to be signed by us. Yubico does not endorse nor support use of DFU for users<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2122">dreamss</a> — Fri Dec 19, 2014 5:07 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-01T20:32:11+01:00</updated>
<published>2014-12-01T20:32:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6417#p6417</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6417#p6417"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6417#p6417"><![CDATA[
Where did they say they could update older keys?<br /><br />I don't think they have the physical capability to do what you are asking. Being upset about it won't help.<br /><br />You bought keys that did not advertise U2F. You got keys that didn't have U2F. Just because a later product was released with this feature doesn't mean you are entitled to have that feature added to your older device.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Mon Dec 01, 2014 8:32 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dreamss]]></name></author>
<updated>2014-11-29T14:05:39+01:00</updated>
<published>2014-11-29T14:05:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6408#p6408</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6408#p6408"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6408#p6408"><![CDATA[
nice to see you guys wont bother to reply or even try to acomodate customers, glad I invested on several keys from you guys. not seeing why i should bother to waste more money with your company or recomend your products<br /><br />you guys says your able to update our keys, and wont bother to even offer a paid service to do so once we wiped our keys<br /><br /><br />thanks for nothing<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2122">dreamss</a> — Sat Nov 29, 2014 2:05 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-11-10T09:51:47+01:00</updated>
<published>2014-11-10T09:51:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6161#p6161</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6161#p6161"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6161#p6161"><![CDATA[
ruvhell,<br /><br />you have been already contacted by our orders dpt. I strongly recommend you to delete your personal order information as someone may use social engineering to get through.<br /><br />I will edit the post for you, please be more mindful in the future about this.<br /><br />Tom<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Mon Nov 10, 2014 9:51 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ruvhell]]></name></author>
<updated>2014-11-07T09:26:42+01:00</updated>
<published>2014-11-07T09:26:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6146#p6146</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6146#p6146"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6146#p6146"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />Unfortunately there is no method for updating the firmware on pre-3.3 NEOs...<br /></div><br /><br /><br />Hello. Order Number: xxxx Invoice xxxx<br />Wednesday 22 October, 2014 I ordered YubiKey NEO. On Wednesday 5 November I received an order. When I ordered I read on site that it supports U2F.<br />in cach from 20 October 2014 17:27:00 GMT we see<br /><!-- m --><a class="postlink" href="http://webcache.googleusercontent.com/search?q=cache:http://yubico.com/products/yubikey-hardware">http://webcache.googleusercontent.com/s ... y-hardware</a><!-- m --><br />that PREMIUM NEO was support U2F Security Key <br /><br />But now in Neo Manager I can not run (select) it. (I see that firmware is 3.2.0 and U2F not support)<br /><br />Ticket 00008413 unanswered<br /><br />I want that you will have sent me a NEO key that supports U2F.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3264">ruvhell</a> — Fri Nov 07, 2014 9:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dreamss]]></name></author>
<updated>2014-11-05T03:18:13+01:00</updated>
<published>2014-11-05T03:18:13+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6131#p6131</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6131#p6131"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6131#p6131"><![CDATA[
can we pay and send u guys our youbkey to get it updated.. currentlyh own 3 neos<br /><br />AND I DONT WANT TO FREAKING WASTE MONEY BUYING A NEW NEO EVERY YEAR TO GET NEW FEATURE SUPPORT<br /><br />the lack of forsight on this its on you guys... this is freaking lame<br /><br /><br />what im gonna do with this old worthless neos? -_-<br /><br /><br />With regards to the YubiKey NEO and DFU…<br />– The YubiKey NEO technically does support DFU, but requires the new firmware image to be signed by us. Yubico does not endorse nor support use of DFU for users.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2122">dreamss</a> — Wed Nov 05, 2014 3:18 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bmalkow]]></name></author>
<updated>2014-10-30T09:33:03+01:00</updated>
<published>2014-10-30T09:33:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6070#p6070</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6070#p6070"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6070#p6070"><![CDATA[
Maybe this is not right thread for this question, but:<br /><br /><div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />Unfortunately there is no method for updating the firmware on pre-3.3<br /></div><br /><br />Does it means that firmware 3.3 is upgrdable? For example if you find bug in PGPApplet then it can be fixed? Or if FIDO finish specification of U2F NFC, then current applet can be upgraded?<br /><br />You should prepare article about it. We should know if bought device will be the same to end of world, or there is a way for bugfixes or protocol changes. First release of NEO coddled us a bit <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><br /><br />So, please, write official statement about future of latest devices with firmware 3.3.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2338">bmalkow</a> — Thu Oct 30, 2014 9:33 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jborgstrom]]></name></author>
<updated>2014-10-27T15:17:03+01:00</updated>
<published>2014-10-27T15:17:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6030#p6030</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6030#p6030"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=6030#p6030"><![CDATA[
What if I own a NEO developer edition, is there an U2F applet I can download and install?  Or do I have to read the spec and implement it myself? <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3208">jborgstrom</a> — Mon Oct 27, 2014 3:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2014-10-23T00:22:07+01:00</updated>
<published>2014-10-23T00:22:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=5925#p5925</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=5925#p5925"/>
<title type="html"><![CDATA[Re: YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=5925#p5925"><![CDATA[
Unfortunately there is no method for updating the firmware on pre-3.3 NEOs, and no discounts offered at this time. The cheapest way for an existing NEO owner to add U2F functionality is to purchase a Security Key ($18 with no shipping costs on orders over $35 on Amazon), or $23 with standard US shipping from the Yubico Webstore ($18 + $5 for standard shipping).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Thu Oct 23, 2014 12:22 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[svanya]]></name></author>
<updated>2014-10-22T23:24:29+01:00</updated>
<published>2014-10-22T23:24:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1537&amp;p=5922#p5922</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=5922#p5922"/>
<title type="html"><![CDATA[YUBIKEY NEO with firmware 3.2.0]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1537&amp;p=5922#p5922"><![CDATA[
I have YUBIKEY NEO ($50) with firmware 3.2.0.<br />I want to use U2F with Google. So I must buy new one with firmware 3.3.0?<br />Is there any discount for new one?<br /><br />Thanks.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2977">svanya</a> — Wed Oct 22, 2014 11:24 pm</p><hr />
]]></content>
</entry>
</feed>