Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 8:19 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 10 posts ] 
Author Message
PostPosted: Fri Jul 10, 2009 11:34 pm 
Offline
Site Admin
Site Admin

Joined: Wed May 28, 2008 7:04 pm
Posts: 263
Location: Yubico base camp in Sweden - Now in Palo Alto
We've got the question a couple of times - can a Yubikey1 be firmware upgraded to become a Yubikey2 ?

The answer is no, and believe me - there is no business quirk here to force people to buy new hardware.

The Yubikey2 has an entirely new hardware, comprising a different USB chip with a ROM structure. The firmware for Yubikey2 is rewritten from scratch for this completely different USB chip.

But - we have a limited offer where Yubikey1 owners can buy a Yubikey2 at a 40% discount.

With the best regards,

JakobE
Hardware- and firmware guy @ Yubico


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Sun Jul 12, 2009 1:41 am 
Offline

Joined: Fri Jun 20, 2008 2:59 am
Posts: 84
Slightly off topic.. I know the V1 keys could not be firmware upgraded at all. Is this limitation the same for the V2 keys? I.e. if you release a fresher 2.x firmware can keys be updated by any means?


Top
 Profile  
Reply with quote  
PostPosted: Mon Jul 13, 2009 12:21 am 
Offline
Site Admin
Site Admin

Joined: Wed May 28, 2008 7:04 pm
Posts: 263
Location: Yubico base camp in Sweden - Now in Palo Alto
Well, actually the other way around. The Yubikey1 can be upgraded by us using some specialized equipment, although we've never taken back keys and upgraded them. The logistical problem of handling it compared with the low value of a single key makes this somewhat meaningless.

The Yubikey2 on the other hand has a ROM structure so updating the firmware is REALLY impossible, i.e. not just a practical limitation :)

With the best regards,

JakobE
Hardware- and firmware guy @ Yubico


Top
 Profile  
Reply with quote  
PostPosted: Mon Jul 13, 2009 12:32 am 
Offline

Joined: Fri Jun 20, 2008 2:59 am
Posts: 84
Well I guess at least this means there's no worry of getting malicious firmware put on them :lol:


Top
 Profile  
Reply with quote  
PostPosted: Fri Sep 18, 2009 9:04 pm 
Offline

Joined: Fri Sep 18, 2009 9:03 pm
Posts: 1
For those of us that weren't paying attention in June and July, is there still an upgrade discount?


Top
 Profile  
Reply with quote  
PostPosted: Mon Sep 21, 2009 9:12 am 
Offline

Joined: Thu Jul 02, 2009 4:07 pm
Posts: 1
Yeah, I bought several of the 1.0 yubikeys for guys here at my office and they arrived the day the 2.0 was announced. How can we take advantage of this upgrade discount, please?


Top
 Profile  
Reply with quote  
PostPosted: Tue Aug 03, 2010 8:59 am 
Offline

Joined: Wed May 12, 2010 6:21 am
Posts: 8
Location: LITHUANIA
But what about 2.1 -> 2.2? Is it possible to upgrade firmware?


Top
 Profile  
Reply with quote  
PostPosted: Wed Sep 08, 2010 8:13 am 
Offline
Yubico Team
Yubico Team

Joined: Mon Feb 22, 2010 9:49 am
Posts: 183
As mentioned earlier in this forum thread, as the Yubikey2 has a ROM structure so updating the firmware is REALLY impossible, i.e. not just a practical limitation.


Top
 Profile  
Reply with quote  
PostPosted: Thu Sep 16, 2010 6:20 pm 
Offline

Joined: Sun Aug 01, 2010 3:08 am
Posts: 6
I"m sure they did this intentionally trying to force people to buy a new key. Which won't happen with me. (yes I know you already stated you didn't do it for this reason).


Top
 Profile  
Reply with quote  
PostPosted: Fri Oct 01, 2010 3:32 am 
Offline
User avatar

Joined: Tue Jan 13, 2009 6:33 am
Posts: 20
Well TC93 don't get me wrong but since I first emailed Yubico around Nov 2008 I've been a cynical pain to the staff at Yubico.
And they've been pretty good at considering all points of security and conferring back & forth.

But as for intentional (to generate sales) or not, I prefer ROM over firmware upgrade-ability, because a ROM firmware avoids potential vulnerabilities.
(Vulnerabilities like some kind of an autorun worm/trojan. Such as many sysadmins saw appearing on USB-drives last year...)

In this modern era, ROM chips are still cheaper to produce/buy then a programmable chip that can be used for firmware that is flashed/upgraded.
(Flashed ha! How many of you recall flashing UV across an eeprom window to ready it for reprogramming?)
Now, as I recall the V1 were around $40 each a few years back, I'm sure the ROM chip and higher production quantities have both helped reduce the price to $25 each.

Anyways, I only use my version 1.3.1 Yubikey for logging into these forums and the wiki nowadays.

My Rant:
I'm keeping in mind, that I know someone who purchased a "maxed out" IBM PS/1 PC that he picked up from the store one morning.
He saw on the evening news that the new PS/2 was on sale that afternoon at the very same store, and he wasn't offered anything regarding this "oversight", no discount, no trade option, no apology, no nothing...

So I feel that Yubikey has been fair in offering some discount to V1 key owners.
Besides, how many successful businesses give everything away for free? Even the "NFP" charities must have someone giving them money...


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 10 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group