David wrote:
You will need a YubiKey NEO with firmware version 3.3 or above to support U2F - that firmware was released at the end of September 2014. Older YubiKey NEOs which do not support U2F will be indicated by the NEO Manager tool, and cannot be upgraded to the newer firmware. The firmware of all YubiKeys is locked down to prevent attacks against the YubiKey directly, like the BadUSB attack.
@David, I understand the firmware is locked down to prevent attacks but YubiCo needs to find a better/safer way to get latest firmware (i.e. sending it to you for update) or at least provide other alternatives like discount on new one. You can't expect everyone to throw away the key and buy a new one every time an update to firmware is released, do you?. It is not like it is cheap you can throw it away, I paid $50+10 for my neo (firmware 3.1.2) and I am sure everyone like me who has neo with firmware < 3.3 is pretty mad because we can't use it as a Google Security Key
. Please provide us a better alternative instead of simply saying buy a new one --- not a good business model for a hardware vendor!