Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 6:21 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Mon Jan 06, 2014 5:24 pm 
Offline

Joined: Mon Nov 11, 2013 12:21 am
Posts: 2
I'm somewhat confused over the YubiKey NEO and am looking for some clarifications.

Several articles such as this one refer to the YubiKey NEO as a new device coming this year but I thought the YubiKey NEO already exists.

Is the YubiKey NEO with U2F different than the existing YubiKey NEO devices available today? If so, how are they different?

Thanks.


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Wed Jan 08, 2014 10:59 am 
Offline
Site Admin
Site Admin

Joined: Wed Nov 14, 2012 2:59 pm
Posts: 666
Hello,

The Yubikey NEO is already available for sale on https://store.yubico.com

The U2F protocol will be supported by the NEO only when it will be finalized. The U2F is currently developed under the FIDO alliance working group.

We do not have an ETA for when this is going to happen.

_________________
-Tom


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 08, 2014 4:20 pm 
Offline

Joined: Wed Jan 08, 2014 4:03 pm
Posts: 7
Tom wrote:
Hello,

The Yubikey NEO is already available for sale on https://store.yubico.com

The U2F protocol will be supported by the NEO only when it will be finalized. The U2F is currently developed under the FIDO alliance working group.

We do not have an ETA for when this is going to happen.


I think the confusion lies in the multiple press releases regarding the NEO and FIDO compliance. For example:

Quote:
"The YubiKey NEO is a product extension of the YubiKey family, used by millions of users in over 120 countries, and is the first authentication device to be Universal Second Factor (U2F) FIDO Ready™..." "...The YubiKey NEO integrates with FIDO's open standards to provide you full ownership and security of your identity across all online services."

http://www.marketwired.com/press-release/yubico-introduces-industrys-first-fido-ready-universal-2nd-factor-authentication-device-1866207.htm


Wordsmanship indeed.

The press releases (and most of the info on the Yubico site) are misleading for the fact that they do a great job touting the features and functionality of the NEO with U2F, but they go just far enough without actually disclosing that the U2F standard is not yet finalized, and the current hardware/firmware iteration may or may not be compliant.

From a marketing standpoint, I can understand the reasoning here: It's CES, and Yubico wants to create buzz around the NEO and sell the most units. However, I think that if everyone buys a NEO (like I did), only to find that it ends up not being FIDO compatible (hardware/firmware), you're only shooting yourselves in the foot.

Now, if Yubico is confident that the product as sold today will be compliant, I understand the risk.

Just my two cents.


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 08, 2014 5:23 pm 
Offline

Joined: Mon Nov 11, 2013 12:21 am
Posts: 2
I'm looking at the various statements I've read.

From http://www.yubico.com/products/yubikey- ... y-neo-u2f/
Quote:
Yubico expects to have U2F compliant YubiKey NEOs available for the public during 2014.


Then Tom's reply:
Tom wrote:
The U2F protocol will be supported by the NEO only when it will be finalized. The U2F is currently developed under the FIDO alliance working group.

We do not have an ETA for when this is going to happen.


But then when you look at the YubiKey Neo description from the store ( https://store.yubico.com/store/catalog/ ... ucts_id=72 ) it is already advertised as supported.
Quote:
Emits One Time Passwords (OTP) through both NFC (Near Field Communication) and USB interfaces
Mobile authentication through NFC contactless technology (NDEF type 4), works with Android, RIM, Windows Phone, Symbian
Featuring Mifare Classic, for legacy physical access control systems
Common Criteria certified bank grade authentication ICs
CCID compliant USB token, including secure element and JavaCard
Current version limited to an experimental OpenPGP applet
First authentication device to comply with Universal 2nd Factor (U2F) requirements



I do want to get a YubiKey NEO at some point but I don't want to buy it now knowing that a new feature may not be supported by today's purchase. Since the store already lists U2F as a feature, yet news articles are saying Spring 2014 and now Tom saying no ETA, how will I know when the best time is to purchase one of these?


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 08, 2014 5:28 pm 
Offline

Joined: Wed Jan 08, 2014 4:03 pm
Posts: 7
Correct - this is where the confusion stems from.


Top
 Profile  
Reply with quote  
PostPosted: Sun Jan 12, 2014 10:52 pm 
Offline

Joined: Sat Sep 20, 2008 7:09 pm
Posts: 6
What is the liklihood that U2F will be an applet that can be installed on an existing NEO? I'd like to buy a NEO now, but if it won't eventually support U2F I'll wait.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Heise IT-Markt [Crawler] and 13 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group