Comments (8)
Smart cards in general aren't very open and wouldn't be eligible for RYF. But Nitrokey Start doesn't contain a smart card and therefore meets RYF criteria. In fact we applied Nitrokey Start for RYF but got rejected. FSF's justification was that only one certified product in the portfolio could confuse people. For me, it's a ridiculous reasoning.
from nitrokey-pro-firmware.
No, but we have OSHW certificate.
from nitrokey-pro-firmware.
@jans23 Not to be rude, but you should really consider applying. The FSF has approved very few products and many people (including myself) would like to see more. You appear to meet all the requirements.
If you choose to, you may contact them here: [email protected]
from nitrokey-pro-firmware.
@jans23 Thank you for the explanation. However, you stated that the FSF didn't want to only certify one product. Why is this, are not all Nitrokeys Free Software?
from nitrokey-pro-firmware.
@asddsaz perhaps because of this paragraph:
To prevent confusion among customers about exactly what product has been certified, any other products offered by the seller, which are not certified by the FSF, must be easily distinguishable from certified products: their names must not be similar and their packaging must also not be similar.
https://www.fsf.org/resources/hw/endorsement/criteria
Regarding "are not all Nitrokeys Free Software?"
Smart cards in general aren't very open and wouldn't be eligible for RYF. But Nitrokey Start doesn't contain a smart card and therefore meets RYF criteria.
from nitrokey-pro-firmware.
According to FSF, our products containing a smart card aren't eligible, even though their firmware is free software.
from nitrokey-pro-firmware.
According to FSF, our products containing a smart card aren't eligible, even though their firmware is free software.
Is there a reason the smart cards would not be RYF compliant?
User installation of modified software
The seller must give the user, along with the product software source code, the practical capability to install replacement software for any and all of the free software in the device. This means the product must have the requisite facilities to install software in the processors that run free software, and include adequate and sufficient documentation on how to use them. If software is required for this installation, it is considered part of the product software.
@jans23 Is it not possible to update the source code on the smart cards? What segment of the FSF's RYF criteria is NitroKey not compliant with?
-Thanks
from nitrokey-pro-firmware.
It's not possible to update OpenPGP Card's firmware and it's source code is not entirely published yet because APIs are under NDA.
from nitrokey-pro-firmware.
Related Issues (20)
- Nitrokey HSM: handle v4.0 smart cards
- Question: Support EC operations HOT 1
- Request: support longer OTP secrets, up to 64 bytes
- Nitrokey HSM: timeout on initialization after heavy use
- Nitrokey HSM: invalid serial number after a heavy load
- Allow to set a custom USB serial number
- WRONG_PASSWORD after accessing Nitrokey with scdrand HOT 10
- Adjust firmware for the new MCU
- Customise firmware HOT 3
- Adding Curve25519 support (on my own) HOT 2
- Consider using stack canaries via -fstack-protector* flags HOT 2
- Instructions with modern OpenOCD? HOT 6
- HW4: swapped red and green LEDs
- Lock device before Factory Reset execution
- Add HMAC for AES key
- OTP functionality HOT 7
- Document minimum compiler version
- Nitrokey Pro firmware upgrade from 0.9 -> 0.14 impossible from nitropy? HOT 6
- R3 Nitrokey Pro failure to enable update mode HOT 6
- PGP key used to sign binary firmware is not available HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from nitrokey-pro-firmware.