Release

New Firmware Release

On January 15 we received a potential vulnerability report about the TKey firmware through our bug bounty program. The reporter had discovered that code that should erase memory where sensitive data is stored, is optimised away by the compiler. We deem the firmware problem a fairly benign bug because no sensitive data is leaked and the memory is erased and hardware protected anyway.

Continue reading

TKey Signature tool released

Today we are publishing another officially supported application, TKey Signature tool (tkey-sign). TKey Signature tool is a command line tool (tkey-sign) for signing and verifying files using a cryptographic signature done on the Tillitis TKey. It uses the TKey device signer (the same device app tkey-ssh-agent uses) for the cryptographic signatures.

Continue reading

How the TKey Random Number Generator App works

Introduction The TKey Secure Random Number Generator app allows a user and a client system to get high-quality random numbers from a source separate from the client. A unique feature of the app is that it can also sign the random data delivered, thus allowing the user to verify the integrity of the generator, the integrity of the data, and the origin of the data delivered. But a secure random number generator must also deliver high-quality random numbers. In this blog post, we will look at how the generator works and the measured quality. In a coming blog post will discuss the signing and verifying in more detail.

Continue reading

Update

Update Update April 3, 2023: All is finalised and web shop is open! An update on our release and what’s remaining. Plan was to release and open our web shop by the end of last week. During final work, we found that USB communication with the TKey didn’t work on MacBook in all use cases. This is now corrected and we are currently double checking everything on the firmware.

Continue reading