Bonum Certa Men Certa

A FIDO/FIDO2 False Sense of Security for Premium Prices

Military-grade nonsense that is proprietary and untrustworthy (monopolised by the likes of Google and Microsoft)

Manifestation against missileSummary: From the attack on software freedom (including Richard Stallman and other leaders/luminaries) we've seen a shift to attacks on privacy itself, e.g. auditable encryption; today we discuss the troubling developments in the FIDO/FIDO2 space

THE ESSENCE of Free/libre software is control, liberty, autonomy, independence, security, decentralisation and sometimes privacy too. Those are all just words that convey concepts in English. It's better understood in the absence of those things (when one lacks or loses freedom). As RMS puts it, to paraphrase a bit, either the user controls the program or the program is an instrument by which some corporation (or government) controls the user. It's really that simple. To alleviate that unjust leverage of power (developers or developers' employer) over computer users we need freedom-respecting software that is audited by many and forked if mischief occurs. This helps ensure that the public interest is prioritised, not the bottom line of some business/es. That does not mean that no business can exist; many businesses are based around distributing and supporting Free software. Perfectly moral and ethical business practices are compatible with the Four Freedoms.



"Earlier this year there was a major incident, which saw millions of rogue certificates being issued by Let’s Encrypt..."With all that in mind, we've grown cynical if not deeply concerned about the Linux Foundation. The institution itself is a misnomer (it promotes operating systems other than Linux), its biggest players (leadership) are monopolistic proprietary software companies, it advocates mass surveillance, and it works for Microsoft (which in turn works to undermine Linux).

Earlier this year there was a major incident, which saw millions of rogue certificates being issued by Let’s Encrypt, which is connected to the Linux Foundation and hosted/coded on Microsoft servers. These certificates were later revoked, but there was no transparency about what had happened. Can we trust one CA to manage so many certificates? Look at its backers and sponsors. These certificates aren't free; if they seem to be free, it's because someone foots the bill to gain something, such as the US government receiving back door access to undermine encryption (by access to private keys or similar). They're already done that even inside Switzerland, covertly of course! So do we trust Let’s Encrypt? Not really, even less so after that incident. There was never clarity and now even an explanation of what was done, who the culprit was and so on.

But this article isn't about Let’s Encrypt. It's about FIDO2. The patterns may be similar, at least some salient points. "I don't know if you've been keeping up with the developments in hardware security tokens," one reader told us this week, "but I have been very alarmed with the developments that are happening with regards to FIDO2. I feel like this is another attempt to stomp out competition just like TLS CAs did before Let's Encrypt was a thing."

"We use GnuPG a great deal here in Techrights. Most of our messages are encrypted."The reader is a bit of an expert in that domain. Also remember how the founder of Ubuntu originally amassed his wealth. "Right now," the reader noted, "companies that make products like Yubikey and Titan Security Key are selling obscenely overpriced hardware just because it has a "FIDO2 Certified" logo on it. I feel like hardware security tokens are going to end up in the same situation that happened with TLS CAs where a few bodies monopolise the system and dictate who gets to be a "trusted provider". A FIDO2 certification costs about $6500 USD, last time I checked. As someone that uses GnuPG and its open ecosystem of hardware, it pains me to see the monopolisation and profiteering that's happening around the security space."

We use GnuPG a great deal here in Techrights. Most of our messages are encrypted.

"I hope you can share this message with the right people," our reader appealed, "to combat the monopolisation and anti-competitive attempts by organisations like FIDO Alliance. There's nothing open about the FIDO Alliance. The firmware for most of those devices are closed-source and the only reason people are duped into buying them is because of the "FIDO2 Certified" seal on those products. I feel like this is a turning point in cybersecurity history and we need to kill this attempt at monopolisation before we end up with the tragedy that happened with TLS CAs."

"A mechanism for trust among parties, e.g. encryption, is crucial in a free and democratic society."How many billions of dollars were washed down the drain because of these? And we ended up with "trusted" CAs that are mostly in bed with the world's biggest spying operation. Which means they might be worse than useless...

"We decide who to trust with our OpenPGP certificates," our reader noted. "We don't let other bodies make that decision for us. Let's work together to make sure we nip this FIDO nonsense in the bud. We've got the platforms and people. The WebAuthn W3C steering members are stuffed with Google, Microsoft, and (surprise) Yubico people. I'm almost certain that they're using embedded cryptography MCUs in their closed proprietary products and then making a eye-watering profit margin."

Notice that their stuff is controlled partly by Microsoft and the NSA (in GitHub). So they clearly do not value or grasp basic security.

Our reader noted: "The OpenSK project on GitHub (by Google, I believe) uses an overpriced board and there's a nice disclaimer at the bottom that OpenSK is not FIDO certified (this is blatant FUD). They aren't even using the embedded crypto MCUs on the Nordic chip. They have gone with the excuse that their software-driven crypto is "research quality" code. OpenSK is a blatant attempt to spread FUD about uncertified FIDO hardware. Yubico are in on it as well.

"We might be the first site to touch this subject, but there's more on the way for sure.""Nitrokey has a FIDO2 product and I think it's uncertified by the looks of things. I know Nitrokey people are very closely linked to GnuPG devs because I've been around GnuPG dev a lot recently. I'm pretty sure the folks at Nitrokey see the dangers of monopolisation but they're keeping it quiet (probably in fear of the media pull Google et al have). I would also prefer remaining anonymous, thanks for allowing that..."

A mechanism for trust among parties, e.g. encryption, is crucial in a free and democratic society. Those who undermine the encryption basically maintain keys to the castle. They've long attempted to put back doors (or back door access, e.g. via third parties) to everything. Sometimes the media describes that as "weakening" encryption, but that actually means breaking; weak means broken.

We might be the first site to touch this subject, but there's more on the way for sure. "Wanted you to be the first to throw a punch though," our reader noted, "because people in the community trust you on these things."

But there's lots more on the way. Stay tuned. ⬆

Recent Techrights' Posts

Nearly 1,000 People at EPO 'Met' to Plan Further Strikes and Impending Action to Dethrone Corrupt Leadership
Exploring the purchasing "power" of EPO leadership (buying elections while doing cocaine in public)
 
Gemini Links 24/09/2026: Laziness, Outdoor Seating, "AngelNova’s Interview Malware and Its North Korea Connection"
Links for the day
Links 24/09/2026: Slop "Linked to Disturbing Culture of Sexual Assault"; "Zelensky Warns Russia’s War Will Expand if It Is Not Ended Soon"
Links for the day
Winding-up petition served on Reform UK Party Limited (Nigel Farage)
Reprinted with permission from Daniel Pocock
Appliances Should be Dumb
Any "Smart Home Appliance" is basically a thing that does not last long, does not work as advertised, and is generally unfit for purpose
SLAPP Censorship - Part 198 Out of 200: It Sounds Like Garrett is Now Sending People to Silence Critics (Including His Own Spouse)
This week Garrett is having a somewhat karmic experience
Links 24/09/2026: Slop Contaminating KDE, Slop-Focused Data Centres Have Severe Environmental Impact
Links for the day
SLAPP Censorship - Part 197 Out of 200: Garrett Became So Poor That He Wants Others (in Another Continent) to Pay for His Own Legal Work Being Faulty
They lie to courts
The Register MS Has Become a Slopfest
This is the behaviour of a perishing publisher
Gemini Links 24/09/2026: Requiem for a Season, Philosophy, Rube-Goldberg Machine, ROOPHLOCH 2026, and Git over Gemini
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 23, 2026
IRC logs for Wednesday, September 23, 2026
IBM Grapevine: Development Outsourced to LLM Slop and It Results in Many Bugs
IBM is circling down the drain and every insider knows it
Microsoft Gives Many People the 'Booty' This Week, Not Counting PIPs (Silent Layoffs and 'Voluntary' Layoffs)
Microsoft PIPs allegedly target "20-25% in some teams."
Links 23/09/2026: Pax Silica Hub Ruins a Country for a Pyramid Scheme (Slop), Convicted Felon's Press Block Resembles Iran, Russia, China
Links for the day
Gemini Links 23/09/2026: Stuck, Gambling, Fury Road, IPFS, and More
Links for the day
The Register Got Paid Today to Spew Out "AI" Almost 50 Times (Keeping the Pyramid Scheme Buzzing in Headlines)
paid-for spam
SLAPP Censorship - Part 196 Out of 200: Sending Someone to Our Doorstep to Ship Approximately 5 KG of Legal Papers (Instead of to Our Representatives)
it is not about law, this is lawfare
IBM's Anderon Already Smells Like a Fraud and IBM Insiders Heckle the Lies From the Management
Sabine Hossenfelder recently made some videos which explain in simple terms why IBM is lying and has already lied about this for years
Links 23/09/2026: Mass-Surveillance by Clownflare and "Data Centre" Crunch Commences
Links for the day
Same Name/Brand, Not the Same Project/Product
What is Linux becoming?
Germany, Like Switzerland, Will Dump Microsoft's Proprietary Software and Disservices, Then Dump Windows for GNU/Linux
This impacts not only the Windows revenue; this corrodes any "rents" Microsoft was getting from "subscriptions"
3 Years Divorced From Americans
Next year we plan to pursue the UK's Court of Appeal
The Register MS Uses Slop About Slop (in Images)
Months ago we caught The Register MS using slop for text as well
There Are Likely Over a Thousand Internet Relay Chat (IRC) Networks Online, Net Gain of 16 Seen This Month by Andreas Gelhausen's netsplit.de
It's good that they're still tracking that sort of stuff
SLAPP Censorship - Part 195 Out of 200: Two Years Since Garrett, Graveley and Lozza Worked in Parallel to Censor Techrights
It began in September 2024, shortly after we had sued Garrett
Linux Kernel Becoming a Slopfest - Part 8 - In Conclusion
this can invite more SCO-like problems in the future
Microsoft Shuts Down More Studios, Morale Low, More Mass Layoffs Ahead of Reports
They pretend it's not happening or that it's a lot smaller than it actually is
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 22, 2026
IRC logs for Tuesday, September 22, 2026
Gemini Links 23/09/2026: Ljubljana, Poetry, and FORTRAN
Links for the day
The EPO's Central Staff Committee (CSC) Shows Job Insecurity at Europe's Second-Largest Institution
Who would want to join a company with such low job security?
There Are Thousands More Microsoft Layoffs (Including Silent Layoffs), Not Hundreds
Microsoft does have layoffs and today is no exception (except Microsoft talks about it)
Gemini Links 22/09/2026: Disability Studies, Slop Boosters, and TkInter
Links for the day
Links 22/09/2026: Flock is Collapsing Amid Mass Backlash and Internet Society Collaborates With the 'Epstein Class' (Trafficking of Women)
Links for the day
SLAPP Censorship - Part 194 Out of 200: The Court Needs to Also Look Into Microsoft-Controlled Restricted Boot Advanced by An American (Garrett) to Promote Monopoly and Back Doors Everywhere
Kill switch sold as 'security' is like euthanasia sold as a cure
Linux Kernel Becoming a Slopfest - Part 7 - Infested With or Plagued by Bot-Generated Slop, Committed by Microsofters
Slop is a security threat; even the person committing slop to Linux might not be aware that there's a back/bug door in the code
Raspberry Pi Has Microsoft Secrets Inside, Now DRM
now we deal with SBCs that have DRM in them, put there for commercial reasons
Edward Snowden Lost His Voice, Then His Leaks Lost Exposure (Access Denied)
When states want to deny people access to some information they have many tools at hand
2 Hours Ago The Register MS Published a Page That Says "AI" 42 Times Because It Was Paid to Do So
Still inflating the bubble for money
Gemini Links 22/09/2026: Scout Night, Cybernetic Capitalism, and Thoughts on Companies Forcing People to Adopt Plagiarism Engines
Links for the day
Links 22/09/2026: "An Arsenal of Surveillance" and Slop Bots Suggest Starting Wars
Links for the day
SLAPP Censorship - Part 193 Out of 200: Breaks GNU and Linux, Tries to Silence Critics, Loses All Money, Looks for Microsoft Allies and Sponsors
The latest emotional knee-jerk reactions serve to confirm what we have long said
Things Will Only Get Better (as We Go Backwards)
It only gets better. If you go back in time.
UK High Court Shows SRA is Totally Useless in Curbing SLAPPs, This Has Impact on Our Reporting on the SRA Next Week
We'll carry on our coverage and soon finish the current series that so we can get on with more time-sensitive ones
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 21, 2026
IRC logs for Monday, September 21, 2026