Purpose of Security Keys
Since we are cryptocurrency users, the role and importance of an authenticator key is easy for us to understand, as it is basically the same as a hardware wallet, just for your account logins. The authenticator key is the best way to prevent a hacker from accessing your account as he essentially would have to physically have access to your key. This is a level of security that no one thinks they need until they get pwned, much like how people get lazy with backups until their drive crashes and it is too late.
The most common form of 2FA (Two Factor Authentication) is to send a verification link through email. While this works, it assumes that the email is secure and the user will not be tricked by phishing attempts (a fake link that encourages you to enter your login information on it, so they can steal it). Currently the standard method of 2FA that is considered to be secure is to use your cell phone to receive verification texts either by link or code. Links are rendered obsolete due to phishing concerns, and codes are safer because they are only used once, so even if someone intercepts the text, it is unlikely for them to figure out which account the verification code works for before the user that requested the code can use it first. To further eliminate even this small risk, authenticator programs like Google generate a time based code utilizing an authentication key (like a crypto seed) so there isn’t any online traffic a hacker could intercept.
The reason a phone is the commercial standard 2FA is because everyone has a phone. However for anyone interested in privacy and security, we know that the cell phone is also the biggest threat in terms of tracking not just by the government, but also by commercial and political interests as all the connectivity of the phone makes it very vulnerable to a wide variety of easy attacks. The solution is a security key which like a hardware wallet is a purpose made device that is so dumbed down that malware cannot infect it because physically there isn’t any space for malicious code to reside in. This is particularly beneficial as if the device that runs an authenticator program is infected, the authentication key could be stolen and the hacker can generate real time login codes, negating the benefit of the authenticator. By carrying an authenticator key, you can be detached from your devices and can log in securely to your accounts from any device, much like what we can do with our cryptocurrency hardware wallets.
The ”original” physical security key is Yubikey which was made in 2007. When people talk about a security authentication key, they are almost always referring to a Yubikey. While there are several other manufacturers of security keys, they are all basically inferior copies of the Yubikey. Onlykey is different with the primary difference being that it is PIN password protected (which auto wipes the key after 10 failed attempts but prevents accidental wipe by requiring unplugging and replugging every 3 failed attempts) and a secondary benefit of having a 24 account password manager integrated into the key. Onlykey is not a new company, as they have been around since 2014. However they are rarely talked about because of how dominant Yubikey is. Unlike Yubikey, Onlykey is made in America, but this can be a con for foreigners where the Yubikey is more accessible to those in the EU. Pricewise, Onlykey and Yubikey are essentially the same price at $60, with Onlykey being $8 cheaper if you buy their 2 pack bundle. For foreigners, Yubikey is cheaper as the International version of Onlykey is $75+shipping. However, one of the features of Onlykey that always makes it cheaper is that the firmware can be updated unlike the Yubikey. This means that if a vulnerability is found in Yubikey, you have to throw it away and buy another one, and you have to keep doing this forever, which sends the Yubikey’s true cost to be far higher than the Onlykey. While this is technically a security feature, in reality the risk is equal if not greater considering that most people do not constantly monitor vulnerability alert newsfeeds and may end up using a compromised key for years as a result.
Security Key Failures
While a security key is the highest level of protection for your online accounts, it can be defeated. The most common way is if the website has a password/account recovery option that is not authenticator key protected. However most websites that have this function now use a recovery email or device option instead of just a question and answer, and so the best solution to this issue is to buy a spare device solely for recovery purposes and to not use it for anything but that. This reduces the chance of malware being able to compromise it. Used or even some new low feature smartphones can be purchased for under $50 shipped for this purpose. You actually should also have a spare computer for the purposes of setting up the Onlykey due to the way the backup system works. If you don’t have an old laptop to use, I recommend getting a raspberry pi which can be as cheap as $30.
Other than exploiting recovery, the second most common way to defeat an authenticator key is malware on the device the key is being used on. The common target is to steal the login credential like the cookie or some other RAM data that is created after the authenticator key unlocks the account. This is why it is always recommended to regularly log out of your accounts to invalidate the old login and to be careful of the browser extensions you use as this is a common way to steal your cookies.
Another way a security key can be bypassed is if the website itself is hacked and the login information is stolen. This threat is why you should be changing your passwords once per year anyways since most data breaches actually come from the websites not from you, and it often takes a couple of months for the data that is sold to be used by hackers. When you have a security key you should redo the security key code when you also change passwords. Security keys never give out the code, as much like hardware wallets they only output a generated temporary login credential, so the website or a password manager breach is the only way to steal it. It should be understood that this is also why a security key will not compromise your privacy even if you use the same key for two different accounts. This is because the key does not have any ID and the output is always different due to being generated by the key code you use for each account. This is not true when using a phone or computer to run an authentication program unless the output is manually inserted into another device to log onto your account.
Onlykey Construction
I purchased the two key pack (
https://onlykey.io/products/two-onlykey-bundle-always-have-a-backup). Just like with hardware wallets, you should buy two as if one breaks, you want to ensure you will be able to restore your data on a spare key just in case the company that produces the hardware goes out of business one day or you otherwise are unable to order a new one in time. While Onlykey can save a text file to restore all this data, you cannot read or change this data without an Onlykey, so the two is one, one is none principle still applies. Even though we can be confident Onlykey isn’t going out of business anytime soon, you don’t want to wait a week for a new key to ship before you can access your accounts. With non-PIN protected keys like Yubikey, if your key is stolen then it is a race against time to change your account login credentials before they access it. Onlykey isn’t at risk of this as much due to the PIN protection, but it’s still just nice having two keys to be able to confirm the backup function works without having to erase the original copy of the key.
The two key pack comes with the rubber protective case and a keychain for each. I believe these two things already come with the single Onlykey package, but if it doesn’t, this alone counts for $20 of the cost. It also comes with a USB adapter which allows mounting into Android (USB-C) or Iphone interface which is sold for $10. It’s nice, but I don’t need to use them since I don’t use an Iphone (for sale here!
https://anonbazaar.com/listing/59kZ). The keychain attachment is likely made of a zamak alloy and is non-magnetic. For this reason I would not trust its durability and it is better to tie cord direct from the onlykey lanyard hole. For greatest durability, a braided steel wire lanyard should be used (think of the battery cap tethers used on military electronics like night vision or LAMs). I believe it is important to have the key on a lanyard not just so you don’t drop it into an inaccessible space, but also so you don’t forget it somewhere. I have my Onlykey attached to a retractable ID badge lanyard attached to a mini carabineer so I can clip it to my belt loop and if I walk away without grabbing my key, the key will automatically be unplugged and snap back to me. While that kind of violent motion isn’t good for the key’s longevity, it’s better than losing track of it. On this note, I recommend getting a USB extension cable and plugging it in from your computer and mounting the female end to your desk so you can quickly and accurately hit the buttons of the key without having to reach into whatever awkward space your available USB ports are. It is extremely important to not “misclick” the buttons on the Onlykey as will be apparent in programming. I wish they used tactile buttons, but I guess the reason for capacitance sensors is durability, particularly against dust and water.
The packaging leaves a lot to be desired. It is cheaply made by a piece of printed cardstock folded in half and sealed with double sided tape. The reason the packaging matters is that in theory someone could take out the key and modify it with a backdoor and then reseal it and sell it as a new key. The actual probability of this kind of threat is actually very low. Especially since you should be buying 2FA stuff direct from the manufacturer and not from a retailer. Onlykey is sold on Amazon, but buying direct is actually cheaper.
As far as the key itself, it’s actually fairly sturdy. This torture test shows how incredibly reliable it is. It is at least equal to a Yubikey, if not exceeding it.
https://www.youtube.com/watch?v=iGRQl-7wMgE
Programming Slots
To program the Onlykey you need a computer running the Onlykey program. In theory you could program with a smartphone, but you need Linux OS installed on the phone.
The Onlykey can support 24 accounts referred to as slots (unlimited if only used as a challenge-response authentication key). This is split into two profiles of 12 slots, each profile protected by its own PIN. It should be noted that knowing only one of the PIN can compromise the accounts of the other PIN. The only reason two PINs are used is because there are only 6 buttons on the key, each button representing one account either by a short or a long press. So the point of the PIN isn’t to obfuscate accounts, but to better select each profile. To make things simpler, I set the first button of the pin to 1 or 2 to indicate which profile I want, and then the rest of the PIN is the pass itself. Onlykey supports a PIN up to 10 digits, so sacrificing one digit to selecting profiles will not significantly degrade security.
If you enter the PIN wrong 10 times, it wipes the Onlykey. To avoid accidentally wiping the key, you should not insert the key into a USB port unless you immediately unlock it (or use a USB port that has a switch to turn off). This is good practice but somewhat superfluous as to help prevent the possibility of accidentally hitting the pin, the Onlykey has to be unplugged and replugged after every 3 failed attempts and will signify this by blinking red. There is an option to add a self destruct pin which when entered will wipe the key. I do not recommend this as there isn’t really a situation where you would need to do this. If you did need to wipe the Onlykey in a hurry, I doubt you would have time to enter the PIN either. You would be much better off throwing the key on the ground and shooting it with your handgun.
Note that if you want to change the PIN or passphrase you need to enter config mode by holding 6 for 5 seconds then entering the pin. The light will turn from green to red. You should not leave your device in config mode for long so you don’t leave it unattended and someone changes the settings. In the preferences you can permanently disable the ability to enter config mode without a full factory reset but I don’t see the purpose of that.
Once the PIN is setup, figure out the layout of the accounts. As you cannot really label the buttons since the key is so small, you need to determine a logical way to group your accounts into the slots so it is easily remembered. When Onlykey logs in, the programming cannot be stopped so if you hit the wrong button, you may enter the wrong login credentials which potentially can compromise them. Example, if you accidentally input your username and password into a search engine. One important thing to note is that a long press is defined as holding down a button for 2-5 seconds. In order to ensure you hold the button long enough count to 3. You should set the most important accounts to the slots that you hold down, as slots that only require a quick tap are more likely to be accidentally triggered. You should always hold the Onlykey by the sides to avoid this. From what I can tell, originally the Onlykey did not have a rubber case and so it was very easy to accidentally hit the buttons. With the rubber case, it is virtually impossible to accidentally activate a button. If you want to be extra safe, you can pull out the Onlykey by pulling on the lanyard instead of the sides.
If you do forget which account is in which slot and you don’t have the Onlykey program installed, you can just open up a text editor and hit the button and see what is typed out. For ease of use, I recommend placing accounts you often use together into the same profile so you don’t have to keep unplugging and reinserting your key and entering a PIN to reach slots in the other profile. For example, I have my business accounts on one profile, and my personal fun accounts like gaming and shopping on the other profile.
One of the biggest complaints about Onlykey is that it is more complex to setup than Yubikey. While this is true, it’s really not that big of a deal. The only complex part is setting up the password manager as it selects text boxes and types into them on its own to automate the login process. Programming a slot is really just filling in the form and adding delays and commands to press tab or enter to select the next field. You should always use advanced mode as the other two modes are the same but doesn’t show all the options. You do not need to fill in all the boxes in advanced mode for it to work.
One quirk to programming is that since the Onlykey is designed to never give out information unless prompted to by pressing a button, when updating or changing information, there is no indication that any of the boxes are filled out. This can be confusing you forget what you did, so you may have to wipe the slot and refill it from scratch if you can’t figure it out. Note that no changes will be made to a slot unless you check mark the box to the left of each entry. IMO this is a poor design, but the point is to ensure you don’t accidentally overwrite data you aren’t sure about changing. When inserting passwords, type it out on a notepad and then copy and past it into the slot boxes. This ensures you don’t create typos as the text is concealed. Note that there is a possible bug where when using caps lock on the Username field it does not make the Onlykey output all caps. For case sensitive logins, this will cause the login attempt to fail. You have to manually shift when creating capital letters. This may also be an issue with passwords, but I copy it from the random generation as recommended in the user manual so I don’t know.
Note that the typing speed of the Onlykey is set in the slot settings, not in the Preference tab. I do not exactly know what the Preference tab typing speed is for, but it could just be a vestigial option from the earlier generations of Onlykeys for the purposes of backwards compatibility. As a side note, in the preferences you can also set a button to lock the computer and Onlykey instantly which is an interesting feature.
2FA
Onlykey supports 4 standards if 2FA from order of strongest to weakest which pretty much ensures the Onlykey can be used on any website that uses 2FA. Use this website to look up which standard of 2FA a specific website uses.
https://www.dongleauth.com/
1. FIDO2 and FIDO Universal 2nd Factor Authentication (U2F)
2. OATH TOTP
3. Yubico One-Time Password
4. Challenge-Response
1 and 4 are setup automatically by logging into the website, turning on your account’s 2FA settings in the website, and inserting the key.
2 use Google Authenticator which is the most common 2FA option due to the reliance of smartphones. To use this you copy the authentication code the website provides and copy it into a slot of your Onlykey in the Onlykey program. I recommend copying this code into a secure password manager as you will never be able to get Onlykey to release this code ever again into a human readable format. If you lose the code you can just login and have the website generate a new code, but having it saved somewhere makes it easier to manipulate the Onlykey, such as if you want to shift one account to a different slot.
If you are coming from Yubico you can move your login credentials over to Onlykey but I just moved completely into Onlykey. There is no reason to keep using Yubico as far as I can see.
It should be noted that AnonBazaar does not support Onlykey as 2FA is done through messenger programs. You can still use the Onlykey to one touch login username and password credentials.
One annoying thing about the Onlykey is that an android program for it does not exist. The reason the setup program is important is because authenticator keys naturally do not have a clock synchronized to the internet which is needed to generate TOTP authentication codes. Instead you have to visit Onlykey’s app website (
https://apps.crp.to/) and leave it open in your browser to do the same function. I recommend reserving one of the slots for this website so you don’t have to remember it, you can just press a key and jump to that website.
Backup
One of the best features of the Onlykey is that you can create a backup of the key in the form of a text file. This allows keys to be duplicated or restored very quickly. It is important to note that while the backup file is encrypted and not in human readable format, if someone has an Onlykey they can install it onto their key without requiring your PIN because the backup does not integrate the PIN. Backup files are encrypted with a passphrase that the user creates, but this is stored in the Onlykey desktop program. For this reason it is important to keep the backup file secure. The best way to do this is to generate and store the backup file onto an airgapped device, such as a Raspberry Pi or a spare laptop that is never connected to the internet.
One huge warning is the possibility of corrupted backups. The way backups are made is the Onlykey will type a long string into a text box of the Onlykey program which is then saved as a notepad file. This takes several minutes. If the key mistypes such as because the computer lags, the file will be corrupted. After generating a backup, you can click verify to ensure there isn’t corruption and this should be done every time. But also after restoring an Onlykey with a backup file, you should create another backup file and verify that to ensure the upload process did not introduce corruption either. Corrupted backups may create usable Onlykeys, but will not allow that Onlykey to make a backup.
The risk of silent erasure is why you should avoid deleting backup files so if a backup does get corrupted, you can roll back to an older usable backup with minimal data loss. For this reason Onlykeys should not be used as your sole password manager. In fact you probably should secure your password manager with an Onlykey.
Extra tools
The interface program includes some extra tools, although these require internet access. These can also be accessed through the Onlykey website if the device you are using does not have the Onlykey program installed. One tool encrypts and decrypts text or files. While the files are not uploaded to the internet, it still requires internet connection to perform. The other allows GPG (OpenPGP) and SSH keys to be generated by the Onlykey instead of stored on the computer.
Conclusion
Coming from the Yubikey 4, I think the Onlykey is a vastly superior product and I’m glad I bought it over a Yubikey 5. While many claim Onlykey is harder to setup than Yubikey, that is only true if you integrate the password manager programming. If you just use an Onlykey as only an authenticator like Yubikey, it is equally as easy to set up. However having the password manager is well worth the initial trial and error process of setting up as it removes a lot of the hassle of using an authentication key by automating and speeding up the login process. The main appeal of the Onlykey is that I have much more security in carrying it daily as even if the key is lost or stolen, I can have confidence whoever has it will not be able to use it. With a Yubikey if they know what my accounts are, they could use the key to get in. Even with newer thumbprint scanners, your finger print can be stolen (ironically this might possibly be performed off the surface of the key body itself). So a PIN is actually safer, this link shows the difficulty of bypassing the PIN (
https://docs.onlykey.io/security/). The most important factor is that if someone steals your Onlykey, they still cannot use it without knowing one of the PIN and if they can't guess it in 10 tries, the data will be wiped. With the Yubikey it is totally blind and with its NFC you could potentially get your credentials swiped (although the physical coordination to perform that kind of attack is very unlikely).
The only thing that would make me abandon Onlykey is if there was some kind of code exploit that undermines its security. Onlykey is open source, but I do not have the skills to audit it. It should be noted that although the firmware can be updated (which was the primary reason I switched from Yubikey), Onlykey has not updated the firmware since 2022. While the lack of activity is scary, this is probably more of a “if it isn’t broke, don’t fix it” situation. I’ve had more products ruined by unnecessary updates (looking at you, Microsoft) than not enough, so I’m not really that concerned. Supposedly the reason for the lack of activity is Onlykey is going to release a new generation in a few years. However I have not found any official confirmation of that.