Using onlykey without PIN

Greetings,

I saw that this has been requested before by somebody. But, I wanted to emphasis that using the key without a PIN is very convenient, and serves the purpose of OnlyKey which is convenience .

When we talk security, OnlyKey barely adds any benefits against today’s threats. But, it’s super convenient to use, and manage passwords.

Using OnlyKey without a PIN is actually secure for many. The threat are those APT hackers that are after corporate data, not the waitress.

I hope there will be a new firmware allowing the key to be used without a PIN.

You can use OnlyKey DUO without a PIN.

For other comments here I think many would disagree with these statements. A device that can fully log into your most important accounts without any physical security would not be a feature we would support. Losing a device without a PIN could be disastrous for a user and for the corporate data that user has access to.

3 Likes

That’s true IF you have the URLs, and usernames there :smiley: But, if possible, we would love to have the option.

This would also eliminate the OnlyKey self-destruction after 10 incorrect PINs.

We, the Tor community, recommend OnlyKey for people traveling to oppressive regimes. Many activists and reporters rely on it. They can face torture and prison if they enter countries such as Turkmenistan, Miamar, Russia, China, Iran, etc.
I’m a big Tor exit operator. The cops can come in on me again any day. I want the SSH keys to my servers on the OnlyKey to be bulletproof.

If you don’t need a PIN, the small OnlyKey DUO is much more convenient. You can leave it permanently stuck in your laptop.

Hey @Mango_Mungo ,

The list of countries you provided is very misleading, and could cause people to look away from the real danger.

The only place where people get detained 6 months or more for not unlocking their devices is the US, and the UK (could be some EU countries as well).

That’s where OnlyKey second profile come into play. Because entering a wrong pin to wipe out the OnlyKey would count as ‘Tampering with evidence’ in the US. That is few years in jail trying to protect your wife’s nudes. in the UK, that is obstructing justice, even worse. Here I listed some articles for you information.

I don’t want to discuss which country it is worse to be arrested in. In some you disappear forever and not just 6 months, or pay a ridiculous fine.

Your examples confirm how important the PIN’s & OnlyKey self-destruction is at almost every border. Important data on the server in the data center, SSH keys on the Onlykey.

1 Like