PicoKey App #217

Open
opened 2025-12-13 00:36:13 +08:00 by zequinha-taveira · 18 comments
zequinha-taveira commented 2025-12-13 00:36:13 +08:00 (Migrated from github.com)

PicoKey App ?????

PicoKey App ?????
zyp114514 commented 2026-01-07 08:41:48 +08:00 (Migrated from github.com)

Its paid, only30euro ;p

Its paid, only30euro ;p
zorrolo commented 2026-01-07 23:24:43 +08:00 (Migrated from github.com)

Its paid, only30euro ;p

it's the license fee per device.
So 30€ per each physical key... 💸

> Its paid, only30euro ;p it's the license fee **per** device. So 30€ per **each** physical key... 💸
Chr0n0stasis commented 2026-01-08 17:35:42 +08:00 (Migrated from github.com)

In that case why not buy yubikey

In that case why not buy yubikey
dolence commented 2026-01-09 00:51:29 +08:00 (Migrated from github.com)

YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever.

YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever.
lockedmutex commented 2026-01-09 00:52:04 +08:00 (Migrated from github.com)

YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever.

Here’s an open-source commissioning tool I built that works with this firmware, in case it helps.
Tho the appimage has some issues rn, try to use rpm or deb or compile from source.
https://github.com/librekeys/picoforge

> YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever. Here’s an open-source commissioning tool I built that works with this firmware, in case it helps. Tho the appimage has some issues rn, try to use rpm or deb or compile from source. https://github.com/librekeys/picoforge
Chr0n0stasis commented 2026-01-09 01:10:56 +08:00 (Migrated from github.com)

YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever.

Yubikey costs 80 dollor for the most with NFC support

> YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever. Yubikey costs 80 dollor for the most with NFC support
Chr0n0stasis commented 2026-01-09 01:11:34 +08:00 (Migrated from github.com)

YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever.

And the BASIC ver costs 30 to 40 dollors

> YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever. And the BASIC ver costs 30 to 40 dollors
dolence commented 2026-01-09 01:17:04 +08:00 (Migrated from github.com)

I have a question. I'm in the process of registering my license and I saw it is per device. If I register a device In the future I will be able to unregister it and register another? I'm asking this because I'm using an RP2040 and I want to switch to an RP2350 later.

I have a question. I'm in the process of registering my license and I saw it is per device. If I register a device In the future I will be able to unregister it and register another? I'm asking this because I'm using an RP2040 and I want to switch to an RP2350 later.
polhenarejos commented 2026-01-09 01:42:11 +08:00 (Migrated from github.com)

I have a question. I'm in the process of registering my license and I saw it is per device. If I register a device In the future I will be able to unregister it and register another? I'm asking this because I'm using an RP2040 and I want to switch to an RP2350 later.

RP2040 is not technically supported in the PicoKey App. Despite it runs the latest version of Pico Fido (v7.2), due to security aspects I cannot recommend RP2040, as it represents a real risk for the final user. Note that in the upcoming versions support for RP2040 will be deprecated and removed.
Referring to your question, it is not possible to "unbind" the license, as it is binded to the serial AND the board type. Thanks to this, it is possible to commission the boards automatically.

> I have a question. I'm in the process of registering my license and I saw it is per device. If I register a device In the future I will be able to unregister it and register another? I'm asking this because I'm using an RP2040 and I want to switch to an RP2350 later. RP2040 is not technically supported in the PicoKey App. Despite it runs the latest version of Pico Fido (v7.2), due to security aspects I cannot recommend RP2040, as it represents a real risk for the final user. Note that in the upcoming versions support for RP2040 will be deprecated and removed. Referring to your question, it is not possible to "unbind" the license, as it is binded to the serial AND the board type. Thanks to this, it is possible to commission the boards automatically.
zorrolo commented 2026-01-09 03:53:03 +08:00 (Migrated from github.com)

YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever.

@dolence
Due to recent events I did broad research and came to conclusion that the most affordable yet reputable alternatives are from token2 (e.g FIDO2 Key bundle). Another good alternative is Nitrokey Passkey when you cannot or don't want to use a Yubikey.

Depending on where you reside and for what use case you are looking there are more worthy contenders. The biggest advantage compared to picokey is that you don't need to buy the hardware and flash the firmware yourself before commissioning it. Moreover these are commercial solutions, you get warranty and it is meant to be used after you purchased it, no need to tinker until it works.

With picokey you make a mistake –kaching– pay another €30 each time, your €5-€10 MCU is also trash... 💸 💸 💸

> YubiKeys are expensive and hard o find where I live. I made the purchase. Would be nice to have an AppImage version and a repository for auto updates with gearlever. @dolence Due to recent events I did broad research and came to conclusion that the most affordable yet reputable alternatives are from token2 (e.g [FIDO2 Key bundle](https://www.token2.com/shop/product/fido-bundle-2-x-fido2-usb-keys)). Another good alternative is Nitrokey [Passkey](https://shop.nitrokey.com/shop/nkpk-nitrokey-passkey-418?category=7#attr=) when you cannot or don't want to use a Yubikey. Depending on where you reside and for what use case you are looking there are more worthy contenders. The biggest advantage compared to picokey is that you don't need to buy the hardware and flash the firmware yourself before commissioning it. Moreover these are commercial solutions, you get warranty and it is meant to be used after you purchased it, no need to tinker until it works. With picokey you make a mistake $–kaching–$ pay another €30 each time, your €5-€10 MCU is also trash... 💸 💸 💸
cmichel5 commented 2026-01-09 07:39:18 +08:00 (Migrated from github.com)

No way I'll pay that much for the app. Specially if it's tied to only 1 device.
I'll just switch completely to Token2 moving forward.
It's cheaper, and they have been proven to be quite reliable. Without all the bugs and quirks from Pico Fido.
It's a no brainer...

No way I'll pay that much for the app. Specially if it's tied to only 1 device. I'll just switch completely to Token2 moving forward. It's cheaper, and they have been proven to be quite reliable. Without all the bugs and quirks from Pico Fido. It's a no brainer...
dolence commented 2026-01-09 10:22:35 +08:00 (Migrated from github.com)

I haven't seen it was tied for only one device until I tried to activate.

I haven't seen it was tied for only one device until I tried to activate.
dolence commented 2026-01-13 00:02:20 +08:00 (Migrated from github.com)

What's the contact channel for refund request? I didn't have any devices registered yet.

What's the contact channel for refund request? I didn't have any devices registered yet.
polhenarejos commented 2026-01-13 00:24:13 +08:00 (Migrated from github.com)

Please contact me by mail to handle the refund

Please contact me by mail to handle the refund
MiniProjectDIY commented 2026-01-26 14:09:03 +08:00 (Migrated from github.com)

I purchased a license just to support your open-source work. I haven’t registered any physical keys yet.
To be honest, I’m a little confused about the app’s business model — I’m not entirely clear on what the actual difference is between registering a key and not registering one.

I purchased a license just to support your open-source work. I haven’t registered any physical keys yet. To be honest, I’m a little confused about the app’s business model — I’m not entirely clear on what the actual difference is between registering a key and not registering one.
polhenarejos commented 2026-01-26 16:39:55 +08:00 (Migrated from github.com)

Registering the board is a necessary step to perform the commissioning automatically. When you register a board, the serial board and board model are linked and it is possible to reconfigure some parameters (like LED, GPIO button, memory size, etc.) automatically. This brings the possibility to support all boards with just one single binary file, even the boards that are not officially supported.
Without registering the board, the app is just works in read-only mode. All parameters are detailed, but you cannot write/modify them.

Registering the board is a necessary step to perform the commissioning automatically. When you register a board, the serial board and board model are linked and it is possible to reconfigure some parameters (like LED, GPIO button, memory size, etc.) automatically. This brings the possibility to support all boards with just one single binary file, even the boards that are not officially supported. Without registering the board, the app is just works in read-only mode. All parameters are detailed, but you cannot write/modify them.
tcurdt commented 2026-01-26 21:36:38 +08:00 (Migrated from github.com)

Originally, I didn’t want to pile on. From my own experience, I know that OSS doesn’t pay the bills - but I have to be honest, @polhenarejos, the business plan here feels a bit off.

You’ve built something great, and people would genuinely want to support you. But right now, I’m struggling to see the incentive. Why would someone choose this over getting a key from a reputable manufacturer?

At the moment, it reads a bit like a misstep in monetization rather than the opportunity it could be.

Originally, I didn’t want to pile on. From my own experience, I know that OSS doesn’t pay the bills - but I have to be honest, @polhenarejos, the business plan here feels a bit off. You’ve built something great, and people would genuinely want to support you. But right now, I’m struggling to see the incentive. Why would someone choose this over getting a key from a reputable manufacturer? At the moment, it reads a bit like a misstep in monetization rather than the opportunity it could be.
apiening commented 2026-02-08 02:21:23 +08:00 (Migrated from github.com)

It’s sad to see this happening. You should really rethink your business model quickly, @polhenarejos, and let me explain why:

  • Your project is very interesting, and I’m sure I’m not the only one who would happily pay EUR 30 for a configuration app, even if it were just to support the project. But charging EUR 30 per device, just to tinker with it—no way. This actually motivated me to research alternatives and check out https://[redacted]
  • As a professional user (owning 5+ YubiKeys), I have to say that I see very little chance of pico-fido being adopted in the industry to secure IT assets, simply because it lacks certification based on an external security audit. Companies don’t invest tens of thousands of euros to protect their assets and then choose unaudited open-source software just to save a few bucks. Charging the same amount as industry-grade, certified FIDO2 keys is completely out of scope.

I really hope you find a way to keep this project going, but I’m afraid this approach will only push users away and lead to forks.

It’s sad to see this happening. You should really rethink your business model quickly, @polhenarejos, and let me explain why: - Your project is very interesting, and I’m sure I’m not the only one who would happily pay EUR 30 for a configuration app, even if it were just to support the project. But charging EUR 30 per device, just to tinker with it—no way. This actually motivated me to research alternatives and check out https://[redacted] - As a professional user (owning 5+ YubiKeys), I have to say that I see very little chance of pico-fido being adopted in the industry to secure IT assets, simply because it lacks certification based on an external security audit. Companies don’t invest tens of thousands of euros to protect their assets and then choose unaudited open-source software just to save a few bucks. Charging the same amount as industry-grade, certified FIDO2 keys is completely out of scope. I really hope you find a way to keep this project going, but I’m afraid this approach will only push users away and lead to forks.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dearsky/pico-fido#217