personal-security-checklist/6_Privacy_and-Security_Gadgets.md

42 KiB
Raw Blame History

Awesome PRs Welcome License

Hardware for Protecting Privacy and Security

A curated list of (DIY and pre-built) devices, to help preserve privacy and improve physical cyber security 🔐

Too long? 🦒 See the TLDR version instead.

Note: This section is intended just to be a bit of fun, it is entirely possible to stay secure and anonymous, without having to build or buy anything


Contents

Basics

Item Description
USB Data Blocker
Data Blocker
There are many exploits that allow an attacker to infect your device with malware and/ or steal data, when you plug it in to what appears to be a USB power outlet. If you are charging your phone while travelling, a USB data blocker will prevent anything other than power from getting to your device, by removing the connection between the 2 data wires. The PortaPower brand, also comes with a fast charging chip, since without the data connection your device would otherwise charge at minimum speed
Microphone Blocker
__
A microphone blocker is a device that prohibits audio hacking, in the form of a hardware accessory for a smartphones, laptops etc. It functions as a dummy mic jack, so the device thinks it has a microphone plugged in, and hence disables the internal one
Faraday Pouch
__
Faraday Shield is an enclosure that blocks electromagnetic fields. It is useful to keep any device which could be hacked through sending or receiving signals in such a case, such as car keys, or a smart phone. Larger versions are availible for tablets and latops.
RFID Blocking Cards
__
If you are concerned about card skimming, you can use an RFID blocking sleeve to protect your contactless payment and identity cards. However there are proportionately very few RFID-skimmer crimes reported, and most credit cards have a low contactless limit
Web Cam Covers
__
Web cam covers are quite self-exoplanetary, they physically conceal the lenses on your laptop or phone camera, to prevent a malicious actor (hacker, government, corporation etc) from watching you through the camera. It may sound paranoid, but unfortunately it happens, and it is a relatively simply process for someone to gain remote access to a webcam. Even Mark Zuckerberg covers his webcam! Of course you could just use some tape, rather than buying a cover
Port Blockers
__
There are many attacks that involve an attacker inserting a USB device (such as a BadUSB/ Rubber Ducky/ Malduino) to an open USB port. Adding a port blocker doesn't render you safe from this, since the attacker could take the time to try and remove it, but it could protect you for an opportunistic attack
Privacy Filter
__
Privacy filters are polarized sheets of plastic, that when placed over a computer screen prevent screen visibility from any angle other than straight on. They make it harder for anyone to look over your shoulder and see your data confidential
YubiKey
__
The YubiKey is a small hardware device used to secure access on mobile devices, computers, and servers to all of your online accounts. It allows for second-factor authentication, hence protecting anyone other than you from logging in. It is said to be more convenient and more secure than using a mobile authenticator, but there are reasons for and against
Encrypted Kingston Data Traveler
__
Good value, easy-to-use with no installation required. Built-in hardware encryption and high password protection. Also optionally allows for automatic cloud backup option to protect against data loss (which doesn't say much about their faith in this USB device, but jokes aside-) this is a very affordable and well rated little device
Hardware Encrypted USB 3.0 Drive
__
OS & Platform independent, with 100% hardware encryption, so it works perfectly with all operating systems. USB 3.0 with Read/Write Speeds of 116/43 MBps. GDPR complient and FIPS 140-2 Level 3, NLNCSA DEP-V & NATO Restricted Level Certified with real time military grade AES-XTS 256-bit hardware encryption
Hardware Encrypted External Hard Drive
__
Similar to the iStorage hardware encrypted USB 3.1 drive, this external hard drive has high capacity and strong hardware encryption. Data is encrypted with FIPS PUB 197 Validated Encryption Algorithm, and against a 7 - 15 digit alpha-numeric pin, with erasing capabilities for multiple failed login attempts
Fingbox - Home Network Monitoring
__
Fing Box is an optional companion to the Fing App. It provides network monitoring and security capabilities, to protect your home/ work network. As well as the functionality of the app, the FingBox allows you to block intruders and notify you about unknown devices as well as analyse your network for vulnerabilities, such as open ports. You can also see which devises are near your home at what time (even if they're not connected to your WiFi), and improve network speed with scheduled analysis and bandwidth allocation. Best to try out the Fing app alone, before buying the FindBox, but both are great products for netowrk monitoring and security
Bootable Drive Eraser
__
Easy-to-use bootable USB will completely erase your hard drive with military grade destruction, making it near-impossible for any files or personal data to be recovered. This should be done before you sell, or dispose of any hard drive. Of course there are various .ISOs you can download and flash to a USB yourself if you do not want to spend money, but this USB supports all devices and is quick and easy to use, with excellent results
Mobile Privacy Screen
__
Similar to the laptop/ monitor privacy filter, this screen protector will prevent anyone from seeing what is on your screen when reading from an angle
Kensington Lock
__
Quite self-explanatory, this lock will make it harder for someone to steal your laptop, and get to your data. Of course it does require that your laptop has the Kensington Security Slot, which many do
Anti-Surveillance Clothing
__
Facial recognition is being rolled out in most countries now, the patterns on these clothes, will confuse facial, object and number plate recognition, injecting junk data in to the systems, hence making it harder for automated systems to monitor and track you
Solo Key
__
Another FIDO2 physical security key for 2-facto authentication and storing encryption keys. SoloKeys have both open source hardware and software, they are easy to use out of the box, but can also be used for developers and makers, since there is a well documented CLI
Nano Ledger
__
If you are in possession of BitCoin or other crypto then one of the most secure ways to store, send and receive coins is with a hardware wallet. Ledger has a solid reputation when it comes to hardware encryption, and the main principle behind their wallets is to provide full isolation between the private keys and your easy-to-hack computer or smartphone
Cold Storage
__
If you are not planning on spending your crypto any time soon, and do not want to trust a tech-based solution, then consider this metal cold storage wallet. Unlike writing your private key down on paper, this will not fade, and cannot be destroyed by water, fire of other environmental circumstances. Of course you could just engrave your key on a small sheet of aluminium
Anonabox
__
Plug-and-play Tor router, that can be used with public WiFi while travelling, or at home. Anonabox provides easy access to the deep web and lets you bypass censorship, protect your location, deter data collection and more. It can also be used with a VPN, or for online hosting. Of course you could build a similar product your self using a Raspberry Pi and a WiFi range extender
Deauth Detector
__
Most WiFi hacks begin by sending deauth packets, so that connected clients will briefly be disconnected to the network. This ESP8266 comes pre-flashed with @SpaceHuhn's deauth detector (which you can view here, on GitHub). Once it detects deauthentication or disassociation frames, it will activate a speaker to notify you
Librem 5
__
Security and Privacy focused smart phone by Purism. With hardware kill switches and specially designed software, this device runs Linux, and does not track you. It Separates CPU from Cellular Baseband, uses IP-Native Communication First and Decentralized Communication by Default. The source code is user-controlled, and has layered security protection. Purism also have other security-focused products
Slate Travel Router
__
The GL-AR750S-Ext can serve as a Wi-Fi access point, a pfSense firewall or a portable router with always-on VPN connectivity. It's great for controlling your network (firewall, VPN, ad-block, web filtering, data limits and more) when traveling or away from home

DIY Security Products

Don't want to spend money? Most of the products above, plus some that wearn't included can be built at home with some pretty simple hardware and open source software. The following list will point you in the right direction to start making!

See Also DIY Networking Hardware

  • Network-wide add-block - Pi Hole is a simple yet powerful app, that can be installed on a Raspberry Pi, and once you've updated your routers DNS servers to point to it, all resources on the blacklist will be blocked, at the point of origin. This makes it much more powerful than a browser add-on, and will also speed your internet up
  • Encrypted USB - You can use VeraCrypt to create an encrypted USB drive, using any off-the shelf USB drive
  • USB Sanitiser - CIRCLean is a hardware solution to clean documents from untrusted (obtained) USB drives. It automatically converts untrusted documents into a readable but disarmed format and stores these clean files on a trusted (user owned) USB key/stick.
  • Hardware Wallet - Using the Trezor Shield or Trezor Core and a Raspberry Pi, you can create your own hardware wallet for safley storing your crypto currency private keys offline. See this guide for building. If you enjoyed that, you can also run your own BitCoin and Lightning Node Raspiblitz
  • AI Assistant Mod - Project Alias runs on a Pi, and gives you more control and increased privacy for both Google Home and Alexa, through intercepting voice commands, emitting noise interference + lots more. If your interested in voice assistants, then also check out Mycroft- an open source, Pi-based alternative to Google Home/ Alexa
  • Home VPN - Pi_VPN lets you use OpenVPN to connect to your home network from anywhere, through your Pi. See this guide for set-up instructions. This will work particularly well in combination with Pi Hole.
  • USB Password Manager - Storing your passwords in the cloud may be convinient, but you cannot ever be certain they won't be breached. KeePass is an offline password manager, with a portable ddition that can run of a USB. There's also an app. See also KeePassX and KeePassXC which are popular communnity forks with additional functionality
  • Automated Backups - Syncthing is a privacy-focused continuous file synchronization program. You can use it to make on-site backups as well as encrypted and sync your data with your chosen cloud storage provider
  • Bootable Drive Eraser - You can flash the DBAN or KillDisk ISO file onto a USB, boot from it and securly, fully wipe your hard drives. This is useful to do before selling or disposing of a PC.
  • Deauth Detector - Since most wireless attacked begin by sending out deauthentication packets, you can flash SpaceHuhns DeatuhDetector, onto a standard ESP8266 NodeMCU, plug it in, and wait to be notified of wireless deauth attacks
  • Tor WiFi Network - Using OnionPi, you can create a second wireless network, that routed traffic through Tor. This is very light-weight so can be done with just a Pi Zero W. Here is a configuration guide
  • Faraday Case - If you want to block signals for devices such as car keys, smart phone, laptop or even just RFID-enabled cards and passports, you can line a box or pouch with Faraday Fabric
  • GPS Spoofer - If you don't want to be tracked with GPS, then using a SDR you can send out spoof GPS signals, making near-by GPS-enabled devices think that they are in a totally different location. (Wouldn't recommend using this while on an airplane though!). You can use gps-sdr-sim by @osqzss, and run it on a Hacker RF or similar SDR. Here's a guide outlineing how to get started, you'll also need a NooElec HackRF One or similar SDR. Check your local laws first, you may need a radio license.

If you are confident with electronics, then you could also make:

  • USB Data Blocker - By simple removing the data wires from a USB adapter, you can create a protector to keep you safe while charing your device in public spaces. See this guide for more info (note: fast charge will not work)
  • Hardware Encrypted Password Manager - Even better than a software-encrypted password manager, is the hardpass0.2 which is a very simple hardware-encrypted USB store, using GnuPG Smart card, GNU Password Standard and this source code all running on a Pi Zero. See also the Zamek Project, using this source code to achive a similar functioning hardware-password manager
  • U2F USB Token - Similar to the FIDO2 2-factor authentication USB keys, U2f-Zero by Conor Patrick, lets you turn a Pi Zero into a second-factor auth method. Note: project no longer activley maintained, see NitroKey instead
  • True Random Number Generator- Standalone - The FST-01 is an open source hardware RNG with good documentation, and see the neug source code
  • PC auto-lock Flash Drive - Turn a flash drive into a lock/ unlock key for your PC, allowing you to quickly lock your device when needed [deprecated]
  • Headless Pi Zero SSH server - Create an small test server, that you can SSH into for development, in order to not have to run risky or potentially dangerous code or software directly on your PC, see this artticle for getting started

Paranoid Security Gadgets

We can go even further, these products are far from essential and are maybe a little over-the-top. But fun to play around with, if you really want to avoid being tracked!

  • Self-Destroying PC - The ORWL PC will wipe all data if it is compromised, and has many other safeguards to ensure no one other than you can access anything from your drive. Comes with QubeOS, Windows or Linux, and requires both a password and fob to log in. See more: orwl.org
  • True Random Number Generator - FST-01SZ is a tiny stand alone USB 32-bit computer based on a free hardware design. (NeuG is an implementation of a TRNG for GD32F103 MCU). See More: Free Software Foundation: Shop
  • Card Skimmer Detector - Ensure an ATM or card reader does not have an integrated skimming device. See more at Lab401
  • Voice Changer - Useful to disguise voice, while chatting online. See more: UK | US
  • Ultra-Sonic Microphone Jammer - Blocks phones, dictaphones, voice assistants and other recording devices. Uses built-in transducers to generate ultrasonic signals that can not be heard by humans, but cause indistinct noise, on redording devices, making it impossible to distinguish any details of the conversations. See more UK | US
  • Reflective Glasses - Blocks faces from most CCTV and camera footage, and stops facial recognition from being able to map your face. See more: Reflectacles
  • Bug Detector - Able to detect radio waves, magnetic fields, in order to find hidden wired or wireless recording or camera equipment and transmitting devices, Note: has limited accuracy. See more: UK | US
  • Active RFID Jamming - Armour Card is a slim credit-card shaped device, which when in contact with any readers creates an electronic force field, strong enough to "jam" and readings from being taken by emmiting arbitrary data. Aimed at protecting cred cards, identity documents, key cards and cell phones. US | ArmourCard Website
  • Anti-Facial Recognition Clothing - Carefully printed patterns that confuse common facial recognition algorithms. See more: Amazon UK | Redbubble | Monoza
  • Tor Travel-Router - Plug-and-play travel router, providing WiFi with VPN or Tor for more private internet access, also has Wi-Fi uplink and range extender with a clear user interface. See more: Anonabox.com | Amazon
  • Hardware Password Manager - MooltiPass is an offline, hardware encrypted USB password manager, with desktop and mobile browser integrations. You can export your KeePass database onto it, for secure authentication on the road, and the hardware is open source. See More: TheMooltiPass.com | Hackaday
  • GPS Jammer - In the DIY list, there was a link to how to build a GPS spoof device using an SDR. But you can also buy a GPS jammer, which may be useful if you fear that you are being tracked. They are aimed at preventing UAVs from operating in your area, but can also be used to confuse other tracking devices near by, there's a variety of models with varying power and range availible from $50 - $500. AliExpress
  • Faraday Cases - A Faraday cage or Faraday shield is an enclosure used to block electromagnetic fields. This can be really useful for electronics, since many devices are constantly transmitting and recieving, which is the worst when you are trying to avoid being tracked. Their have been numerous reportings that governments can apparently track phones, even when they are powered off, and since smart phones often do not have removable batteries, the only option is often to shield them from any em waves. See SilentPocket.com | Faraday Box | Faraday Phone Pouch
  • p@ss™ Bracelet - Fun password generator wristband, allowing you to generate hard to guess, unique passwords for each of your online accounts, and not have to remember them. Tindie
  • DNA Invisble - An open source recipe that erases and deletes 99.5% of DNA left behind, and obfuscates the remaining 0.5%. You leave your DNA behind all the time, once analysed this is able to say a lot about your genetic makeup, and who you are. Learn more about this threat in this video, See DNA Invisible
  • Forensic bridge kit - Allows for write blocking to prevent unauthorized writing to a device, and for crating images with out modifying data. See more: Amazon
  • Firewalla - Tiny open source smart firewall. Has many useful features: VPN Server, Ad-blocker, powerful monitoring, security analysis and family controls. Firewalla.com | Tindie
  • IoTMATE v2b-CL - Plug-and-play open source home automation module, does not require internet access and has some good privacy controls, making it a more secure alternative to big-name IoT hubs (Note: requires technical and electrical knowledge to install and configure). Tindie
  • Stand-alone Drive Eraser - Allows you to erase drives, without connecting them to your PC. Availible in different modesls for different needs. See More: Amazon
  • Shredder - It is important to safely dispose of any documents that contain personal information. This is a very affordable shredder - it cuts pieces into security level P-4 sizes (5/32" by 15/32"). It also shreds credit cards into the same size. Amazon
  • Device Timer - This non-smart device can be used to turn various devices (such as lights or radio) on or off at certain times. It's useful to deter people when you are away. Amazon
  • SurfEasy Key - A portable web browser you can carry in your pocket for private and secure browsing on the go. Provides encrypted storage and anonymous browsing features. Again, you can make your own version with an encrypted USB, and a portable executable. fightforthefuture.org
  • QUANTUM - Multifunctional crypto device, is an open source secure, reliable and simple cross-platform cryptocurrency wallet and password manager. See more: crypto-arts.com | Tindie
  • Private Texting LoRa Transceivers | A pack of 2 private texting unit, which are small companion radios for a smartphone, allowing you to communicate independently from celluar networks, great for privacy, security and when you have no service. Tindie
  • TrueRNG - Generates a stream of True Random Numbers for use in Simulations, Security, and Gaming. Tindie

Network Security

Gadgets that help protect and anonamise your internet, detect & prevent intrusions and provide additional network controlls, both at home and while traveling. There are many products like this availible, some of them are over-priced for what they are, others provide some really essential network security features. It is possible to re-create some of these solutions yourself, to save money above.

  • Anonabox - Plug-and-play Tor router. Wi-Fi uplink and range extender with user interface, also has VPN options and USB ports for local file sharing. Amazon | Anonabox.com
  • FingBox - Network monitoring and security, for what it offers Fing is very affordable, and there is a free app that you can use before purchasing the hardware to get started. Fing.com | US | UK
  • BitdefenderBox - Cybersecurity home firewall hub, for protecting IoT and other devices. Has other features such as parental controlls and is easy to set up. US | UK
  • Flashed-Routers - Pre-configured branded routers, flashed with custom open source firmware, for better security, privacy and performance. flashrouters.com
  • Firewalla - Tiny open source smart firewall. Has many useful features: VPN Server, Ad-blocker, powerful monitoring, security analysis and family controls. Firewalla.com | Tindie
  • Trend Micro Box - Protect home networks from external and internal cyber attacks. Detects intrusions, vulnrabbilities, remote access, web threats and provides other security features. US | US
  • AlwaysHome Duo - USB VPN with accelerated virtual networking to your home or office network, crossing geo-blocking and firewall mechanisms. US | UK
  • Firewalla Red - An intrusion detection and intrusion prevention system, with a web and mobile interface. Also has Ad-block, VPN, internet controll features and insights. US | Firewalla.com
  • LibertyShield - Pre-configured, plug-and-play multi-country VPN router, note that after 1 year there is a monthly subscription. US | UK
  • Gigabit Travel AC VPN Router - A fully-featured dual-band travel router with VPN capabilities. US | UK
  • InvizBox - Tor router, that provides speed, privacy and security for all devices connected to it. Invizbox.com | Amazon
  • InviziBox Go - Portable VPN: https://amzn.to/386ikPT
  • WatchGuard Firebox - Business-grade network firewall. US | UK

DIY Networking Hardware

  • Pi-Hole - Network-level advertisement and Internet tracker blocking application which acts as a DNS sinkhole. Pi-Hole can significantly speed up your internet, remove ads and block malware. It comes with a nice web interface and a mobile app with monitoring features, it's open source, easy to install and very widley used
  • IPFire - A hardened, versatile, state-of-the-art open source firewall based on Linux. Its ease of use, high performance and extensibility make it usable for everyone
  • PiVPN - A simple way to set up a home VPN on a any Debian server. Supports OpenVPN and WireGuard with elliptic curve encryption keys up to 512 bit. Supports multiple DNS providers and custom DNS provividers- works nicley along-side PiHole
  • E2guardian - Powerful open source web content filter
  • OpenWRT Powerful custom router firmware, with great security, performance and customization features. See more custom router firmware
  • SquidGuard - A URL redirector software, which can be used for content control of websites users can access. It is written as a plug-in for Squid and uses blacklists to define sites for which access is redirected
  • PF Sense - Widley used, open source firewall/router
  • Zeek - Detect if you have a malware-infected computer on your network, and powerful network analysis framework and monitor

See more open source firewall apps

For most projects, a Raspberry Pi 3 or 4 is more than enough. You could also build your own hardware, see this guide on constructing a gateware firewall yourself.

Secure Computing Devices

  • ORWL PC - A self-destroying PC, that will wipe all data if it is compromised, and has many other safeguards to ensure no one other than you can access anything from your drive. Comes with QubeOS, Windows or Linux, and requires both a password and fob to log in. See more: orwl.org
  • Librem 5 - An open source security and privacy-focused phone, running PureOS, built by Prism. See More: puri.sm/products/librem-5
  • Armadillo Phones - Encrypted phones, SIMs and Networks, provide zero-trust communications and pro-active defences. Their keychain software is open source, and they also provide encrypted SIMs, and servers. See More: ArmadilloPhone.com
  • KryptAll - Provides secure mobile networking, for encrypted celluar calling. However without being open source, these devices are harder to verify. See More: KryptAll.com
  • Ano-Phone - Android devices loaded with additional security defences. Not open source. See More: ano-phone.com
  • Secure Group - Hardware-encrypted smart phones, for privacy and security. See more: SecureGroup.com
  • Librem Laptop - The Librem 13, Librem 15 and Librem Mini are well-speced, open source hardware-encrypted computing devices by Purism. They have several hardware features, like physical connectivity switches, and tamper-proof hardware. See More puri.sm

Hardware Encrypted Storage

Hardware-based encryption uses a devices on-board security to perform encryption and decryption. It is self-contained and does not require the help of any additional software. Therefore, it is essentially free from the possibility of contamination, malicious code infection, or vulnerability, and able to be used on any platform.

If the device itself becomes compromised, your data will remain safe. Really useful backing up, transporting and sharing personal data safely. For maximum security, you can combine hardware encryption with software encryption.

Reliable options include:

  • AES Hardware encrypted USB 3.0 external hard drive enclosure for HDD or SSD: US | UK
  • Integral 256-bit AES USB 3.0 (Software required), 16GB, 32GB, 64GB. US | UK
  • iStorage 256-bit AES USB 3.0 Pro (Hardware Encrypted), with keypad, 8GB, 16GB, 32GB, 64GB. US | UK
  • IornKey Rugged Enterprise-grade encrypted USB Pen, 4GB, 8GB, 16GB, 32GB, 64GB, 128GB. US | UK
  • iStorage 256-bit AES USB 3.0 Personal (Hardware Encrypted), with keypad, 8GB, 16GB, 32GB, 64GB. US | UK
  • Lexar JumpDrive Fingerprint USB 3.0 (Software required), 32GB, 64GB, 128GB, 256GB. US | UK
  • iStorage 256-bit Hardware Encrypted external USB 3.1 SSD Drive. 128GB, 256GB, 512GB, 1TB. UK
  • iStorage 256-bit Hardware Encrypted external USB 3.1 HDD Drive. 1TB, 2TB, 3TB, 4TB. US | UK

Alternatively, a cheaper option would be a software-encrypted USB. VeraCrypt is cross-platform open source encryption application. It's surprisingly simple (see this how-to guide), and very secure. Combine this with an ordinary USB drive, this high-speed (300mb/s) 256GB flash drive is a great option

For encryption your boot drive, you can use BitLocker (Windows), FileVault (OSX), or any of these options for Linux.

USB Data Blockers

Small, low-cost but essential devise. It attaches inbetween your USB cable and the charging socket, and will physically block data transfer and syncing while charging. Totally mitigates the risk of being hacked via a USB exploit, and stops anything being uploaded to your device.

  • PortaPow 3rd Gen, USB A, 2-Pack. Red | White | Black
  • PortaPow Dual USB Power Monitor with Data Blocker, usful for monitoring power consumption and managing which devices are allowed data connections. US | UK
  • Privise USB A Data Blocker. US | UK
  • Data-only Micro-USB cable. Be sure that it is actually data-only, you can count the pins at each end. Again PortaPow make a legitimate safe-charge cable. US | UK
  • USB-C ondom. An open source power-with-no-data USB-C data blocker. Tindie

PortaPow (3rd gen) is one of the best options, since it has a SmartCharge chip (which isn't usually possible without the data wire).

You can also build your own very easily, here is a schematic.

Word of Warning: Sometimes the cable itself can be dangerous. See O.M.G Cable, it looks like a totally authentic phone cable, but is actually able to deploy advanced exploits often without you being able to identify. It is always best label your cables, to ensure you are using your own, safe wire.

FIDO U2F Keys

Using a physical 2-factor authentication key can greatly improve the security of your online accounts. See twofactorauth.org for a list of websites that provide 2FA.

  • Yubico USB A + NFC Key - classic key with solid reputation. UK | US | Yubico
  • YubiKey 5 Mobile and Nano Keys - USB A Nano | USB C | USB C Nano
  • Thetis - Durable. mobile-friendly USB-A FIDO U2F Key. US | UK | Thetis.io
  • Solo Key - An open source U2F and FIDO2 key, USB A + NFC. US | UK | SoloKeys.com
  • OnlyKey - A pin-protected hardware password manager with FIDO2/ U2F. It allows a user to log in without a password or typing out a 2FA code. OnlyKey.com | US | UK
  • Librem Key - Makes encryption, key management, and tamper detection convenient and secure. Includes an integrated password manager, random number generator, tamper-resistant smart card plus more. Puri.sm

The Verge has a good article comparing hardware keys.

If you are interested in reserarching how to build your own key, see U2f-Zero by Conor Patrick, lets you turn a Pi Zero into a second-factor auth method. Note: project no longer activley maintained, see NitroKey instead

Crypto Wallets

The most secure medium to store your currency is cold (offline) wallets, since they cannot be hacked. Of course it is vital that you keep your private keys somewhere that they cannot be stolen, and cannot be lost or destroyed. Electronic devices can make it easy to securely store and spend crypto currency. Choose a wallet that is open source, and with a good reputation. Ensure you backup your seed, and keep it somewhere safe.

  • Trezor is fully open source and implements a firmware-based security on top of known hardware. Trezor.com
  • Ledger takes a more black box approach, but their devices are very well tested and secure. They are also easy to use and durable, with good support for a range of crypto. Ledger.com
  • Indestructible Steel Wallet, for private key. US | UK
  • QUANTUM is a Multifunctional crypto device, that is an open source secure, reliable and simple cross-platform cryptocurrency wallet and password manager. crypto-arts.com | Tindie

Always ensure the packaging has not been tampered with, buy direct from the manufacturer when possible.


See Also

Contributions welcome and appreciated - to propose an edit raise an issue or open a PR. See: CONTRIBUTING.md

Licensed under Creative Commons, CC BY 4.0, © Alicia Sykes 2020

Attribution 4.0 International


Found this helpful? Consider sharing it with others, to help them also improve their digital security 😇

Share on Twitter Share on LinkedIn Share on Facebook Share on Mastodon