Nicholas TongSoloKeys Solo 2

58 / 60

the security key that shipped three years late

6 min read 1,340 words

Two FIDO security keys from other makers, a white key fob and a blue USB key, between a ThinkPad and an Android phone, standing in for the Solo 2

The envelope arrived in March 2024, three years after I paid for what was inside it. One security key, a colorful silicone sleeve, and a card that thanked me for my patience. In spring 2021 I backed the crowdfunding campaign for the Solo V2 on the strength of the pitch: a FIDO2 key whose firmware you can read, rewritten in Rust on an NXP chip, from the people who made the first open source FIDO2 key. The pitch was honest. The schedule was fiction. Both facts belong in this review, because the second one is what you're actually buying from a small hardware company.

Today it's the Solo 2, in stock at $35 in USB-A and USB-C, $46 for the Plus with NFC, EU shop shipping in three to five working days. The question the delay history leaves you with is whether the company will still be answering email in 2031, and it deserves worse than a footnote.

the part everyone gets wrong

Open source gets treated as a synonym for secure, and it isn't one. Here's the thing: open firmware buys you inspectability, not assurance. Someone still has to look, and the record of looking for this hardware is thinner than the licenses imply. Doyensec audited the original C firmware in early 2020, ten person-days, and found a high severity firmware downgrade attack, fixed in v3.1.0, report published. That audit covered the Solo 1, the STM32 device whose code no longer runs on the Solo 2. I could not find a published third-party audit of the Rust rewrite that the Solo 2 actually runs. I could be wrong about this, and if I am, someone will tell me, and I'd genuinely like to be wrong, because the gap between what the openness implies and what I can point at is the real trust question.

The inverse mistake goes the other way. People treat a YubiKey's closed, permanently locked firmware as the safe default, and it's a defensible choice, but it isn't no-trust, it's relocated trust: you can't read it, and you can't patch it either. In 2021 Yubico disclosed a key-generation bug in older 5-series firmware and the remediation was a replacement key, because there is no update path. Every security decision on a key like that is frozen at the factory. The Solo 2 makes the opposite bet, that a key you can update and read is worth more than a key you can't touch. Both bets are reasonable. They're just bets.

what open firmware actually buys you

Concretely: Rust firmware, dual licensed Apache 2.0 and MIT, on the NXP LPC55S69. The hardware is CERN-OHL-S, schematics and all, on GitHub. The Trussed framework underneath is co-maintained with Nitrokey, so the same software foundation ships in a competitor's product, and either company's code review benefits both. The key speaks FIDO2/WebAuthn and U2F for the web, plus OATH for one-time codes, PIV for SSH, OpenPGP for signing, and the PIV implementation carries ML-DSA-44, a post-quantum signature algorithm. Around 100 resident passkeys, same ceiling shape as the YubiKey 5. The touch sensor is capacitive with three contact points, so you rest a finger on it instead of tapping a tab.

Two variants ship at the same price. The Secure model runs only SoloKeys-signed firmware with the bootloader locked and attestation certificates present, so services can verify it's a genuine SoloKeys device. The Hacker model ships with its bootloader open, so you flash your own builds, and carries no attestation by design. A company selling a version of its own product that exists so you can stop taking its word for it is making a statement most security vendors never make.

Telemetry, since I always check: there is none. No battery, no radio except the Plus's NFC, no cloud account, no app beaconing to anything. OATH codes are generated on the device, not validated against a vendor's server the way Yubico OTP phones home to YubiCloud. The only network touch in this key's life is a firmware file you fetch yourself and apply through solo2-cli, and on the Secure model the bootloader rejects anything unsigned. An update path is also an attack path, and the signature check is the fence around it, so it matters that the fence is readable.

where it breaks

The delivery history is the first break, and it's documented. By mid-2022, backers were asking openly on the project's GitHub whether the effort was dead, and one of them wrote that past a certain point a stalled campaign stops being bad luck and starts being fraud. The company's own summer 2023 post blamed delays in design changes, machinery delivery, and then poor quality control from certain suppliers. The first retail units that summer were a Limited Edition with glitter suspended in the epoxy over the microcontroller, which I choose to read as the founders' sense of humor. General availability came that fall, support replaced the reported NFC defects, and the store has been restocked since, terms of service updated as recently as June 2026. Alive, then. Small, slow, alive, and the X account's March 2026 post asking "Is this thing still on?" tells you the communication cadence.

Durability is the second break, and I'm the wrong person to be gentle about it. My YubiKey has been through the dryer twice. The Solo 2 is a bare circuit board in a stretchy silicone sleeve, and I don't believe the sleeve survives a keyring year, let alone the dryer. Mine lives in a desk drawer, where it works perfectly, because that's what it's built for.

Then the small stuff. NFC is the $46 Plus only, so my USB-C unit does desktops and laptops and my phone taps the YubiKey instead. Managing the key, updates included, means solo2-cli and a terminal; the promised graphical manager is coming soon, which is what coming soon looked like last year too. And sites that demand verified attestation will take the Secure model and refuse the Hacker one, worth knowing before you buy the fun one.

why I carry both

The full admission: the Solo 2 sat un-enrolled in that drawer for about six months, because moving forty-something account registrations onto a new key felt like a weekend I didn't have, and a key nobody trusts with logins is a $35 paperweight. When I finally did it, the accounts that matter took one evening, the long tail two more, and the hours were all clicking, not hardware.

The arrangement now, and the actual recommendation under this review: the ring key is the YubiKey I wrote about before, the drawer key is the Solo 2, and both are enrolled on the accounts where losing access would cost me days. Two vendors is the security feature here, more than any spec. A bug in one vendor's crypto, one bad firmware push, one bankruptcy, shouldn't take out both credentials for my email at once. Two YubiKeys share one firmware lineage. A YubiKey and a Solo 2 don't share anything, which is the point.

  • Buy two keys no matter whose, and enroll the backup the same evening as the primary. The drawer key is the product.
  • Set the PIN before first enrollment; some sites and browsers require it.
  • Update the Secure model's firmware deliberately, from the vendor's own GitHub, never from a link that arrived in a message.
  • If you want to verify instead of believe, the Hacker model at the same price is the honest way to do it.
  • If terminals aren't your thing, wait for the GUI or buy the boring key, because an update you're afraid to run is an update that never happens.

What I can verify about the Solo 2: the code, the schematics, the price, the store, the working FIDO2 stack in front of me. What I can't: a third-party audit of the firmware it runs, or the company's answer to what happens to the update pipeline when the team loses interest. Openness doesn't answer that for you. It lets you watch.

Register the drawer key the same week you register the ring one.