Through my connection with PraizedMedia (a client of Les Laboratoires Phoenix- managed data infrastructure), I received a ‘Swekey‘ device. It look like an normal USB key, but their website seem to push toward something much more useful (and potentially dangerous). Hence, I decided to try it. It is advertised as :
The swekey is a small USB key that secures access to any swekey enabled web sites.
Swekey secured web sites won’t let you login without your swekey plugged to your computer.
The swekey can also be used to secure corporate’s intranet, unix servers access, and database administration.
[...]

Swekey device, Photo by Pascal Charest
The website mention integration with WordPress, SSH, putty, MediaWiki, Zabbix, Magento, SugarCRM… and much more… In fact they even speak about integration with any OpenID enabled websites – Might be very cool and interesting. Lets see how it work.
I’m an hacker at heart, so I don’t normally read much of a device documentation, but in this case – I was lost. How is the device working? Is it a key with auto-run partition + dedicated browser, is it the equivalent of an RSA key, is there any software to install ? To answer my questions, what would be better that some tests in a protected GNU/Linux workstation (which is what normal people do : plug it in and see what happen):
The device auto-detection work and recognize the device as an USB CDROM drive (from dmesg):
usb 2-8: new full speed USB device using ohci_hcd and address 3
usb 2-8: configuration #1 chosen from 1 choice
Initializing USB Mass Storage driver…
scsi10 : SCSI emulation for USB Mass Storage devices
usbcore: registered new interface driver usb-storage
USB Mass Storage support registered.
usb-storage: device found at 3
usb-storage: waiting for device to settle before scanning
usb-storage: device scan complete
scsi 10:0:0:0: CD-ROM Musbe Swekey 1.03 PQ: 0 ANSI: 0
sr1: scsi-1 drive
sr 10:0:0:0: Attached scsi CD-ROM sr1
sr 10:0:0:0: Attached scsi generic sg3 type 5
cdrom: This disc doesn’t have any tracks I recognize!
usb 2-8: reset full speed USB device using ohci_hcd and address 3
Then : Nothing. No auto-mount, no dialog box… Kinda of left there. The partition cannot be mounted…
Going to their website, I learn the official working steps: “BUY” (pseudo-done), “PLUG” (done), “REGISTER” (ugh?) and I’m “READY”. The REGISTER (the step I’m at, right ?) section give me an error of ‘missing plug-in’ from Mozilla Firefox 3.0.14. Ok, browsing “Support”/”Download” inform me of missing dependencies (a software must be installed) to access the device. I download the x64 GNU/Linux version and … hum ?
pcharest@hydra:~/Desktop/swekey$ cat README
Swekey client
This package install:
- the swekey-client command line tool
- the swekey HAL module
- the swekey Mozilla pluginThe swekey-client command line tool gives you the list of plugged swekeys
and let you calculate OTPs with them.type:
swekey-client –help
to get the available optionsTo install swekey-client just type:
sudo ./install
or
./install
if you are rootTo uninstall swekey-client just type:
sudo ./uninstall
or
./uninstall
if you are root
I have no idea what is an OTP but let say I try installing the client:
sudo ./install
and validate the device is detected:
./swekey-client –list
It work and give me a device ID. Good, at least the device is known by the system. I still don’t know how it should work. I guess I should be installing the Mozilla plug-in the readme mentionned, but… I never found it. I guess the client install worked (and it was included) because after a Mozilla reload, the Manage section of their web page give (or might also be one of the random file I clicked on) :
Registration is not mandatory but it will allow you to disable a lost or stolen Swekey.
So… I don’t really need to register the key… lets try it then (which I’ve been trying to do for quite a long time at this point).
I own quite a few Zabbix servers, so, from the list of supported service :
ZABBIX is an enterprise-class open source distributed monitoring solution.
A swekey integration exists, it is still a patch but you can ask for it if you need to test it.
Ok, still want to test the device – So i try with MediaWiki:
And it started to work well : creation of an account (user+password), then I get asked if I want to bind this account to my Swekey. This won’t allow me to auto-login but will require the key to be present in any computer (with the installed software) to access the account.
Summary: As a summary, I’d say that while it give a boosted security (require the Swekey to log) – it does seem to go a bit over the limit of the permanent fight between conviviality and security. Installing the software is complicated and might be very problematic on system without administrator access… Personally, having tried both, I would prefer Paypal key ID to be integrated to more website. There is no need to ‘install’ the software on any computer and it give you the same added security the Swekey does.
I just put the link of your blog on my Facebook Wall. very nice blog indeed.“–’
i understand i’m a little away topic, but i just wished to say i like the layout within your blog. i’m new towards blogegine platform, so any advice on getting my blog looking better can be appreciated.
http://necaisemlognserrate.corank.com/tech/framed/slow-Computer-Solution_2
I always visit your blog everyday to read new topics.”-*”;
I’m a blog crazed person and i love to read cool blog like yours.`-:.-
Thank you so much for your job, I do value your dedication and I suppose you have done more than I would count on. Thank you
http://www.thoughts.com/quitsmokingfast/quit-smoking-easy-and-natural-way-to-do-it quit smoking
The long-term tigers of terazosin [b]how does blood thinner coumadin[/b] on the quinidinesee of surgery, uninterested urinary resbala or stannous stockings of bph are physicaly to sidetrack determined.
Wow, you seem to be very knowledgable about this kind of topics.-;`~~
Perhaps you should also a put a forum site on your blog to increase reader interaction.`:’:’
An fascinating dialogue is value comment. I believe that you must write extra on this topic, it won’t be a taboo subject however typically people are not enough to talk on such topics. To the next. Cheers
Love your blog man! Would you be interested in exchanging links?
I have been reading out a few of your articles and i can claim clever stuff. I will definitely bookmark your website.
Wow, amazing weblog layout! How lengthy have you ever been running a blog for? you made running a blog look easy. The full glance of your site is magnificent, well the content material!
thanks for this great post wow… it’s very wonderful
Woh I like your content , saved to favorites ! .
This really helped me because I’m doing a project and your blog is so informative. Thanks and keep up the good work.
You’d outstanding recommendations there. I did a hunt on the matter and observed that quite possibly people i’ve talked to will agree with your weblog.
The new Zune browser is surprisingly good, but not as good as the iPod’s. It works well, but isn’t as fast as Safari, and has a clunkier interface. If you occasionally plan on using the web browser that’s not an issue, but if you’re planning to browse the web alot from your PMP then the iPod’s larger screen and better browser may be important.
I am typically to running a blog and i actually recognize your content. The article has really peaks my interest. I’m going to bookmark your site and keep checking for brand spanking new information.
It is perfect time to make some plans for the future and it is time to be happy. I’ve read this post and if I could I want to suggest you few interesting things or suggestions. Maybe you can write next articles referring to this article. I wish to read even more things about it!
You realize you’re getting previous when you stoop to tie your shoes and wonder what otherwise you can do while you’re down there.
Howdy for ones outstanding article, truthfully I am just essentially romantic the actual brand new Microsoft zune, expectation this kind, in addition to the extremely good feedbacks a few other humans have written, will help you to determine whether is it doesn’t answer you’re looking for.
http://www.iken-lifestyle.com/tw/forum/profile.php?mode=viewprofile&u=93664
you are actually a excellent webmaster. The site loading pace is incredible. It sort of feels that you’re doing any unique trick. Furthermore, The contents are masterpiece. you’ve performed a excellent job in this matter!
I ought to admit that your site is very interesting. I have spent a lot of my free time reading your content. Thank you a lot!
http://kube.ru/forum/profile.php?mode=viewprofile&u=1856
If its not to much to ask could you write some more about this. I have been reading your blog alot over the past few days and it has earned a place in my bookmarks.
A lot of of the commentary on this particular web site dont make sense.
Very well said, your blog says it all about that particular topic.,:.,”
I intended to send you a very small word in order to thank you very much again just for the exceptional advice you have documented in this article. It has been certainly strangely generous of people like you to supply freely just what a lot of people would’ve sold for an e book to earn some bucks on their own, certainly given that you might well have done it if you desired. Those techniques likewise acted like a good way to fully grasp someone else have the same interest much like mine to see very much more with regards to this problem. I think there are some more fun sessions ahead for folks who take a look at your website.
Your blog would increase in ranking if you post more often.~.*:`
The post was uninspiring. Life continues.
Hey just wanted to give you a quick heads up. The words in your post seem to be running off the screen in Firefox. I’m not sure if this is a formatting issue or something to do with browser compatibility but I figured I’d post to let you know. The layout look great though! Hope you get the problem fixed soon. Cheers
Ich hoffe es kommen weiterhin so gute Berichte. Immer auf den Punkt gebracht und immer informativ. Danke Danke Danke. Bis bald.
Everything is very open and very clear explanation of issues. was truly information. Your website is very useful. Thanks for sharing.
RSS Feeds on your blog sometimes does not work.`”;*,
Hello, Neat post. There is an issue together with your site in web explorer, would check this… IE nonetheless is the market chief and a good section of people will omit your great writing due to this problem.
http://www.traffictravisdownload.com/