Skip to content

Security

Identity sovereignty: why open-source hardware is the only real wall against phishing

Do you trust your company to passwords? Discover why open-source hardware (Nitrokey) and the FIDO2 standard are the only real defence against modern phishing.

Published updated 3 min read

In today's cybersecurity architecture, the perimeter is no longer a physical network. The new load-bearing wall is user identity. Yet most companies still entrust their most critical access (root accounts, system administrators, executives) to methods the modern attacker already knows how to get round with their eyes closed: passwords, SMS codes or software-based authenticator apps. If your security depends on something that can be copied, pasted or intercepted on a screen, you don't have security; you have a promise.

“In cybersecurity, convenience without sovereignty is simply a vulnerability with better marketing.”

The end of “blind faith” in closed hardware

When a company acquires closed-source (proprietary) security solutions, it is performing a dangerous act of faith. There is no humanly possible way to audit whether that hardware contains backdoors imposed by foreign surveillance legislation.

At Oksigenia, our methodology is based on radical transparency. That is why, in our deployments on Docker infrastructures and managed servers, we apply open-source hardware standards. This is where the German engineering of Nitrokey comes in.

Why FIDO2, and why auditable hardware?

Phishing-resistant authentication based on the FIDO2 standard is not a suggestion; it is the gold standard required by regulations such as the NIS2 directive in Europe and the high-security protocols in Latin America.

In a global context where foreign legislation such as the US Cloud Act can compromise closed-source devices, Oksigenia is committed to digital sovereignty. By integrating solutions based on Nitrokey hardware (Germany), we ensure that your company's “root of trust” does not depend on black boxes subject to the laws of third countries, but on transparent, auditable technology.

  • Impregnable by design: The private key never leaves the security chip. A hacker on the other side of the world cannot clone something that requires physical presence and a human touch. We raise the bar by using devices such as the Nitrokey 3, whose firmware is written entirely in Rust. This language guarantees memory safety by design, eliminating critical vulnerabilities such as buffer overflows.
  • Sovereignty versus “black boxes”: Because the hardware is 100% auditable and made in Germany, we remove any suspicion of industrial or government espionage. You can see what is inside the code; there are no secrets between the hardware and your business.
  • Operational efficiency: Implementing physical keys drastically reduces support incidents. This efficiency is backed by data: using these protocols cuts calls to technical support over lost credentials by 92%. We don't just protect your data; we optimise your IT costs by eliminating reactive password management.

The Oksigenia model: armoured identity

We don't sell “security USB sticks”. We design the managed identity protocol your business needs to be sovereign:

  1. Infrastructure hardening: We “weld” access to your Docker containers and VPS servers with physical keys. Without the authorised Nitrokey, unauthorised remote access is, quite simply, mathematically impossible. This level of armour in Debian and Docker environments meets the “state of the art” required by the NIS2 directive and the Esquema Nacional de Seguridad (ENS).
  2. Identity custody: We establish redundancy protocols. Your business continuity must never depend on a single lost physical device. We design the scheme of master and backup keys.
# Access level configured by Oksigenia:
$ login --identity-check
> Method: FIDO2_Hardware_Key [REQUIRED]
> Verification: Human_Touch_Detected [OK]
> Firmware_Audit: Open_Source_Verified [OK]
> Access: GRANTED (Sovereign Mode)

It is not security, it is sovereignty

If your organisation handles critical assets, you cannot afford security based on the “promises” of big corporations that won't let you see their blueprints. It is time to move to digital sovereignty. At Oksigenia, we combine the transparency of open source with the robustness of German hardware so that you are the sole owner of your access.

Is your infrastructure ready for the post-password world, or are you going to wait for the next attack to force you to change?