# Using Trezor as the only passkey to access nns.ic0.app

**URL:** <https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083>\
**Category:** Developers\
**Tags:** nns\
**Created:** [October 28, 2023, 12:08pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083 "2023-10-28T12:08:13Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 28, 2023, 12:08pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/1 "2023-10-28T12:08:13Z")

</div>

Ultimate target is above average security(better than on a pin-protected phone with a TPM chip that protected by fingerprint) while staying convinient to use

As I understand it, Ideally you’d go with quill and airgapped PC but this seems needlessly complicated and unconvinient, and all wiki docs I was able to find are terribly out of date

Let’s assume user does the following:

- creates a new Internet Identity and selects trezor as the only device allowed to sign-in
- doesn’t backup secret phrase offered on NNS
- creates a backup of trezor’s secret phrase instead and stores it securely
- remembers his 7 digit nns id
- protects his trezor with a strong PIN

How secure such scheme would be?

1. Can U2F be ALWAYS restored from a trezor seed phrase on another trezor device?
2. What if Trezor stops manufactoring or all trezor wallets vanish from existence completely, can I still sign-in by other means if I have my trezor secret phrase?

I dislike using ledger due to recent events(even a hint of private keys leaking makes me sick)  
quill and airgapped PC sound good but are inconvenient to use  
What are other secure alternatives I might be missing?

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 28, 2023, 7:01pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/2 "2023-10-28T19:01:58Z")

</div>

Hello?

Nobody is interested in discussing this?

---

<div class="post-metadata">

**Author:** ![amircryptola1](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@amircryptola1](https://forum.dfinity.org/u/amircryptola1)\
**Post date:** [October 28, 2023, 8:28pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/3 "2023-10-28T20:28:36Z")

</div>

It’s a Saturday, give people some time to respond 🙂

---

<div class="post-metadata">

**Author:** ![bjoern](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/bjoern/32/2100_2.png) [@bjoern](https://forum.dfinity.org/u/bjoern)\
**Post date:** [October 30, 2023, 9:00am UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/4 "2023-10-30T09:00:01Z")

</div>

There is no universally correct answer to your question. In particular, I don’t know how the U2F implementation on Trezor works, but from my experience with the U2F implementation on Ledger, I would strongly assume that setting up a second Trezor device with the same seed phrase should lead to the same keys used by the U2F app, and thus your proposed scheme makes sense. (You could test that by resetting your Trezor and setting it up from the seed phrase again.) I am using a Ledger U2F device as a backup method for my II, for exactly the same reasons. I don’t use it for day-to-day operations because it’s still somewhat inconvenient.

To respond to your questions more concretely:

1. While I would expect this to be true, since otherwise the U2F implementation on the Trezor would be entirely pointless, it’s something that you should be able to just try.
2. The following is worth a try (but I don’t know the answer): Is the Trezor U2F app compatible with the Ledger one?

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 30, 2023, 9:12am UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/5 "2023-10-30T09:12:59Z")

</div>

I verified that U2F secret on Trezor is deterministically derived from the seed phrase. Resetted my trezor to factory defaults and restored from the seed phrase, was able to sign in via U2F to nns app with no issues.

I would be grateful if someone who owns some other U2F capable device could check if it’s possible to enter the same seed phrase on BOTH devices(say trezor and ledger) and still be able to sign in to the nns app via U2F on BOTH devices.

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 30, 2023, 9:16am UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/6 "2023-10-30T09:16:45Z")

</div>

For the NNS app itself it could be cool if we could:

- to disable the warning of seed phrase backup. Burry it somewhere in settings and make a BIG RED warning where user should confirm

Ideally when I sign-in to the nns app via U2F and have the backup of the U2F device itself I would never-ever want to reveal the seed phrase on the nns app itself(oh no, seed phrase directly in mem of PC). It’s just an additional security threat to think about.

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 30, 2023, 9:18am UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/7 "2023-10-30T09:18:44Z")

</div>

Btw how come there’s a seed phrase on NNS available for backup, when I signed in via U2F?..  
I must be misunderstanding something fundamental here

---

<div class="post-metadata">

**Author:** ![bjoern](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/bjoern/32/2100_2.png) [@bjoern](https://forum.dfinity.org/u/bjoern)\
**Post date:** [October 30, 2023, 10:00am UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/8 "2023-10-30T10:00:15Z")

</div>

Just a quick note: The recovery phrase you see in II (that’s not in the NNS dapp) is _completely independent_ from the one on your Ledger or Trezor. The phrase is generated and maintained in the browser; it’s an additional one.

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 30, 2023, 10:54am UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/9 "2023-10-30T10:54:35Z")

</div>

Yea, I understood that. This is why I’m saying that in my case it’s an extra security threat I need to think how to take care about.

If someone manages to acquire this “different” seed phrase(I never want it to exist in the clear text in the first place, especially in memory of my PC jeez) - I’m screwed no matter if everything else I’ve done is still secure…

---

<div class="post-metadata">

**Author:** ![bjoern](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/bjoern/32/2100_2.png) [@bjoern](https://forum.dfinity.org/u/bjoern)\
**Post date:** [October 31, 2023, 1:51pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/10 "2023-10-31T13:51:55Z")

</div>

Yeah I agree. None of my IIs has the recovery phrase set up.

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 31, 2023, 2:10pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/11 "2023-10-31T14:10:45Z")

</div>

Is there any way this can be changed?..  
Seems like a huge security hole in my setup ☹

---

<div class="post-metadata">

**Author:** ![bjoern](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/bjoern/32/2100_2.png) [@bjoern](https://forum.dfinity.org/u/bjoern)\
**Post date:** [October 31, 2023, 3:05pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/12 "2023-10-31T15:05:15Z")

</div>

Can’t you just delete the seed phrase through the [II frontend](https://identity.ic0.app/)?

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 31, 2023, 3:20pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/13 "2023-10-31T15:20:44Z")

</div>

Ugh, I just noticed there’s a delete button.  
haha, dumb me

Thanks!

---

<div class="post-metadata">

**Author:** ![let4be](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/let4be/32/25128_2.png) [@let4be](https://forum.dfinity.org/u/let4be)\
**Post date:** [October 31, 2023, 3:26pm UTC](https://forum.dfinity.org/t/using-trezor-as-the-only-passkey-to-access-nns-ic0-app/24083/14 "2023-10-31T15:26:06Z")

</div>

I just checked once again on an empty II  
it’s not exactly what I want, in order to delete it I have first to REVEAL the seed phrase… and I want it to never exist in the clear text on my device in the first place

If I never set it in the first place, there’s nothing to delete and this dumb window asking me if I want to set it shows every time I log into nns.ic0.app
