How viable do you think this project is?

Northstrix

Free Member
Nov 7, 2023
26
4
Hello everyone!

For the last one and a half years, I have been working on Midbar, a hardware data vault. Unlike hardware authentication devices, it can store your login credentials, credit card information, notes, and phone numbers. Midbar encrypts your data and requires a master password and, in some cases, four additional RFID cards to access it. With Midbar, you don't have to worry about memorizing the login credentials and credit card information for the services you use. It does that for you.
Compared to software vaults, Midbar provides more security because it does not have thousands of other processes running alongside it, significantly contributing to making it almost invulnerable to side-channel attacks. Additionally, Midbar utilizes sophisticated integrity verification and superencryption features.

Recently, I started having thoughts about turning Midbar into a startup in the near future. I figured that before I make any decision on that matter I should go to a couple of forums and ask for your opinion on this project.
Does this project seem useful to you?
Would you actually buy Midbar if it was available on the market? If you would how much would you be willing to pay for it?

Please tell me what you think about Midbar and its viability. Your opinion is very important to me.

The complete source code of Midbar as well as lots of links to tutorials for various versions of Midbar are available on my GitHub page. My nickname there is the same as on that forum. (I can't post a link here for the reason unknown to me)

Best regards,
Maxim Bortnikov
 
Hi @Northstrix and welcome to UKBF.

TBH, I'm not at all sure what it is you do. Why is this a hardware data vault if all you are doing is storing my CC details? Something my browser already does for me.

@Nico Albrecht may have an opinion on this.
 
Upvote 0
I didn't understand a word of what it is that you do.

Is that important? It depends on whether I am your target customer (or a conduit to that customer).

In most cases the viability/ success of your business won't be down to the brilliance of your product, but where you position it in terms of your customer's needs and wants

Who is your customer?
What need / desire do you fulfill?
Why will they want your product over someone else's?
 
  • Like
Reactions: ethical PR
Upvote 0
Are you saying that this is basically a portable physical data repository that is unlocked by physical means (such as rfid cards) so sort of the data equivalent of a briefcase handcuffed to a couriers wrist ? A usb stick with a physical padlock to stop unauthorised access ?

I can see it having a use for some sectors but i think they are quite niche and not me - even when i was dealing with loads of sensitive personal data what we did was weapons grade encrypt the zipped data file then write to a portable usb stick that was formatted ext3 (in the expectation if dropped and picked up by A.N.Other it would likely be reformatted by any machine they put it in)
 
Upvote 0
I don't think I'm your target market, primarily because I prefer to travel as light as possible so wouldn't want to carry around a physical "vault" in addition to a physical unlock device. I don't even travel with any payment cards, no wallet or cash, and when I need to pay for things my watch (or mobile if I'm carrying my phone) does it for me.
These days I usually only travel with my watch on my wrist and some earbuds to listen to Spotify (via my watch). An App on my watch can also unlock my car, and as more cars have this ability I see less and less cars needing their own keys.

I may not be your target market, but as general feedback I would refer you to the last three questions @Mark T Jones asked in his post above. Answer these and then pass the Mum Test and you will be on the right track.
 
Last edited:
  • Like
Reactions: Mark T Jones
Upvote 0
Hi @Northstrix and welcome to UKBF.

TBH, I'm not at all sure what it is you do. Why is this a hardware data vault if all you are doing is storing my CC details? Something my browser already does for me.

@Nico Albrecht may have an opinion on this.
You're right, your browser extension, and the established password manager can perform the same fucntion as the hardware data (password) vault that I've developed. The only difference between them is that a hardware data vault is much harder to crack. The encryption used by most of the existing solutions such as password managers is extremely strong and almost uncrackable, but, the problem with the password managers is that this piece of software runs on a machine with thousands of other processes running alongside it, and some of these processes can be malicious.
Hardware password vault unlike it's software equivalent, is almost completely isolated from the external world, making it extremely hard to hack because in addition to the strong encryption, the are no processes running on it except from those that are required for the vault to function. If you use a hardware password vault, you kind of exchanging convenience for the additional layer of security.
 
Upvote 0
If you use a hardware password vault, you kind of exchanging convenience for the additional layer of security.
Who have you identified as your ideal type of customer, for example which industry sectors?
My next question would be, have you done any market research into that sector to see what they currently use and why they currently use it. This part of your Business Plan will help you identify the size of market, whether it is viable, and what your marketing strategy would be to win orders from them.
 
Upvote 0
Not only credit card details, but also the arbitrary strings that you choose to encrypt.
Nope. No idea what this even means.

Which is the whole problem. Your idea needs to pass the Mum test.
 
Upvote 0
I didn't understand a word of what it is that you do.

Is that important? It depends on whether I am your target customer (or a conduit to that customer).

In most cases the viability/ success of your business won't be down to the brilliance of your product, but where you position it in terms of your customer's needs and wants

Who is your customer?
What need / desire do you fulfill?
Why will they want your product over someone else's?
I assume that my customers are the people who have a lot to loose if they're personal data gets stolen, and they'd rather pay an extra $100 (or similar amount of money) for a physical data vault where they can store their login credentials, credit card information, notes, and phone numbers then lose a fortune if their data gets stolen.

Midbar allows its owner to store their data in a digital fortress, so they can have a bit more peace of mind. So if a user desires to exchange the convenience for the utmost security, they can have it.

I believe that a customer would want Midbar over someone else's product for several reasons:
  • High level of security that's not provided to them by the software vaults;
  • Open-source code. So the customer can audit it (or pay someone else to do it for them) and find out for themselves how secure it really is;
  • Since its source code is open, Midbar can be customized as much as the user wants and the underlying hardware allows.
 
Upvote 0
Who have you identified as your ideal type of customer, for example which industry sectors?
My next question would be, have you done any market research into that sector to see what they currently use and why they currently use it. This part of your Business Plan will help you identify the size of market, whether it is viable, and what your marketing strategy would be to win orders from them.
Thank you for that and for the previous suggestions.

Ideal type of customer is the one who has a lot to lose if their data gets stolen.
As for the industry sector, mostly sectors that handle a lot of payments and have lots of banking accounts, like banks and import/export companies,
I haven't done a lot of market research, although after taking a look at the market I discovered that there are only two things where Midbar excels over its competitors.
  • It's much secure than its software alternative;
  • Unlike hardware authentication keys, Midbar can also store user data such as notes, credit card information, and phone numbers.
 
Upvote 0
Are you saying that this is basically a portable physical data repository that is unlocked by physical means (such as rfid cards) so sort of the data equivalent of a briefcase handcuffed to a couriers wrist ? A usb stick with a physical padlock to stop unauthorised access ?

I can see it having a use for some sectors but i think they are quite niche and not me - even when i was dealing with loads of sensitive personal data what we did was weapons grade encrypt the zipped data file then write to a portable usb stick that was formatted ext3 (in the expectation if dropped and picked up by A.N.Other it would likely be reformatted by any machine they put it in)
To some extent yes. It's unlocked either by a master password that you enter on a separate keyboard connected to the device, or by a combination of the master password and four RFID cards.
Let me give you an example of the difference between the Midbar and its sofware equivalent.
Imagine the two fortresses.
One of them is standing in the middle of a metropolis with thousands of malicious actors trying to break in.
Another one is as good as the first one, except it stands on a distant island separated from the world by an ocean, so when it comes to breaking in, it's hard to break in to both of these, but, if you attempt to break into the second fortress, you first need to reach it.
 
Upvote 0
Thank you for that and for the previous suggestions.

Ideal type of customer is the one who has a lot to lose if their data gets stolen.
As for the industry sector, mostly sectors that handle a lot of payments and have lots of banking accounts, like banks and import/export companies,
I haven't done a lot of market research, although after taking a look at the market I discovered that there are only two things where Midbar excels over its competitors.
  • It's much secure than its software alternative;
  • Unlike hardware authentication keys, Midbar can also store user data such as notes, credit card information, and phone numbers.
So basically it's competeing on two fronts at the same time.
Who have you identified as your ideal type of customer, for example which industry sectors?
My next question would be, have you done any market research into that sector to see what they currently use and why they currently use it. This part of your Business Plan will help you identify the size of market, whether it is viable, and what your marketing strategy would be to win orders from them.
So basically it would compete on two fronts:
1) It would directly compete on the "secure storage of information" market (don't how else to call it)
2) It would indirectly compete with the hardware authentication keys because it does their job but offers more features.
 
Upvote 0
Ideal type of customer is the one who has a lot to lose if their data gets stolen.
As for the industry sector, mostly sectors that handle a lot of payments and have lots of banking accounts, like banks and import/export companies,
This is too vague. You want to be very specific; such as your target market is truck drivers in the south of England who hold a HGV3 licence in their 30's to 50's. You want to really narrow it down, very specifically.
I haven't done a lot of market research
Then you can do this part. You do need to step back and think about your market, marketing and research. I know @Mark T Jones has written a guide on business planning but I cannot find it, maybe you can add a link Mark?
 
  • Like
Reactions: ctrlbrk
Upvote 0
This is too vague. You want to be very specific; such as your target market is truck drivers in the south of England who hold a HGV3 licence in their 30's to 50's. You want to really narrow it down, very specifically.
Ok, thank you.
One thing though, do I need to focus on one market, or can I narrow it down for the several markets at the same time?
 
Upvote 0
I assume that my customers are the people who have a lot to loose if they're personal data gets stolen, and they'd rather pay an extra $100 (or similar amount of money) for a physical data vault where they can store their login credentials, credit card information, notes, and phone numbers then lose a fortune if their data gets stolen.
Or they could buy a safe from Argos and do the same.
 
Upvote 0
. It's unlocked either by a master password that you enter on a separate keyboard connected to the device, or by a combination of the master password and four RFID cards.
So, I need to carry a keyboard around with me or have 4 additional cards in my wallet (which defeats the object)!

Can this be done on a smartphone?

YOu really need to define your specific market and not generalise on 'people with a lot to lose' - too vague. If there was a miltary or top level security application, you could use this to demonstrate the benefits.
 
Upvote 0
So, I need to carry a keyboard around with me or have 4 additional cards in my wallet (which defeats the object)!

Can this be done on a smartphone?

YOu really need to define your specific market and not generalise on 'people with a lot to lose' - too vague. If there was a miltary or top level security application, you could use this to demonstrate the benefits.
Yes, you need to have an external keyboard to interact with Midbar.
Of course it can be done on the phone, but then it would be no different from the established password managers, and perhaps there would be no point developing a new password manager while there are lots of good and time tested options.
But the point of Midbar is to provide the extra security by removing the vault away from any foreign process.
That's actually one of the reasons why I called this project Midbar (desert in Hebrew), because it when I looked at the password vault market I discovered that it's basically a desert around the thriving oasis of the password manager market.
 
Upvote 0
I almost get it but not quite. Is this device a USB dongle so is essentially air-gapped when not plugged in or radio? If radio, how is it as secure as you say?

The main problem with encryption is that in order to use the information the computer must un-encrypt it. The key to do that must be in the PC which is surrounded by all the other processes that you say aren't running on your device but at the point of encryption/unencryption they are. If the bad actor is already in the PC how will your device stop access to the data its protecting?

What happens if I lose the device or leave it at home? Is my PC bricked?

It's not widely known that full disk encryption is available for all operating systems and you've already bought it, at the moment I'm not seeing a major advantage but I am seeing a few problems, ,unanswered questions and a major inconvenience. But this might be because I don't fully understand it yet.

I think you need to spell out your proposition more fully. A good way of doing that is to imagine you have the product fully developed and write an advert for it.
 
Upvote 0
I think you need to spell out your proposition more fully. A good way of doing that is to imagine you have the product fully developed and write an advert for it.
Thanks, I'll take it into account,
I almost get it but not quite. Is this device a USB dongle so is essentially air-gapped when not plugged in or radio? If radio, how is it as secure as you say?

The main problem with encryption is that in order to use the information the computer must un-encrypt it. The key to do that must be in the PC which is surrounded by all the other processes that you say aren't running on your device but at the point of encryption/unencryption they are. If the bad actor is already in the PC how will your device stop access to the data its protecting?

What happens if I lose the device or leave it at home? Is my PC bricked?

It's not widely known that full disk encryption is available for all operating systems and you've already bought it, at the moment I'm not seeing a major advantage but I am seeing a few problems, ,unanswered questions and a major inconvenience. But this might be because I don't fully understand it yet.

It's not a USB dongle it's a separate device that doesn't need a PC to operate once it programmed.
Midbar encrypts the user data using its own keys that are partially derived from the master password that you enter on a separate keyboard connected it.

If your PC is already infected with the malicious software, then only what you enter on it would be compromised. Unfortunately Midbar doesn't protect from that.

I think taking look at photos of Midbar might give you better understanding of what this device is, unfortunately I can't post a link here. You can find lots of photos of Midbar in the GitHub repository. my nickname there is the same as on this forum.
 
Upvote 0
Thanks, I'll take it into account,


It's not a USB dongle it's a separate device that doesn't need a PC to operate once it programmed.
Midbar encrypts the user data using its own keys that are partially derived from the master password that you enter on a separate keyboard connected it.

If your PC is already infected with the malicious software, then only what you enter on it would be compromised. Unfortunately Midbar doesn't protect from that.

I think taking look at photos of Midbar might give you better understanding of what this device is, unfortunately I can't post a link here. You can find lots of photos of Midbar in the GitHub repository. my nickname there is the same as on this forum.
By the way, only part of the encryption keys are stored in the permanent memory, another part of the encryption keys is derived every time you enter the master password and disappears when you power the Midbar off.
 
Upvote 0
It sounds like a solution looking for a problem, but that could be because I don't get how it works, or who would want to use it. One may help define the other...

You've not explained it to any useful extent, you've talked around some of its functionality and some of what it can do, but not what it physically is or how it actually works in any given situation; e.g.
  • What is its form factor, what does it weigh etc
  • How does it work; e.g. what do I have to connect it to add/retrieve data, plus what access points are there; wi-fi, Bluetooth, USB etc and how do these work
  • What access does it have to the processes you describe it as being used for; e.g. a credit card is useful because it's physical (a card with the relevant info on it), or can be uploaded in a digital wallet to pay for things. A physical vault, not so much if I need a laptop to access my card data in a shop, or to pay online I have to run some 3rd party application on my laptop rather than typing my card details in or using Apple Pay etc
  • How does it replace/interact with other 3rd party security and 2FA; e.g. if I'm using it with any banking/payment type situation, the 3D secure and 2FA processes are driven by the bank side security, so you will still need to use their app, or receive a text to complete any security processes
  • If to use cards/banking etc you still need to use other security measures and expose data using the normal online/app/wallet security solutions, how does the vault help anyone
A stand alone siloed security product in a cloud driven connected world would have very limited uses that I can see. As the vault would not be able to access any other 2FA type security services unless you agreed commercial terms and licensed the product to those 3rd parties.
 
  • Like
Reactions: ctrlbrk
Upvote 0
It sounds like a solution looking for a problem, but that could be because I don't get how it works, or who would want to use it. One may help define the other...

You've not explained it to any useful extent, you've talked around some of its functionality and some of what it can do, but not what it physically is or how it actually works in any given situation; e.g.
  • What is its form factor, what does it weigh etc
  • How does it work; e.g. what do I have to connect it to add/retrieve data, plus what access points are there; wi-fi, Bluetooth, USB etc and how do these work
  • What access does it have to the processes you describe it as being used for; e.g. a credit card is useful because it's physical (a card with the relevant info on it), or can be uploaded in a digital wallet to pay for things. A physical vault, not so much if I need a laptop to access my card data in a shop, or to pay online I have to run some 3rd party application on my laptop rather than typing my card details in or using Apple Pay etc
  • How does it replace/interact with other 3rd party security and 2FA; e.g. if I'm using it with any banking/payment type situation, the 3D secure and 2FA processes are driven by the bank side security, so you will still need to use their app, or receive a text to complete any security processes
  • If to use cards/banking etc you still need to use other security measures and expose data using the normal online/app/wallet security solutions, how does the vault help anyone
A stand alone siloed security product in a cloud driven connected world would have very limited uses that I can see. As the vault would not be able to access any other 2FA type security services unless you agreed commercial terms and licensed the product to those 3rd parties.
  • Midbar is still at the stage of being the DIY project, it's to early to talk bout the form factor and weight, but I guess that the weight of the lightest version of Midbar with battery should exceed half a kilo. as form the form factor, I believe it would be similar to the iPhone 4.
  • Only one version of Midbar connects to the Wi-Fi, a version that stores the data in the cloud (just google "DIY IoT Data Vault With Google Firebase (Midbar Firebase Edition V1.0)" you should be able to easily find a tutorial for it). Other (roughly couple a dozen) versions of Midbar store the data either on the SD card or in the microcontroller built-in flash memory. You can retrieve data from Midbar either by connecting it to a computer and retrieving it via the USB keyboard emulation or the Serial Terminal software, depending on a version. Or you can simply look at display, and manually type the data on the keyboard.
  • When it comes to processes, a program that runs on your computer has to share its resources with other programs, from the point of the operating system these are all processes (one program can be split into a couple of dozen processes if not more). Midbar works completely independently from your computer, and it doesn't have an operating system. It only does what it's programmed to do. This approach makes it almost invulnerable to the side channel attacks.
  • 3D secure isn't supported;
  • 2FA isn't supported, but can be added in the future, it's actually not that hard to add;
  • Unfortunately, Midbar is powerless when it comes to protecting your computer from the malicious software. The purpose of Midbar is to serve you as a "digital fortress on a remote island" that has the cutting edge security features combined with the physical isolation from networks and other computational devices (except for that one version of Midbar that stores encrypted user data in the cloud).
 
Upvote 0
  • Midbar is still at the stage of being the DIY project, it's to early to talk bout the form factor and weight, but I guess that the weight of the lightest version of Midbar with battery should exceed half a kilo. as form the form factor, I believe it would be similar to the iPhone 4.
  • Only one version of Midbar connects to the Wi-Fi, a version that stores the data in the cloud (just google "DIY IoT Data Vault With Google Firebase (Midbar Firebase Edition V1.0)" you should be able to easily find a tutorial for it). Other (roughly couple a dozen) versions of Midbar store the data either on the SD card or in the microcontroller built-in flash memory. You can retrieve data from Midbar either by connecting it to a computer and retrieving it via the USB keyboard emulation or the Serial Terminal software, depending on a version. Or you can simply look at display, and manually type the data on the keyboard.
  • When it comes to processes, a program that runs on your computer has to share its resources with other programs, from the point of the operating system these are all processes (one program can be split into a couple of dozen processes if not more). Midbar works completely independently from your computer, and it doesn't have an operating system. It only does what it's programmed to do. This approach makes it almost invulnerable to the side channel attacks.
  • 3D secure isn't supported;
  • 2FA isn't supported, but can be added in the future, it's actually not that hard to add;
  • Unfortunately, Midbar is powerless when it comes to protecting your computer from the malicious software. The purpose of Midbar is to serve you as a "digital fortress on a remote island" that has the cutting edge security features combined with the physical isolation from networks and other computational devices (except for that one version of Midbar that stores encrypted user data in the cloud).
Yep, but what's it for? You say credit cards, secure keys/strings etc. However, almost all the scenarios you describe will mean the secure data regularly needs to be entered in to computers, apps, wallets, epos systems etc, exposing them to the very scenarios Midbar can't protect from.

As you don't intend for it to be compatible with any 3rd party security systems, I don't see what added security this then gives, nor who the target user would be?
 
Upvote 0
It’s still very confusing. If I go to the pub and want to pay for my beer I tap my credit card on the reader.

If I buy a gentleman’s magazine online I enter my card details.

If I buy petrol for the car I use the card reader on the pump.

Why do I need to lug your mid bar around to do all that?

You really haven’t yet sold me a good reason why I need your product.
 
  • Like
Reactions: ctrlbrk
Upvote 0
Yep, but what's it for? You say credit cards, secure keys/strings etc. However, almost all the scenarios you describe will mean the secure data regularly needs to be entered in to computers, apps, wallets, epos systems etc, exposing them to the very scenarios Midbar can't protect from.

As you don't intend for it to be compatible with any 3rd party security systems, I don't see what added security this then gives, nor who the target user would be?
I guess that's the end of the road. It seems to me that in my attempt to make the whole "securely store data -> securely make use of data" chain stronger I simply made the already strong and almost unbreakable part of it even stronger while neglecting the actual fragile part and making it less convenient.
I guess that Midbar would either remain a mark on my portfolio or if I'm lucky and put enough effort to it becomes a very niche device for the customers with very specific needs, for whom securely storing data is actually more important that "securely making use of it."

Anyway. Thank you all for your feedback. I would definitely have something to think about for at least a couple of days (if not weeks).
 
  • Like
Reactions: Ozzy
Upvote 0
It’s still very confusing. If I go to the pub and want to pay for my beer I tap my credit card on the reader.

If I buy a gentleman’s magazine online I enter my card details.

If I buy petrol for the car I use the card reader on the pump.

Why do I need to lug your mid bar around to do all that?

You really haven’t yet sold me a good reason why I need your product.
Well maybe you're right. There's no reason why you would need Midbar if you value convenience of using the services around you.
I guess it can be primarily useful for the small minority of customers who, for example, have lots of credit cards and bank accounts, and for whom securely storing them in a safe place, and picking some of them up from time to time while making some notes along the way is much more important that convenience of paying for the goods with one tap of a card.
 
Upvote 0
Well maybe you're right. There's no reason why you would need Midbar if you value convenience of using the services around you.
I guess it can be primarily useful for the small minority of customers who, for example, have lots of credit cards and bank accounts, and for whom securely storing them in a safe place, and picking some of them up from time to time while making some notes along the way is much more important that convenience of paying for the goods with one tap of a card.
I suspect that will be a very small number of people. And they will no doubt already have secure systems in place. If they don’t they are unlikely to ever seek out a product such as yours.

Don’t want to be all negative but you still haven’t made a compelling case as to why your metal wallet is any better than keeping my leather wallet zipped up in my inside pocket.
 
Upvote 0
hardware data vault. Unlike hardware authentication devices, it can store your login credentials, credit card information, notes, and phone numbers. Midbar encrypts your data and requires a master password
How does your solution compare with Samsung Knox ( Whitepaper here ) Specially with Knox Vault providing independent from the primary processor that runs Android, code running on the Knox Vault Processor is resistant to attacks that exploit shared resources, such as software side-channel attacks that can compromise other software executing on the same processor.

This separation means Knox Vault protects sensitive data even if the primary processor itself is completely compromised.

The list of really cool features and what it can do can be found in the whitepaper listed above.

How does your solution you developed would hold against Samsung Knox development which is rated at military grade protection and very easy to use for an end user.
 
Last edited:
  • Like
Reactions: fisicx
Upvote 0
How does your solution compare with Samsung Knox ( Whitepaper here ) Specially with Knox Vault providing independent from the primary processor that runs Android, code running on the Knox Vault Processor is resistant to attacks that exploit shared resources, such as software side-channel attacks that can compromise other software executing on the same processor.

This separation means Knox Vault protects sensitive data even if the primary processor itself is completely compromised.

The list of really cool features and what it can do can be found in the whitepaper listed above.

How does your solution you developed would hold against Samsung Knox development which is rated at military grade protection and very easy to use for an end user.

WOW. That's an amazing technology, it's everything I wanted Midbar to be and even more than that.
It seems to me that this technology offers more security than Midbar while also being more convenient than an average established password manager.
It even offers protection from differential power analysis, something that I'm still learning to defend against.
I guess that the best argument for the Midbar I have left is "If you can't afford a device that supports Samsung Knox, you can buy a device that is, at the very best, 30% version of Knox. And you can get the complete source code of that device for free."
Anyway, thank you for introducing me to that technology.
I guess I'll have to completely rethink the concept of Midbar.
 
Upvote 0
If you can't afford a device that supports Samsung Knox,
You're looking at this in the wrong light. Samsung Knox is an entire subsystem integrated alongside the existing phone. Samsung invested over $100 million in its development, testing, and verification. Even the most advanced labs worldwide haven't identified any flaws or security issues in it yet.

There's speculation that Samsung could potentially manufacture the entire Knox system, hardware, and software combined, for under $18 per unit and selling it to 3rd parties ensuring healthy profit margins on top.

Third-party companies could acquire it at $18 per unit, add their customized hardware enclosures, include additional features, and create a product costing, let's say, $36. This could then be retailed for around $99 or £79.

Currently, Knox technology is exclusive to Samsung Galaxy S21 and later models. However, there's no barrier preventing Samsung from selling it to third parties tomorrow. Can you match such competitive pricing and robust security features at that price point. Don't forget the convenience Knox offers in comparison to yours.
 
Last edited:
  • Like
Reactions: fisicx
Upvote 0
You're looking at this in the wrong light. Samsung Knox is an entire subsystem integrated alongside the existing phone. Samsung invested over $100 million in its development, testing, and verification. Even the most advanced labs worldwide haven't identified any flaws or security issues in it yet.

There's speculation that Samsung could potentially manufacture the entire Knox system, hardware, and software combined, for under $18 per unit and selling it to 3rd parties ensuring healthy profit margins on top.

Third-party companies could acquire it at $18 per unit, add their customized hardware enclosures, include additional features, and create a product costing, let's say, $36. This could then be retailed for around $99 or £79.

Currently, Knox technology is exclusive to Samsung Galaxy S21 and later models. However, there's no barrier preventing Samsung from selling it to third parties tomorrow. Can you match such competitive pricing and robust security features at that price point. Don't forget the convenience Knox offers in comparison to yours.
If that's the case there's no way Midbar can compete with Knox for a significant share of the market.
Even if I get rid of the expensive display and use the plain STM32 as the core coupled with the cheap OLED and 12 buttons, the cost of components for the version without battery would be roughly $7 - $10, not to mention the cost of assembly and an SD card. And still it wouldn't be a subsystem that would function alongside your phone.
It seems to me that what I would end up with (in the best case scenario) is a $40 - $50 vault (for which you need to buy an external SD card) that has some cryptographic features utilized by Knox, offers some protection from the side channel attacks (definitely more than a software password vault), but not merely as good as the Knox. And not merely well designed and integrated as Knox.
I guess in that case, the the only unique thing I could offer to the potential customers is the complete source code of Midbar (that they can get for free anyway).
Assuming of course, that Samsung won't choose the Red Hat model (open source code, but you pay for using it), because if they do, then the whole market is theirs and it would be nearly impossible to compete with them.
Thank you for bringing this case. That was helpful.
 
Upvote 0
Skimming through thus again, it shows a very consistent trend in posts by enthusiastic product creators, in that the OP has fully engaged with anyone who wants to discuss the tech, whilst glossing over posts around real marketing.

I've no idea whether thus is a viable market, but here are things that I do know

1. The target market isn't techies - they will just distract and tie you in knots with tech talk.

2. The likely end user will give a nod to technology, but will actually buy on their own criteria, possibly

Compliance
Ease of use
Portability

(All guesses until market research is done)

3. If there is a market, the winner will be the one with the best marketing, not the one with the best tech.

This is the essence of business!
 
Upvote 0
Skimming through thus again, it shows a very consistent trend in posts by enthusiastic product creators, in that the OP has fully engaged with anyone who wants to discuss the tech, whilst glossing over posts around real marketing.

I've no idea whether thus is a viable market, but here are things that I do know

1. The target market isn't techies - they will just distract and tie you in knots with tech talk.

2. The likely end user will give a nod to technology, but will actually buy on their own criteria, possibly

Compliance
Ease of use
Portability

(All guesses until market research is done)

3. If there is a market, the winner will be the one with the best marketing, not the one with the best tech.

This is the essence of business!
Thank you for your feedback. I think I finally got it.
 
Upvote 0
It seems to me now that the best way to make Midbar competitive on the market is to make it fit on your key chain, light as a USB flash drive, equip it with the convenient software that would allow you to interact with Midbar without knowing a thing about the technology it's built-on, make it stylish, launch a good promotion for it, convince the end user that this device is exactly what they need to solve their problems (whatever they might be), and do an extensive market research before even considering what to do with it and whether I should even try to get Midbar to the market.

In any case. Thank you all for your feedback. That was very helpful to me.
 
Upvote 0
So all you offer is an encrypted flash drive with some sort of app that lets me access the data.

Pretty much the same as hundreds of existing vendors already sell.
 
Upvote 0
So all you offer is an encrypted flash drive with some sort of app that lets me access the data.

Pretty much the same as hundreds of existing vendors already sell.
Well, I believe that at that point I don't even know what I should offer. All I have now is several versions of a DIY project with open source code, I don't know what to turn it into, and whether I should even try to bring it to the market. The more time I spend on this forum, the better I'm beginning to understand that I focused too much on the technical part of the project, while neglecting the marketing part. It seems to me that I should stop guessing what to do with Midbar and do a firm market analysis instead.
 
  • Like
Reactions: fisicx
Upvote 0

Latest Articles