Hardware You Hold, Keys You Own
Keys you own live on hardware you hold: wallet and mID on a phone chip, device-bound keys in eFuse and NVS on home boards — Security you can put in a pocket.

Keys you own are the opposite of a password stored in a company vault. Hardware you hold is the opposite of a key minted in a data center and downloaded as a file. Device-bound keys live in a chip you already carry — Secure Enclave, StrongBox, TPM — or in eFuse and NVS on a board that sits by the door. Steal the account database and you get scramble. Steal the laptop without the face or the finger and you still get scramble. Security becomes a physical fact: the key is in the room with you.
This is the Security primitive made something you can put in a pocket. The wallet is a view of money that never handed an aggregator your login. mID is the check that a token is yours, done locally, no OAuth phone-home. On a Home Companion board, the honest place for identity is an eFuse-wrapped secret that survives a reflash, not a default password printed on a sticker. Hardware you hold, keys you own — same sentence at three sizes.
Trust, Security, and Incentive land on silicon. You trust a chip you can throw in a bag. Security is the refusal of "we'll keep a spare key in case you forget." Incentive is a login that is faster than typing, and a house gadget that cannot be cloned from a firmware dump.
Why Keys You Own Must Live On Hardware You Hold
A key in the cloud is a key the cloud can be asked for. A key in a password field is a key a phishing page can catch. Device-bound keys close both holes. The private half never leaves the chip. The unlock is a biometric or a PIN the chip already understands. Hardware you hold is the whole threat model: lose the device, revoke it, enroll another from the vault you still have on a peer. Do not call a vendor to mint a replacement of you.
The NIST Zero Trust Architecture says every device is its own perimeter. Keys you own are how a person becomes a perimeter. The NIST Secure Software Development Framework is why the software talking to that chip should be memory-safe — a beautiful enclave next to a smashable C parser is a joke. Hardware you hold is only as serious as the process that asks it to sign.
The Electronic Frontier Foundation keeps repeating the lesson: recovery that requires a vendor is recovery the vendor can be compelled to abuse. Keys you own refuse that recovery. Friends backup is the human spare — shares, not a company escrow. Hardware you hold plus people you named is the adult pair.
Digital Freedom without this page is a slogan. A vault whose master key sat on a server was always a rental.
How Keys You Own Get Bound To A Device
You do not need a hardware-wallet hobby. You need the devices you already unlock every morning to be the place the secrets live.
Keys You Own In The Wallet And In mID
The wallet is the money face of keys you own. Balances on one screen. Credentials that never boarded an aggregator. The signing that says "this view is mine" happens on the phone you are holding. Hardware you hold is the bank card that does not photocopy well.
mID is the check on the other side of a login. A site verifies a token locally. No round trip to MATA. No JWKS refresh that becomes a warrant target. Device-bound keys make "Sign in with Sovereign ID" a tap, not a new password. Own your digital identity is the human walkthrough. This page is the pocket version: keys you own, chip you already have.
Hardware You Hold In The House — eFuse, NVS, A Board By The Door
A doorbell that phones home has a key in a vendor cloud. A Home Companion board should have keys you own in silicon on the board. eFuse holds a secret that is painful to extract and honest about what "device identity" means. NVS keeps the endpoint identity across a reflash so the camera is still the same peer after you update it. Hardware you hold includes the cheap plastic on the porch, not only the flagship phone.
You do not have to flash firmware at dinner to benefit. You have to refuse gadgets whose only identity is an account you typed into an app. Era 4 is that refusal at household scale. Device-bound keys are how the refusal is real.
Device-Bound Keys Versus A File You Copied To A USB Stick
A PEM file on a stick is hardware you hold in the weak sense. Anyone who images the stick has the key. Device-bound keys do not copy. They sign. Export is not the product. That is the property people hate the first time they hear it and love the first time a laptop is stolen at a cafe.
Keys you own in this stronger sense need a second device and a Friends list, because there is no "email me the key." Hardware you hold is a pair, not a singleton. The Freedom Guide enrolls the passkey first for that reason.
What Changes When Keys You Own Never Leave The Chip
Daily life gets quieter. Recovery gets more honest. The house gets less talkative.
Phishing Shrinks When Keys You Own Cannot Be Typed
A typed secret can be typed into the wrong box. Device-bound keys cannot. Hardware you hold answers a challenge the phishing site cannot complete. That is Security you feel as "I did not get owned by a fake bank page." Incentive is the same tap you already use to open the phone.
Leave the password-manager anxiety for the old web. Keep the apps. Change where the signing happens. What is Digital Freedom is that life, not a hair shirt.
Hardware You Hold Makes A Lost Phone A Revoke, Not A Life Sentence
Lose the phone. Revoke it from a peer that still has keys you own. Enroll the replacement. The vault was never only on the lost chip. Hardware you hold is plural on purpose. A single hero device is a single point of failure you chose.
If every device is gone, Friends backup is the door. Not MATA. Not a reset email. People and a threshold. That is Trust with a names list.
Incentive: Keys You Own Are Faster Than The Rental They Replace
Face ID is quicker than a password manager's extra hop through a vendor. A house that signs locally is quicker than a camera that waits on a region. Hardware you hold wins on time as well as on principle. The Disco Party later uses the same idea at mesh scale: identity on the guest, not at the door.
The Foundation of Trust is where this starts. The five eras are where it spreads to files, cameras, and a shop. Keys you own stay the non-negotiable. Hardware you hold stays the place they live. The Learn index is the next article when you want the family version, the photo version, or the era that puts a board on the porch.
The same key on a board is mID on the chip. What that key signs is the IAMHUMAN signature. Household custody is Digital Freedom for families.

