Is a separate USB key meaningfully more secure?
Is a separate USB key meaningfully more secure?
The user experience is also better with U2F than previous 2FA systems. When GitHub prompts you for U2F, you press the yubikey and are instantly logged in. No typing random numbers with n seconds, no fake keyboard.
YMMV of course, but if you've tried U2F, it feels incredibly slick.
I have a Yubikey on my keychain (it can easily withstand this), and it takes very little effort to plug it into the USB port when I require it. Less than it would be to take my phone out.
As a side-note, some time ago the Yubikey had a vulnerability with its GPG module so they shipped out new ones for free. I now have the old key (with no GPG keys loaded on it) permanently plugged into my USB hub at my desktop. It is amazingly convenient.
Heck, all someone needs to do is grab the one permanently plugged into your USB hub on your work desktop after you've left for the day.
Just sayin'...
If user security has taught us anything in the last 20 years, it's that security features have to be convenient or may as well not exist. I think we'll be seeing a lot more 2FA options in the next few years. In this segment, user choice is a huge improvement in and of itself. I've also been testing Duo push for some internal stuff, which is a phone-based experience that's as smooth as silk. To each their own!
For computers you frequently use, you can get multiple keys and leave them in the port (Yubico makes a small one that stays in the port and only sticks out enough for you to be able to touch it, but it's a bit pricey).
Passwords are weak vs. many types of hacks, U2F is strong. And vice-versa (easy to steal the Yubi-key + computer, but they still need the password).
Most of the USB keys are in a form factor that fits well on an existing key ring. If you are like most people, you presumably also already have a pile of keys connected to a key ring on you at all times.
You don't have to unlock your phone device and launch the appropriate app, you just need to plug into an open USB slot on the machine you are using.
The downside is that it takes a USB port, which is one of the reasons I hated this years MacBook so much.
UPDATE: I found the exact model I have on Amazon
http://www.amazon.com/Yubico-Y-110-YubiKey-NEO-n/dp/B00O8ST7...
A fully isolated component like a Yubikey has a smaller attack surface area for these kinds of things (easier to audit smaller code, no sustained Internet or cellular connectivity).
[1]https://www.duosecurity.com/blog/understanding-your-exposure...