The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.
The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.
I personally find the token much more convenient than a TOTP code via app on my smartphone. And the U2F/FIDO part is very interesting as it eliminates phishing as a risk.
I ordered a Yubikey 5 NFC just now to play around especially with the NFC part and see if I can do something useful on my phone with that. I'm still looking for a password manager that could use an NFC Yubikey to unlock it on a smartphone.
AFAIK that's what lastpass+yubikeyneo (nfc) did, and what this should also be able to do.
If you are using additional backup u2f token (2 tokens in total) hacker has chance 1:500 000 to find out correct PIN is my assumption right ?
WebAuthn, U2F and similar FIDO based schemes are sending some public key signed blobs over the network. A PIN is purely a local protection, it's not sent over the wire. So a hacker can't just try guessing the PIN. First they need to steal your physical token, only then could they start guessing PINs for the stolen token.
How does that work? Can't the challenge response be MITM?
I'm not saying it's not impossible, but the it's not the primary attack U2F is designed to prevent.
Works great
That said the cheaper yubi do this as well. I use my yubi 4 for securing my ssh key as well though this is a) a pain & b) likely theater.
Maybe I’ll look into a YubiKey though. My problem is that I’m halfway in my own personal transition from USB A to USB C
It's also faster and easier (no pulling out your phone, getting a code, typing it in, just touch the key).
Plus, the keys have other features (GPG keys, etc...) which can be useful.
[1] https://medium.com/@0x0ece/why-choosing-a-fido2-security-key...