Maybe the issue is just that it's so easy to attack password-protected systems that nobody even needs to attack keys.
Maybe the issue is just that it's so easy to attack password-protected systems that nobody even needs to attack keys.
Services that support them either have them locked down so hard that if you lose a single Yubikey (there's often no backup second key option), you're very screwed. Others go the other option, and have too easy to reset systems, SMS fallbacks, or other total bypasses of the security tokens.
For SSH and GPG, authentication keys are generally the least of your concern. The content you're controlling are much more valuable than the authentication itself. Can an attacker just wait until you SSH somewhere, and leverage that access? Can they wait until you'd press the button for another benign purpose and use that authentication in a malicious way? The answer is almost always yes, which reduces the value of these sort of devices substantially. They don't protect against local compromise, in which case a keyfile sitting on your local host is just as secure and a lot more convenient.
So I think in general private keys aren't improved with a token, since a compromised private key is supposed to be a local compromise.
In addition, these places tend to have less technical users and "plug it in and press during login" isn't terribly difficult
If an attacker can exfiltrate your private key they can probably keylog your passphrase & your VPN details
PIV/GPG smartcard solves he former and 2FA solves the latter so something like a yubikey/nitrokey gives you both in one device
Anecdotally I do have a friend who had his private key & passwords pilfered which was noticed when someone tried logging in from some other country.
There's a 2008 Fedora incident of this sort, a Fedora Administrator's private key was "stolen" by bad guys and used to upload replacement packages which is well documented e.g. https://lwn.net/Articles/326170/.
I think we should assume that this has also happened plenty of times to organisations which have a default posture of not telling you about incidents at all unless required by law.