For the specific combination of Macs with Touchbar and U2F and Chrome, you can already get this experience with onboard hardware. I expect most client devices will converge on having some kind of hardware-backed U2F credential built in. But Yubikey is more general right now. OTP is easy to implement and eminently compatible; it just presents as a keyboard and sends keystrokes. HMAC is great for not just authenticating but signing specific transactions. The GPG applet is just another GPG key, and the PIV applet is just another X.509 cert, so a number of applications can be upgraded to hardware-backed credentials with little or no change.
If your business is seeking "higher" assurance (yes, assurance levels are very subjective) then certificate-based MFA can meet the needs better. Or, if your business is working with sensitive data/systems, phones may be banned from the office (e.g. military, intelligence, banks, etc.).
It feels like Yubikeys are a shim until the phone UX as a factor improves (and there’s more server side support) and/or smart card adoption for identity improves. If Touch ID and Face ID are good enough for most secure transactions in the Apple ecosystem (including Apple Pay), seems like a reasonably high assurance.
Crooks know Barry's password but Push MFA is needed to sign into his account and conduct some crime
Crooks somehow get Barry to go to a site they control believing it is for Work [there are a lot of ways to do this step, links in email, hijacking forgotten subdomains, typo squatting, the list goes on]
The site says "Hi Barry, we need to do Push MFA"
Crooks sign into Barry's real account with the password, causing a Push MFA to happen.
Barry was expecting Push MFA because the bogus site prompted saying it would happen so OKs it.
Crooks have now successfully passed the MFA
One nice thing about Yubikey instead of phone, is that since it only does one thing, you are far less likely to need to upgrade it. In the past, I have lost a 2 factor on my phone when upgrading since it is not backed up.
e.g. my last big corporate employer would sometimes randomly take any laptops that had not been properly physically secured during a meeting or over lunch. You'd come back and somebody groans "Oh no, we were only gone a few minutes". Yes we were, and you didn't bother locking your laptop so now you're going to have to grovel to somebody to get it back.
Granted it does many things well, I think the most common case with Yubikeys is we only use them for one or two of their possible functions, and they’re cheap enough that this is okay; like a screw driver with half a dozen bits in the handle, but I just use the Philihp’s Head bit. In earlier Yubikeys, they could get stuck in PIV mode (like getting a bit stuck in your screwdriver), but I doubt anyone ever noticed.
There is something I intrinsically like about pressing a hardware button.
These are all relatively minor things, but they add up to a strong preference for the yubikey (I've used the simple blue u2f key with a button).
After reflecting on this list, I think the security model is probably the biggest one. In more colloquial terms: I'm already used to keeping track of my keys with a certain amount of care. A yubikey does not require me to adjust my habits; it's just another key.
My employer uses Duo, which supports phone push, yubikeys, or webauthn/touchID in chrome.
I almost always use touch ID. I do have a yubikey and phone push as a backup, but I really want to minimize using my personal device for work (and don't want to carry two phones).
A yubikey is much less obnoxious to carry around than an extra phone.
* Something you know (your username/password).
* Something you have. The Yubikey or other hardware token.
If you lose your Yubikey, by itself it should not allow access to anything. I keep mine on my keyring with my keys, which I haven't lost yet.
I also tried something like this https://www.amazon.com/Spider-Accessory-Split-Rings-Pack/dp/.... It worked pretty well for a few weeks, but then the central piece loosened up and the keys started falling off in my pocket; not recommended unless you can find one that's really sturdy.
as to being clunky, it’s because your employer doesn’t care about it, so you have the clunky (and much cheaper) yubikeys.
lack of verification of who is using it is simply not an important part of the threat model.