My ssh keys never leave the yubikey.
I have a different dedicated yubikey in each computer, with its own unique key, and a stolen key is useless without its unlock PIN.
My ssh keys never leave the yubikey.
I have a different dedicated yubikey in each computer, with its own unique key, and a stolen key is useless without its unlock PIN.
Do you leave computers in weird places? Are you getting robbed once a year? Are you a high stakes poker player or CEO of a shady company?
I have like 4 laptops and two main desktops and if I didn't have 4 yubikeys in them then this would be a multiple-times-daily occurrence. Yubikeys aren't that expensive, and I mostly use the usb-c "nano" ones which are designed to live 24/7 in a computer's port, only sticking out about 2-3mm. Sometimes I have to move them around to other temporary machines but for the most part having approximately the same number of keys and computer workstations means that this is pretty infrequent.
I even have two Davinci Resolve Studio activation dongles for this same reason, and I can't physically edit video on two different computers at once, one would do if I were willing to keep track of where it is and shuffle it around between my various machines as needed.
It's pure speed/convenience, not a response to some data threat.
you don't need the physical key to "enroll", you just keep a copy of its pubkey.
So, the ideia is for you to have two devices, each with its own key, the first device you use daily and the second you use store in a safe location.
if your first device in daily use stop working or is lost you use the second device you have stored to login to your systems to remove the keys from the lost device and add the keys for a new device that replace it and then store the second device back in a safe location.
I wrote about my endeavour with this approach just few days ago [1].
[1]: https://github.com/Ciantic/thoughts/blob/master/2021/yubikey...
Most VPS provides "web console" access. It connects like terminal, like Digital Ocean's web-console that doesn't require SSH access [1].
[1]: https://www.digitalocean.com/docs/droplets/resources/console...
As backup you can also use OpenPGP cards which cost much less than a yubikey. Or a cheaper Fido2 token if you use Fido2 for SSH access (I don't yet but it's coming into vogue). An OpenPGP card will cost about a tenner, you'll need a card reader to use it but for backup purposes it's perfect.
Using Yubikey to mean U2F is like people saying "Google this term", "the image is Photoshopped", "Hoover the floor", "grab me a Kleenex", or even "take the escalator". It possible "Yubikey" could become a generic trademark, but if possible people should be wary of using brand names in this way before it 'sticks'.
Additionally, the term Yubikey isn't likely to become synonymous with 2FA in any case. Most people don't know that yubikeys work in several different, independent modes, such as FIDO/U2F 2FA, or CCID smartcard, or Yubico OTP (those long annoying strings your yubikey types when it brushes your thigh or hand).
The CCID smartcard mode requires a pin, which is technically two factor authentication (knowledge of PIN and possession of yubikey), which is an entirely different thing than FIDO/U2F 2FA (which is what most people mean when they talk about using a yubikey for 2FA, not that "yubikey" and "2FA" are interchangeable terms).
This is further complicated by the fact that CCID smartcard mode can be used for ssh (via gpg-agent, with ssh keys inside the yubikey itself), AND, separately, OpenSSH (with other keys) can use a yubikey for U2F.