I understand that for someone that moves between multiple physical machines it may be a benefit of convenience, but what threat vector does a physical key eliminate that exists for passphrased "normal" SSH keys?
I understand that for someone that moves between multiple physical machines it may be a benefit of convenience, but what threat vector does a physical key eliminate that exists for passphrased "normal" SSH keys?
Even if the malware got your one time password when you thought you confirmed a legitimate operation, the attacker wouldn't get persistent access.
Edit: Also, most people don't use them, so some attackers won't bother with more complex target.
The second one is trickier since you need to do processing to prove that you have a private key, so you'd have to send the key to your own computer which breaks the whole point. You could use a separate "key" computer who owns the keys and that computer is the one that proves that it has the private key, but at that point you'd be better off using a normal security key since it's basically the same thing.
As for the simple storage device, you can just copy it to another one.
Also as others mentioned, the private bits are not exposed to the operating system, so no process can access it.
A dedicated hardware device never exposes the key to the OS itself - if your host gets compromised, power it off, re-image or replace it, and your keys are still protected - malware on the host didn't steal the underlying key. It might have pre-signed some attestations or similar (hopefully your token requires hardware user input like pushing a button to use it), but it won't have had any access to your key, so can't "clone" it.
You can also enforce usage of YubiKeys, but you can't really enforce every developer sets a passphrase on their locally generated SSH key file.
And it's a convenient, and consistent way of authentication: Your work Google Workspace account uses and enforces a YubiKey, your AWS account login uses and enforces a YubiKey, and now your GitHub account also uses (but cannot not yet be made to enforce AFAIK) a YubiKey. It's less hassle than using one-time codes with fifty-seven different apps and cloud environments, so there's not much user push back.