If I tap the device while a malicious process is attempting to access another machine in the background, what good does this device do?
If I tap the device while a malicious process is attempting to access another machine in the background, what good does this device do?
From a threat model perspective, biometrics are far from perfect. This setup avoids disclosing the biometric to the host system though - the yubikey itself validates the biometric and signs (or doesn't sign) a response with an internal protected private key. If you had a sensor built into a laptop or workstation, you are trusting that sensor. Some old ones used to expose raw fingerprint data to the operating system, which is clearly bad.
If the user brings their own reader, you don't need to expose any biometric information beyond the yubikey itself (which is issued per user), so a host compromise or a rogue system won't be able to compromise someone's biometrics. Admittedly in this case a lot of the threat models that make sense would involve shared computers etc, and those have their own security issues.
Personal use case: I have my 1password account locked with a YubiKey, which means that if somebody would steal my credentials they can't get in without one of my devices. However, I still can technically use it from a browser on a friend's computer if I really needed to.