> The attack surface of yubikey vs a laptop you carry around is interesting.
If you use the term "Yubikey" to describe the simplest model of Yubikey and not as a generic term to describe these security keys. Both Yubikey and their competitors are offering more advanced models: models which aren't simply unlocked by a tap on the device.
Then the attack surface compared to a laptop you carry around certainly becomes very interesting.
The security key I use most (I've got several models) have their own tiny screen and are protected by a PIN and won't work anymore after three wrong PINs (and let's not shift the goalpost by discussing what happens if you forget your PIN, that's another subject).
A friend of mine and his colleagues, sysadmins at a major ISP, all use "OnlyKey". They're protected by a PIN too (no screen but six digits on the security key). One PIN to register the security key, another PIN to auth.
Then there are security keys, including Yubikeys, only unlocked by fingerprints: now we're talking about Ethan Hawke stealing your laptop, your security key and recreating your fingerprints from a glass he stole at the bar (it's not impossible, but we're very far from "we stole your laptop while the session was unlocked").
> like a rubberducky or teensy flashed with some malware installing HID emulator.
Wait, what would a teensy used for nefarious purposes do here? You can't sniff what's inside the Yubikey. It's kinda the whole point: it's a challenge/response only answered by knowing a secret protected by the HSM on the Yubikey. There's nothing to sniff. If you didn't intercept and modify the key while the person registered on a service, you'll never be able to auth without unlocking the actual key which was used to register to the service. You may be able to sniff and relay the auth but you'd still not be able to extract the secret out of the security key.
> Because if not then all that added layer of secure feelings is pointless from an operational security perspective
I don't know: all the big security hacks we saw recently would all been stopped cold dead in their tracks had U2F/webauthn been used (like the, supposedly, Plex related on where one dev had a years old, compromised, version of Plex which was used to exploit his home computer, which then allowed to get inside the company's network for all was needed to log in to the company's network was to sniff a password).
Google reports there have been zero break ins since years, since when they moved all their employees to mandatory U2F (then switched to webauthn and I take it now to passkeys?).
I'm overall confused by your comment... What kind of attacks are you exactly talking about? Someone stealing your laptop then installing a teensy in your laptop and putting the laptop back in place, without you noticing? Or just someone stealing your laptop while the Yubikey is in it?
Are you actually saying that because some Yubikey aren't protected by a PIN and because some people leave this model of Yubikey in their laptop at all times, all security keys don't offer any additional protection compared to a laptop being stolen?