Not that I worry about that, but it is worth pointing out that you may lose some legal protections when you use physical things rather than your knowledge.
Not that I worry about that, but it is worth pointing out that you may lose some legal protections when you use physical things rather than your knowledge.
Additionally, it's a bit silly in the context of email since the authorities will obtain it from the service provider anyway.
That said, you can still add an encryption key to your phone and you're back to "knowledge based" with the additional caveat a thief would also need the hardware as well.
[1] https://news.ycombinator.com/item?id=33550824
[2] https://www.selectlawpartners.com/faqs/do-you-have-to-give-p...
More to the point, this is also not what the average computer user is worried about. It assumes that they’re targeted by police, have something they need to keep secret, and that those police can compel physical access but scrupulously obey civil rights protections.
There's nothing preventing you from password-protecting your YubiKeys.
Exceptions do exist; two I can think of are passkey-based cryptocurrency wallets and the so-called "PRF extension" that allows using a passkey as a source of entropy for e.g. locally encrypting a password manager's database.