Hacker News new | ask | show | jobs
by jwr 2830 days ago
IMHO the YubiKey is not useful for any of those. It's excellent for storing OpenPGP keys and U2F, reasonably good for X.509 (as much as expected for X.509 I guess), and not good for much else. Using it for TOTP IMHO makes no sense, it's better to use your phone.
1 comments

Using it for TOTP makes sense if you have more than one phone or want to use TOTP on your desktop through Yubico authenticator.
Authy is excellent for this. I've got it on my phone and tablet. I'm reluctant to use it on my desktop because I don't want to type in a huge password but I regard my 2015 MacBook as less secure than my devices that are protected by touch. You might be OK with that or have a laptop with touch ID.
Exactly. Additionally phones can be rooted and that exposes the underlying secret but Yubikeys are tamper resistant.