Hacker News new | ask | show | jobs
by techslave 2190 days ago
in california, if your employer requires you to have a phone for 2FA or other purposes, they must reimburse you at least partially. yubikeys are cheaper.

as to being clunky, it’s because your employer doesn’t care about it, so you have the clunky (and much cheaper) yubikeys.

lack of verification of who is using it is simply not an important part of the threat model.