Hacker News new | ask | show | jobs
by antonjs 993 days ago
As someone shopping for physical 2FA tokens right now, do you have any recommendations?
4 comments

YubiKeys.

Just use FIDO2. I have no idea why OP is trying to use the YubiKey OTP protocol, which is legacy.

I wasn't trying to use it, I was just looking around and came across the "YubiKey Personalization Tool", which doesn't show anything about FIDO2.

Now that FIDO2 has been mentioned as something that solves this issue, it turns out there's another tool called the "YubiKey Manager", which allows you to configure/toggle various "applications" on a key, including Yubico OTP and FIDO2.

YubiKeys are fine, just avoid their proprietary OTP thing. They're fairly configurable and also do FIDO/WebAuthn, as well as TOTP/HOTP, PGPcard and PIV.
I like my OnlyKey.
nitrokey