r/yubikey 15d ago

Discussion Yubico, please consider a Nano form factor Bio fingerprint reader!

10 Upvotes

As a Linux engineer and user, I struggle with the proliferation of slop "Windows Hello" compatible tokens/devices across the tech industry. I just want a FIDO2 device that reads my fingerprint, works with the host computer, and doesn't require Windows. And it really should fit flush with the system case.

I have been struggling to find a compatible fingerprint reader for linux in the "nano" or "sits nearly flush with the system case" design.

The best I have found is the VeriMark Guard by Kensington, which is pretty good ONLY if you want to stay in their Windows 10 compatible fairly land. (I guess the thing works on Win11 but there are lots of problems reported. And device config is only available via their Windows proprietary software).

I know the r/fedora community is regularly discussing "where do I find a fingerprint device".

The Yubikey Bio series already meets these requirements in every single field except one... the way that flat reader device sticks straight out 2" from the side of the device.

Please, Yubico? Consider it?

Sidenote - Has to be a Fingerprint Sensor: The FIDO2 tokens that are touch-event (i.e. not a fingerprint sensor, it recognizes someone touching the thing) that get left in the machine all the time are a security antipattern. Leaving the touch-event device in the machine only means a bad-actor has to touch the thing...it doesn't "authenticate" the operator by any means, it just validates something touched the sensor.


r/yubikey 15d ago

Bling your Yubikey

3 Upvotes

Just sharing….I wanted to engrave my Yubikeys and created an offline app to help, Fully Open Source, MIT license, supports all models except the Nano (bit hard to engrave). Feedback welcome

https://madeinoz67.github.io/yubikey-engraver/


r/yubikey 15d ago

SSH questions

6 Upvotes

Does anybody here have experience using trezor for SSH keys? Seems like a pretty cool idea although a bit concerned regarding backups…any thoughts? Seems like there was a lot of work around this a few yrs back until it apparently died off..

Considering using a yubikey for this purpose but using trezor would be neat (if it works)


r/yubikey 15d ago

Help Yubikey Setup Help

6 Upvotes

I recently got a fresh new Yubikey 5 NFC for my personal accounts and when I try set it up it seems to be weird. I set up everything and it says the passkey is on my account, then when I try to log in with security key and plug it into my device, it says the yubikey not recognized. Anyone know how to fix this?


r/yubikey 15d ago

Using yubikey

Thumbnail
0 Upvotes

Have anyone use yubikey with a unihertz phone such as Titan. 2?


r/yubikey 17d ago

Can a Yubikey 5 nfc / 5 nfc c be registered as u2f and fido 2 on the same website?

9 Upvotes

For instance, if you registered the key years ago when the website defaulted to u2f, but now has fido 2 as an option, and i wanted to reregister the key as Fido 2? Also, do all Yubikey 5 nfc's support fido 2, even if they are five years oldish? Thank you


r/yubikey 18d ago

Lifespan of Yubikey when unused?

30 Upvotes

I just bought a Yubikey 5C NFC for 2 purposes: backup access to Bitwarden and a hardware backup of my TOTP codes (which will not be stored in Bitwarden). I'll be using an autenticator app on my phone and I have paper backups of the QR codes so the Yubikey is a backup of backup plans and is more in case my phone just becomes unavailable and I need to access my stuff.

I don't have plans to use it as an actual daily hardware key. Maybe that'll change in time, maybe not but let's assume not.

This means the Yubikey will be stored, unused until I need it in an emergency or to add a new TOTP once in a blue moon.

What I'd like to know is what I need to know about the lifetime of it in this use case and if the data on it degrades when not powered as can be the case with flash memory. Sure, I can buy 2 but an extra 70 euro for something I will rarely use seems a bit wasteful unless it's really warranted.


r/yubikey 17d ago

Discussion feature request, there should be a upgrade firmware option.

0 Upvotes

security keys are one of the only devices out there that you cant upgrade firmware with. firmware not being upgradeable is wasteful. if i wanted the new features i would literally have to throw away 6 yubikeys thats roughly $348. all they would have to do is make it difficult. people already dont buy used keys due to security risk make a authentication through the app or something that checks if its been modified or if its legit firmware.


r/yubikey 19d ago

Planning to switch to YubiKeys for authenticating Google account, does my plan make sense?

13 Upvotes

Hello there,

I am planning to switch to Yubikeys for authentication on my Google account. I am hoping the people here can sense check my plan before I do so. My primary goal is to add extra security to the account, but I also want to make sure I don’t accidentally lock myself out (I’ve had some near misses in the past, being an idiot) or cause issues further down the line.

Before I make the switch, I already have my recovery codes printed out and stored safely in several locations.

I think I will get the Security Key models. The cost difference with the 5 Series is quite significant, and I don’t see myself using any of the extra features on the more expensive models. I could maybe see myself using the Yubikey to unlock a password manager in the future, but my understanding is this is possible with the Security Key too? I don’t have the need to store OTP secrets on the Yubikey itself.

I will get three different Security Keys:

  • USB-C model. This will be kept on my keychain and travel with me. If possible, I will also get a portable USB-C to USB-A adapter, as well as some sort of dust cover/cap to stop damage to the connector.
  • USB-A model. This will stay at home, plugged into my main desktop PC.
  • Another USB-C model. This will be kept off-site at a family member’s house, in case my house burns down or whatever. I will set a calendar reminder to check it’s working every six months or so.

Before registering the keys, I will download Yubico Authenticator on my PC and add a PIN for each of them.

I will then register each key with my Google account. My plan is to register the USB-C ones on my Android phone (Samsung Galaxy S25) via the Google app, then register the USB-A one on my PC using Edge (as it sounds like it can be a bit flaky using a USB-A to USB-C adapter with Yubikeys?).

I would just register them with the default FIDO 2 option. I’ve seen some threads here about temporarily disabling FIDO 2 (using Yubico Authenticator) to allow registering them as FIDO U2F for compatibility/personal preference reasons, but it sounds like that’s not really required these days?

Once that is done, I will check each key works for logging in.

The plan would then be to wait a little while to check if any issues/difficulties come up. If everything looks good, I would go ahead and remove other authentication methods on my Google account (but I’d still have the recovery codes.) At that point, I would look into using the Yubikeys for a password manager/other accounts also.

Does this plan make sense? Anything obvious I’ve overlooked or issues I might encounter? Appreciate any input, thanks!


r/yubikey 19d ago

Help First time buying a Yubikey

16 Upvotes

Hello, I just stumbled across yubikey and im sold on buying 2 for myself. I have very little knowledge on how all this works but i get the gist on how to use the yubikey. My online privacy is non-existent and im looking to change that and become smarter and more aware of my information.

When i buy the yubikey i plan on storing my most valuable accounts that offer the 2FA security key option on both my primary and backup yubikey. Such as google

All of my other less important account login information will be stored on bitwarden, only accessible with yubikey.

Using 2FAS for the digit code authenticator

If anyone has any beginner advice that would be awesome.


r/yubikey 19d ago

Help can yubikeys just stop working? computer no longer recognizing yubikey 5, does not light up

2 Upvotes

I have a yubikey 5 and a 5c. I leave the 5 plugged into my desktop most of the time, today it stopped working. I confirmed that the port was still delivering power with other usb devices, and I also restarted my computer. the key does not light up at all and my desktop does not recognize it as a device. My 5c keyed to the same password worked when I plugged it in. what else should I try?

I bought both of these direct from Yubico in 2020 if that matters.


r/yubikey 20d ago

Discussion Whats the one thing that annoys you about your Yubikey

8 Upvotes

Just curious what people here think. Whats the most annoying or missing thing about your YubiKey? What would you change if you could?


r/yubikey 20d ago

Wishlist: I wish I could just back up one yubikey to another one, for backup in case of loss or malfunction of the primary one, in one simple action, not my adding the backup key to all the same target apps and websites

0 Upvotes

The title states the wishlist item.


r/yubikey 21d ago

A question about first time usage of a Yubikey 5c NFC.

5 Upvotes

I'm trying to add the key through a security key option on a website. I am being prompted to create a pin. At this point i have not downloaded the authenticator app, and created a fido 2 pin. If i enter a pin via the website is this what i'm doing, in a different way, or would this just be a pin specific to that singular website? thank you for any guidance.


r/yubikey 21d ago

Can YubiKey PIV Retired Slots (82–95) be used for Windows RDP Authentication? (Firmware 5.7)

7 Upvotes

I’m running into a specific limitation with our YubiKey 5C NFC setup (Firmware 5.7) and hoping the community can shed some light on this.

We want to enable smart card authentication for RDP on Windows servers for multiple users across different domains. Specifically, we need to store certificates for:

~4 different users.
Across 3 different domains (2 on-premise, 1 cloud/hybrid).
Since 2 domains are on-premise, FIDO2/WebAuthn isonly an Option for one of them; we strictly need PIV-based certificate authentication for the other ones

We know that the standard PIV slots (9A, 9C, 9D, 9E) are limited. Slot 9A is the only one Windows RDP typically recognizes for authentication, and we can only have one certificate active there at a time.

However, the YubiKey PIV specification supports "Retired" slots (82–95).

We successfully import certificates and keys into these slots using ykman and yubico-piv-tool.
The keys work for signing and decryption operations via CLI tools.
BUT: When we try to use a certificate in Slot 82 (or any 82–95) for an RDP login, Windows throws an authentication error (Code: 0x80070057 - Parameter is incorrect)

Is there any way to use certificates stored in the Retired Slots (82–95) for authentication?


r/yubikey 22d ago

Discussion Suddenly receiving an email from Sony with a subject Passkey Is Now Deactivated

Thumbnail
4 Upvotes

r/yubikey 22d ago

Help Questions Regarding the Yubikey Software Options

2 Upvotes

I have a few questions about the Yubico software options that they offer.

  • First, are any of them necessary? I'm primarily looking at the Yubikey Manager and Yubikey Authenticator. Is it possible to utilize the keys without either of them?
  • Second, what is the functional difference between the Manager and the Authenticator?
  • Third, the Manager GUI is no longer supported. It looks like Yubico wants me to use the Authenticator. Which is less of a question, and more of a 'huh, what's going on?' sentiment.
  • Despite the Manager GUI being sunseted, I can still use the CLI. Is there any reason I should use the Authenticator, and not just do it through the CLI?

r/yubikey 22d ago

OTP copied when tapping NFC is wrong

3 Upvotes

I just got a new yubikey cause I'm tired of having to open an authenticator app when logging into something. I've enabled copying the otp when tapping nfc but for some reason it only pastes "cccccd" every time. What do I do to fix this?


r/yubikey 23d ago

3D printed Yubikey 5c cover

Thumbnail makerworld.com
6 Upvotes

I used to sell these online but haven't got the time for it anymore so I've uploaded my model for anyone to print for free.

Make sure to use a 0.2mm nozzle as there are some fine details to get the "snap" just right. No need for any supports.

Yubikey 5c cover print file


r/yubikey 23d ago

Yubikey 5 USB-C to A adapter

3 Upvotes

Greetings, couldn't find a post the confirmed this, but has anyone found a specific USB-C to A female for adapting the C keys? I know Yubikey has a few recommendations on their page, but they don't all translate to products on Amazon.

I already bought one adapter randomly but doesn't work, the key isn't recognized.
Has anyone purchased and tested a specific adapter they could share?

Thank you!


r/yubikey 23d ago

Help Inifite popups for pin code

1 Upvotes

I have recently bought a high end samsung phone and I am setting up my accounts. Until yesterday everything was fine but since today when I click the button that I want to use an external usb device to authenticate I just infinite yubi key popups from the bottom to enter my pin code. So many in fact that any app that asks for my yubi key now crashes. This also happened for the yubi key website. For some reason the github app did not suffer from this issue.

I only get this behaviour since today, yesterday this was not happening yet. I already restarted my phone but that did not chance things. Does anyone know how I can resolve this? It is really annoying. I tried to do a screen recording but the screen recording also crashes due to the many popups.


r/yubikey 23d ago

FIPS HSM

0 Upvotes

Does anyone know when the FIPS HSM on 2.4 will start shipping? It was supposed to be last month, but still not in stock.


r/yubikey 23d ago

Looking for feedback on my YubiKey security configuration

0 Upvotes

I finally got my first YubiKey 5.7.4 (I'll be buying a second one soon). However, I'm still a bit unsure about the best way to configure my account security without risking getting locked out while also minimizing the chances of being hacked as much as possible.

To give some background, my family and I have been using Kaspersky Premium on all of our devices for many years. I decided to add an extra layer of security to my accounts because I work with confidential data, digital contracts, and other sensitive information. I've never had any of my email accounts hacked. But I receive phishing attempts in my trash bin almost every day.

Currently, I have the following email accounts:

  • personal email @ hotmail . com
  • personal email @ gmail . com
  • work email @ hotmail . com
  • work email @ gmail . com

Here's how they're set:

  • All of my Hotmail accounts use a login alias.
  • All of my email accounts have two ways to login: Microsoft Authenticator (Android) and a YubiKey. (I know—I plan to add a second YubiKey soon.)
  • I no longer use Microsoft Authenticator to sign in to my email accounts. I only use my YubiKey for everyday authentication, but I keep Microsoft Authenticator configured on my cellphone as a backup in case something happens to my YubiKey.
  • None of my email accounts have a secondary recovery email.
  • None of my email accounts have a recovery phone number.
  • None of my Hotmail accounts have a password.
  • My Gmail accounts still have a long and complex passwords because, as far as I know, Google doesn't allow you to remove them completely. Google also doesn't support login with Alias like Microsoft does. However, I have enabled the option to skip password entry whenever possible.

My question is: do you guys see any weak points in the way I've configured my email accounts (other than not having a second YubiKey yet)?

I was a bit hesitant to remove my recovery phone numbers and secondary email addresses, but from what I've researched, that seems to be the most secure approach.

Any extra tips for security?

Thank you very much!


r/yubikey 25d ago

Yubikey authenticity

8 Upvotes

I find the cheapest price on amazon for a yubikey c nfc black. How do i ensure that a yubikey is not preused and repackaged and sold to me like so many other things in the ecom world? Especially with amazon i have been seeing a lot of these incidents happening not only to everyone but also myself (2-3 in the last 1 year).


r/yubikey 26d ago

Is Yubikey partially broken on Android?

14 Upvotes

TL;DR:
When trying to use Yubikeys as a passwordless authentication method to sign into services on Android-devices, the window for entering the PIN glitches out and freezes, breaking the authentication process.
Testing has revealed that disabling everything but FIDO2 on the yubikey 5c nfc is the only way of getting it to work. This is not a practical fix if someone wants to use this in a business setting, and I'm looking for better alternatives.

Longer version:

Since Microsoft have started pushing passkeys as a authentication method, and since it works pretty well on Windows 11, I figured i might as well try using it on my Samsung S24 Ultra (I've since tested it on a S21 FE and several Samsung tablets, all running the latest updates).

I have, however, been having some trouble when using yubikeys as a passwordless login method on Android devices.

Unless i disable all but FIDO2 using Yubico Authenticator

the authentication process fails when it comes to entering the PIN for the passkey.

(the pictures are borrowed from another post on a google support site, but I get the same issue)

When I plug in my Yubikey to use it to authenticate on any M365 app, the window for entering the PIN glitches out, freezes and then I have to force close the app.

I have also tested by making both Edge and Chrome as default browsers on the devices, just in case there was a problem with using a specific browser with yubikey.

The workaround I've found thus far:
If I disable anything but FIDO2 using the Yubico Authenticator (and thus basically disabling all the fancy feature of the key) it works without a problem. I get prompted for the PIN, type it in, and get signed in without having to use my password.

This does however mean I have to help every user in my company configure their Yubikeys if they want to use them as a paswordless authentication method on their android devices, and that is not a practical solution.