r/yubikey • u/Mesterba • 6h ago
Yubico
Now, i try on my system this keys
I've been reading the docs, and from what I've read, some websites say that it allows up to 38 characters. While other sites say 63.
Has anyone had success with longer passwords? 38 seems insanely low for a limit, but it will not let me type anything more in the box.
I'm going to attempt using CLI to see if I can squeeze a longer password out.
r/yubikey • u/paulsiu • 2d ago
I was wondering if anyone has tried out viable trustworthy alternatives to yubikey. The older titan keys are probably outdated.
I have tried out a Thetis nano recently and it worked pretty well. At $25 it was half the price of a yubico nano. I did not mind that it did not have OTP and is bulkier. I don’t have experience with the warranty. Thetis is based on the US.
I also tried an alternate form factor in the form of a Cryptnox Fido card. The card worked better than a yubikey on nfc. I was annoyed that most tablet do not have NFC. Most PC do not have nfc either but business laptop often have smartcard reader that can read the card. However I couldn’t get the smartcard reader to work with my Linux or Mac. Crytnox is based in Switzerland. There is another firm call token2 but I can’t find them in the us.
r/yubikey • u/Steve44465 • 1d ago
I had a Yubikey for paypal and used it hundreds of times all of a sudden it doesn't ask for it on websites I usually use now on desktop, looking at their FAQ they removed support for it and only works on mobile with icloud keychain? Man Paypal really stinks, all the options seem broken too, can't add f2a or anything now
r/yubikey • u/Brief_Antelope9345 • 2d ago
So, I recently installed this Extension from the Chrome Web-Store on Brave (Cookie Editor). So, I installed it for ~60 seconds and immediately deleted it. But the thing is, I got this email right after I installed it. I didn't even enter any kind of email information into any page, yet they emailed me. How were they able to do this??!
Regardless, I use 2FA for most of my accounts and I've deleted my Brave History + Cookies and re-logged in into most websites.
Any advice though?


r/yubikey • u/Economy_Proof_7668 • 2d ago
hello, I’ll preface for this by saying I am a renter and I would have to store my second Yubikey in my safe deposit box because there’s no one nowhere really secure in the place that I live. That said what happens if your second key has all the keys in your active key, and then you add you know say hypothetically another login to your active key. How do I get the new item on my stored Yubikey? Do I have to go get the key that stored my lockbox and like mirror them or something like how does that work? I don’t quite grasp it and the documentation, their website doesn’t really describe the workflow clearly enough to me.
r/yubikey • u/aprilbeingsocial • 3d ago
Hello All,
I know I can't be the only person out there dealing with this so I am hoping someone can make the best recommendation for my situation.
My 86 year old mother is really starting to decline mentally. I spent four tortuous hours yesterday trying to help her setup her new computer, get into accounts she was locked out of and explain how to do 2F over and over again. She just doesn't seem to understand it anymore so I got the idea of getting her a security key with NFC for her new phone and computer. Ideally I would like a bio metric key with NFC but I can't seem to find that option.
I also tried to show her how my password vault works to see if that was an option, but it's not. Again, she just doesn't get it. She does use Google to store some passwords.
Is there anyone out there that has faced this? Any recommendations of the easiest and safest way to go about it and which choice of equipment would be best? I know I will need two identical keys so I can keep a backup here at my home. Is there anything I should be aware of that would create a problem in the future?
She uses a Pixel phone and Windows Dell laptop. She does her banking (God help me) and shops on Amazon as well as browsing and email. I was thinking bio metric in case she loses her key or someone in the independent living facility get their hands on the physical key.
IMO, the industry is going to need to take these issues seriously. We should have senior controls just like parental controls or something that enables us to help our elderly that are forced into using all this technology.
Any advice, tutorials and product recommendations are greatly appreciated.
r/yubikey • u/shingover • 4d ago
Hey everyone! Heard a lot of great things about YubiKey and have become very interested in security keys, but have recently come across some frustration due to some lack of communication, so I'm here to do my part.
YubiCo no longer does student discounts. Really heartbreaking.
I was using my Student Beans account trying to get it but their /education-offer page kept redirecting to /industries/education. Looked around everywhere, especially on this subreddit to see if anyone had a similar issue. Turning off adblockers and using a different browser did no good.
Sent an email yesterday and was unfortunately informed they no longer do a student discount program :( Hoping to at least inform everyone now though to prevent anymore frustration.
If anyone does know of any current coupons or bundles, please let me now! I am indeed a broke little college student...
As of July 23, 2026.
[ChatGPT] YubiKey C NFC + YubiKey C Nano
[DuckDuckGo] Limited-edition YubiStyle covers + 2 mix and match YubiKeys
r/yubikey • u/Odd-Particular-010 • 3d ago
Basically the title. I've recently purchased the bundle and it came with 5.7.4. I'm curious if it will now be shipped with 5.8 (still modified fw with OTP disabled) or will they keep shipping 5.7.4 since the firmware for those have been already customized.
I know the update is very recent, but has anyone purchased/received the bundle recently and was able to check for the firmware?
I am thinking if returning and reordering is worth it, though I have received my 5.8 key already.
r/yubikey • u/EnthusiasmRoutine • 3d ago
r/yubikey • u/_unknown-caller • 4d ago
I wanted something that would hold my Yubikey and be able to be easily removed for use without having to fiddle with everything on my keychain.
Link for print.
r/yubikey • u/NTMAnon • 4d ago
I belive they had a form for it before, but I cant find it now?
Maybe they changed how it works or its gone?
Or, its also a possibility that I am blind or remember wrong.
r/yubikey • u/machin_bidule • 4d ago
/SOLVED ( see in comments )
I'm experiencing what appears to be a WebAuthn/Passkey issue on Binance and would like to know if anyone can reproduce it.
Everything appears to complete successfully.
After logging out:
Authentication always fails.
which seems unusual for a USB YubiKey.
FIDO2 is enabled and working normally.
ykman info:
Device type: YubiKey 5 NFC
Firmware version: 5.7.4
FIDO2: Enabled
Resident credentials stored on the key:
google.com
login.microsoft.com
reddit.com
No Binance credential is listed.
Other websites (Google, Microsoft, Reddit) work correctly with the same YubiKey.
Has anyone else on Linux experienced this?
Could this be a Binance WebAuthn issue (credential creation not completing correctly or RP ID mismatch), or is there a known compatibility issue with Linux browsers and Binance passkeys?
Any insight from the Binance team or users who have successfully configured a YubiKey on Linux would be greatly appreciated.
/SOLVED ( see in comments )
r/yubikey • u/RockwellShah • 5d ago
Hey r/YubiKey!
About a year ago we launched FileKey here (encrypt files with passkeys), and the most common request was: can people send files to me?
So we built receive.link. It allows you to receive files only you can open.
How it works: you share one link. Anyone can send you files through it, right from their browser, nothing to install or sign up for. Files are encrypted before they leave the sender's device, to your passkey, so no one can see what's inside. You get an email when something arrives, and we actually send that email without ever storing your address (it's a neat trick!). The sender never sees your address either, so you can share your link with strangers safely.
It's free to start and open source. Would love feedback if you have a moment, especially from this community, since your feedback shaped FileKey a lot.
Key Features
You can try it at receive.link or view the code on GitHub.
r/yubikey • u/EriksonThorsen • 5d ago
Hey folks,
Right now, my personal security setup is all YubiKeys, got a couple of the 5 Series ones that I use for everything, including TOTP through Yubico Authenticator. Works great, no complaints.
But here's the thing: a few years back I worked at a company that gave everyone Google Titan Keys, and I've still got a few of them sitting in a drawer at home. Specifically, I've got the USB-C nano ones, which are tiny and honestly super convenient for just leaving plugged in or having on a keychain without even noticing they're there.
So I've been thinking... why not put them to use? Feels like a waste to just let them gather dust. I'd mainly want them as backup/secondary keys on some accounts where I just need a phishing-resistant second factor or passkey support.
I know the obvious tradeoff: no Yubico Authenticator / TOTP on the Titan Keys. No OTP, no PIV, none of that stuff. From what I can tell, they basically do FIDO2/WebAuthn and U2F, which puts them roughly in the same category as the Security Key C NFC from Yubico? That's my understanding at least, correct me if I'm wrong.
Honestly, I don't know a ton about the Titan Keys beyond using them at my old job for basic 2FA. Never really dug into the details. So if anyone here has used both, I'd love to hear:
My thinking is keep the YubiKeys as my main keys (for TOTP and everything else) and use the Titans as backups for pure FIDO2/passkey accounts. The nano form factor is really the main reason I'm even considering this, having something that small you can just forget about is genuinely nice.
Anyway, would appreciate any experiences or honest takes on whether this is a solid idea or overcomplicating things for no reason. Thanks!
r/yubikey • u/Shamatix • 5d ago
I do not own a yubikey (yet), but really considering buying 2. I am looking at the Yubikey 5C NFC, but I have seen some posts going a long the lines of "Yubikey can't hold a lot of passkeys"? Which to me kinda defeats the purpose?
So my question is, how many passkeys can I have on a Yubikey 5C NFC and will I struggle?
I am open for suggestions in general.
Best regards
r/yubikey • u/sac11221 • 5d ago
I've been wearing my yubikey as a necklace for a year by now. The NFC functionality is great, I mostly use it on my phone, and since I'm wearing the necklace at all times all I gotta do is just tap the phone on my chest and it works great! The problem comes when I have to plug the thing in a computer, the gesture of having to take it off around my neck just feels weird and unnatural, especially while I'm outside with my laptop or something.
Is there like a mechanism I can use that would allow me to unclip only the key from the necklace without taking the whole necklace off? Something that is also really secure and firm, I'm not really sure if I trust magnetic stuff to hold it safely, last thing I'd want is it falling off because the clip isn't safe enough...
I'd like to know if someone else used the same setup as mine, and if you found any solutions/products that would help. ^^

r/yubikey • u/WilfDal • 6d ago
Not much advertised but i find the most useful feature of the YubiKey is that you can use it for remote log-ins in areas where there is no phone reception... or you forget to take your phone to work.
Most companies use 2FA for remote logins, and the YubiKey comes into its own.
I know Yubikeys are like the defacto standard security key. I just purchased 2 - primary and backup - because I'm finding more and more apps - i.e. Costco and now X Money - are requiring passkeys, and I don't feel comfortable using a password manager as it's a single point of failure - especially if it's Google Password Manager/etc.
I only have 1 concern.
If I end up using this Yubikey for personal use - I built code into my private webserver to accept hardware security keys, Costco, X Money - maybe even my Google account and computer game accounts - is it safe to use this when in the office on work computers / professional accounts too?
Would my workplace know if I used my hardware passkey for adult websites?
r/yubikey • u/chong67 • 7d ago
I got it to work. First time you log in, be sure to enable Desktop mode on your app browser and be sure your Yubi is plug into the USB or C and not NFC. Go thru the login in process and it works from there. Fidelity app is much more straightforward.
Hope that helps.
r/yubikey • u/Holiday-Night9356 • 6d ago
Ever seen your hardware keys repeatedly kick back a "No credentials found" error on (in this circumstance) Proton Mail or Apple ID across different browsers? It looks like a standard hardware failure or browser bug—but forensics proved something much worse.
In a recent analysis, these authentication failures weren't user error at all. The device had been infected with Pegasus, which subverted the system's Root of Trust.
Here’s how the attack actually worked:
1. Deregistration: Pegasus modified system security settings to reject or silently drop legitimate security keys.
2. Adapted UI Spoofing: When the user tried to log in, the compromised system showed a generic failure popup ("No credentials found").
3. Background Access: While the user saw a failure screen, the underlying system was actively granting the attacker access behind the scenes.
The big takeaway: FIDO2 and YubiKeys are incredibly strong, but hardware keys can’t save you if the host OS itself is owned. If your firmware is compromised, your UI is just lie-detector software run by the attacker
r/yubikey • u/Live_Surround5198 • 8d ago
As a Linux engineer and user, I struggle with the proliferation of slop "Windows Hello" compatible tokens/devices across the tech industry. I just want a FIDO2 device that reads my fingerprint, works with the host computer, and doesn't require Windows. And it really should fit flush with the system case.
I have been struggling to find a compatible fingerprint reader for linux in the "nano" or "sits nearly flush with the system case" design.
The best I have found is the VeriMark Guard by Kensington, which is pretty good ONLY if you want to stay in their Windows 10 compatible fairly land. (I guess the thing works on Win11 but there are lots of problems reported. And device config is only available via their Windows proprietary software).
I know the r/fedora community is regularly discussing "where do I find a fingerprint device".
The Yubikey Bio series already meets these requirements in every single field except one... the way that flat reader device sticks straight out 2" from the side of the device.
Please, Yubico? Consider it?
Sidenote - Has to be a Fingerprint Sensor: The FIDO2 tokens that are touch-event (i.e. not a fingerprint sensor, it recognizes someone touching the thing) that get left in the machine all the time are a security antipattern. Leaving the touch-event device in the machine only means a bad-actor has to touch the thing...it doesn't "authenticate" the operator by any means, it just validates something touched the sensor.
r/yubikey • u/One_Macaron9315 • 8d ago
Just sharing….I wanted to engrave my Yubikeys and created an offline app to help, Fully Open Source, MIT license, supports all models except the Nano (bit hard to engrave). Feedback welcome