Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have had a yubikey neo on my keychain for almost 4 years now. It is thin plastic and seemed like it might not hold up this long, but it has been going strong. I think they have changed designs to make it smaller since (which would be stronger). They do make solid products.

That said, I would rather use Google Authenticate (TOTP) for two factor. Getting my phone out is a regular thing. Getting the yubikey out and plugging it in seems more of a hassle. Passpack is the only thing I have to use the yubikey for -- would be happy if they provided TOTP. Spending $40 for two factor these days is kind of ridiculous.



Why not just leave it plugged in. That might be tricky in a train or so, but normally its fine. I use a Nano and just leave it in most of the time.

Its not only more convinient, its also far, far safer then TOTP.

The will not support TOPT because that would require constant power.

You can get a U2F only stick for 18 bucks from them. Once in a while (for example when github interduced U2F the sell 2 for 5$).


I regularly use 8 different devices (laptops and desktops). That's USD$400 in keys if I were to keep them in devices, not including shipping, currency conversion, etc.

Then there's the concern about who has access to those keys when I'm not around.

I keep a backup key in a safe location, and my primary on my keychain which is typically in my pocket.



TOTP requires an app, Yubico Authenticator.


Exactly, and if you are going to use an app anyway, you may as well have the app keep the token.


I actually still use it because this was I can use somebody else phone or some other device if I need to. That has come in very handy before.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: