Here's five great uses for your YubiKey (2024)

Key Takeaways

  • Enhance SSH security with a YubiKey
  • Replace TOTP apps with a YubiKey
  • Safeguard passwords with a YubiKey

YubiKeys have been on the scene for well over a decade now, and have slowly but surely been growing to support more and more use cases. YubiKeys offer a second hardware factor for authentication, requiring not only that a code or key is provided, but that the physical device is inserted as well. They even include a physical button, or biometric sensor on some models, to ensure that the device is physically touched and can't be remotely manipulated. Here are some great ways to make use of your YubiKey that you might not be taking advantage of yet.

5 Secure SSH with your YubiKey

Great for homelabs or cloud-resourcesHere's five great uses for your YubiKey (1)

If you're a bit of a homelabber, have a home NAS or media server, or run servers in the cloud, one great use for your YubiKey is to add it as a second authentication factor to your SSH connections. This will require your YubiKey to be connected to the device initializing the SSH connection, and can require physical input or touch identification as well.

There are multiple ways to set this up, each with its pros and cons, outlined in Yubico's documentation. If you're just authenticating to a Linux server you control, we'd recommend using FIDO2, although there are other options. PGP keys can be generated on your YubiKey and used with OpenSSH, but FIDO is the easiest to set up. You'll want to generate a discoverable key, which means that your key can be used by any computer that it's inserted into, in order to generate an SSH key that resides on your YubiKey. You'll need to secure it with a pin. The generated public key will be stored on your computer, while the private key file generated is simply a reference to the actual private key, which is stored on your YubiKey.

There are some caveats to be aware of. At the time of writing, this wasn't supported on Windows, and the bundled version of OpenSSH on macOS disables this functionality.

4 Generate TOTP codes with your YubiKey

Replace authenticator apps with your hardware key

Here's five great uses for your YubiKey (2)

One of the best uses for a YubiKey is to replace your regular authenticator apps. Most two-factor authentication codes for websites and apps use a technology known as TOTP, or Time-Based One-Time password. This is the four or six-digit code generated by your authentication app when you log in to an app or website. TOTP works by saving a secret to your device (often encoded in a QR code), which works in conjunction with a hashing algorithm and a counter to generate time-based codes. In effect, this means that both your device and the server need to keep track of the counter, based on the current time, in order to be aware of which hashed value is valid at a given time.

While this is mostly done in authentication apps, your YubiKey is capable of generating these codes for you. It can even require hardware authentication (like biometric/touch) to do so. This is a great security improvement, since someone who has been able to remotely compromise the device your codes are on remotely would not be able to physically grant access (this is also why it's safest to keep your 2FA codes on a phone or mobile device, not on your laptop or PC.)

Not all YubiKeys support TOTP 2FA, but the documentation makes it easy to set up using the Yubico Authenticator desktop app.

3 Secure your password manager with a YubiKey

Add an extra step to your most valuable login

Password managers have been all the rage in recent years and have some big advantages to offer. Using them to generate a unique, random password for each website you visit can help protect against your passwords being lost in data breaches, and help simplify your online life by providing secure, cloud-synced access to all your passwords in a central location.

Most password managers require at least one second authentication factor (as well as a strong master password), and your YubiKey is perfect for this. I use Bitwarden, which offers easy integration (for enterprise or premium users) to incorporate the use of any recent YubiKey. Ensure you save your recovery codes somewhere safe though, as losing access to your second factor, i.e. losing your YubiKey, can leave you permanently locked out of your account. Due to how password managers like Bitwarden encrypt your data to limit their access to your passwords, there's nothing they can do once your account is locked, which could potentially leave you locked out of all of your accounts!

If you're self-hosting Bitwarden, fret not, YubiKeys are supported there too!

Your mileage may vary depending on your password manager, but most should support YubiKeys natively. If not, you can always use a TOTP code on your YubiKey in its place.

2 Secure your online accounts

It's easy to miss sites that support hardware keys

Here's five great uses for your YubiKey (3)

Source: Yubico

This one is a little obvious, but it's surprisingly easy to forget to set up your YubiKey on some websites. The list of supported sites is growing all the time. Some examples of how I've personally overlooked using my YubiKey would be to secure my iCloud, GitHub, and AWS IAM logins. Other common sites like Reddit, YouTube, and Instagram all have support, which can greatly help protect your logins.

It's worth reviewing the list of supported services (which is growing all the time) on Yubico's website. It's also worth taking some time, perhaps on a lazy Sunday, to double-check that you've saved recovery codes for your second factor on all of these sites. Remember, if your YubiKey is lost or stolen you'll no longer be able to access your login.

1 Secure your desktop logins

Great if you want some extra security on your devices

Here's five great uses for your YubiKey (4)

Source: Yubico

If you're concerned about the physical security of your device, this can offer some reassurance. Both macOS and Windows support using your YubiKey to log in to your local accounts, although there might be some caveats. Windows only supports login for local accounts, meaning that this is unsupported if your PC is set up with a Microsoft account (don't worry though, you can convert it reasonably painlessly).

On Windows, you'll need to install the Yubico Login Configuration app, which will register itself as a separate authentication provider. From there, you'll need to enter both your regular local account username and password, as well as insert your YubiKey. You won't need to press your YubiKey, and again, it's important to save your recovery codes.

macOS is simpler, allowing you to pair your YubiKey as a smart card in any version of macOS past High Sierra. You'll need to download the YubiKey Manager application, where there's a designated option to set things up for macOS. You'll need to set a pin. Your Mac will then ask you for your pin in the login field to authenticate with a YubiKey when locked. Unlike Windows, there are some significant caveats to setting your YubiKey as the only authentication method on macOS, so we don't recommend it. You'll still be able to use touch ID to log in, as well as your regular user password, so we recommend setting a strong password and keeping it somewhere safe (like a backup key).

YubiKeys are great for enhancing your security

YubiKeys are great for enhancing both your practical security and your own peace of mind. In today's world of seemingly endless threats and scares online, it can be reassuring to have something you physically own and control which keeps your accounts truly safe. We should note that YubiKeys, while some of the most popular and well-supported, aren't the only hardware keys available. Some alternative models can be cheaper and more accessible, though they may sacrifice some features.

We'd recommend everyone consider a YubiKey if you are looking to enhance your security online, especially if you want to get away from using your phone for annoying 2FA codes without sacrificing the security.

Here's five great uses for your YubiKey (2024)

FAQs

Here's five great uses for your YubiKey? ›

A single YubiKey has multiple functions for securing your login to email, online services, apps, computers, and even physical spaces. Use any YubiKey feature, or use them all.

What can I use my YubiKey for? ›

A single YubiKey has multiple functions for securing your login to email, online services, apps, computers, and even physical spaces. Use any YubiKey feature, or use them all.

Is Yubico a Chinese company? ›

Founded in 2007 by former CEO now Chief Evangelist Stina Ehrensvärd, Yubico is a private company with offices in Santa Clara, CA, Bellevue, WA, and Stockholm, Sweden. Yubico CTO, Jakob Ehrensvärd, is the lead author of the original strong authentication specification that became known as Universal 2nd Factor (U2F).

What are the benefits of YubiKey 5? ›

Highest assurance authentication that's fast and easy

A physical security key, that can be added to a keychain and plugged into a computer, tablet or mobile device, adds an extra layer of protection on top of passwords to offer the strongest second factor authentication protection against phishing attacks.

Should I keep my YubiKey plugged in? ›

Do I need to keep my yubikey plugged in all the time? A. No, you only need to insert your yubikey when you are prompted to do so during login. Leaving it plugged in could result in the yubikey being lost or damaged.

What can I store on a YubiKey? ›

The YubiKey is designed to be a user authentication or identification device. The applications on the YubiKey hardware are limited to contain only authentication secrets and keys either generated internally or loaded by users; none of the functions on a YubiKey are designed for mass storage of data.

Can I use a YubiKey for personal use? ›

Find all the ways you can stay secure with a YubiKey

Whether it is for work or personal use, or both, leverage the Works with YubiKey program to find all the dynamic ways you can stay secure online, at work, or on your favorite device with helpful tips and how-to guides.

Why is Yubico so expensive? ›

It is costly to design, mould, manufacture, sell and support a hardware product, even something as small as this. Since you don't want your 2FA company to go out of business there is good value in knowing they have a stable business model that can actually support a company rather than just burning capital.

Is buying a YubiKey worth it? ›

The Yubico Security Key C NFC is the best choice: It's affordable and will work with just about every site that supports security keys. If you're already familiar with security keys and need or want more-advanced features, the Yubico YubiKey 5C NFC is a pricier but worthwhile choice.

Can YubiKey have malware? ›

Yubico's YubiKey is built on a foundation of strong authentication. This robust resistance to phishing offers malware protection because it hinges on the ability to detect these attacks before they take place.

What is the lifespan of a YubiKey? ›

A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites.

What happens if someone steals your YubiKey? ›

So, what happens if you lose your YubiKey? In that case, you can still use your Authenticator app (phew!). While you can't create a backup YubiKey, you can always contact Yubico to get a replacement key.

Where should I put my YubiKey? ›

Insert your YubiKey in your computer's USB port, and touch it or press the button on it. Give your browser permission to access your YubiKey, if needed.

Does YubiKey work without Internet? ›

Unlike SMS codes and mobile push authentication, YubiKeys do not require a cellular connection to operate. In fact, they don't even require batteries or have any other external dependency. Simply plug the key into a USB port on your device and touch to authenticate.

Do I have to use YubiKey every time? ›

YubiKeys and Security Keys:

Eliminate the need to reach for your phone to open an app, or memorizing and typing in a code—simply touch the YubiKey to verify and you're in. Are trusted—You don't need to use the YubiKey every time you log in. Once an app or service is verified, it can stay verified.

Can I use YubiKey for all my passwords? ›

The YubiKey works with Password Safe to protect your passwords using two-factor authentication (2FA). Both a master password and a YubiKey are needed to enable access to your Password Safe file, which contains the usernames, websites, passwords and other information for all of your online accounts.

What can I do with an old YubiKey? ›

Here are some great ways to make use of your YubiKey that you might not be taking advantage of yet.
  1. 1 Secure your desktop logins.
  2. 2 Secure your online accounts. ...
  3. 3 Secure your password manager with a YubiKey. ...
  4. 4 Generate TOTP codes with your YubiKey. ...
  5. 5 Secure SSH with your YubiKey. Great for homelabs or cloud-resources. ...
Apr 29, 2024

Why should I use a YubiKey? ›

Passwordless authentication: A YubiKey allows users to securely log in to their online accounts without the need for a password, relying solely on the physical YubiKey.

Top Articles
Effective Ways to Remove and Deactivate an RFID Tag
Python for Algo Trading Strategies: Libraries and Frameworks | marketfeed
Katie Pavlich Bikini Photos
Gamevault Agent
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
Non Sequitur
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Rogold Extension
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Free Carnival-themed Google Slides & PowerPoint templates
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 5766

Rating: 4.7 / 5 (77 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.