YubiKey Hardware (2024)

YubiKey Hardware (1)

What is a YubiKey?

A YubiKey is a multi-protocol multi-factor hardware authenticator, providing strong authentication to a wide range of services and situations. While YubiKeys come in a number of different form-factors, each is built around the same core chipset and firmware, allowing a uniform experience regardless of the model used.

YubiKey form factors

YubiKey 5 USB-A

YubiKey 5 NFC

YubiKey 5 Nano

YubiKey 5C

YubiKey 5C Nano

YubiKey 5C NFC

YubiKey 5Ci

YubiKey Hardware (2)

YubiKey Hardware (3)

YubiKey Hardware (4)

YubiKey Hardware (5)

YubiKey Hardware (6)

YubiKey Hardware (7)

YubiKey Hardware (8)

USB-A

USB-A / NFC

USB-A

USB-C

USB-C / NFC

USB-C

Lightning / USB-C

YubiKeys can connect to computers via a direct physical connection (USB-A, USB-C or the Apple Lightning port) or, for some models, via Near Field Communication (NFC). Regardless of how the device is connected to another machine, the interactions of all of the functions remain the same.

For details specific to each device series, refer to the Yubico Technical Manuals for each device.

Each YubiKey has a unique serial number identifying the specific device. The serial number is printed on the YubiKey’s body (both as a number as well as a 2D barcode for some models), as well as being accessible by a number of different functions by a connected computer. Regardless of how the serial number is read, it will remain the same, allowing for a uniform method of inventory tracking in both the physical and cyber spaces.

How does a YubiKey work?

When connected to another computer, the YubiKey identifies itself as a composite USB device, depending on the number of functions active. When connected physically, the YubiKey will have a different identifier depending on its current state. These Product ID and iProduct values are listed in the document, YubiKey USB ID Values guide.

When communicating with a PC or mobile platform, the YubiKey will identify itself as three devices: either a USB HID Keyboard (direct physical connection) or passive NFC NDEF Tag (NFC only); a CCID reader with a smart card inserted; and a HID FIDO Authenticator. Communication for various functions on the YubiKey will use one of the three channels.

The HID Keyboard interface passes output from the YubiKey to the host system as keystrokes from a virtual keyboard, and can use the HID Keyboard channel to communicate back to the YubiKey. For NFC interactions, this is replaced using the NFC Data Exchange Format (NDEF) tag to pass data to the host device. The CCID interface uses the standard smart card transport and Application Protocol Data Units (APDUs) to interact with the YubiKey. Finally, the HID FIDO communication allows for FIDO Client to Authenticator Protocols (CTAP1/2) to communicate with the YubiKey for U2F or WebAuthn Authentication.

Every YubiKey has a gold contact which allows for a physical touch to be utilized. This allows functions on the YubiKey to require an actual human to trigger them, protecting against software attacks attempting to hijack the functions of the YubiKey remotely. When using NFC, the act of tapping a YubiKey against an NFC reader provides the same function.

To provide direct feedback to users, every YubiKey has an LED which will light up when the YubiKey is being communicated with, or will flash when the YubiKey requires user action.

What can a YubiKey do?

The YubiKey has five functions which support all of the authentication protocols supported by the YubiKey, with an internal management function for managing the YubiKey itself. These functions are referred to as Applications, and include:

On the YubiKey, each Application has a dedicated memory space within the secure cryptographic element, and no Application can access data stored in any of the others. For more details on what data can be stored in the YubiKey, refer to YubiKey User-Loaded Data.

The YubiKey Management Application provides the serial number and YubiKey firmware version to the other Applications, as well as being able to turn on or off access to the other functions over the physical port or NFC communication channels. Further, the YubiKey Management Application can be secured with a 16 byte lock code, preventing unauthorized modification to the YubiKey.

YubiKey Hardware (2024)

FAQs

Why is YubiKey so expensive? ›

It is costly to design, mould, manufacture, sell and support a hardware product, even something as small as this. Since you don't want your 2FA company to go out of business there is good value in knowing they have a stable business model that can actually support a company rather than just burning capital.

What is the lifespan of a YubiKey? ›

A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites. Portability: I have a smartphone, a work laptop, a home laptop, and a home desktop. My Yubikey has USB and NFC, so it can trivially be used with all of them.

What is inside a YubiKey? ›

The Infineon chip is a 16-bit dual-CPU microcontroller with 512Kb of flash and 16Kb of RAM. The chips' CPUs perform cross-verification of each other's calculations, thus protecting the integtity of data, which makes it difficult to tamper with the chip.

Should I leave my YubiKey plugged in all the time? ›

Do I need to keep my yubikey plugged in all the time? A. No, you only need to insert your yubikey when you are prompted to do so during login. Leaving it plugged in could result in the yubikey being lost or damaged.

Is it worth buying YubiKey? ›

The Yubico YubiKey 5C NFC supports many authentication protocols, so it works anywhere security keys are accepted. If you can make the most of its advanced features, such as signing and encrypting with OpenPGP, it's well worth the price.

Can a YubiKey be hacked? ›

While YubiKey is designed to be secure, it is not immune to attacks. There have been instances where YubiKeys have been hacked or compromised. Common attack vectors on hardware keys include physical attacks, side-channel attacks, and firmware vulnerabilities.

What if someone steals my YubiKey? ›

If you lose your Yubikey, you can still use your phone authenticator app, but you cannot create a backup Yubikey. However, Yubikey also provides methods to recover your account, so you can get a replacement. An advantage to Yubikey is that it comes on a USB that cannot be identified.

Can YubiKey get malware? ›

Yubico's YubiKey is built on a foundation of strong authentication. This robust resistance to phishing offers malware protection because it hinges on the ability to detect these attacks before they take place.

Can YubiKey be tracked? ›

Status.io is a hosted status page platform that supports YubiKey authentication, providing companies a simple and secure way to track incidents, schedule planned maintenances, and broadcast status notifications.

What happens when you touch YubiKey? ›

The act of tapping and holding an NFC-enabled YubiKey to the NFC reader on a mobile device takes the place of touching the gold contact to generate an OTP. The OTP is passed as part of the NDEF tag, which is supported on most mobile devices with NFC.

How many YubiKeys should you have? ›

A: Many of our customers actually purchase several spares for maximum security and peace of mind. This is not a bad idea when guarding extremely critical accounts. Starting off, you should be fine with 1-2 spare keys.

Do you tap or insert your YubiKey? ›

Insert YubiKey & tap

On a computer, insert the YubiKey into a USB-port and touch the YubiKey to verify you are human and not a remote hacker.

Does YubiKey require a subscription? ›

You can purchase directly from Yubico or you can purchase from Yubico's channel partners, i.e., distributors and resellers (see Purchasing Through Resellers/Distributors below). There are two modes of purchase, Subscription or Non-subscription (Perpetual).

Is it safe to buy YubiKey from third party? ›

Yubico highly recommends not purchasing keys from un-approved sources. Only keys purchased from our web-store or authorized resellers are valid for warranty service. Keys purchased from resellers are subject to that reseller's warranty and return policies.

What is special about YubiKey? ›

The YubiKey supports one-time passcodes (OTP)

The YubiKey communicates via the HID keyboard interface, sending output as a series of keystrokes. This means OTP protocols can work across all OSs and environments that support USB keyboards, as well as with any app that can accept keyboard input.

How many times can a YubiKey be used? ›

With WebAuthn, you can use the same YubiKey for unlimited sites and accounts. Just make sure to keep your YubiKey in a safe place and don't share it with anyone else.

Is YubiKey made in China? ›

Made in Sweden & USA.

Top Articles
Quel délai pour contester une opération faite avec ma carte bancaire ?
From baby boomers to snowflakes – decoding generation nicknames - Times of India
Bj 사슴이 분수
Kevin Cox Picks
Craigslist Monterrey Ca
Aquatic Pets And Reptiles Photos
Conduent Connect Feps Login
Dusk
Craigslist Pets Southern Md
Oppenheimer Showtimes Near Cinemark Denton
Busted Newspaper S Randolph County Dirt The Press As Pawns
Classic Lotto Payout Calculator
Tracking Your Shipments with Maher Terminal
Wisconsin Women's Volleyball Team Leaked Pictures
Carolina Aguilar Facebook
50 Shades Darker Movie 123Movies
Cyndaquil Gen 4 Learnset
Elemental Showtimes Near Cinemark Flint West 14
Dtab Customs
Hollywood Bowl Section H
Ibukunore
Noaa Ilx
Sprinkler Lv2
Xsensual Portland
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Directions To Cvs Pharmacy
Filthy Rich Boys (Rich Boys Of Burberry Prep #1) - C.M. Stunich [PDF] | Online Book Share
Scripchat Gratis
Big Boobs Indian Photos
Vip Lounge Odu
Purdue Timeforge
3473372961
Manuel Pihakis Obituary
Great Clips On Alameda
Selfservice Bright Lending
Final Fantasy 7 Remake Nexus
11301 Lakeline Blvd Parkline Plaza Ctr Ste 150
Noaa Marine Weather Forecast By Zone
Invalleerkracht [Gratis] voorbeelden van sollicitatiebrieven & expert tips
Academy Sports New Bern Nc Coupons
Great Clips Virginia Center Commons
Tyco Forums
Joblink Maine
Abigail Cordova Murder
Craigslist Sarasota Free Stuff
Fallout 76 Fox Locations
Uno Grade Scale
303-615-0055
Lagrone Funeral Chapel & Crematory Obituaries
Cognitive Function Test Potomac Falls
Texas 4A Baseball
Latest Posts
Article information

Author: Mr. See Jast

Last Updated:

Views: 6372

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.