Simplify and Secure Your Online Logins With a YubiKey (2024)

As we become more dependent upon online platforms for social and professional purposes, it grows increasingly important that we embrace stronger online security measures. One of the most important steps you can take to secure your online services is setting up two-factor authentication. This protocol—commonly abbreviated as 2FA—requires you to type in a password and also provide one other piece of proof that you are who you say you are before you can log in to a service. One of the more common 2FA methods in use today employs six-digit passcodes that are sent to your phone via text message. When a unique scramble of numbers shows up on your phone, you type them into the browser along with your password at the login screen. Combined with a strong passphrase like those generated by password managers such as 1Password or LastPass, a 2FA login is quite effective at verifying your identity.

But no matter how strong a password is, or what level of code-based authentication a website is using, any system that sends codes in a text message can be compromised from afar by a skilled attacker. The best way to set up two-factor authentication is to use a secure app on your phone to generate those six-digit codes or to carry a piece of hardware that can verify your identity.

A device like the YubiKey is just that sort of hardware. These little key-shaped fobs plug into your computer and, along with your password, complete the second half of a 2FA web login. A hacker might find a way to snoop on your passwords or intercept a six-digit 2FA code while it’s being sent to your phone, but they’d be hard pressed to snatch an actual key off your keychain.

We should note that if you already have 2FA set up through an app like Google Authenticator or Duo Security, that's great. A YubiKey will simply provide another, more convenient method of authentication. If you lose your YubiKey or forget it at home, you can use the secure code generator on your phone to complete your 2FA logins.

What Is It?

The YubiKey—like other, similar devices—is a small metal and plastic key about the size of a USB stick. They plug into your computer, and some also connect to your phone. You can use them in either place, along with your password, to authenticate web logins. Think of it as a physical key that, instead of unlocking a door, unlocks your online life.

Several manufacturers make these types keys, and they all basically work the same way. They adhere to an industry standard called Universal 2nd Factor, or U2F. The standard weds hardware-based authentication with public key cryptography—a set of tools that’s extremely difficult to compromise. These U2F keys simplify the process of securely accessing online services like Google, Facebook, Dropbox, Windows, and Mac OS. They also support password managers like Lastpass, Dashlane and Keepass. U2F keys can even be used to unlock your Mac or Windows PC from the home screen.

Which One Should I Get?

There are several models of U2F key to choose from; all of them look like variations on a compact USB stick. We’re concentrating on the YubiKey here simply because it's the most popular option, but you can use the instructions below with any key that supports U2F and the similar FIDO2 standard. Also (full disclosure!) we started giving away YubiKeys to new WIRED subscribers as free gifts earlier this year. If you receive one from us, you may wonder how to use it.

Made by the company Yubico, which helped draft the open U2F and FIDO2 standards, the keys are durable, water-resistant, and battery-free. There are key-shaped models that attach to your keychain, and “nano” models, designed to be less awkward when plugged into a laptop. The full-size YubiKey 4 Series ranges from $40 to $60 and comes in versions for USB-A ports or USB-C ports. For Android users, there's the NFC-compatible YubiKey Neo for $50 that lets you access your online services on your phone. You can also plug it into USB-A ports on your PC or other devices. For something more economical, you can try the brand new Security Key for USB-A ports. It costs only $20, and it’s compatible with any services that support U2F and FIDO2. Finally, government-regulated institutions might be interested in the YubiKey FIPS, which meets common regulatory requirements. To dig deeper into which key is right for you, take Yubico’s quiz here.

Getting Started

Once your YubiKey arrives in the mail, you start by activating it. Go to Yubico’s website and select your YubiKey. Next, choose the services you’d like to use your YubiKey to log in to. Popular services that support U2F and FIDO2, like Facebook, Google, and Dropbox, are listed at the top. Also among the top choices are computer login options for Macs and Windows PCs. You can set up your YubiKey for use with password management solutions like Dashlane and LastPass, and developer platforms like Github and Bitbucket. Just about every service you can access with non-SMS-based two-factor authentication lets you add a YubiKey to your login protocol.

To give you a clear example, let's set up a YubiKey to work with Facebook. Note that for Facebook, the YubiKey can only log you in if you're using the latest version of Chrome or Opera. The hardware keys will work with Mozilla Firefox and Microsoft Edge on some services, but other services are more fickle—check the browser requirements for each of your most commonly used web services. For the ones that don't support your hardware key, you can use a 2FA code-generator app instead.

On the YubiKey setup page, click on Facebook. Yubico will send you to a Facebook page called "What is a security key and how does it work?". To set up your YubiKey, Facebook directs you to Security and Login Settings. Since a YubiKey is one of the factors in a two-factor authentication process, if you don’t have 2FA set up yet, Facebook will guide you through setting that up first. This usually involves providing Facebook with a phone number to text you a one-time passcode. Once that’s set up, go back to the Security and Login Settings page and look underneath where it says "Setting up extra security." Next to the menu item "Use two-factor authentication," click Edit. Under "Security Keys," you’ll find the option called "Add Key."

Simplify and Secure Your Online Logins With a YubiKey (2024)

FAQs

Simplify and Secure Your Online Logins With a YubiKey? ›

YubiKeys support multiple authentication protocols so you are able to use them across any tech stack, legacy or modern–flowing effortlessly with the user. No more reaching for your phone to open an app, or memorizing and typing in a code – simply touch the YubiKey to verify and you're in.

Can you go passwordless with YubiKey? ›

YubiKeys make passwordless possible

Passwordless can be achieved using legacy Smart Card protocols, or modern FIDO2 / Passkey authentication secured by PIN or biometric identification. The multi-protocol YubiKey offers total flexibility, and can store up to 100 passkey credentials.

Can I use YubiKey for all my passwords? ›

The YubiKey works with Password Safe to protect your passwords using two-factor authentication (2FA). Both a master password and a YubiKey are needed to enable access to your Password Safe file, which contains the usernames, websites, passwords and other information for all of your online accounts.

What is the point of a YubiKey? ›

The YubiKey is a device that makes two-factor authentication (2FA) as simple as possible. Many apps, online services, and computers enforce 2FA every time a user wants to connect. Instead of a code being texted to you or generated by an authenticator app, you press a button on your YubiKey, and you're logged in.

Is it safe to buy YubiKey online? ›

Yubico highly recommends not purchasing keys from un-approved sources. Only keys purchased from our web-store or authorized resellers are valid for warranty service. Keys purchased from resellers are subject to that reseller's warranty and return policies.

Is YubiKey obsolete? ›

It's possible that YubiKey may become less necessary as passwordless login options become more widely available, but it's unlikely that it will become completely obsolete. Passwordless login options such as biometric authentication and security keys can offer a more secure and convenient way to access accounts.

Is YubiKey safer than Authenticator app? ›

Authenticator apps provide a layer of security and are a convenient option for use by many, but they are still vulnerable to phishing due to the 30-second window. Security keys, like the YubiKey, are considered to be both more convenient and more secure. Yubico also provides a use in conjunction with the YubiKey.

What happens if someone steals my YubiKey? ›

So, what happens if you lose your YubiKey? In that case, you can still use your Authenticator app (phew!). While you can't create a backup YubiKey, you can always contact Yubico to get a replacement key.

Is it safe to keep YubiKey plugged in? ›

Leaving it plugged in could result in the yubikey being lost or damaged.

Which password manager works best with YubiKey? ›

KeePass Works With YubiKey | Yubico.

How long will a YubiKey last? ›

A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites. Portability: I have a smartphone, a work laptop, a home laptop, and a home desktop. My Yubikey has USB and NFC, so it can trivially be used with all of them.

Is Yubico a Chinese company? ›

Yubico is founded in Stockholm, Sweden making secure login easy and available to everyone, and enabling one single authentication key to work across any number of services.

Why is YubiKey so expensive? ›

It is costly to design, mould, manufacture, sell and support a hardware product, even something as small as this. Since you don't want your 2FA company to go out of business there is good value in knowing they have a stable business model that can actually support a company rather than just burning capital.

How much does a YubiKey cost? ›

Here at Keytos, we're not only proponents of the tech, but we're also power users! The TL;DR here is that the cost of a YubiKey is anywhere between $25 for the Security Series and $95 for the YubiKey FIPS series.

Can I use YubiKey with my Amazon account? ›

AWS IAM and root users can use their YubiKey as a multi-factor authentication (MFA) device to add an extra layer of protection on top of their username and password.

Can I use YubiKey for online banking? ›

The YubiKey is a modern and scalable solution that works without additional software and you can easily register your YubiKey with Novum Bank's online banking systems, without visiting a branch. It is one of the best ways to protect your bank account from cyber threats.

Can I use YubiKey with keeper? ›

Users can protect their Keeper vault with FIDO WebAuthn compatible hardware security keys, including YubiKey and Google Titan keys, which provide secure and easy two-factor authentication (2FA). Security Keys are configured in the Keeper Web Vault or Keeper Desktop App.

Is it good to go passwordless? ›

Whether or not passwordless authentication is safe depends on your definition of safe. If safe means harder to crack and less prone to the most common cyberattacks, then yes, passwordless authentication is safe. If by safe you mean, it is impervious to hacking, then no, it's not safe.

Can I use YubiKey as a 2FA? ›

YubiKeys as the gold-standard for multi-factor authentication: Eliminate the need to reach for your phone to open an app, or memorizing and typing in a code. Are easy to use—simply touch the YubiKey to verify with your account and you're in. Are reliable and can be set up with applications and services in minutes.

Does my YubiKey support FIDO2? ›

The YubiKey 5 Series is a hardware based authentication solution that offers strong two-factor, multi-factor and passwordless authentication with support for multiple protocols including FIDO2, U2F, PIV, Yubico OTP, and OATH TOTP.

Top Articles
What happens to credit card debt when you die?
List of Top 10 Toughest Exams in India 2024 - PSLM
Radikale Landküche am Landgut Schönwalde
Victory Road Radical Red
Jennifer Hart Facebook
J & D E-Gitarre 905 HSS Bat Mark Goth Black bei uns günstig einkaufen
Ingles Weekly Ad Lilburn Ga
Chase Bank Operating Hours
Robinhood Turbotax Discount 2023
Hawkeye 2021 123Movies
Kristine Leahy Spouse
Kent And Pelczar Obituaries
What is international trade and explain its types?
Florida (FL) Powerball - Winning Numbers & Results
Bros Movie Wiki
ExploreLearning on LinkedIn: This month's featured product is our ExploreLearning Gizmos Pen Pack, the…
OpenXR support for IL-2 and DCS for Windows Mixed Reality VR headsets
Accuradio Unblocked
Belly Dump Trailers For Sale On Craigslist
Dr. med. Uta Krieg-Oehme - Lesen Sie Erfahrungsberichte und vereinbaren Sie einen Termin
Slope Tyrones Unblocked Games
Jayah And Kimora Phone Number
Site : Storagealamogordo.com Easy Call
Acts 16 Nkjv
Kringloopwinkel Second Sale Roosendaal - Leemstraat 4e
Fsga Golf
Vegas7Games.com
Riversweeps Admin Login
The Listings Project New York
Elbert County Swap Shop
Essence Healthcare Otc 2023 Catalog
Pixel Combat Unblocked
Hobby Lobby Hours Parkersburg Wv
Mississippi Craigslist
Himekishi Ga Classmate Raw
Pay Stub Portal
Mosley Lane Candles
Nsu Occupational Therapy Prerequisites
Tmka-19829
Indiefoxx Deepfake
Gets Less Antsy Crossword Clue
Ticket To Paradise Showtimes Near Regal Citrus Park
Discover Wisconsin Season 16
Panorama Charter Portal
No Boundaries Pants For Men
Cuckold Gonewildaudio
Marcal Paper Products - Nassau Paper Company Ltd. -
Dietary Extras Given Crossword Clue
Missed Connections Dayton Ohio
라이키 유출
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6018

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.