Touch protection · Yubikey Handbook (2024)

Touch protection

The Yubikey 4 introduces a new touch feature1that enables a second layer of protection when using a private key stored on the device. The access will be conditioned by a user physically triggering the touch sensor, which detracts malware issuing command on the Yubikey without user knowledge.

The touch event is requested for up to 15 seconds, after which the Yubikey turns off the notification.

The touch sensor can be configured with the following parameters:

  • off: touch is disabled
  • on: touch is enabled
  • fix: touch is enabled and can not be disabled unless a new private key is generated or imported.

Touch protection can be configured individually on each one of the GPG private keys and requires the use of the Admin PIN.

References

  1. https://developers.yubico.com/PGP/Card_edit.html
    Touch protection · Yubikey Handbook (2024)

    FAQs

    Why is my YubiKey touch not working? ›

    Check to see if the YubiKey's LED is lit - if not, the YubiKey may not be receiving power. The issue may be as simple as the YubiKey is inserted upside down for USB-A connectors. Alternatively, the USB port may not be functioning correctly - if that is the case, try on a different USB port or computer.

    Why do I have to touch my YubiKey? ›

    The Yubikey 4 introduces a new touch feature1that enables a second layer of protection when using a private key stored on the device. The access will be conditioned by a user physically triggering the touch sensor, which detracts malware issuing command on the Yubikey without user knowledge.

    How to disable YubiKey Touch? ›

    Connect your YubiKey to your computer. Open the YubiKey Manager and select the YubiKey you want to modify. In the 'Applications' section, select the OTP application and click the 'Edit' button. In the 'General' tab, uncheck the 'Enabled' checkbox and click 'Save'.

    Is YubiKey more secure than 2FA? ›

    Other 2FA methods typically only send you a six-digit code to confirm your identity, mostly because it would be unreasonable to expect humans to type much more than that. YubiKeys don't require you to manually enter a code, so they're free to use much longer codes. That's more secure.

    What is the lifespan of a YubiKey? ›

    A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites.

    Why my touch is not working? ›

    Sometimes, a touch screen will stop responding due to built-up dirt and grime or problems with the case or screen protector. Since this is pretty easy to either deal with or rule out, it's a good idea to thoroughly clean your device if a reboot doesn't do the trick.

    How do you test if YubiKey is working? ›

    Testing the Credential
    1. Insert the YubiKey into the computer.
    2. Click the Yubico OTP button. The following screen, "Test your YubiKey with Yubico OTP" shows the cursor blinking in the Yubico OTP field.
    3. Tap the metal button or contact on the YubiKey. The OTP appears in the Yubico OTP field. ...
    4. Click Validate.
    May 7, 2020

    Where to touch YubiKey? ›

    Yubico OTP Validation
    • The YubiKey is inserted into the USB port. ...
    • The user touches the YubiKey OTP generation button.
    • Internally, a byte string is formed by concatenation of various internally stored and calculated fields, including as a non-volatile counter, a timer and a random number.

    Should I keep my YubiKey plugged in? ›

    Do I need to keep my yubikey plugged in all the time? A. No, you only need to insert your yubikey when you are prompted to do so during login. Leaving it plugged in could result in the yubikey being lost or damaged.

    Can you unplug YubiKey? ›

    The YubiKey identifies as a USB keyboard to your PC, and does not need to be ejected when removed – you can just pull it out!

    How do I turn off touch key? ›

    Prevent the touch keyboard from appearing outside of tablet mode
    1. Select Start > Settings > Devices > Typing .
    2. Under Touch keyboard, if Show the touch keyboard when not in tablet mode and there's no keyboard attached is On, select it to turn it Off.

    What if someone steals your YubiKey? ›

    So, what happens if you lose your YubiKey? In that case, you can still use your Authenticator app (phew!). While you can't create a backup YubiKey, you can always contact Yubico to get a replacement key.

    What are the risks of YubiKey? ›

    The theft scenario is indeed disturbing because if the thief learns your PIN and then steals the Yubikey, you're facing severe problems: the thief can easily check all your passkeys, get access to your accounts, remove all the passkeys and register only the stolen Yubikey, change the password, remove any other 2FA ...

    Which YubiKey is most secure? ›

    The YubiKey 5 FIPS certified security keys meet the highest level of assurance (AAL3) of the new NIST SP800-63B guidelines.

    How do you reset a YubiKey? ›

    Unplug the YubiKey once and then plug it back in via the USB port. Touch the YubiKey on the sensor (golden area) twice within 10 seconds to confirm the reset. The YubiKey has been successfully reset. Afterwards, if necessary, you can set a new PIN again using the Security Key PIN function.

    How do I get my YubiKey to work? ›

    The versatile YubiKey requires no software installation or battery so just plug it into a USB port and touch the button, or tap-n-go using NFC for secure authentication.

    How do I refresh my YubiKey? ›

    Option 2 - Reset Using the YubiHSM SDK

    Insert the YubiKey into a USB port. Open Command Prompt (Windows) or Terminal (Mac / Linux). Type yubihsm-auth --action reset and press Enter.

    Top Articles
    Here is how much money you need to retire
    The Sustainable Investor's Dilemma - Ethical Or ESG Investing? | Koody
    Skigebiet Portillo - Skiurlaub - Skifahren - Testberichte
    Urist Mcenforcer
    Ds Cuts Saugus
    Vaya Timeclock
    The Realcaca Girl Leaked
    Blairsville Online Yard Sale
    Www Craigslist Louisville
    Ribbit Woodbine
    Https Www E Access Att Com Myworklife
    Truist Drive Through Hours
    Bubbles Hair Salon Woodbridge Va
    Find The Eagle Hunter High To The East
    Wilmot Science Training Program for Deaf High School Students Expands Across the U.S.
    Nhl Tankathon Mock Draft
    Teacup Yorkie For Sale Up To $400 In South Carolina
    Craigslist Pearl Ms
    Xfinity Cup Race Today
    Imouto Wa Gal Kawaii - Episode 2
    South Bend Weather Underground
    Sherburne Refuge Bulldogs
    Bn9 Weather Radar
    Student Portal Stvt
    Bolly2Tolly Maari 2
    8002905511
    Himekishi Ga Classmate Raw
    Prévisions météo Paris à 15 jours - 1er site météo pour l'île-de-France
    DIY Building Plans for a Picnic Table
    Frequently Asked Questions - Hy-Vee PERKS
    Dtlr On 87Th Cottage Grove
    Santa Cruz California Craigslist
    Buhsd Studentvue
    Poe Flameblast
    Pokemon Reborn Locations
    1v1.LOL Game [Unblocked] | Play Online
    Stanley Steemer Johnson City Tn
    877-292-0545
    Saybyebugs At Walmart
    2 Pm Cdt
    Deepwoken: How To Unlock All Fighting Styles Guide - Item Level Gaming
    Shell Gas Stations Prices
    Peace Sign Drawing Reference
    Frontier Internet Outage Davenport Fl
    Cvs Coit And Alpha
    Dayton Overdrive
    Mikayla Campinos Alive Or Dead
    Nkey rollover - Hitta bästa priset på Prisjakt
    One Facing Life Maybe Crossword
    What Are Routing Numbers And How Do You Find Them? | MoneyTransfers.com
    Latest Posts
    Article information

    Author: Edwin Metz

    Last Updated:

    Views: 6387

    Rating: 4.8 / 5 (78 voted)

    Reviews: 85% of readers found this page helpful

    Author information

    Name: Edwin Metz

    Birthday: 1997-04-16

    Address: 51593 Leanne Light, Kuphalmouth, DE 50012-5183

    Phone: +639107620957

    Job: Corporate Banking Technician

    Hobby: Reading, scrapbook, role-playing games, Fishing, Fishing, Scuba diving, Beekeeping

    Introduction: My name is Edwin Metz, I am a fair, energetic, helpful, brave, outstanding, nice, helpful person who loves writing and wants to share my knowledge and understanding with you.