The problem with hardware authenticators is compatibility across devices. One job I worked at a while back used Yubikeys, which were great… if you were logging in from your work PC. If you need to access your work email from your phone, that wasn’t really an option without getting an exception made to your account, which required IT doing a manual reconfig of your account. And obviously they were reluctant to do that, because that just opened up more security risks that the Yubikeys were meant to prevent.
I mean that sounds more like a money problem to me. There all multiple different types of yubi keys that work for different types of USB and lightning as well as NFC if you want that. The only reason you wouldn’t be able to use a yubikey on your phone is because you weren’t supplied with a yubi key that works with phones and only the cheapest option with a regular USB A plug.
dracs@programming.dev 1 year ago
Yubikey and other hardware security keys now support NFC which makes the mobile support really good. A quick rap to the back of the phone and you’re done.
BeanCounter@sh.itjust.works 1 year ago
I wish it wasn’t as expensive as it is now to get in my country. I need at least two of them for me to not feel paranoid about losing it but the price stops me from getting
onetwo.Chozo@kbin.social 1 year ago
Oh, that's good to know! It's been years since I've used one, so I don't think the support was there yet. That definitely relieves some of the problems I had with them, in that case.
dracs@programming.dev 1 year ago
Yeah, I had one of the earlier ones Yubikeys without NFC. I remember having to get a USB mini to full USB converter and plug it into that to login to things like LastPass. Thankfully I only needed to do it once for the initial login.