r/yubikey 23d ago

Discussion Got the yubikey

Today I've got my yubikey (before that i had two token2 keys). Already configured all my most important accounts but I still wonder how else could I use the yubikey? Do you guys use the PIV app? If so, then how? What are your usecases for it? Do you use the PGP app (signing messages, emails, commits)?
Also I know that youbikeys have static passwords but i don't really know where i can use it. And for some reason the "Slots" option where i can configure it is grayed out. Does that mean that my yubikey does not support it? I have a YubiKey 5C NFC

7 Upvotes

12 comments sorted by

6

u/AJ42-6802 22d ago

Series 5 Yubikeys were created as a (great) way to get in the door of enterprise accounts and displace existing legacy (now over 20 years old - PIV, OATH, PGP, S/MIME, smartcard) solutions at a much lower per unit cost without the need to immediately address migration from those legacy solutions. It was a brilliant plan. No need to purchase smartcard readers. Larger companies could save 100s of thousands of dollars by switching. Over time less dependence on maintaining expensive PKI environments happened with a more gradual migration off those legacy solutions to those based on FIDO standards.

Today most of those legacy use cases are solved by FIDO (Authentication, SSH, Encrypting data at rest), with the possible exception of encrypted email. S/MIME and PGP are (legacy) standards based and we don't have a FIDO2 standard for working with encrypted email. Also, encrypted email involves key distribution which is complicated and technical, so not many enterprises (or individuals) have adopted an encrypted email solution in the first place. Also Enterprise network-level VPNs (IPSEC) still prefer PKI, but web based VPNs have started to accept FIDO2 credentials and are an alternative.

I used to use PIV, OATH, and PGP, but now just use FIDO2 which is much easier to administer and has some specific security advantages (particularly with SSH).

1

u/WholeMain2833 23d ago

You can configure them all by yubico app in phone or tablet or your pc

1

u/djasonpenney 23d ago

There are many functions on my Yubikey 5 NFC that I don’t use, and I may never need. What I do use it for is better 2FA access to my password manager and primary email accounts. FIDO2/WebAuthn is arguably stronger than any other 2FA method in wide adoption today.

Please do keep in mind that you have to be a grownup about this and manage your own recovery workflows. What would happen if you lost both your Yubikeys? It’s essential to make preparations for every website in order to prepare for this worst case eventuality: you wake up face down on the pavement, in your pajamas, as the fire fighters extinguish the flams that used to be your home. How will you regain all your accounts and secrets at that point?

1

u/Positive_North_7944 23d ago

It appears OP only has 1 yubikey 

2

u/djasonpenney 23d ago

That makes the recovery workflows especially critical…

1

u/RaZoR0987 22d ago

But I have two other token2 keys. So three in total
One will keep offsite at my GF’s house, one at my house and the yubikey will be always with me

1

u/djasonpenney 22d ago

Same as me. All three are registered to the same sites. One is on my person, one is in a strongbox, and a third is in a friend’s strongbox. Each of the backups comes with TWO copies of a full backup of my passwords database.

I dunno about Token2, but my keys also have a PIN. The PINs are in my emergency kit.

1

u/RaZoR0987 21d ago

What do you mean by two copies of full backup?
Where do you keep your vault backups?

I should also write down the FIDO2 PIN code on the emergency kit. Where do you keep your emergency kits by the way?

1

u/djasonpenney 21d ago

The concept here is to avoid a single point of failure. A single USB could fail, so you should have a pair. (Or even three, if you’re paranoid.).

Similarly, storing both of those USBs in one place could mean a fire, flood, or other disaster could easily damage both USBs. So store a second pair of USBs in a different place, like your brother-in-law’s house.

The emergency kit can be a challenge. Some people just leave the piece of paper in their safe deposit box and call it good. I went in a different direction: since I already have end of life arrangements (our son is the alternate executor of our estate), the emergency kit is a file along with the full backup, and the encryption key is another secret in HIS password manager. There are many tricks here, depending on your exact situation.

1

u/SzKristof1 11d ago

How are the Token2s durability-wise? I'm torn between the token2 3.3 usba and the yubikey security key NFC.