This isn’t strictly a privacy question as a security one, so I’m asking this in the context of individuals, not organizations.

I currently use OTP 2FA everywhere I can, though some services I use support hardware security keys like the Yubikey. Getting a hardware key may be slightly more convenient since I wouldn’t need to type anything in but could just press a button, but there’s added risk with losing the key (I can easily backup OTP configs).

Do any of you use hardware security keys? If so, do you have a good argument in favor or against specific keys? (e.g. Yubikey, Nitrokey, etc)

  • johannesvanderwhales@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    So I get very confused over which protocol is which. I think the cheaper keys lack support for OAUTH. Which is required for things like windows login.

    • sugar_in_your_tea@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      0
      ·
      5 months ago

      Yes, they don’t have OATH (not OAuth, that’s a different thing), Smart Card, or PGP. I don’t know what Windows uses (haven’t used Windows in >10 years), but Linux can use FIDO IIRC.