This isn’t strictly a privacy question as a security one, so I’m asking this in the context of individuals, not organizations.

I currently use OTP 2FA everywhere I can, though some services I use support hardware security keys like the Yubikey. Getting a hardware key may be slightly more convenient since I wouldn’t need to type anything in but could just press a button, but there’s added risk with losing the key (I can easily backup OTP configs).

Do any of you use hardware security keys? If so, do you have a good argument in favor or against specific keys? (e.g. Yubikey, Nitrokey, etc)

  • Snot Flickerman
    link
    fedilink
    English
    153 months ago

    Mostly yubikey users in here so shout out to fully open source SoloKeys.

      • @sloppy_diffuser@sh.itjust.works
        link
        fedilink
        English
        33 months ago

        I use an OnlyKey and Mooltipass interchangeably. Prefer the lower tech OnlyKey. My passwords are half memorized passphrase and half random characters on the device. Only use for disk encryption, main account, and password manager.

    • Jae
      link
      fedilink
      13 months ago

      Solokeys is a completely dead project at the moment.

      The last commit in their repos was well-over a year ago and they don’t respond to emails at all. I’d recommend against them for the time being.