• MystikIncarnate@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    I too have a yubikey. My advice, have something that functions as a backup.

    Other than that, yes. It’s way better than alternatives.

    • warpotato@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      Yeah, I got 4 because I’m paranoid about losing access to things, and still spread out backup TFA mechanisms… I don’t trust technology to be reliable enough, heh.

      • MystikIncarnate@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Personally, I have the second Gen Google Titan USB keys, I upgraded from the first Gen some time ago. They’re Fido2 so they’re very equivalent to yubikey in most respects.

        I use my yubikey for work. I connect it to anything and everything I can. I use Microsoft’s authenticator as my backup for work.

        I have a pair of Fido2 keys for personal with totp backups, and recovery codes as a last line of defense (stored in a secure location), and one Fido2 key with totp backups for work.

        Ironically, the least secure account I have is for my bank, which doesn’t support Fido2 (or anything other than SMS).