I have an authenticator app connected to everything else possible. There as an older post about this, but it is now locked so i am creating a new one to share my findings. Yubikeys are physical authentication devices from yubico!
Disabled email email is not terrible if it is a secure service like protonmail, and it is secured via. Unfortunately, normal microsoft accounts cannot use this feature at this time. Unofficial subreddit to discuss all things yubikeys.
On the other hand, it's rare that a feature that many people want comes out in a firmware upgrade. I currently have my yubikeys set up for: I feel you should use fido2 for every service that allows it. I'm trying to maximize the security of my accounts.
Using a yubikey through an rdp session. Their security keys are significantly cheaper than yubikey (fido2,webauth., totp support with nfc+usb c ~ 18$). If any of you guys have used them, would definitely love a review. It does not accept 4 digit pins during setup, i was able to set a 6 digit pin for the key.
The $650 yubikey is probably more ideal; R/yubikey current search is within r/yubikey remove r/yubikey filter and expand search to all of reddit I've recently come across a security key brand token2. I have a yubikey as a main, would want.
But, that's cost limiting right now. I'm considering buying the upcoming yubikey 5c nfc and started wondering in general how well does the thing work in practice. Would the yubikey fips, despite being an older design, be more secure than a yubikey 5, in theory? Logging into your computer with the yubikey as a fido2 device is only possible for enterprise accounts that use azure ad.
Basically, if it supports totp but not fido2, that is your second best option, so that is the way to go. What are the pros and cons of getting one and starting to use it? Solved my yubikey hardware was not being seen on my vm connected over rdp. I heard the fips model has more oversight on the design process, and breaks if tampered with.
How convenient and fast it is to authenticate with yubikey instead of (say) google authenticator? Does the nfc work well with mobile phones? Are they worth a shot? They are certified on fido2alliance and a swiss company.