

So the one nice thing is that you can use the Yubikey 5 as a TOTP generator via the Yubico Autheticator app.

I have, on my phone right now, six separate 2FA apps (Yubico Authenticator, Duo, Symantec VIP, MS Authenticator, my German bank's PhotoTAN app, and one of my US bank apps that has a built-in code generator). All of my other services, including the two above that have to use TOTP for mobile app access, have to use either use TOTP as a second factor or some other method if it doesn't support TOTP. LastPass: Doesn't support a security key through FIDO2/U2F, but does support YubiOTP as a second factor.Īnd that's about it.

Same with Facebook, you'll need TOTP for app access.ĭuo: Supports the security key, but limited iOS support inside embedded browsers and lack of app support means I have to use Duo Push as a backup. Twitter: Supports a security key as a second factor only on the web interface. It works great on both the web and their apps on my phone (via the Lightning connector).įacebook: Supports a security key as a second factor on the web interface only, does not support it via the mobile app yet. Google: This is the only service that fully supports a security key as a second factor (does not yet support passwordless). So here's basically been my experience using the Yubikey 5Ci on an iPhone: I have a little more than a dozen different accounts that have one or more types of 2FA enabled, and only one of them fully supports a security key as a second factor. What this means is that if you're hoping for the Yubikey to be your sole 2FA tool, you're probably going to be sorely disappointed.

So for a lot of services you're going to need to set up TOTP codes as a backup method. So before you start down this road, understand that you're going to be pretty disappointed. There are only a handful of web services that support it, and most that do don't support it 100% (i.e., they support it from the web interface, but not their mobile apps). So the first thing you need to realize is that support for security key authentication is extremely limited right now. By this I mean the rotating codes like in Google Authenticator, in case you weren't already aware. Note - in re-reading this response, I realized I used the term TOTP codes. So I recently got a Yubikey 5Ci, and here's my takeaways.
