Yubico Review | Password Manager (2024)

Pros & Cons of Yubico

  • Adds two-factor or multifactor authentication to almost any password manager to vastly increase security
  • Reduces logins to one-tap and makes two-factor authentication much faster and more convenient with compatible services
  • Options for wide range of user types and security levels
  • Low-cost YubiKeys available for individual use

Cons

  • Must pair with a password manager for full password management services
  • Not compatible with every account service
  • Choosing the right key to purchase and learning exactly how to best use it can be confusing
  • Users need to purchase a backup key because keys could become lost or stolen

Key Features of Yubico

We believe there are five important features in which every value-rich password security service should excel. Below, take a look at how Yubico fares in the areas of security and encryption, app compatibility, usability and ease of use, password sharing, and price.

Security & Encryption

Yubico Review | Password Manager (1)

Using a YubiKey two-factor authentication device goes a long way in protecting passwords and a user’s other vital information from phishing attacks and hackers. Two-factor or multifactor authentication works by requiring a person (or program) attempting to log in to an account to provide the service with something they know (a password) and something they have, such as a text message or physical device such as a YubiKey.

Because YubiKeys are unique physical devices, they can’t be hacked remotely. The devices also keep a user’s information from being shared between online services. Additionally, when a YubiKey is paired with a password manager, it ensures that even if a hacker uncovers a user’s master password, the rest of the user’s passwords remain protected.

Unlike other two-factor authentication methods, YubiKeys don’t store any of a user’s data, so even if the key itself is lost or stolen, there would be no way for another person to access the user’s information. YubiKeys don’t require a network connection or rely on a certain type of software to run.

Users can even enable multifactor authentication by pairing a YubiKey with a one-time PIN. With the FIPS series, the device allows developers, businesses and government agencies to meet the highest level of authentication assurance level requirements.

App Compatibility

Yubico Review | Password Manager (2)

YubiKeys pair with several major password managers and many online services, such as social media sites, cloud storage and cryptocurrency, to add an extra layer of security to users’ passwords and other important information.

To pair a YubiKey with a compatible mobile device or computer, users may be able to physically plug the key in via a USB or other type of port. Depending on their device and whether or not the YubiKey is NFC-enabled, users may also be able to simply hold the key next to an NFC chip-equipped device to pair them through near-field communication.

YubiKeys are also compatible with many browser types, including Edge, Chrome, Firefox, Safari and Brave, but exact browser compatibility will depend on the particular key used, the version of the browser and its configurations.

To help users figure out exactly what websites, devices and other digital services are compatible with each key, the Yubico website contains a searchable, comprehensive online catalog listing hundreds of services.

YubiKey App Compatibility

Security Key SeriesYubiKey 5 SeriesFIPS Series
Windows Computer LoginNoYesYes
macOS Computer LoginNoYesYes
Linux Computer LoginNoYesYes
Google AccountYesYesYes
Microsoft AccountYesYesYes
Salesforce.comYesYesYes
Dashlane PremiumYesYesYes
KeeperYesYesYes
LastPass PremiumNoYesYes
1PasswordYesYesYes
FacebookYesYesYes
TwitterYesYesYes
GithubYesYesYes

Usability & Ease of Use

Yubico Review | Password Manager (3)

Yubico designs its two-factor and multifactor YubiKeys for consumers of every level, from individuals looking for a password protector for personal use to businesses and developers. It aims to speed up logins, works across all computers and mobile devices and provides comprehensive customer and technical support.

Pairing a YubiKey with a compatible password manager is easy. Typically, a password manager’s vault settings will include an option for two-factor or multifactor options, and from there, a user can begin to set up their YubiKey.

In Keeper, for example, a user would simply log in to their Keeper vault and go to Settings and then click “Edit Two-Factor” to add an additional 2FA such as SMS text messaging. Then, the user can turn on security keys, insert their YubiKey into their USB port and simply follow the on-screen instructions.

Once a YubiKey is paired with a password manager, users can typically log in to their vaults or password manager apps by simply plugging their YubiKey into their devices and tapping. When a user is ready to access online accounts, the password manager can auto-fill usernames, passwords and other types of forms, and users can tap their YubiKey for a two-factor-authenticated log in.

Additionally, using YubiKey with other services directly is easy. A user doesn’t need to register their YubiKey with Yubico, and they can use Yubico’s website to select their YubiKey and identify all of its supported online services. Users can then click “Learn more” to find instructions on how to pair their YubiKey with each service.

Password Sharing

While YubiKeys don’t directly share passwords, YubiKeys can pair with password managers such as Keeper, LastPass, and Dashlane that are able to securely do so. This way, families, businesses and even individuals can more securely share their passwords with hardware-supported protection.

Price

Because Yubico knows consumers have a variety of needs, there are multiple YubiKey series with a variety of prices and features. Within each series, individual key pricing varies primarily depending on the type of device connector, such as USB-A, USB-C, NFC or lightning.

Each product comes with a free, one-year warranty and is designed to be tamper-resistant. Additionally, Yubico provides free shipping if a user purchases two or more keys. The company recommends users purchase at least two keys of any type so that one may serve as a backup in case the other is lost or stolen.

The lowest-priced keys Yubico offers are in its Security Key series. These range from $20-$27 and are designed for more basic, individual consumer use. While they do offer strong authentication methods, they’re not compatible with as many devices or account types as keys in the YubiKey 5 series or FIPS series.

Yubico describes its YubiKey 5 series as offering its most “feature-rich” keys and is well-suited to either individual or business use. YubiKey 5 keys range from $45-$70 and function to prevent hacker infiltration, are compatible with most online services and allow users to log in to accounts with one tap.

FIPS series keys range from $46-$69 are designed for developers, with business and government use in mind. They’re designed to lower IT costs and allow entities to meet the top authenticator assurance level requirements.

SeriesYubiKeyPrice
YubiKey 55 NFC$45
5 Nano$50
5C$50
5C Nano$60
5Ci$70
Security KeySecurity Key by Yubico$20
Security Key NFC by Yubico$27
YubiKey FIPSFIPS$46
C FIPS$58
Nano FIPS$58
C Nano FIPS$69
YubiHSMYubiHSM 2$650
Experience PackPasswordless Starter Kit$95

How Yubico Works

Yubico Review | Password Manager (4)

FunctionalityHow It Works
Setting up the vaultVisit Settings in a compatible password manager to enable and setup two-factor or multifactor authentication with a YubiKey
Logging in to accountsInsert YubiKey into device or hold near NFC-enabled device; pair YubiKey with a password manager for one-tap logins (password manager auto-fills forms; tapping YubiKey authenticates)
Creating passwordsPassword-less login available with Microsoft accounts; use a password manager or manually create passwords
Changing passwordsOne-time password support; manually change passwords or pair with a password manager to automatically manage existing passwords
Sharing loginsPair YubiKey with compatible password manager that can share passwords with another YubiKey user
Recovering accountNo account registration required to authenticate; users should have a backup YubiKey in case original is lost, stolen or damaged
Advanced security featuresWorks with one-time passcodes; smart card authentication, FIDO U2F support; password-less authentication with FIDO2

What Customers Are Saying

Yubico customers praise YubiKeys for their ease of use, versatility and strong security functionality. One user says, “I use my Yubikey almost every day for multifactor authentication. It’s super simple to use, easy to use pragmatically, and just provides a great experience for dealing with MFA — especially when security is important.”

Other customers point out how easily YubiKeys work with their password manager. One reviewer says, “Yubikey by Yubico works great with LastPass to provide two-factor authorization into my save password vault … Using it is as simply as plugging in the device to my laptop computer and using the hardware interface.”

Bottom Line

Ultimately, individuals and businesses who value knowing their passwords and other important information are completely secure can greatly benefit from easy-to-use YubiKeys. While they do require a bit of setting up to pair with compatible password managers, combining the two makes for an incredibly strong and useful combination, made even easier by YubiKeys’ simple touch feature and ability to pair with NFC-enabled devices.

Yubico Review | Password Manager (2024)

FAQs

What is the best password manager that works with YubiKey? ›

KeePass is a free, open source password manager that supports strong, hardware-backed YubiKey two-factor authentication, enabling users to easily and efficiently protect their accounts from takeovers.

Does YubiKey work with password managers? ›

While YubiKeys don't directly share passwords, YubiKeys can pair with password managers such as Keeper, LastPass, and Dashlane that are able to securely do so. This way, families, businesses and even individuals can more securely share their passwords with hardware-supported protection.

Can YubiKey replace a password manager? ›

The solution: YubiKey + password manager

Using a password manager application is the best way to create and maintain unique and strong passwords for all your account logins, and protecting your password manager with a YubiKey is the most secure way to manage multiple digital credentials.

Is YubiKey really secure? ›

YubiKeys are trusted by the world's largest companies and users have experienced 0 account takeovers.

Can someone hack a YubiKey? ›

The power of touch. YubiKeys require a user to be physically present, so remote attacks are impossible.

Do banks allow YubiKey? ›

Many Bank of America online banking users that have a YubiKey, can now register their security key for account sign-in two-factor authentication (2FA) as well as setting up the Secured Transfer feature to add an extra layer of physical security to their online account.

What if my YubiKey is stolen? ›

If you lose your Yubikey, you can still use your phone authenticator app, but you cannot create a backup Yubikey. However, Yubikey also provides methods to recover your account, so you can get a replacement. An advantage to Yubikey is that it comes on a USB that cannot be identified.

How many passwords can you store on YubiKey? ›

OATH (Yubico Authenticator) - the YubiKey 5's OATH application can hold up to 32 OATH-TOTP credentials (AKA authenticator app codes).

What is the catch with password managers? ›

Password manager programs are a target for hackers. It's not easy to login using multiple devices. If the main password is used/typed/saved on a computer with malware, your main password can compromise all your other passwords controlled by the PM - all your passwords are only as secure as your master password.

Can YubiKey get damaged? ›

Our product's quality is top of mind for us and if your YubiKey is damaged we ask that you submit a support ticket with the following information. The order number or copy of invoice from when you purchased the YubiKey. A valid shipping address in the event we send a replacement YubiKey to you.

Which is the safest password manager? ›

The Best Password Managers

We've updated this with more information about the LastPass breach. 1Password and Bitwarden remain our picks. Almost everyone should use a password manager. It's the most important thing you can do—alongside two-factor authentication—to keep your online data safe.

Does a YubiKey expire? ›

If I understand it correctly, no. The yubikey has no clock. However, it does have several counters, some of which are reset when you unplug it, while some are stored even when you unplug it. The counters enables the authorization server to keep track of the state of the yubikey.

Is it OK to leave YubiKey plugged in? ›

Do I need to keep my yubikey plugged in all the time? A. No, you only need to insert your yubikey when you are prompted to do so during login. Leaving it plugged in could result in the yubikey being lost or damaged.

Can YubiKey get malware? ›

Yubico's YubiKey is built on a foundation of strong authentication. This robust resistance to phishing offers malware protection because it hinges on the ability to detect these attacks before they take place.

How many times can a YubiKey be used? ›

A Yubikey can be used for an unlimited number of accounts if you're using WebAuthn. You also have an unlimited number of accounts for U2F. If you're using your Yubikey for TOTP, you can only hold 32 accounts.

Can a YubiKey go through airport security? ›

YubiKeys are made of one solid and robust piece of plastic so are safe to go through airport scanners. They don't require batteries, have no breakable screens, don't need a cellular connection, and are water-resistant and crush-proof.

Where can I store my YubiKey? ›

Where to store your spares. When your spares arrive, make sure to keep them somewhere safe but accessible – like in a wallet, file cabinet, or personal safe. If you choose to stay with one YubiKey, that's fine, but be careful not to lose or misplace it. If you do, you may be without access to your accounts for a while.

Why is YubiKey so expensive? ›

It is costly to design, mould, manufacture, sell and support a hardware product, even something as small as this. Since you don't want your 2FA company to go out of business there is good value in knowing they have a stable business model that can actually support a company rather than just burning capital.

Do Google employees use YubiKey? ›

Google Stopped the Scammers Cold with Security Keys.

That's when they handed out 85,000 security keys—the actual brand was Yubikey—to their employees and required every employees to use their security key every time they logged into their email or Google accounts.

Can I store passwords on YubiKey? ›

Using the YubiKey Personalization tool a YubiKey can store a user-provided password on the hardware device that never changes. Please note that a static password does not provide the same high level of security as one-time passwords.

Do you still need password with YubiKey? ›

The YubiKey works with Password Safe to protect your passwords using two-factor authentication (2FA). Both a master password and a YubiKey are needed to enable access to your Password Safe file, which contains the usernames, websites, passwords and other information for all of your online accounts.

Why do companies use YubiKey? ›

Thousands of companies and millions of end-users use YubiKey to simplify and secure logins to computers, internet services, and mobile apps.

Can YubiKey be tracked? ›

YubiKeys can be easily numbered, tracked, and managed as a state asset. If a user leaves the organization, the YubiKey can be quickly and securely reassigned to another user.

Does YubiKey store private keys? ›

Owners can secure private keys with the YubiKey by importing them or, better yet, generating the private key directly on the YubiKey. Private keys cannot be exported or extracted from the YubiKey. The YubiKey supports various methods to enable hardware-backed SSH authentication.

Do security experts recommend password managers? ›

Yes, password managers are safe to use, and that's a fact that not only the vast majority of cyber-security specialists agree with, but we do as well. After all, a password manager uses advanced encryption to protect your credentials, while without it, your passwords are accessible to anyone.

What is downside of using password manager? ›

The biggest disadvantage of a password manager is that because access to all of your passwords is protected by a single strong password, there is the potential risk that an attacker could gain access to all of your passwords with one hack of your password manager.

Has a password manager ever been hacked? ›

Even a password manager requires users to have one closely guarded master password, and even password managers have been hacked, as in the recent case of LastPass.

Why does Windows not recognize YubiKey? ›

YubiKey not detected

If Yubico Login for Windows does not detect that a YubiKey has been inserted, it is likely due to the key not having OTP mode enabled, or you are not inserting a YubiKey, but instead a Security Key, which is not compatible with this application.

Do I need to eject my YubiKey? ›

This YubiKey must be removed if utilizing after the authentication process and kept on your person to ensure utmost security following its activation.

Is there a better password manager than LastPass? ›

For almost everyone, 1Password is a better password manager than LastPass. There's so little difference between the general user experience, availability, and price of the two apps, that the additional security and transparency of 1Password make it the easy choice.

Which password manager is better than 1Password? ›

Ultimately, Keeper is a better password manager than 1Password. Its strong security with unyielding encryption and authentication options are a huge plus.

What is one of the most popular password managers? ›

Best Password Managers of 2023
  • Best for Extra Security Features: Dashlane.
  • Best Free Option: Bitwarden.
  • Best Enterprise-Level Manager: Keeper.

Does YubiKey work offline? ›

To use the cache logon function, the following two settings are required. In order to log on with the YubiKey without a network connection, YubiKey's Challenge Response Feature must be enabled. Please refer to the cache logon expiration date for service settings.

Can I use the same YubiKey on multiple devices? ›

Can I use one YubiKey with multiple devices? Yes! Just plug your YubiKey into any computer and log in the way you normally would. That's really it—you'll be able to log in to all of your accounts, same as before.

How many YubiKeys do I need? ›

TLDR: You do not need to issue each employee two Yubikeys. Provision and issue one per regular employee; have a second backup for any "admin" account that can perform auth resets for others, and then keep a few spares on hand that you can quickly provision if one fails or is lost. Yeah, 2 is one, one is none.

What services are compatible with YubiKey? ›

Using a Microsoft account with a YubiKey gives you quick and easy access to services such as Outlook.com, Office, Skype, OneDrive, Xbox Live, Bing and more. Just tap your YubiKey and you're in. No password required.

Does LastPass support YubiKey? ›

Compatibility - The YubiKey works seamlessly with LastPass Premium, Families, Teams or Enterprise on major browsers, such as Google Chrome and Firefox, across multiple platforms, including iOS and Android with the LastPass App.

Can I unlock 1Password with YubiKey? ›

Learn how to set up a security key, like YubiKey or Titan, so you can use it for two-factor authentication in 1Password. Two-factor authentication provides an extra layer of protection for your 1Password account.

Is YubiKey compatible with Bitwarden? ›

Registering a YubiKey with Bitwarden just takes a few clicks in the Two-step Login tab under Security in Account Settings. You can choose YubiKey OTP or, if your YubiKey supports it, FIDO2 WebAuthn.

How long does a YubiKey last? ›

Q: How long does the YubiKey last? A: We don't artificially limit the life-span of any YubiKey. The internals of the YubiKey's security algorithms currently limits each key to 30+ years of usage. The Yubikey is powered by the USB port and therefore requires no battery and there is no display on it that can break.

What happens if you lose a YubiKey? ›

If you lose your Yubikey, you can still use your phone authenticator app, but you cannot create a backup Yubikey. However, Yubikey also provides methods to recover your account, so you can get a replacement. An advantage to Yubikey is that it comes on a USB that cannot be identified.

Does a YubiKey need to be plugged in all the time? ›

Do I need to keep my yubikey plugged in all the time? A. No, you only need to insert your yubikey when you are prompted to do so during login.

Which is better 1Password or LastPass? ›

For almost everyone, 1Password is a better password manager than LastPass. There's so little difference between the general user experience, availability, and price of the two apps, that the additional security and transparency of 1Password make it the easy choice.

Which YubiKey is best for me? ›

If most of the accounts are accessed from your mobile device, then the Yubikey 5 NFC is a better key. If most of the accounts you want to secure don't require OTP, then the Security Key is a budget-friendly option.

Does YubiKey work with Chrome? ›

Chrome offers a simple, secure, and fast experience to browse the web – with Google's smarts built-in. Chrome automatically protects users from security threats like phishing and dangerous sites, and incorporates native support for YubiKeys with U2F and WebAuthn APIs.

How many passwords can YubiKey hold? ›

OATH (Yubico Authenticator) - the YubiKey 5's OATH application can hold up to 32 OATH-TOTP credentials (AKA authenticator app codes).

What happens when I touch my YubiKey? ›

The YubiKey has an integrated touch-contact that triggers the OTP generation. Generated OTPs are sent as keystrokes by the emulated keyboard, thereby allowing the OTPs to be received by any text input field or command prompt.

Can Bitwarden get hacked? ›

Has Bitwarden ever been hacked? No, Bitwarden has never been hacked. However, even if it does get hacked, since your data is fully encrypted and hashed before leaving your local device no one from Bitwarden's staff can access your data, and neither can hackers.

Where does YubiKey store data? ›

Each function on the YubiKey can only accept and store data in the proper format for securely authenticating with the various supported validation protocols. All loaded information is stored in the secured EEPROM in the memory space allocated with the applications utilizing the data.

Top Articles
Latest Posts
Article information

Author: Gov. Deandrea McKenzie

Last Updated:

Views: 5982

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Gov. Deandrea McKenzie

Birthday: 2001-01-17

Address: Suite 769 2454 Marsha Coves, Debbieton, MS 95002

Phone: +813077629322

Job: Real-Estate Executive

Hobby: Archery, Metal detecting, Kitesurfing, Genealogy, Kitesurfing, Calligraphy, Roller skating

Introduction: My name is Gov. Deandrea McKenzie, I am a spotless, clean, glamorous, sparkling, adventurous, nice, brainy person who loves writing and wants to share my knowledge and understanding with you.