How to Choose the BEST 2FA Key for Security (Yubikey)

All Things Secured
11 Aug 202206:24

Summary

TLDRIn this informative video, Josh from All Things Secured guides viewers on selecting the right Yubikey for their 2FA needs. He breaks down the decision into three key questions, addressing the necessity for secure one-time passcodes, extended authentication support, and the ideal form factor for various devices. Josh clarifies that while the 5 series offers advanced features like passcode storage and OpenPGP, the Security Key series is a cost-effective choice for individuals. He also highlights the importance of choosing the right plug type, such as USB-A, USB-C, or NFC, for convenience across multiple devices. The video aims to demystify the selection process and help users invest wisely in their online security.

Takeaways

  • 🔐 Yubikey is a top choice for security keys, offering various options to suit different needs.
  • 🛡️ The Security Key series is the entry-level option, suitable for basic 2FA needs.
  • 🗝️ The 5 Series and 5 FIPS Series are more advanced, offering the ability to store one-time passcodes and extended authentication support.
  • 👍 The Yubikey 5 Series has its own authenticator app, allowing for secure one-time passcode storage and use.
  • 🚫 Some companies still do not support 2FA hardware keys, making the 5 Series particularly useful for those needing compatibility with authenticator apps.
  • 👤 The Bio Series introduces fingerprint authentication, adding an extra layer of security for those who require it.
  • 💼 The Bio, 5 Series, and 5 FIPS Series are geared towards business use due to their advanced features.
  • 📱 Consider where and how you will use your security key, as this will influence whether you need USB-A, USB-C, or NFC capabilities.
  • 🔌 The Bio Series does not offer an NFC version, which may be a limitation for those wanting mobile device compatibility.
  • 📲 The 5Ci model provides a lightning plug for Apple devices, but it's more expensive and may not be as convenient as using an NFC key.
  • 🔄 The nano versions of the 5 Series are designed to stay plugged into computers, but this may not be the best security practice.

Q & A

  • What is the primary purpose of the video?

    -The primary purpose of the video is to help viewers choose the right Yubikey 2FA security key for their specific needs.

  • What are the different Yubikey series mentioned in the video?

    -The different Yubikey series mentioned are the Security Key Series, the Bio Series, the 5 Series, and the 5 FIPS Series.

  • Which Yubikey series can store one-time passcodes?

    -The Yubikey 5 and 5 FIPS series can store one-time passcodes.

  • Why might someone choose the Yubikey 5 series over the Security Key series?

    -Someone might choose the Yubikey 5 series if they need to create secure one-time passcodes or require advanced features like OpenPGP for email.

  • What is NFC and why is it relevant for Yubikey users?

    -NFC stands for Near Field Communication. It allows users to tap their Yubikey on a mobile device for authentication instead of plugging it in, which is convenient for modern mobile devices.

  • Which Yubikey series does not offer an NFC version?

    -The Bio series does not offer an NFC version.

  • What advantage does the Yubikey Bio series offer?

    -The Yubikey Bio series offers fingerprint authentication, adding an extra layer of security by ensuring that only the owner can use the key.

  • Why might the nano versions of the Yubikey 5 series not be ideal for all users?

    -The nano versions are designed to stay plugged into a computer at all times, which could be a security risk if the computer is stolen.

  • What are the different plug types available for Yubikeys and why are they important?

    -Yubikeys come with USB-A and USB-C plugs, which are important to match the ports on your devices. The 5Ci also offers a lightning plug for Apple devices, but NFC might be a more convenient option.

  • What does the video suggest about using Google Authenticator with Yubikey?

    -The video suggests that while you can use Google Authenticator, the Yubikey 5 series offers its own authenticator app that can store one-time passcodes, providing an alternative if you have privacy concerns with Google.

Outlines

00:00

🔑 Choosing the Right Yubikey

Josh from All Things Secured introduces Yubikey as the top security key on the market and aims to guide viewers in choosing the right 2FA key for their needs. He outlines the different series available—Security Key, Bio, 5 Series, and 5 FIPS—and promises to help viewers save money while making an informed decision.

05:06

📱 One-Time Passcodes and Security

Josh explains the importance of one-time passcodes for accounts that support only authenticator apps. He highlights that only the Yubikey 5 and 5 FIPS series support storing these codes, which can be used with Yubikey's own authenticator app. He suggests the 5 series for those needing this feature and the Security Key series for those content with existing authenticator apps.

🖐️ Extended Authentication Support

Josh addresses the need for extended authentication support, typically for business use or highly privacy-conscious individuals. He introduces the Bio series, which includes fingerprint authentication, providing an additional security layer. He notes that this feature may be overkill for most individuals but valuable for enterprises.

💻 Choosing Based on Device Compatibility

Josh advises viewers to consider where they'll use their security key and the type of connection they need—USB-A, USB-C, or NFC. He mentions that the Bio series lacks NFC, while the 5 series offers various connection types. He emphasizes the convenience of NFC for mobile devices and suggests selecting a key based on device compatibility and usage scenarios.

⚠️ Considerations for 5Ci and Nano Versions

Josh discusses the 5Ci, which includes a lightning plug for Apple devices but is more expensive and less convenient than NFC. He also critiques the nano versions meant to stay plugged into computers, arguing that they undermine the purpose of 2FA security. He recommends sticking with USB-A or USB-C options for most users.

🛒 Final Recommendations and Support

Josh concludes by recommending choosing between USB-A or USB-C and considering whether extra features like one-time passcodes or smart card capabilities are necessary. He encourages viewers to use affiliate links for purchases, as he earns a commission. He assures viewers that his recommendations are genuine and invites them to watch a follow-up video on setting up their first 2FA key.

Mindmap

Keywords

💡Yubikey

Yubikey is a brand of security keys that provides an additional layer of authentication beyond just a password. In the video, Yubikey is highlighted as the best security key on the market, suggesting that it is a reliable and trusted choice for two-factor authentication (2FA). The video discusses various Yubikey models, indicating the brand's range of products designed to cater to different user needs and preferences.

💡2FA (Two-Factor Authentication)

2FA, or two-factor authentication, is a security process that requires users to provide two different authentication factors to verify their identity. The video's main theme revolves around choosing the right 2FA key, emphasizing the importance of this security measure in protecting online accounts. The script mentions that the point of the video is to help viewers select the appropriate 2FA key for their situation.

💡Security Key Series

The Security Key Series is one of the Yubikey product lines mentioned in the video. It is positioned as an entry-level option for users looking to implement 2FA. The script suggests that this series is suitable for individual consumers who want a cost-effective solution for securing their online accounts.

💡5 Series

The 5 Series is a higher-end line of Yubikey products that offers additional features compared to the Security Key Series. The video explains that the 5 Series allows users to store one-time passcodes, which is a feature not available in the Bio or Security Key series. This makes the 5 Series particularly appealing for users who require more advanced security options.

💡NFC (Near Field Communication)

NFC is a technology that enables communication between devices over a short distance without the need for an internet connection. In the context of the video, NFC is a feature available in some Yubikey models, allowing users to authenticate by simply tapping their key on a compatible device, such as a smartphone. This provides a convenient method for using 2FA on mobile devices.

💡Fingerprint Authentication

Fingerprint authentication is a biometric security measure that uses unique patterns in a person's fingerprints to verify their identity. The video discusses the Bio Series from Yubikey, which includes a fingerprint sensor for added security. This feature allows the key to be used only by the authorized individual, enhancing the security of the 2FA process.

💡One-Time Passcodes (OPT)

One-time passcodes are temporary codes used for authentication that expire after a short period or after a single use. The video explains that certain Yubikey models, specifically the 5 Series, can store these passcodes, allowing users to generate and use them without relying on an authenticator app. This feature is particularly useful for securing accounts that do not support physical security keys.

💡OpenPGP

OpenPGP is a standard for data encryption and decryption that provides a way to secure email communication. The video mentions that the 5 Series Yubikey supports OpenPGP, which is an advanced feature for email security. This indicates that the 5 Series is designed for users who require robust privacy measures for their email communication.

💡USB-A and USB-C

USB-A and USB-C are types of USB connectors used for connecting devices. In the video, the presenter discusses the importance of choosing the right type of USB connector for a Yubikey based on the user's devices. USB-A is described as 'old-school' and USB-C is mentioned as becoming the standard for newer computers, indicating the need to match the security key's connector to the user's hardware.

💡5Ci

The 5Ci is a specific model of Yubikey that features a lightning plug for Apple devices. The video mentions the 5Ci as an alternative for users of Apple products, but also notes that it is significantly more expensive and that using an NFC key might be just as convenient. This highlights the trade-off between convenience and cost for users choosing a Yubikey model.

Highlights

Yubikey is considered the best security key on the market.

Guides viewers on choosing the right 2FA key for their needs.

Differentiates between the Security Key Series, Bio Series, 5 Series, and 5 FIPS Series.

Yubikey 5 and 5 FIPS series can store codes from authenticator apps.

Mentions the limitation of certain companies not supporting 2FA hardware keys.

Yubikey has its own authenticator app for storing one-time passcodes.

Bio Series offers fingerprint authentication for added security.

Bio Series acts as 2FA on top of 2FA, suitable for business enterprise use.

Security Key series is recommended for individual consumers.

Consideration of where and how the security key will be used.

Different plug options: USB-A, USB-C, and NFC for various devices.

NFC capability allows for tapping the key on mobile devices.

Bio series does not offer an NFC version.

Advises against permanently plugging in nano versions for security reasons.

Recommends choosing between USB-A or USB-C based on device compatibility.

Suggests considering the value of additional support for one-time passcodes or smart card capabilities.

Provides a step-by-step guide on setting up the first 2FA key in a follow-up video.

Transcripts

play00:00

Yubikey is considered the best security key on the  market right now, and no, they’re not paying me to  

play00:05

say that. But one of the most common questions  I get from people who are looking to buy a 2FA  

play00:09

security key is this: which one should I buy? Do  you need the Security Key Series or the 5 Series?  

play00:15

Do you need NFC? Fingerprint authentication?  What about the 5C, the 5C Nano or the 5Ci?

play00:22

If you’re confused, you’re not alone, but by  the end of today’s video, I promise you’ll know  

play00:26

exactly which 2FA key is right for you and more  than likely, you’ll save a bit of money as well.

play00:35

My name is Josh, this is All Things Secured,  

play00:37

and I’m going to assume you already know  what a 2FA key is and what it’s used for.  

play00:41

The point of this video is strictly to help  you choose the right key for your situation.

play00:46

And in the case of Yubikey, we’re talking about a  choice among the entry level Security Key series,  

play00:51

the Bio Series, the 5 Series and the highest  standard 5 FIIPS Series. And spoiler alert  

play00:57

if you’re the kind of person who  doesn’t watch a video to the end,  

play01:00

you’re probably going to want  to purchase one of these 4 keys.

play01:03

Ok, this shouldn’t take long,  

play01:05

but let’s break it down into three simple  questions you need to answer for yourself.

play01:09

First, do you need the ability to create or use  secure one-time passcodes? While every Yubikey  

play01:16

can be used as a hardware security token, only  the Yubikey 5 and 5 FIPS series allows you to  

play01:22

use the key to store codes that you would  normally get from an authenticator app.

play01:26

Why does this matter? Well, let’s say that you  have an account you want to secure that only works  

play01:30

with authenticator apps, not physical security  keys. And believe it or not, there’s still quite  

play01:37

a few companies out there who don’t yet support  2FA hardware keys. For example, I can’t use this  

play01:43

key to secure my ProtonMail account, at least  at the time I’m recording this video, but they  

play01:48

do allow me to secure with a time-based one-time  passcode from an app like Google Authenticator.

play01:55

What most people don’t know is that Yubikey also  has its own authenticator app and certain keys  

play02:00

can store these one-time passcodes or OPT that  the app then decodes. I can either plug it in or,  

play02:07

if it’s an NFC key, just tap it on my  phone and the codes appear like magic.  

play02:12

Like I said, this only works with the Yubikey 5  series, not the Bio or the Security Key series,  

play02:18

but if you’re one of those people  who fears that Google might be using  

play02:21

their authenticator app to link your mobile device  to your identity, this is a solution that works.

play02:27

Do you need to create secure one-time passcodes?  

play02:30

Then go with the 5 series. Are you  ok still using Google Authenticator,  

play02:34

Authy or some other authenticator app? Then save  some money and go with the Security Key series.

play02:40

Second question: do you need extended  authentication support? Usually this only applies  

play02:46

to businesses, with stuff like smart card support  or to those who are incredibly privacy conscious  

play02:52

with the OpenPGP for email. If none of that makes  sense to you, then you probably don’t need it.

play02:57

Or if you fear somebody stealing your key and  using it without your permission, extended  

play03:02

authentication in the form of a fingerprint  sensor might be appealing to you. That’s where  

play03:06

this Bio series comes in handy. Unlike pretty  much any other 2FA key on the market, the Bio  

play03:10

series from Yubikey allows you to configure your  fingerprint so that only you can use your key.  

play03:15

It’s like setting up 2 factor authentication  on top of your 2-factor authentication.

play03:20

Honestly, it’s overkill for most individuals  

play03:23

but possibly a very attractive  option for business enterprise use.

play03:26

So hopefully by now you understand which series  is right for you. Generally speaking, the  

play03:31

Bio, 5 series and 5 FIPS series are meant for  businesses to use, while the Security key series  

play03:37

is for individual consumers. You would probably  do great using the Security Key series if you  

play03:41

want - and it will save you some money. I use the  5 series personally, but that’s only because I  

play03:48

care about being able to store one-time passcodes  and OpenPGP. I realize that might not be you.

play03:55

Well that leads us to our final question:  Where will you be using your security key?

play03:59

Take a moment to consider all the places where  you might use 2 factor authentication. Your phone.  

play04:04

Your laptop. Your spouse’s laptop. Your tablet  device. Which plug covers you on the most devices?  

play04:11

And remember, you can always carry around an  adapter as well. Do you prefer an old-school USB,  

play04:19

which is formally named the USB-A and looks like  this? In my case, I need a USB-C, which is quickly  

play04:25

becoming the standard for all newer computers,  along with the NFC or near field connection, which  

play04:30

I use on my mobile device. When you see those  letters NFC, just know that this is the technology  

play04:35

that allows you to tap the key on the back of your  phone instead of plugging it in. The NFC works on  

play04:41

iPads, iPhones, Samsung, Google Pixel…pretty  much any modern mobile device out there.

play04:45

The Bio series is the only one that doesn’t  offer an NFC version, so for this reason  

play04:50

I’d only seriously be considering one  of these four options highlighted here.  

play04:55

You should already know whether you need  the 5 series or the security key series,  

play04:59

so now just choose either USB-A or USB-C, and they  all have NFC capability for your mobile devices.

play05:06

As a side note, you could purchase the Yubikey  5Ci, which gives you a lightning plug for Apple  

play05:11

devices, but not only is this significantly  more expensive, I’ve also found that it’s  

play05:16

just as easy if not easier to simply tap my NFC  key on the phone instead of plugging the 5Ci in.

play05:22

The 5 series also sells these smaller nano  versions that are meant to stay plugged into your  

play05:26

computer at all times, but I gotta say, this just  doesn’t seem like a good idea to me. If somebody  

play05:32

breaks into your home or steals your laptop or  something like that, keeping your 2FA security  

play05:37

key permanently plugged into your computer seems  to negate the purpose of having a 2FA key in the  

play05:42

first place. So unless I’m missing something,  I think it’s best to stay away from these keys.

play05:47

In the end, unless you’re purchasing for a  business, I advise you to choose between USB-A  

play05:51

or USB-C and then decide whether it’s  worth the extra 20 or so dollars for you  

play05:55

to be able to have addition support by way of  one-time passcodes or smart card capabilities.

play06:01

If this video was helpful, the best way you can  support me is by using the affiliate links you’ve  

play06:05

seen in this video or in the description below.  Yubikey did not pay me to say anything in this  

play06:09

video, but they will give me a commission if  you choose to purchase their key using my link,  

play06:13

and this is what I use and recommend to  my own family and friends, I promise.  

play06:17

Once you’ve received your key,  check out this video next that  

play06:20

goes step-by-step into how you set  up your first 2FA key. Take care.

Rate This

5.0 / 5 (0 votes)

الوسوم ذات الصلة
2FA SecurityYubikey GuideSecurity KeyNFC AuthenticationFingerprint KeyUSB-A vs USB-COne-Time PasscodesAuthenticator AppEnterprise SecurityPersonal Security
هل تحتاج إلى تلخيص باللغة الإنجليزية؟