TrustRadius Insights for Yubico YubiKeys are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.
Pros
Streamlined Login Process: Users highlight Yubico YubiKey's streamlined login process. The process significantly reduces multifactor authentication time from up to 30 seconds to less than a second. This efficiency has been highlighted as a key benefit by many users who value quick and hassle-free access to their accounts.
Remote Document Signing: The ability to sign documents remotely using certificates stored on Yubico YubiKeys is highly valued by users, offering convenience and flexibility in document signing from any location. This feature enables users to securely sign important documents without being physically present, enhancing productivity and workflow efficiency.
High-Security Features: Users commend the high-security features of the Yubico YubiKey, such as storing a number of private keys, and providing superior capabilities compared to other security key brands. The robust security measures implemented in the device give users peace of mind regarding the security of their sensitive information and systems.
I always use it to access my work email and my personal email. Like my systems like AWS, I always use my Yubico YubiKeys.
Pros
Right now I don't know, but I like very much this product because for me it's a lot of security on my systems and my personal stuff.
Cons
I saw in these, I don't know the name of the industry, but it is like ybi, but you can open your doors with that. It's great because for example, in my house, I have a door and I can unlock it with my cell phone. But if I can open with Yubico YubiKeys, I think it's a great opportunity.
Likelihood to Recommend
I think it should work. I think it's best when you try to open a computer and you try to access an email and for example, Salesforce and the other systems. And the last, I don't know because I am a heavy user of this.
We're using it for MFA in the business, using it primarily with password manager, so use it to generate passwords, long and encrypted passwords, and then also to help us protect us with email. Personally, I use it from all my bank accounts.
Pros
Yeah, just peace of mind, some security, and not worried about whether or not the public key and private key is going to work. MFA is kind of weak, so it gives us a level of confidence.
Cons
I can't think of anything.
Likelihood to Recommend
I haven't found one where it's less appropriate except that my wife doesn't want to use it. It's too technical for her, so I guess she'd be better off saying why she doesn't want to use it. Nothing. She's even that way with password managers, so I can't think of anything, quite frankly.
I can talk more about it in my personal capacity. So I use it to secure all of my own personal services, Google, social media, government, login services, basically anything that supports two FA and supports a hardware token, I'll use that over OTP, SMS, or anything is just simply the most secure solution I have found. I've always heard of people getting, "oh, my account's been hacked, my things, my account's being drained." I don't have this problem because I use hardware security module.
Pros
It's very easy to use. So I use the USBC and NFC one, so not only can I either insert it into a USB-C port, which the new iPhone 15 or iPad has, but you can also just tap it using NFC. So it's really easy across the broad range of devices to authenticate.
Cons
The only con is hardware based, so if it's in the other room you might have to get off the sofa to go get it. But aside from that, I mean I think that trade off is worth the security provides.
Likelihood to Recommend
Anything where you value the security of access to data? Financial data, whether it's personal or professional, is highly useful because it provides us with that extra layer of physical security protection. If the data is something you're signing up for where you don't really care, it doesn't really matter at that point if it's a throwaway account on an internet site. But anything where security is important, definitely.
VU
Verified User
Team Lead in Information Technology (Computer Software company, 501-1000 employees)
So Yubico YubiKeys have been essential for protecting the most critical accounts at my company, especially ones that we just can't afford for them to get compromised. So knowing that we can use it as a passkey and go passwordless or use it for two-factor authentication has been pretty critical to securing accounts and also gives us a lot of peace of mind knowing that we're not sharing two-factor authentication codes. Trying to sync that between vaults, knowing that there's just one hardware solution. If someone loses their key, we can just remove it from the account. Gives a lot more peace of mind than some of the other two-factor options.
Pros
I would say very simple to use. It's something that everyone can figure out. Just plug it in, press the little button, and you're good to go.
I would say the fact that it is easy to manage an account so you can label each key so you can have one for each employee. If that employee notifies you that they lost it or they're no longer with the company, you just go and remove it.
I think one thing I like as well is that somebody has to be at the device to initiate the key. So even if you leave it plugged into your device, you walk away somehow a hacker gets remote access, they're moving the mouse around, they try to go to an account. Even if your Yubico YubiKeys is plugged in, unless you're there to press it and physically give it input, it's still not going to send the credentials. So that's a big sell for me.
Cons
As easy as the management is, it still can feel a little bit overwhelming as you add more and more keys and more team members. And there's also a bit of reliance on trusting that team member to tell you, "Hey, I lost the key." Because what happens if they lose it? They don't tell you someone gets a hold of it, then all of a sudden they have the physical key into the account where if you're using something that's a password solution, like syncing 2FA codes with a password manager, you need the knowledge of what the master password to get into the vault. So unless that employee tells someone which they could choose to do, but assuming they don't, it's a little bit more difficult in my mind to gain access that way instead of just stealing someone's key if they get pickpocketed or just so many ways that potentially that key could get in the wrong person's hands.
Likelihood to Recommend
I think whenever you're either a small team that works together in person or you're a company that has the resources to give each employee a Yubico YubiKeys, that's a great use case. I've found it's maybe not as great if you're working with freelancers that are remote because you don't know necessarily the lifespan of the freelancer. You may work with them for three months and then maybe you start working with a different freelancer. So to mail out Yubico YubiKeys for that very part-time freelance position is not necessarily the easiest. So in those cases, I've resorted to just syncing the two-factor codes and giving them a log into a password manager because that's much easier to onboard. So yeah, I guess that would be maybe one of the downsides is onboarding users, getting them started. But if you have a small team in person or you've got the resources, and you've got an IT department, then onboarding is not as much of an issue.
VU
Verified User
C-Level Executive in Corporate (Media Production company, 1-10 employees)
I use Yubico YubiKeys to log into our single sign-on to gain access to our sensitive systems and data. It's much easier to log in with a Yubico YubiKeys versus doing it with a password and much more, not only easier but more secure because it's physically on me versus a password that could be stolen.
Pros
It identifies who I am by being able to scan my fingerprint. It verifies that I am the user because it's physically on me. So it does a great job of authentication and it's very convenient in its form factor. It's very small, it can fit on my key chain.
Cons
Sometimes the product's just not on me, so I have to run downstairs or run to my car to get it. And then in that case, maybe using an on-device authentication, then I switch to that.
Likelihood to Recommend
I think this product is well suited for any enterprise that wants to roll out pass keys because it's fully compliant with that. And any company that's worried about password risk, this is a good replacement for that.
Integration with VPN could be better-- login requires user, password for step one, then password + Yubikey for step two. Why make me enter the password twice?
Likelihood to Recommend
Seems suited for workplace MFA. Would be nice to integrate with other identity verification schemes.
Reducing attack vectors where we can is important -- and Yubico YubiKeys help us do that! Mostly they're used to help access more secure accounts across all our devices. We're a small company, so there's only so much to secure right now, but we have the confidence that Yubico YubiKeys will scale right along with us!
Pros
One-touch authentication
Versatility across devices
Easy to Transport (like with car keys!)
Cons
Difficulty with Mobile Devices (if you discover you now need a USB-C YubiKey instead, for instance...)
Easy to Lose, Hard to Replace
Can I program it with more than one thing now?
Likelihood to Recommend
When I started needing to use my iOS / Android devices more and more, I found my USB-A YubiKey less than helpful.
Use my Yubico YubiKeys for 2FA during the login to enterprise SSO.
Pros
Reliable
Good size and compatibility
Cons
Not sure it is a Yubico YubiKeys problem, but mobile browsers do not always prompt for a PIN code, which is a bit scary
Likelihood to Recommend
If a service supports security keys, I always enable it and enroll my Yubico YubiKeys. On the other hand, I prefer passkeys if they are supported and allowed, which is the case for our enterprise SSO. However, even in this case, I use Yubico YubiKeys for new platforms / browsers or as a backup.
VU
Verified User
Engineer in Engineering (Computer Software company, 10,001+ employees)