this post was submitted on 20 Oct 2025
40 points (100.0% liked)

Privacy

43865 readers
848 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

I am thinking about buying a pair of physical 2FA keys to protect my password manager and sensitive accounts. Which brand and model do you suggest?

If a model with open source firmware doesn't come with big drawbacks, I'd prefer it, because I may learn from the source code and even contribute to it.

NFC is not necessary, and the keys should be USB-A. A fingerprint reader is welcome if the price doesn't increase too much.

Thank you all in advance.

you are viewing a single comment's thread
view the rest of the comments
[–] turtl@lemmy.ml 5 points 2 months ago (3 children)

Why do folks seem to prefer Yubikey over alternatives like Nitrokey or Token2?

[–] Cat_Daddy@hexbear.net 4 points 2 months ago

Longevity (mine is about 15 years old)

[–] utopiah@lemmy.ml 3 points 2 months ago (1 children)

So far nobody provided a good answer (if I missed it, I apologized, please do share) so I'm going to assume it's the typical "Nobody ever get fired for buying from IBM" mindset, namely rely on what is the most popular, confirm it works well while ignoring viable alternatives IMHO, e.g NitroKey.

[–] Godort@lemmy.ca 2 points 2 months ago (1 children)

I’m going to assume it’s the typical “Nobody ever get fired for buying from IBM” mindset

That's pretty much it exactly. Yubico has the required features, are widely supported, and are widely used. They have a track record of reliability.

Other viable alternatives definitely exist, but they don't have the same real-world penetration. The disadvantage with that is if you run into a platform-specific issue, finding someone who has had the same issue before and posted the solution somewhere becomes far less likely.

[–] utopiah@lemmy.ml 1 points 2 months ago* (last edited 2 months ago)

if you run into a platform-specific issue

Well that's of course possible but in theory (which is so different from practice, I get that) if it relies on protocols or specifications rather than vendor specific implementations, e.g. OTP, TOPT, HOTP, U2F, OpenPGP, WebAuthN, etc then it should be fine.

[–] sparkle_matrix_x0x@lemmy.ml 1 points 2 months ago

That the same thing I asked myself...