'ZDNET Recommends': What exactly does it mean?
ZDNET's recommendations are based on many hours of testing, research, and comparison shopping. We gather data from the best available sources, including vendor and retailer listings as well as other relevant and independent reviews sites. And we pore over customer reviews to find out what matters to real people who already own and use the products and services we’re assessing.
When you click through from our site to a retailer and buy a product or service, we may earn affiliate commissions. This helps support our work, but does not affect what we cover or how, and it does not affect the price you pay. Neither ZDNET nor the author are compensated for these independent reviews. Indeed, we follow strict guidelines that ensure our editorial content is never influenced by advertisers.
ZDNET's editorial team writes on behalf of you, our reader. Our goal is to deliver the most accurate information and the most knowledgeable advice possible in order to help you make smarter buying decisions on tech gear and a wide array of products and services. Our editors thoroughly review and fact-check every article to ensure that our content meets the highest standards. If we have made an error or published misleading information, we will correct or clarify the article. If you see inaccuracies in our content, please report the mistake via this form.
Whenever I'm asked for things that are a must-have, a YubiKey is on the top of my list no matter what platform or operating system people are using -- Windows, Mac, or Linux, Android or iOS.
It doesn't matter.
Everyone needs a YubiKey.
A hardware authentication device made by Yubico, it's used to secure access to online accounts, computers, and networks. The YubiKey 5 Series look like small USB flash drives and come in a range of different connectors -- USB-A, USB-C, and USB-C and Lightning combo. There are versions that also include support for NFC.
It offers two-factor authentication (also known as multi-factor authentication or two-step verification) for hundreds of online services, from Facebook, Google, and Twitter, to more specific services such as Coinbase, Salesforce, and Login.gov. Your YubiKey can also be used to secure password storage services such as Bitwarden, Password Safe, and LastPass.
The YubiKey 5 Series keys support a broad range of protocols, such as FIDO2/WebAuthn, U2F, Smart card, OpenPGP, and OTP. Having a YubiKey removes the need, in many cases, to use SMS for two-factor authentication -- a method that has been shown to be insecure.
If your online accounts are keeping something that you can't afford to lose, a Yubikey makes perfect sense. I've been using YubiKeys for years now, and they have been flawless and foolproof.
While one YubiKey is enough to get started with, I have several. Not only does this give me a backup in case I lose one (I haven't yet!), but if I pick a couple with different connectors (say the USB-C/Lightning and a USB-A with NFC), this gives me the flexibility to log into accounts across a range of devices.
This YubiKey features a USB-A connector and NFC compatibility. Like all YubiKeys, this one is water and crush resistant.
This YubiKey features a USB-C connector and NFC compatibility.
This YubiKey features a USB-C connector and a Lightning connector for the iPhone.
A cheaper version of the YubiKey, this one is FIDO certified and works with Google Chrome and any FIDO-compliant application on Windows, macOS, or Linux. Use this to secure your login and protect your Gmail, Dropbox, Outlook, Dashlane, 1Password, accounts, and more.
Note that this YubiKey is not compatible with LastPass, which requires a YubiKey 5. Always check for compatibility with the services you want to use before buying.
A YubiKey is the ultimate line of defense against having your online accounts taken over. And with prices starting at $25, it's one of those indispensable gadgets for the 21st century.
The YubiKey FIDO key supports far fewer protocols and services, and is more aimed at the home users, hence the low price.
Most services to allow you to set up a recovery mechanism in case you lose your security key, but it is highly recommended that you have a minimum of two keys, authenticate all these keys you have with all the services you use. That way you have a backup key in case your main key is lost, stolen, or damaged.
No, they draw their power from the USB port and there's no battery to charge or replace.
Very. They are crushproof, waterproof, and impact resistant. I've carried YubiKeys on my keyring for years and not had a problem. That said, they're no indestructible, so don't go deliberately abusing them.