Stina Ehrensvärd (CEO and founder) Jakob Ehrensvärd (CTO)
Website
yubico.com/products
The YubiKey is a hardware authentication device manufactured by Yubico to protect access to computers, networks, and online services that supports one-time passwords (OTP), public-key cryptography, and authentication, and the Universal 2nd Factor (U2F) and FIDO2 protocols[1] developed by the FIDO Alliance. It allows users to securely log into their accounts by emitting one-time passwords or using a FIDO-based public/private key pair generated by the device. YubiKey also allows storing static passwords for use at sites that do not support one-time passwords.[2] Google, Amazon, Microsoft, Twitter, and Facebook use YubiKey devices to secure employee accounts as well as end-user accounts.[3][4][5] Some password managers support YubiKey.[6][7] Yubico also manufactures the Security Key, a similar lower-cost device with only FIDO2/WebAuthn and FIDO/U2F support.[8][9]
The YubiKey implements the HMAC-based one-time password algorithm (HOTP) and the time-based one-time password algorithm (TOTP), and identifies itself as a keyboard that delivers the one-time password over the USB HID protocol. A YubiKey can also present itself as an OpenPGP card using 1024, 2048, 3072 and 4096-bit RSA (for key sizes over 2048 bits, GnuPG version 2.0 or higher is required) and elliptic curve cryptography (ECC) p256, p384 and more, depending on version,[10] allowing users to sign, encrypt and decrypt messages without exposing the private keys to the outside world. Also supported is the PKCS#11 standard to emulate a PIV smart card. This feature allows code signing of Docker images as well as certificate-based authentication for Microsoft Active Directory and SSH.[11][12][13][14]
Founded in 2007 by CEO Stina Ehrensvärd, Yubico is a private company with offices in Palo Alto, Seattle, and Stockholm.[15] Yubico CTO, Jakob Ehrensvärd, is the lead author of the original strong authentication specification that became known as Universal 2nd Factor (U2F).[16]
YubiKey released the YubiKey 5 series in 2018, which adds support for FIDO2.[17]
^"Specifications Overview". FIDO Alliance. Retrieved 4 December 2015.
^"What Is A Yubikey". Yubico. Retrieved 7 November 2014.
^McMillan (3 October 2013). "Facebook Pushes Passwords One Step Closer to Death". Wired. Retrieved 7 November 2014.
^Diallo, Amadou (30 November 2013). "Google Wants To Make Your Passwords Obsolete". Forbes. Retrieved 15 November 2014.
^Blackman, Andrew (15 September 2013). "Say Goodbye to the Password". The Wall Street Journal. Archived from the original on 3 January 2014. Retrieved 15 November 2014.
^"YubiKey Authentication". LastPass. Retrieved 15 November 2014.
^"KeePass & YubiKey". KeePass. Retrieved 15 November 2014.
of the name "YubiKey" is that it derives from the phrase "your ubiquitous key", and that "yubi" is the Japanese word for finger. YubiKey II and later...
Fastmail also provides for two-factor login using a YubiKey. While associating one or more YubiKeys with a Fastmail account will not prevent normal logins...
the older KeePass 1 (.kdb) databases. KeePassXC supports having key files and YubiKey challenge-response for additional security. The Electronic Frontier...
solutions. Complex setup process compared to security keys like YubiKey. Physical Loss: Losing the OnlyKey device can potentially lock the user out of their...
Multi-factor authentication is also available using TOTP, WebAuthn, or YubiKey OTP. Since PVE 8.1 there is a full Software-Defined Network (SDN) stack...
Retrieved May 28, 2022. "Protect your Proton Account with YubiKey and other security keys". Proton Mail Blog. October 13, 2022. Archived from the original...
Security Modules (HSM) implementations, including YubiKey 4 tokens, often used to generate PGP keys. Keys of lengths 512, 1024, and 2048 bits generated using...
announced that affects RSA keys generated by YubiKey 4 tokens, which often are used with PGP/GPG. Many published PGP keys were found to be susceptible...
Initiative for Open Authentication (OATH) WebAuthn web authentication YubiKey "Password-The Security Issue That the Big Leaders Want to Eliminate". 30...
LastPass Authenticator app for mobile phones as well as others including YubiKey. LastPass is available as an extension to many web browsers, including...
MongoDB and more. Multifactor authentication via Duo Security, SAASPASS, YubiKey, RSA, Google Authenticator (TOTP) and more. Administrative UIs to manage...
authenticator apps, and email in free version, with the addition of Duo and YubiKey OTP for paid customers, with recovery code to bypass the step if a 2FA...
2023. Retrieved May 17, 2023. "How to Unlock Your iPhone With a Security Key". Wired. Condé Nast. February 19, 2023. Retrieved May 17, 2023. "iOS 16.3...
FIDO U2F support. This means that it will now work with YubiKey and other third party security keys. Though this protection is embedded at the service login...
USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and...
authentication devices. Amongst those are hardware tokens like Feitian C200, the Yubikey by Yubico or other U2F/WebAuthn devices. Many smartphone apps compliant...
1Password and Dashlane. In the hardware security key market, Everykey's competitors include Nymi and YubiKey. Everykey has been recognized by many local and...
1967), Swedish-American entrepreneur, CEO of Yubico, co-inventor of the YubiKey Marie Ehrling (born 1955), business executive, chair of TeliaSonera Annika...
which affects RSA keys generated by buggy Infineon firmware used on Yubikey 4 tokens, often used with OpenPGP. Many published PGP keys were found to be...
Grabham; Maggie Tillman (September 10, 2019). "Apple iPadOS preview: All the key new iPad features explored". Pocket-lint. Archived from the original on October...
can be mandated for each sign-in by utilizing hardware tokens (such as YubiKeys) linked to the Google Account. At its debut, ChromeOS was viewed as a competitor...
SMS (since version 4.0.4) scratch passwords list (since version 4.0.4) YubiKey in proprietary Yubico OTP mode (since version 4.3) without2FA for accounts...
OpenKeychain include a modern user interface, support for NFC and the YubiKey NEO. "Android Privacy Guard". 2014-03-24. Retrieved 2014-07-22. "Release...