TrustRadius: an HG Insights company

Yubico YubiKeys

Score9.4 out of 10

139 Reviews and Ratings

What is Yubico YubiKeys?

Yubico YubiKeys make the internet safer with phishing-resistant multi-factor authentication (MFA) by providing simple and secure access to computers, mobile devices, servers, and internet accounts. The Yubico YubiKey stops account takeovers at scale by mitigating phishing and ransomware attacks, and delivers users authentication with a simple touch or tap.

Read more details.

Videos

Who Buys & Uses Yubico YubiKeys

YubiKeys are great for hardware protected MFA

Use Cases and Deployment Scope

Securing sensitive applications for users that do not have or cannot use a mobile device, or that is need a hardware protected device. YubiKeys will also function for desktop MFA and will also be used by IT Administrators that have extra sensitive applications. YubiKeys are also used for accessing VPN when soft tokens are too slow or time out.

Pros

  • Security
  • Multifactor
  • Encrypted passwords

Cons

  • Expense
  • Biometrics
  • resiliency

Most Important Features

  • Security
  • Additional Factors (hardware protected)
  • Portable

Return on Investment

  • Loss
  • Complicated setup for end users
  • Expense

Other Software Used

Okta, Microsoft 365, Delinea Secret Server

Yubico survey

Use Cases and Deployment Scope

We use it either instead of Okta verify, or as a supplement, in case the Okta verify app gets stuck or has an error

Pros

  • Easy to use
  • Portable
  • Secure

Cons

  • Maybe some protection for the connector portion of each key (the part that touches the computer’s port. That way it lasts longer

Most Important Features

  • Price
  • Security
  • Simplicity

Return on Investment

  • Reduces risk

Yubico YubiKeys is a secure easy to use solution that has made our company more secure

Use Cases and Deployment Scope

We currently use Yubico YubiKeys for our higher at risk users that have access to sensitive company information. For us it is an easy secure way for them to be secured and not worry about unauthorized access to sensitive data we need protected. It also assures that we reduce the risk as much as possible for risk of credential theft.

-we are now exploring the ways that YubiKeys can also be used for personal security of items and the different ways to implement the service and hardware to get the most benefit for our company and people.

Pros

  • Fast easy authentication to hardware and software
  • Easy for users to use
  • Easy to keep up with

Cons

  • We have had a couple of instances of issues with the key not working correctly intermittently
  • Some issues with users breaking keys as some models are slightly flimsy
  • Overall we are happy so I can’t think of anything else

Most Important Features

  • Easy to set up
  • Overall great hardware
  • Small form factor
  • Many different options for hardware style

Return on Investment

  • Defiantly a reduction in password resets for some higher level users that we had issues with in the past
  • Feeling secure in the knowledge that our data is secure with using Yubico YubiKeys
  • Easy to integrate and use with our windows products

Alternatives Considered

SecurID

Other Software Used

CrowdStrike Falcon, Proofpoint Threat Intelligence Services, Rapid7 InsightIDR

Usability

Yubico Review

Use Cases and Deployment Scope

So we use the YubiKey for securing most of our cloud services, like Office 365, Microsoft 365 mainly, but also other things like password managers. And as far as the services will let us, we try to use mainly the Yubikeys for the physical security tokens and trying to use them for passwordless access to avoid the risks of password theft.

Pros

  • The setup is very easy. It's well documented and it's well supported with most services.

Cons

  • The backup situation is a hard problem to solve, but it needs to be resolved sooner or later because as it is now, if you have two Yubikeys, you have to enroll them both. When you lose one, you have to remember which one to deactivate and that's a hassle. Fortunately that doesn't happen very often. But having a backup Yubikey that you don't have to enroll everywhere but they can switch over to would be a dream.

Most Important Features

  • Ease of use
  • Hardware security

Return on Investment

  • I'd say it's enhanced our security and it's very easy to get the users to use them. It's very, at least easy to teach them how to use them.

Other Software Used

Google Authenticator, Microsoft Entra ID

Yubico YubiKeys Review

Use Cases and Deployment Scope

The primary problem it solves is the non-repudiation. So knowing that the person logging in is the person who has the key and it's our employee. So the use case is things like there's none other MFAs that you rely on cell phones or QR codes that can be shared. A physical key cannot be shared.

Pros

  • It's fast speed. You don't have any help. Pull out a phone and load a code or pull out a phone and do, yes, this is me. It's like plug it in, pop and acknowledge the MFA request.

Cons

  • I think the supply chain of getting them is probably the biggest challenge. So getting them out to use in a decentralized workforce. So having to go through Amazon or some other reseller and load addresses and try and get them out to employees as a part of our onboarding process.

Return on Investment

  • So risk reduction in terms of accessing very sensitive systems. For example, having root level access to AWS, that's only, we have a multi key set up on the root account and then those shared with say shared issued to a handful of constituents and geographically dispersed so that no one person is held all the keys so to say. So definitely a risk reduction in terms of accessing standard information in enterprise.
  • Speed for the end user is probably most of the largest benefits. I mentioned the shortfalls is just like when someone uses one you have to go through that's like not like, good scanning code, now you have to pull back to some other solution.
  • The onboarding flow of getting them out to use this depending on not necessarily Yubico's function, I know they do do some distribution, but being able to more tightly weave that into an HRS or IT system.