# New to yubikey, some questions

**URL:** https://discuss.privacyguides.net/t/new-to-yubikey-some-questions/23022
**Category:** Questions
**Created:** 2024-12-08T21:08:58Z
**Posts:** 15

## Post 1 by @untitled_unsterile932 — 2024-12-08T21:08:58Z

I’m considering getting some YubiKeys for the first time and had some questions.

My setup: I use Bitwarden as my password manager and Ente for 2FA. I want add 2FA protection to my Bitwarden account but I’d rather not use Ente for these purposes in case I lose my phone. I of course have the codes backed up on a server in my apartment, but I’m more concerned about traveling and not having access

So I was considering using YubiKeys _only_ for Biwarden as my 2FA. I figured I’d carry one on me, have one in a safe at home, and maybe another in my parents safe in their home. So this would be used to login to my Bitwarden vault.

My questions:

1. I see YubiKey make several different keys. Given my usecase above, and needing NFC and USB, which key would I need?
2. Is there any option to protect the key with a code? So for example: I go to unlock Bitwarden on a new device. I enter my Master Password and then when it prompts for 2FA, I connect my YubiKey. Is there any way to require a code to utilize the key?

Anything else I should consider?

---

## Post 2 by @anon73250778 — 2024-12-08T21:49:53Z

> [@untitled_unsterile932](#):
>
> I see YubiKey make several different keys. Given my usecase above, and needing NFC and USB, which key would I need?

Get the 5C it has the most compatibility for connectivity.

> [@untitled_unsterile932](#):
>
> Is there any option to protect the key with a code? So for example: I go to unlock Bitwarden on a new device. I enter my Master Password and then when it prompts for 2FA, I connect my YubiKey. Is there any way to require a code to utilize the key?

You need to press/touch the metal part of the yubikey for it to acknowledge that you want to activate the 2FA. Think of it as a 1 key code. You have to touch it for it to work, otherwise the machine it is connected to doesnt get the code. You dont need to do this for NFC though, only for when it is inserted in the USB slot, because doing the NFC is a concious effort.

---

## Post 3 by @phnx — 2024-12-08T22:33:52Z

1. Get the [**Security Key C NFC**](https://www.yubico.com/product/security-key-series/security-key-c-nfc-by-yubico-black/), it is much cheaper than the 5C NFC though it lacks more advanced functionality (only supports FIDO2). For Bitwarden and other websites that accept passkeys / hardware keys, this is all you need.
2. Yes, previously websites got to dictate whether a PIN was required, but as of Firmware 5.7 and the CTAP2.1 protocol (part of FIDO2) you can set your security key to **always** require a PIN.

---

## Post 4 by @untitled_unsterile932 — 2024-12-09T02:54:53Z

Thank you! Good to know that I can use a pin and I’ll try out the model you suggested

---

## Post 5 by @untitled_unsterile932 — 2024-12-09T02:59:41Z

When you say the 5C has the most compatibility for connectivity, what do you mean?

---

## Post 6 by @anon73250778 — 2024-12-09T05:21:50Z

It means it will work on iPhones and Android (via NFC) as well as desktop systems (Windows/Linux/MacOS via USB)

---

## Post 7 by @untitled_unsterile932 — 2024-12-09T15:09:16Z

But don’t the 5C and the Security Key C NFC support both NFC and USB like @phnx is suggesting?

---

## Post 8 by @Securely0845 — 2024-12-09T15:15:19Z

There are two models, the 5C without NFC and the 5C with NFC, there are also type-A USB models, with and without NFC, as well as a type-C and lightning connector option without NFC.

I’d recommend the 5C with NFC or the Type-A USB with NFC.

---

## Post 9 by @untitled_unsterile932 — 2024-12-09T15:22:24Z

Any reason to go with a 5 series over a Security Key? They both support USB and NFC

---

## Post 10 by @Securely0845 — 2024-12-09T15:38:58Z

That depends on what methods of authentication you want to use with your hardware key.

The Security Key C only supports FIDO2/WebAuthn (hardware bound passkey) and FIDO U2F authentication protocols.

The 5 Series supports FIDO2/WebAuthn (hardware bound passkey), FIDO U2F, Yubico OTP, OATH-TOTP, OATH-HOTP, Smart card (PIV) and OpenPGP.

Typically FIDO2/WebAuthn is sufficient for most users and should cover 99% of regular authentication cases. It should be completely sufficient for your use case of BitWarden second factor for login/authentcation.

---

## Post 11 by @untitled_unsterile932 — 2024-12-09T15:46:23Z

Okay thank you!

---

## Post 12 by @untitled_unsterile932 — 2024-12-13T01:25:42Z

I ended up getting a [Yubico security key](https://www.yubico.com/product/security-key-series/security-key-nfc-by-yubico-black/) and was experimenting with getting it setup on my Bitwarden account and attempting to access the account from different devices.

At first, I assumed I would set it up in the Yubikey section of my account, but that didn’t work. It only seemed to work if I added it to the Passkeys section.

Next, I found that while it seems to work with my iphone, and I was prompted for WebAuthn, it didn’t seem to work with the Bitwarden Desktop app, or on the Mullvad Browser. In both cases, it only prompts me for traiditional 2FA codes.

Is this expected? A little concerning that it might not work in certian insrtances

---

## Post 13 by @untitled_unsterile932 — 2024-12-13T01:33:27Z

I did end up getting a Security Key from Yubico, and using the Yubio Authenticator, I did set a pin. However when I setup the key as my MFA webauthn key for Bitwarden, Bitwarden doesn’t prompt me for the pin when asking for the key.

Is there anything additional I need to do?

---

## Post 14 by @sgp — 2024-12-13T15:50:53Z

You can enable `always-uv`

> [@Recommend Always UV setting for Yubikey](https://discuss.privacyguides.net/t/recommend-always-uv-setting-for-yubikey/20607):
>
> In the light of [https://discuss.privacyguides.net/t/eucleak-yubikey-5-can-be-cloned-in-a-matter-of-minutes/20585](https://discuss.privacyguides.net/t/eucleak-yubikey-5-can-be-cloned-in-a-matter-of-minutes/20585) I noticed we do not yet recommend the always require user vector setting on Yubikeys. This partly mitigates the vulnerability discovered and generally seems good practice. Can be set like: ykman fido config toggle-always-uv Or with settings in the apps.

---

## Post 15 by @untitled_unsterile932 — 2024-12-13T16:54:20Z

Great, that worked for me. Thanks!
