Yubikey 5.8: Verified Authorization for the New Era of Identity and AI
dblitt
20 points
11 comments
July 21, 2026
Related Discussions
Found 5 related stories in 974.8ms across 14,369 title embeddings via pgvector HNSW
- OpenAI mandates hardware-backed passkeys for Trusted Access Cyber members speckx · 54 pts · July 14, 2026 · 59% similar
- Group Pushing Age Verification for AI Turns Out to Be Backed by OpenAI SilverElfin · 41 pts · April 02, 2026 · 46% similar
- Trusted access for the next era of cyber defense surprisetalk · 72 pts · April 14, 2026 · 44% similar
- Qwen3.6-35B-A3B: Agentic coding power, now open to all cmitsakis · 1009 pts · April 16, 2026 · 44% similar
- Better Auth is joining Vercel sync · 120 pts · July 07, 2026 · 43% similar
Discussion Highlights (5 comments)
FireBeyond
They always neglect to mention that you can't (unless something changed recently) upgrade the firmware. It's carefully crouched in wording, but to read the site you'd say "Oh, so I just upgrade". No, you buy a new version of the device. And hopefully it's not like the last vulnerability when at least for a while they kept selling the vulnerable devices to deplete their stock unless you knew enough to ask for one specifically with the new firmware.
Varelion
I believe in, and am a big proponent of physical 2FA being widely adopted -- though I own a half-dozen YubyKeys, I do wonder what their profit margins are. They feel a lot more expensive than they should be.
elevation
> New Era But no PQC?
jtrn
I'm a bit emotional after an extremely long and aggravating day at work, so this is probably situational based, but I HATE the whole god damn security field, and this is one of many examples of why. It's impossible to get simple explanations out of anybody in that field. And it's why security has always been a pain. It's like they're allergic to making plain, straightforward sense. Here’s what this actually means for people who expect stuff to matter in any practical terms. 5.8 changes zero things about how you work. You cannot upgrade older keys to it, you have no reason to buy it, and the two features actually in there have never once been used by anyone outside a lab. The WebAuthn thing could, in theory, make the browser remember your key so you don't have to pin every time you use it, but that only happens when Apple, Google and others implement this proposed standard. Right now, no browser can call it. Not Chrome, not Safari, not anything. The spec is an open pull request. If it ever ships it's years out, and it wont be you that starts using it first, it would have to be some big auth entity. The ARKG thing: same, plus it needs a wallet ecosystem that doesn't exist yet. Yubico shipped firmware whose headline features nothing can currently use, is not relevant for existing hardware, and wrote three pages about AI to sell it. That's the actual story. bleh.
ButlerianJihad
https://utcc.utoronto.ca/~cks/space/blog/sysadmin/YubikeyMos... You know, I owned several revisions of Yubikeys, and I eagerly set them up on every site that would support them. Sadly, unfortunately, they were "not compatible enough" and in fact, it seemed that sites weren't interested in adding or even maintaining existing support, and they fell out of favor with many of us. I really tried! I even went through extraordinary measures to set them up nicely on Ubuntu and Fedora Linux systems! I had ssh keys with mandatory Yubikey auth! It was nearly cybersecurity heaven! I eventually de-registered them everywhere possible, and I got rid of them entirely. In fact I purchased a couple Google Titan keys, and even before registering them, I simply returned them unused. The most secure auth I use now is Microsoft Authenticator, and Google Authenticator for the TOTP stuff. I really don't mind. My general impression is that Yubikeys are "too secure" for consumers to be using. TPTB do not like Yubikeys because of their intrinsically hardened security. TPTB would rather that consumers use security that has some NOBUS breakability in it. I really don't mind, okay?