# Yubikey with Lastpass

**URL:** <https://community.clark.com/t/yubikey-with-lastpass/2041>\
**Category:** Technology\
**Created:** [January 12, 2023, 5:26am UTC](https://community.clark.com/t/yubikey-with-lastpass/2041 "2023-01-12T05:26:35Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [January 12, 2023, 5:26am UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/1 "2023-01-12T05:26:35Z")

</div>

I’ve previously noted my experience requiring a Yubikey to open my VanGuard accounts.

I am pleased to learn my Yubikey to open Lastpass. Recent stories claim Lastpass “might” have been cracked. No proof yet.

I could post my Lastpass name & p/w, but nobody could not open without my Yubikey.

Everyone should use some variation of 2FA for all financials, and I think Yubikey is one of the best.

---

<div class="post-metadata">

**Author:** ![butler](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@butler](https://community.clark.com/u/butler)\
**Post date:** [January 13, 2023, 12:49am UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/2 "2023-01-13T00:49:57Z")

</div>

The concern with the latest Lastpass hack is that a hacker was able to download actual user password vaults.

> **[LastPass security breach update: Customer password vaults were obtained](https://9to5mac.com/2022/12/22/lastpass-breach-password-vaults-obtained/)**
>
> LastPass is back today with its latest statement on the damage of its security breach. While the scope of the attack wasn’t clear in early December, now the company has shared that copies of customers’ password vaults were obtained along with names,...

Yes, everyone should use 2FA and prefer an app like MS Authenticator for OTP over the more common solution of using SMS. The YubiKey is just a much stronger key for 2FA. The future of password is going to be Passkeys:

> **[The Future is Passwordless: How Passkeys Will Simplify Your Life and Protect...](https://ithemes.com/blog/the-future-is-passwordless-how-passkeys-will-simplify-your-life-and-protect-us-all/)**
>
> In this guide to passwordless authentication, you will learn how passkeys overcome the security vulnerabilities of password-based authentication and why you should start using them.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [January 13, 2023, 1:51am UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/3 "2023-01-13T01:51:32Z")

</div>

> [@butler](#):
>
> The concern with the latest Lastpass hack is that a hacker was able to download actual user password vaults

But…“While user password vaults are still protected by their master passwords, the hacker may try brute force, phishing, or social engineering attacks.”

In my case, that means somehow getting my 16 digit pw of numbers, symbols, upper/lower letters, AND THEN get my Yubikey for that code. Foolproof? Of course not, but I feel safe.

---

<div class="post-metadata">

**Author:** ![p1g1](https://avatars.discourse-cdn.com/v4/letter/p/cab0a1/32.png) [@p1g1](https://community.clark.com/u/p1g1)\
**Post date:** [January 13, 2023, 9:11pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/4 "2023-01-13T21:11:17Z")

</div>

I use Lasspass and 2 factor authentication. After reading this post, I am reading about possible additional steps including Yubikey (hardware authentication) and app authentication. Trying to keep with security stuff is painful for me so I try to remember that “a stitch in time saves nine”

---

<div class="post-metadata">

**Author:** ![butler](https://avatars.discourse-cdn.com/v4/letter/b/ac91a4/32.png) [@butler](https://community.clark.com/u/butler)\
**Post date:** [January 13, 2023, 10:53pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/5 "2023-01-13T22:53:24Z")

</div>

> [@robertpri](#):
>
> But…“While user password vaults are still protected by their master passwords, the hacker may try brute force, phishing, or social engineering attacks.”
> 
> In my case, that means somehow getting my 16 digit pw of numbers, symbols, upper/lower letters, AND THEN get my Yubikey for that code. Foolproof? Of course not, but I feel safe.

I dont think so…if they have already downloaded the vault, they only need to crack the Master password. The 2FA only protects access to the passwords while accessing them through Lastpass security.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [January 13, 2023, 11:30pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/6 "2023-01-13T23:30:05Z")

</div>

> [@butler](#):
>
> they only need to crack the Master password

True, but that’s why we must have long 12-16 complex digits, a mix of random upper/lower letters, numbers, symbols.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [January 14, 2023, 12:15am UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/7 "2023-01-14T00:15:43Z")

</div>

> [@p1g1](#):
>
> Trying to keep with security stuff is painful for me

It’s painful and frustrating for everyone. And the hackers work 24/7/365 to find ways for accessing our private stuff.

It never ends.

---

<div class="post-metadata">

**Author:** ![Russ](https://avatars.discourse-cdn.com/v4/letter/r/e36b37/32.png) [@Russ](https://community.clark.com/u/Russ)\
**Post date:** [January 19, 2023, 4:19pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/8 "2023-01-19T16:19:31Z")

</div>

With all the hacks I doubt I would ever trust anyone with my passwords especially a 3rd party for profit corp. They all seem to be getting hacked.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [January 19, 2023, 7:57pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/9 "2023-01-19T19:57:07Z")

</div>

> [@Russ](#):
>
> I doubt I would ever trust anyone with my passwords

Agree, but at last count, I have +450. Yes, I could create my own file encryption, but having to de-crypt for every site would take a lot of time and energy.

---

<div class="post-metadata">

**Author:** ![Russ](https://avatars.discourse-cdn.com/v4/letter/r/e36b37/32.png) [@Russ](https://community.clark.com/u/Russ)\
**Post date:** [January 20, 2023, 1:42am UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/10 "2023-01-20T01:42:23Z")

</div>

I have 2 credit cards, 1 bank, one investment account. The PWs for these are memorized and locked away. I use one desk computer to access only these accounts. I keep my phone as close as my wallet and store some PWs there embedded with data that is only obvious to myself. For non-important sites I just use a common memorable PW. This works well for me. When I croke, the people that will take care of my/our finances know where to look.

---

<div class="post-metadata">

**Author:** ![Gigback67](https://avatars.discourse-cdn.com/v4/letter/g/9de053/32.png) [@Gigback67](https://community.clark.com/u/Gigback67)\
**Post date:** [May 25, 2023, 7:10pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/11 "2023-05-25T19:10:36Z")

</div>

Yubikey is great as long as you get 2-3 of them in case you lose one. Keep the spare in a safe spot easy to get to.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [May 25, 2023, 8:00pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/12 "2023-05-25T20:00:51Z")

</div>

> [@Gigback67](#):
>
> Yubikey is great as long as you get 2-3

Exactly what I did, I have two [one well hidden] and son has one.

---

<div class="post-metadata">

**Author:** ![rjratnip](https://sea2.discourse-cdn.com/flex016/user_avatar/community.clark.com/rjratnip/32/1821_2.png) [@rjratnip](https://community.clark.com/u/rjratnip)\
**Post date:** [May 30, 2023, 3:36pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/13 "2023-05-30T15:36:57Z")

</div>

Was looking to get something like a yubikey, but in reading it seems things are moving towards passkeys. I don’t quite understand everything, but will that make HW keys obsolete? Or, at least passkeys are an alternative where you wouldn’t need HW keys if you want increased security?

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [May 30, 2023, 7:57pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/14 "2023-05-30T19:57:31Z")

</div>

> [@rjratnip](#):
>
> I don’t quite understand everything,

Well, if you understand passkeys, you are years ahead of me! I tried to get a clear [for dummies] explanation of passkeys, and more confused now.

This is one explanation and I don’t understand any of it.

> **[Vodia PBX Passkeys](https://web.vodia.com/blog/vodia-pbx-passkeys?gad=1&gclid=EAIaIQobChMIh6bLwOWd_wIVhRStBh10JwurEAAYASAAEgIpOPD_BwE)**
>
> With the wide availability of passkeys on all mainstream browsers, users and administrators can conveniently access the Vodia PBX while enjoying an unprecedented level of security.

---

<div class="post-metadata">

**Author:** ![rjratnip](https://sea2.discourse-cdn.com/flex016/user_avatar/community.clark.com/rjratnip/32/1821_2.png) [@rjratnip](https://community.clark.com/u/rjratnip)\
**Post date:** [May 30, 2023, 9:22pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/15 "2023-05-30T21:22:00Z")

</div>

> [@robertpri](#):
>
> This is one explanation and I don’t understand any of it.

I did not follow everything in that article, but some of it, and other things I’ve read, sounds like the Public/private key authentication method used in many data communications today. They did mention that when you first login to something that requires the “passkey” authentication method discussed in the article, then a physical key _could_ be used to verify the user, but then once the passkey is created then that would no longer be needed until the passkey expires and you need to generate a new one. You could use other methods to verify a user, like finger print.

In general, I’m not seeing where a HW key will be absolutely necessary in the future. As I understand it today, the HW key currently replaces the 2-factor authentication I currently use on my phone via VIP Access, MS Authenticator, or others. I didn’t really want to spend the $ on a couple of them if they’re going to be rendered optional or obsolete in the near future. I’m fine using my phone for 2FA at the moment.

If someone knows this is incorrect, please chime in.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [May 30, 2023, 9:39pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/16 "2023-05-30T21:39:25Z")

</div>

> [@rjratnip](#):
>
> I did not follow everything in that article, but some of it,

It was a total fog to me. I did several google searches and every time got a wall of links [mostly sales] and most of those sent me to more walls of links. I never did find a “passkeys for dummies” simple explanation.

I have not seen a clear explanation how the Yubikey in my pocket could be hacked.

---

<div class="post-metadata">

**Author:** ![rjratnip](https://sea2.discourse-cdn.com/flex016/user_avatar/community.clark.com/rjratnip/32/1821_2.png) [@rjratnip](https://community.clark.com/u/rjratnip)\
**Post date:** [May 30, 2023, 9:56pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/17 "2023-05-30T21:56:16Z")

</div>

> [@robertpri](#):
>
> I have not seen a clear explanation how the Yubikey in my pocket could be hacked.

Maybe there are other ways, but I think someone would need to be able to create a duplicate physical Yubikey of yours so they could plug it in their device, or steal yours I guess. It would need to have the same security codes in it that yours does so that it could generate the identical 2FA codes. I would put this in the extremely unlikely category. Someone would have an easier time getting someone’s phone that they use for generating 2FA codes via the applications.

Some of the issues I see now with the HW keys is you really need more than one in case one breaks, is lost, or stolen. Then you have to securely store it somewhere and _remember_ where you stored it.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [May 30, 2023, 10:26pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/18 "2023-05-30T22:26:02Z")

</div>

> [@rjratnip](#):
>
> create a duplicate physical Yubikey of yours so they could plug it in their device

Even if they somehow duplicated, or stole, my Yubikey, they would also need the code [which I originally set]. When accessing my vault, after the typical name / password, I plug in the USB Yubikey.

That generates a blank box for the Yubikey code. If correct, then and only then, is the Yubi active, and then I press it’s button and my vault is visible.

Foolproof? Of course not…!!! But unless the hacker can successfully manage all those steps in sequence, my vault should be safe.

[but I am certainly open to perhaps better security]

---

<div class="post-metadata">

**Author:** ![rjratnip](https://sea2.discourse-cdn.com/flex016/user_avatar/community.clark.com/rjratnip/32/1821_2.png) [@rjratnip](https://community.clark.com/u/rjratnip)\
**Post date:** [May 30, 2023, 10:43pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/19 "2023-05-30T22:43:13Z")

</div>

> [@robertpri](#):
>
> That generates a blank box for the Yubikey code. If correct, then and only then, is the Yubi active, and then I press it’s button and my vault is visible.
> 
> Foolproof? Of course not…!!! But unless the hacker can successfully manage all those steps in sequence, my fault should be safe.

That helps me understand how it’s used as it wasn’t totally clear since I don’t have one yet. Maybe it would be worth getting one. If it breaks or I lose it I should be able to call Fidelity or Schwab to change the security setup since they would recognize my voice for security purposes.

---

<div class="post-metadata">

**Author:** ![robertpri](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@robertpri](https://community.clark.com/u/robertpri)\
**Post date:** [May 30, 2023, 10:48pm UTC](https://community.clark.com/t/yubikey-with-lastpass/2041/20 "2023-05-30T22:48:19Z")

</div>

> [@rjratnip](#):
>
> That helps me understand how it’s used

The Yubi can be used on many places, not just one. I also use it for my Vanguard acct and others. And I do have more than one–just in case.

[Next page](https://community.clark.com/t/yubikey-with-lastpass/2041.md?page=2)
