Tom wrote:
Hi,
We are working on something cooler...
Any update on this?
From what I understand Yubikeys now work on any computing device with USB or, in the case of Yuibkey NEO, NFC support.
We are considering using Yubikeys to secure a web service with a target audience of normal consumers. These consumers do not choose our service; our service is provided by our customers (health care organisations) to consumers as a way to view health related data — their own, or that of relatives or friends who granted them access.
The FIDO U2F Yubikeys are not too expensive, and work on any normal computer; for a lot of users this is probably sufficient in terms of accessibility.
I am worried though about the growing group of consumers who exclusively use mobile phones or tablets for their computing needs. For Android devices NFC is an option of course with the Yubikey NEO, and as far as I can tell most of them have a small-form factor USB-slot that can be used for the FIDO U2F Yubikey with a common adapter cable.
But what about Apple's devices? I know there is an adapter for the IPad to get a USB-slot, but that that solution seems lacking in user-friendliness, not to mention its price. Newer Apple phones seem to have NFC-chips, but no one can use them except for Apple as far I know.
How do others approach this? Simply exclude such devices from your service as insecure? Provide another type of hardware token? Does Yubico have something nice up their sleeve for Apple devices?