Simon wrote:
How about programming the YubiKey with a short prefix containing some upper case character? Then you'll get 'fooBar' plus the static OTP.
Hah, and how can we do that Simon? The "staticID" (public id) is modhex encoded too. As far as I can tell, the only way to make the key emit anything NOT encoded is with the auto-navigation feature. But that only emits when the key is inserted first.
Best I can think of is if you need an upper case and a number, type "A1" by hand and then hit the yubikey
Really the main reason that those vocabulary rules exist in password apps is because historically humans are picking passwords that they have to remember. With the yubikey, the vocabulary is more limited, but it's a very long string which makes up for it.