chmac wrote:
I just got my Yubikey and their primary function is in static password mode, along with a sufficiently secure password I've remembered. That way I get outrageously long passwords and if my yubikey is stolen my accounts are not still safe.
I was considering the NEO so I could use the same password scheme on my Android device. However, I decided against this approach for a number of reasons. Currently, the NEO only supports a single configuration by NFC, so I get only static or OTP but not both. My primary use case is static, in which case a standard NFC tag would do the same job at a much lower cost, and can be more easily protected from longer distance attacks.
However, it just occurred to me that I could also use a USB OTG cable and potentially plug the YubiKey into my phone directly. Has anyone tried this? Does it work as expected?
This would allow me to use the yubikey as standard on Android devices (phone and tablet). Seems very interesting...
My workaround for this is yubinotes. I save my static password as an encrypted note, which can only be decoded by the Yubikey OTP. Decrypt, copy and paste.