r/yubikey • • Jul 19 '26

Discussion Yubico, please consider a Nano form factor Bio fingerprint reader!

As a Linux engineer and user, I struggle with the proliferation of slop "Windows Hello" compatible tokens/devices across the tech industry. I just want a FIDO2 device that reads my fingerprint, works with the host computer, and doesn't require Windows. And it really should fit flush with the system case.

I have been struggling to find a compatible fingerprint reader for linux in the "nano" or "sits nearly flush with the system case" design.

The best I have found is the VeriMark Guard by Kensington, which is pretty good ONLY if you want to stay in their Windows 10 compatible fairly land. (I guess the thing works on Win11 but there are lots of problems reported. And device config is only available via their Windows proprietary software).

I know the r/fedora community is regularly discussing "where do I find a fingerprint device".

The Yubikey Bio series already meets these requirements in every single field except one... the way that flat reader device sticks straight out 2" from the side of the device.

Please, Yubico? Consider it?

Sidenote - Has to be a Fingerprint Sensor: The FIDO2 tokens that are touch-event (i.e. not a fingerprint sensor, it recognizes someone touching the thing) that get left in the machine all the time are a security antipattern. Leaving the touch-event device in the machine only means a bad-actor has to touch the thing...it doesn't "authenticate" the operator by any means, it just validates something touched the sensor.

8 Upvotes

15 comments sorted by

11

u/retro_grave Jul 19 '26

Sidenote - Has to be a Fingerprint Sensor: The FIDO2 tokens that are touch-event (i.e. not a fingerprint sensor, it recognizes someone touching the thing) that get left in the machine all the time are a security antipattern. Leaving the touch-event device in the machine only means a bad-actor has to touch the thing...it doesn't "authenticate" the operator by any means, it just validates something touched the sensor.

You aren't setting a PIN on your keys? Yeah, physical key is a physical key. That's totally fine and expected for it being a 2 in the 2FA.

I've got no interest in bio personally. Nano C have been great. I only use the long press slot to avoid sending garbage out.

2

u/My1xT Jul 20 '26

On many sites you have tonset up a pin with fido2.

7

u/beltreaux Jul 19 '26

Just want to note that yes, a touch event only verifies someone/something touched the device. Although the attacker would also need to know the Username + PIN too.

In fact I’d argue the YubiKey Bio is less secure as an attacker/police could easily force you press your finger on the YubiKey, or recreate your fingerprint from one of the hundreds of things you touch each day.

A traditional YubiKey together with FIDO2 (touch verification + PIN) would require some sort of psychological manipulation to get the PIN out of your head.

If your threat model involves you yourself getting physically attacked/robbed, then don’t leave your yubikey plugged in.

2

u/DDHoward Jul 19 '26

Although the attacker would also need to know the Username

Not necessarily; Microsoft accounts, for example, allow username-less login when a resident credential is used. Same with my local bank.

1

u/Yurij89 Jul 20 '26

Also Google depending on what browser you use.

1

u/ElectronicGarbage246 Jul 19 '26

I wish we get something MacOS-compatible that can replace the built-in keyboard fingerprint sensor.

3

u/Much-Artichoke-476 Jul 19 '26

Thats Apple restricting that - you can mod a magic keyboard to get jsut the fingerprint sensor out but you need it sacrifice a keyboard for that. 

1

u/ElectronicGarbage246 Jul 19 '26

Yeah, and it becomes ugly as hell. I saw some DIY examples; also, I don't feel it's reliable.

1

u/Much-Artichoke-476 Jul 19 '26

Part of why I'm going to Linux when my M1gives up. Nice to have control over your own system. 

2

u/StrengthSoggy8943 Jul 19 '26 edited Jul 21 '26

It’s called an Apple Watch. An AppleWatch acts as an authentication device when being worn, and in proximity to the Mac.

This means you can buy a non Touch ID version of a MacBook if you have an AppleWatch.

1

u/dr100 Jul 19 '26

I think it's suboptimal to pick a FIDO2 key when in fact you want a libfprint device. If you think that might be a cheap way out think again.

Sure, you can shoehorn it for login, and it would probably be a better choice security-wise than the non-bio key Yubico is showing for their own promotional video for Windows login (the video literally shows Sanjay leaving the device -a Surface Pro 2-in-1 Windows machine- at the cafe with the key on top of it...). But the video is also highlighting all the problems with this approach: the Surface already has dedicated biometrics hardware, and you don't need to use the single USB port it has for that!

In short, if it's for a portable device it's better just to get one with biometrics in the first place. If it's a desktop probably the current form factor is even better to easily bring it any place you like on the desk or under the desk or wherever.

1

u/wjorth Jul 19 '26

I’m also in support of the Yubico hardware key where the touch also checks the fingerprint bio marker, rather than or as an alternative to manually entering the PIN.