YubiKey 5C NFC
Phishing-resistant two-factor authentication for the accounts that matter most.
$55
Why it's in the kit
Passwords alone are not enough — and SMS 2FA is barely better than nothing. The YubiKey is a physical token that authenticates via FIDO2/WebAuthn, which means even if someone has my password, they can't log in without the key in their hand. I use it on my Google account, GitHub, 1Password, and Cloudflare. One touch, done. No codes to type, no SIM swap to fear.
How I run it
Primary 2FA on Google, GitHub, 1Password, Cloudflare, and Tailscale admin. Registered as two separate keys (one stays in the bag as backup). Lives on the keychain with the Ledger but never leaves the bag — the NFC tap from the pocket is enough for mobile auth.
What I almost bought
- Google Titan Key — Works but the YubiKey has broader third-party service support and a longer track record.
Skip it if
If you use an iPhone and all your critical accounts support passkeys, Apple's built-in iCloud Keychain passkey system covers the same ground without a separate device.
Strengths
- + Phishing-proof — can't be tricked into approving a fake login page
- + Works on mobile via NFC — tap to authenticate
Trade-offs
- − Requires service-side WebAuthn support — not every site supports it yet
More gear
Get the free Creator Kit
Frameworks, blueprints, and models for navigating the decentralized internet, free.