I feel like I'm really missing something on why Yubikeys are such a popular form of 2FA. My previous employer utilized a phone app that would spawn a notification when you were trying to do something requiring a 2nd authentication factor. You had to either enter a 6 digit pin or use a fingerprint to authorize. My current employer utilizes Yubikey, and it just feels clunkier and less secure? I still have to have a pie…
as to being clunky, it’s because your employer doesn’t care about it, so you have the clunky (and much cheaper) yubikeys.
lack of verification of who is using it is simply not an important part of the threat model.