Earlier quoted context omitted.
The justification is absolute rubbish. I The argument is that it reduces attack surface, but compared to what, the alternative to including the yubikey code is not using a yubikey, which reduces security. The alternative to using the browser integration (or the ssh agent) is to use the clipboard, which is likely more code and definitely less vetted code. By the same argument we should remove encryption as well, becau…
>the alternative to including the yubikey code is not using a yubikey, which reduces security. The physics of someone cracking my passphrase and the physics of someone cracking my Yubikey are both in the boil the oceans amount of energy. I'm fine not letting a usb device masquerading as a keyboard have access to my password database. Remember: "When you lose your YubiKey or someone else gets access to it, your databa…
You don't store your password on the YubiKey, you use it as a second factor in addition to your password.
Do you know what a YubiKey is when you argue against it?