{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreihyyv752nzhhe7xyjjcspqdee35rhp76zmpu7l2zv7nv35g52ewgq",
"uri": "at://did:plc:haakkg7y3xdghcdmprxeexso/app.bsky.feed.post/3mjudsgagcww2"
},
"path": "/t/yubikey-vs-authenticator-for-microsoft-account/37253#post_4",
"publishedAt": "2026-04-19T15:50:10.000Z",
"site": "https://discuss.privacyguides.net",
"textContent": "Thanks for the answers. It seems like using only Yubikeys is the better option.\n\nNostromo:\n\n> I don’t rely on security keys exclusively because you can always lose your back ups too.\n\nI was thinking of using four Yubikeys, two at home and two at separate locations far away from here, the probability of losing all four at once would be extremely low.\n\nOnscreen5341:\n\n> The only thing that bypasses FIDO2 are session tokens. If the attacker gets to your session tokens, this means he has compromised one or more devices that you use. In addition, you also **do not get a notification when somebody logs in with a session token or removes session tokens**.\n\nThis sounds interesting, can you explain more? For example, if I log in to Outlook in a browser, is a session token created for the browser, and when I log out it gets erased? What about the Outlook Android app, you only have to log in once and you remain logged in, does this mean that the session token is permanent and someone can steal it to access the account from other devices?",
"title": "Yubikey vs Authenticator for Microsoft account"
}