Slickdeals is community-supported.  We may get paid by brands for deals, including promoted items.
Heads up, this deal has expired. Want to create a deal alert for this item?
expiredMegaweapon posted Sep 30, 2022 7:36 PM

Cloudflare Users (Free to Join): YubiKey 5C NFC $11.60, YubiKey 5 NFC

$10

$45

77% off
+ Free Shipping
312K Views
Visit Retailer
Deal Details
Update: The offer terms have changed. The new terms are listed below under more info.

Cloudflare.com is offering Cloudflare Customers (free to join) the YubiKey 5C NFC for $11.60 or the YubiKey 5 NFC for $10 when you claim the offer via your account. Shipping is free.

Thanks to Community Member Megaweapon for finding this deal.

Instructions:
  1. Sign up (free to join) or login to your Cloudflare account.
  2. Navigate to the Cloudflare dashboard to claim the Yubikey Security Keys offer.
  3. The coupon code will be emailed to you from Yubico in 1-3 days.
More Info:
  • Eligible customers must have an active zone or actively use Cloudflare Zero Trust.
  • Exclusive 'good for the Internet' pricing on security keys
    Cloudflare has partnered with Yubico to offer hardware authentication security keys at a promotional price to eligible Cloudflare customers. Select "Claim my offer" and Yubico will email the offer to the email address associated with your account if you are eligible. Eligible customers must have an active zone or actively use Cloudflare Zero Trust. You may not claim this offer multiple times from the same email and this offer may be restricted to one email per account. Cloudflare may modify, limit, or discontinue this promotion at any time. Offer is subject to Yubico's terms.
  • Both Cloudflare and Yubico developer docs and support organizations will guide customers in setting up keys and integrating them with their Identity Providers and with Cloudflare's Zero Trust service.

Editor's Notes

Written by SlickDealio
  • About the deal:
    • The YubiKey 5 NFC is $35 less (77.77% savings) compared to the regular price of $45.
    • Refer to the forum thread for additional deal discussion.
    • Valid for a limited time or while supplies last.

Original Post

Written by Megaweapon
Community Notes
About the Poster
Deal Details
Community Notes
About the Poster
Update: The offer terms have changed. The new terms are listed below under more info.

Cloudflare.com is offering Cloudflare Customers (free to join) the YubiKey 5C NFC for $11.60 or the YubiKey 5 NFC for $10 when you claim the offer via your account. Shipping is free.

Thanks to Community Member Megaweapon for finding this deal.

Instructions:
  1. Sign up (free to join) or login to your Cloudflare account.
  2. Navigate to the Cloudflare dashboard to claim the Yubikey Security Keys offer.
  3. The coupon code will be emailed to you from Yubico in 1-3 days.
More Info:
  • Eligible customers must have an active zone or actively use Cloudflare Zero Trust.
  • Exclusive 'good for the Internet' pricing on security keys
    Cloudflare has partnered with Yubico to offer hardware authentication security keys at a promotional price to eligible Cloudflare customers. Select "Claim my offer" and Yubico will email the offer to the email address associated with your account if you are eligible. Eligible customers must have an active zone or actively use Cloudflare Zero Trust. You may not claim this offer multiple times from the same email and this offer may be restricted to one email per account. Cloudflare may modify, limit, or discontinue this promotion at any time. Offer is subject to Yubico's terms.
  • Both Cloudflare and Yubico developer docs and support organizations will guide customers in setting up keys and integrating them with their Identity Providers and with Cloudflare's Zero Trust service.

Editor's Notes

Written by SlickDealio
  • About the deal:
    • The YubiKey 5 NFC is $35 less (77.77% savings) compared to the regular price of $45.
    • Refer to the forum thread for additional deal discussion.
    • Valid for a limited time or while supplies last.

Original Post

Written by Megaweapon

Community Voting

Deal Score
+407
Good Deal
Visit Retailer

Top Comments

Join The Conversation

Share your experience with the Slickdeals community

Share information with the community. Please follow our Community Guidelines and be kind!

1K Comments

Sign up for a Slickdeals account to remove this ad.

Oct 1, 2022 1:27 PM
339 Comments
Joined Feb 2017
DsplashqqOct 1, 2022 1:27 PM
339 Comments
Quote from Ferral :
The 2fa that is generated by free software program on your phone (like freeOTP+) is secure enough for most people. Plus, there are so many banks and other sites that dont yet accept physical keys like Yubico.

This is like wearing oven mitts in order to lift up your morning mug of coffee.
These also support 2FA with TOTP codes, up to 32 sites per key if I remember correctly.
Oct 1, 2022 1:34 PM
447 Comments
Joined Dec 2007
darkmeridianOct 1, 2022 1:34 PM
447 Comments
Quote from Ferral :
The 2fa that is generated by free software program on your phone (like freeOTP+) is secure enough for most people. Plus, there are so many banks and other sites that dont yet accept physical keys like Yubico.

This is like wearing oven mitts in order to lift up your morning mug of coffee.
The Yubikeys are so much easier to use than the TOTP codes. I keep one plugged into my work and home computers via an extension cable. I use it for my password manager, Google account, Vanguard, and Coinbase. I wish more websites accepted it but it's actually easier to use than other forms of two factor authentication.
Oct 1, 2022 1:40 PM
447 Comments
Joined Dec 2007
darkmeridianOct 1, 2022 1:40 PM
447 Comments
Quote from jockovonred :
RSA SecurID is similar to YubiKey.
(Not saying anything about scare tactics. More of a PIA for work scenarios at times... Why require a hardware token for an internal, behind a corporate firewall resource? Overkill!).

Edit: and yes, they also require other software based authentication too. Think Okta, RSA, 2fA...
The Cloudflare link actually has a case study of the castle and moat strategy that wouldn't have protected them against a spearfishing hack. The new trend is towards zero trust, where people are getting asked to reauthenticate to access sensitive data silos. Or something like that. I'm not an expert. But hackers were intercepting TOTP codes and feeding them in real time to the genuine site. The hardware keys stopped that from happening. TOTP is vulnerable to MITM attack. FIDO2 is not. And it will not authenticate on the wrong website that looks the same to you.
1
Oct 1, 2022 1:43 PM
447 Comments
Joined Dec 2007
darkmeridianOct 1, 2022 1:43 PM
447 Comments
Quote from redbandana :
Did a little research while walking when I received this alert.

What exactly do these do? I would use this for a laptop or PC, adding an extra layer of protection? What if one lost said key?
You need two keys. One on you and one in a safe place. You use this to log into certain websites, password managers, Google, Facebook, and even Windows 11.
Oct 1, 2022 1:45 PM
154 Comments
Joined Jan 2014
HanH9929Oct 1, 2022 1:45 PM
154 Comments
Quote from Refundroid :
If you've never needed one, I wouldn't go out of my way to get these. Technically what they are saying is true, but IMO, the whole thing is a scare tactic to drive a new business.
Except I actually got sim swapped hacked and its the scariest time of your life when the hacker has full access to your cellphone number and you start getting emails and notifications that your data is being synced to another phone... on multiple big name websites.

This problem is the real deal and people need to be prepared for that situation. Knowing the moment you've been sim swapped is in of itself another thing to be aware of.
Oct 1, 2022 1:48 PM
241 Comments
Joined Jan 2020
RelaxedRose979Oct 1, 2022 1:48 PM
241 Comments
Quote from whoismorpheus :
I recently started using KeePass. Only challenge is that syncing across multiple devices. How do you use USB to login if it doesn't have keyfile. I meant let's say I want to use KeePass on my frd's computer, I have the USB so I have KeePass db + password but how do you get keyfile?
The keyfile should be manually copied to any new device. It's not really made to do a quick access from another computer.

For syncing, I just use Google Drive, OneDrive, DropBox, etc. Just place a copy of the database on each online drive you want. Then use triggers in KeePass to automatically sync on open, close, and save. I can access any new entries on any of my devices, including my phone which eliminates the need to access my passwords on a device I don't own.

https://www.daycast.com/blog/sync...-the-cloud
Oct 1, 2022 1:48 PM
19 Comments
Joined Jul 2018
AlaB4594Oct 1, 2022 1:48 PM
19 Comments
Where do you find the deal ? I couldn't find it

Sign up for a Slickdeals account to remove this ad.

Oct 1, 2022 1:50 PM
153 Comments
Joined Jun 2016
23EEOct 1, 2022 1:50 PM
153 Comments
I've been using Yubikeys for years without issue. While compatible services is somewhat limited, I still highly recommend using them where you can.
Oct 1, 2022 1:50 PM
447 Comments
Joined Dec 2007
darkmeridianOct 1, 2022 1:50 PM
447 Comments
Quote from fw10001 :
Thank you!
Your private keys are not exposed in case of loss. A hacker will not know which sites are stored on the key. The key never hands over secret information; it takes a challenge from the website, performs crypto operations on it, then returns a value. The secrets never leave the key.

Only if the attacker guesses your password on the right websites then there will be a hardware prompt. Most FIDO2 implementations will not even prompt for the hardware key unless the login password was already verified.

Get two or three keys, register them in all of your websites, and label each key so you don't lose track of which one is which. That way you can delete any lost keys from the websites.

Every six months or a year, just do spring cleaning in all of your financial and high value accounts. Change the passwords, make sure the two factor is correct, make sure the backup codes are current and stored, make sure all addresses and phone numbers are up to date. I just do it every six months at the new year and the fourth of July when I have time off work.
1
Oct 1, 2022 1:54 PM
189 Comments
Joined Jan 2006
radfarafOct 1, 2022 1:54 PM
189 Comments
Quote from Regulus :
Seems unnecessary with two factor authentication in wide use these days.
These are for two factor authentication too. It's trivial for someone to steal your phone number by tricking your phone company that their number is yours if they are determined to hack you so SMS-based authentication is really not that good.
Oct 1, 2022 1:54 PM
447 Comments
Joined Dec 2007
darkmeridianOct 1, 2022 1:54 PM
447 Comments
Quote from gallymimus :
Which sadly does you no good when an attacker does a sim swap on you.
I use Google Fi and a Google email for two factor authentication if sms or email are the only means possible. Can't SIM swap Google using social engineering because Google doesn't have customer service. 😆
3
Oct 1, 2022 1:55 PM
1.1K Comments
Joined Jun 2022
TheBigCPabsterOct 1, 2022 1:55 PM
1.1K Comments
Quote from Ferral :
The 2fa that is generated by free software program on your phone (like freeOTP+) is secure enough for most people. Plus, there are so many banks and other sites that dont yet accept physical keys like Yubico.

This is like wearing oven mitts in order to lift up your morning mug of coffee.
Sadly you're right. I've almost purchased YubiKey's about 100 times over the years but then you realize almost no one supports them, and that's a deal breaker. Even if you just have one or two places that won't take it, it's a deal breaker, as it makes the thing pointless. I love the idea and hope we eventually reach a future where it's practical and universally supported but really don't see it happening any time soon ... if ever. So it's software 2FA for me.
1
Oct 1, 2022 1:57 PM
1.1K Comments
Joined Jun 2022
TheBigCPabsterOct 1, 2022 1:57 PM
1.1K Comments
Quote from darkmeridian :
The Cloudflare link actually has a case study of the castle and moat strategy that wouldn't have protected them against a spearfishing hack. The new trend is towards zero trust, where people are getting asked to reauthenticate to access sensitive data silos. Or something like that. I'm not an expert. But hackers were intercepting TOTP codes and feeding them in real time to the genuine site. The hardware keys stopped that from happening. TOTP is vulnerable to MITM attack. FIDO2 is not. And it will not authenticate on the wrong website that looks the same to you.
All true and great plus points for FIDO2 keys BUT when the place(s) you need them don't accept them...it really doesn't matter. And that's the problem. It's a great solution for a very real (and growing) problem, but there's just not enough support. And that's because most people just don't care...hell most can't even get behind basic 2FA as they find it too inconvenient. It's a sad reality.
Oct 1, 2022 2:19 PM
3K Comments
Joined Mar 2012
cyclops13Oct 1, 2022 2:19 PM
3K Comments
Quote from TheBigCPabster :
Sadly you're right. I've almost purchased YubiKey's about 100 times over the years but then you realize almost no one supports them, and that's a deal breaker. Even if you just have one or two places that won't take it, it's a deal breaker, as it makes the thing pointless. I love the idea and hope we eventually reach a future where it's practical and universally supported but really don't see it happening any time soon ... if ever. So it's software 2FA for me.
Which is the best and reliable 2fa app? I have been long contemplating changing all the passwords to google random password and then just securing my google account with a google authenticator app. I already store my passwords in google password manager.

Sign up for a Slickdeals account to remove this ad.

Oct 1, 2022 2:26 PM
339 Comments
Joined Feb 2017
DsplashqqOct 1, 2022 2:26 PM
339 Comments
Quote from cyclops13 :
Which is the best and reliable 2fa app? I have been long contemplating changing all the passwords to google random password and then just securing my google account with a google authenticator app. I already store my passwords in google password manager.
If you're not gonna use the Yubico 2FA paired with the Yubikey, you've got some options. The easiest is Authy, which has optional multi-device support (optional because it may be a con for some depending on your threat model). It supports backup and restore options with a password (in case you break or lose your phone). This is what I was using before the yubikey paired with their OTP app.

Other options I haven't tried:
Microsoft Authenticator
Aegis Authenticator
andOTP
1

Join The Conversation

Share your experience with the Slickdeals community

Share information with the community. Please follow our Community Guidelines and be kind!

Related Searches

Popular Deals

Trending Deals