What's the diff between Yubikey and WebAuthn (using Yubikey) 2FA methods?

The installation, except for a couple of minor(?) details, and usage instructions seem the same after the respective method is chosen from the 2-step Login methods list. I notice that the help for Yubikey recommends using the FIDO2 WebAuthn method instead; why?

The short answer is that FIDO2/WebAuthn provides resistance against phishing.

Here is the documentation for the two protocols:

https://developers.yubico.com/OTP/

https://developers.yubico.com/WebAuthn/

1 Like