<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Identity-Security on krash.dev</title><link>https://krash.dev/tags/identity-security/</link><description>Recent content in Identity-Security on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/identity-security/rss.xml" rel="self" type="application/rss+xml"/><item><title>YubiKey OTP Best Practices</title><link>https://krash.dev/posts/yubikey-best-practices/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/yubikey-best-practices/</guid><description>&lt;p&gt;If you use a YubiKey for one-time passwords (OTP), you’ve probably done it at least once: you meant to type something, touched the key, and a long modhex string landed in Slack, a commit message, or an email. Annoying for everyone, and worse, it’s a real security risk.&lt;/p&gt;
&lt;img loading="lazy" decoding="async" src="../images/slack-screenshot.png" alt="Slack Screenshot"&gt;&lt;p&gt;This post pulls together practical ways to reduce accidental triggers and what to do when a code gets out, plus how YubiOTP compares to TOTP so you can use both wisely. We also cover FIDO2 / WebAuthn and how to use them alongside OTP.&lt;/p&gt;</description></item></channel></rss>