Hey y’all I’m pretty new to reddit as well as personal cyber security so hopefully this is the right place to ask the question.
I currently store the keyfile for my keepass database on a flash drive. Keepass stores the path to the file, so I just have to plug in the usb drive as well as enter my password and it works. I also keep one backup on an HDD that i leave at home. For this situation is a hardware key really better?
the key-file is way better than nothing, but the content is known and visible.
the key element, in my sense, in favor of the yubikey approach is that it’s a challenge-response action based upon a secret key stored in the yubikey; this secret can not be seen nor extracted.