Cloudflare and Yubico team up to lower the barrier to phishing-proof hardware keys
Cloudflare has announced a new partnership with Yubico, the maker of YubiKeys, that gives Cloudflare customers direct access to discounted hardware security keys. The offer, available through the Cloudflare dashboard, brings the price of Yubico Security Keys to as little as $10 per key — part of what Cloudflare calls its “Good for the Internet” pricing.
Hardware keys based on the WebAuthn standard are widely considered the strongest form of multi-factor authentication (MFA), because the cryptographic exchange they rely on cannot be replicated by a phishing site. But despite that advantage, adoption has been slowed by cost and by the logistics of getting physical keys into the hands of users, especially in remote-first organizations. This collaboration is aimed at easing those hurdles.
Why hardware keys beat other MFA
Username and password combinations are a favorite target for phishing, and even the layered defenses that followed — app-based one-time codes and SMS verification — remain vulnerable. Phishing sites evolved to harvest MFA codes in real time, and SIM-swap attacks can give an attacker control of a victim’s phone number.
Hardware security keys close that gap. They present a certificate to the authentication service through a cryptographically secured WebAuthn exchange, a token that a phishing site can’t obtain and later spoof. Users enroll one or more keys with their identity provider; at login, after entering their username and password, they simply tap the key. That also removes friction compared to typing codes from an app.
Enforcing hardware key usage with Cloudflare Zero Trust
Most identity providers now support hardware keys as an MFA option, but administrators have historically lacked a way to require them. If a user can fall back to an app-based code, so can an attacker who has compromised that user’s credentials.
That problem surfaced inside Cloudflare when the company deployed security keys for its own staff. The solution came from the Authentication Method Reference (AMR) standard, which lets identity providers share details about a login attempt, including the type of MFA used. Cloudflare built on that standard to let administrators create rules within its Zero Trust platform that enforce the presence of a hardware key.
With these rules, access policies can be granular. An internal admin tool with access to customer data, for instance, could require a healthy corporate device, a connection from an approved country, and membership in a particular identity provider group — plus a verified hardware-key authentication. A simple marketing page under review might only require identity. The rules can be applied per destination, per user group, or globally as needed.
More than 10,000 organizations already use Cloudflare’s Zero Trust tools internally, and Cloudflare attributes its own block of a July 2022 SMS phishing campaign — which targeted over 130 companies — to the combination of Zero Trust policies and hardware keys.
The obstacles that remain
The security property that makes hardware keys reliable — proving you possess a physical object — is also what makes them hard to distribute. Unlike app-based codes, which cost nothing, keys carry a real price tag. For some teams, even that modest cost can be a deterrent to upgrading from weaker MFA.
Logistics are the other challenge. Cloudflare’s own initial deployment happened to take place at a company-wide retreat; organizations without a central physical gathering point must find a way to ship keys to distributed employees.
How the offer works
- Any Cloudflare customer can request the discounted keys directly from the Cloudflare dashboard, following the banner notification flow.
- Yubico ships the keys to customers at “Good for the Internet” pricing, with a floor of $10 per key.
- Yubico will email customers directly using the administrator email on file for their Cloudflare account.
- For larger deployments, Yubico’s YubiEnterprise Subscription carries a 50% discount on the first year of a 3+ year subscription.
- Both companies’ developer documentation and support teams will guide customers through enrolling keys with identity providers and integrating them with Cloudflare’s Zero Trust service.
Organizations that already own hardware keys can begin enforcing their use without making a purchase — by enrolling keys into an AMR-supporting identity provider like Okta or Azure AD and then setting up rules in Cloudflare Access.



