Yubikey and NitroKey offer NFC and non-NFC versions of their flagship hardware security tokens (HSTs).
NFC is convenient, but can under some circumstances send e.g. challenge-response exchanges in clear text.
Smartcards using RFID, a similar though not identical protocol, can be queried from ~100cm away.
- Are there other ways are NFC HSTs are known to be more risky than their non-NFC counterparts?
- Should users store NFC HSTs in RFID-blocking pouches, like those used for wireless car keys or contactless bank cards?


You can disable the NFC or USB transport per protocol on yubikeys with the yubikey manager. I can imagine that the nitrokey can do that too. So if you don’t want to use NFC just disable it.