I use my Yubikey as a second factor for my KeePass password management.
âYoubiKeys have a PINâ  Not that I know of.  I never enter a set of digits to use my HMAC-SHA Challenge Response.
" If you can login with just the second factor, it is a bad design."  Fully agree!
âif you run apps from untrusted sources. Some exfiltration vectors areâŚâ  Agree
âA program on PC canâ   Anything on my PC could steal my password to log into KeePass as I type it in.   And could read the memory and password as sent to applications etc.
If your system is compromised then youâre screwed.    So back to my point being a âcertified U2F security keyâ really needed?   If itâs lost stolen or the system your using it on is compromised your screwed anyway.
When I am out on the road with just my cell phone and I need to log into say Google and I got my Google authenticator app with itâs new 6 digit number every 30 seconds on my phone along with a stored 15 character  random password (as I canât remember it) is logging in on my phone really 2nd factor?  When that device has both my password and the authenticator app both on the same device?    I donât think so.   So I moved my authenticator app off of my phone and used the authenticator app on my Flipper.  Now I feel I am more secure. Because I must have both devices to gain access to my account.
Just because the Flipper is not fort knocks security, it can still provide increased security in some ways.
Anyway.   Back to the original need, it would be nice if someone could make an app to perform HMAC-SHA Challenge Response on the flipper.