one of the yubico developers who signed version 5.9.0 of their linux tarball two months ago is using an expired RSA key https://developers.yubico.com/yubikey-manager/Releases/
gpg: assuming signed data in '../yubikey_manager-5.9.0.tar.gz'
gpg: Signature made Thu 22 Jan 2026 09:38:27 AM EST
gpg: using RSA key 20EE325B86A81BCBD3E56798F04367096FBA95E8
gpg: Good signature from "Dain Nilsson <dain@yubico.com>" [expired]
gpg: Note: This key has expired!
Primary key fingerprint: 20EE 325B 86A8 1BCB D3E5 6798 F043 6709 6FBA 95E8
this guy walks around with a 2048-bit rsa key for a whole decade
pub rsa2048 2014-01-10 [SC] [expired: 2025-04-29]
20EE325B86A81BCBD3E56798F04367096FBA95E8
uid [ expired] Dain Nilsson <dain@yubico.com>
this isn't a standard yubico practice. look at nigel right above him
pub rsa4096 2019-05-13 [SC] [revoked: 2020-04-15]
1DC4BA2872525B3F2FE8207F5D9C760A3FB51707
uid [ revoked] Nigel Williams <nigel.williams@yubico.com>
4096 and actively revoked after one year. i'm gonna find another email address to harass now