Starting from OpenSSH 8.2, SSH keys support an integration with physical security keys (FIDO2 / U2F). There are 2 new SSH key types introduced: "ed25519-sk" and "ecdsa-sk". What this actually means is that you need to have a hardware security key inserted into your USB port and a button on the security key physically pressed in order to use the SSH key.
Currently, Bitbucket does NOT support those keys however OpenSSH 8.2 was introduced back in February 2020.
I'd like to ask Bitbucket staff to consider adding the support for security keys.
I'm leaving some details below.
Example of command to generate a SK-secured SSH key (PowerShell):
ssh-keygen -t ed25519-sk -O resident -O verify-required -O user=personal -C "Personal key (SK)" -f $env:USERPROFILE\.ssh\id_personal_sk
Meaning of some parameters:
-O resident means that a generated key will be stored on the security key itself.
-O verify-required means that you need to verify the security key presence every time we try to use SSH key.
-O user=personal means that a key will be scoped to a user named 'personal'. You can define different names to store multiple SSH keys simultaneously on the same security key.
How final public key looks like:
sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIOMCvBwsYCZPt1HIHAMZzC0zsCXb7t933kAudU8CP7FBAAAABHNzaDo= Personal key (SK)
Thank you for your time!