PUFido Drive Clife Key - unbox, test and notes

Tags: en blog video tutorial

I received the PUFido Drive Clife Key from SecuX (the product came free, but this post is 100% of my own making, no influence on its content!). This key is interesting because it acts as 2 things at once:

  • FIDO2/U2F security key
  • 128GB USB drive.

I recorded a video about it, in this post you’ll find a summary and some notes, but if you want to watch the video instead, here the iframe! ^^ (subtitles available!)

Video chapters

If you want to understand better what is under the hood of these security keys and why they are special compared to the most known ones, you can follow this other video instead in which I explain how the PUFido technology works: https://youtu.be/JLNijRxZZVQ

What’s inside

The PUFido Drive Clife Key is an evolved version of the regular Clife Key: same security part, now with 128GB of storage attached to it!

A few facts worth knowing:

  • powered by PUF technology (Physical Unclonable Function): the key takes advantage of physical variations that occur naturally during the semiconductor manufacturing, making it practically unclonable
  • WebAuthn 2.0 (passkeys), FIDO2 CTAP1/CTAP2 and U2F support
  • works on Windows, macOS, Linux, iOS, Android, ChromeOS, and probably more
  • the drive part is IP68: water resistant and dust proof

Product page for reference.

Unboxing

The package is reusable, which is a great plus: we lift one side of it and pull quickly to open it (easier said than done, take a look at the video!). Inside there’s just the key and a bit of paper, that’s all.

The drive part

Plugged into my computer (through an adapter, I don’t have USB-C ports at hand) it appears as a simple USB stick: on Linux it showed up right away as /dev/sdg, with a vfat file system and 115 GiB of usable space. I wrote some test files to make sure it was working, no issues at all.

The LED indicator

The key blinks orange + green when connected to a PC, green flashing while it’s acting as a security key, and orange only when used just as a USB drive.

Setting up a PIN

To use the passkey capabilities you need to create a PIN first.

in Chromium

We go to Chromium settings → Privacy and securitySecurity keys (it’s a bit tricky to find) and choose “Create PIN”, then touch it when asked. It’s important to choose a good code that we’ll remember, as there’s no recovery!

in Windows

Instead of using the browser, we set the key up directly from the operating system: SettingsAccountsSign-in optionsSecurity keyManage, touch the key when asked and from there we can add a PIN or reset the key.

Real-world passkey test: runpod.io

For the real world test I chose runpod.io, where we can rent GPU machines and pay just for the time we use them: very useful for 3D renders or local AI workloads.

The flow was straightforward: add a passkey → insert PIN → touch the key when it blinks. Then log out, and verify. In my case I also have a 2FA code to insert, as I have it enabled, but I did not have to input any credential!. If you don’t have a 2FA set up on your account, the key alone is enough to get in - which is exactly the point of this technology.

The big gotcha: resident vs non-resident credentials

This is the part I want you to really pay attention to!

In Chromium’s Security keys page, for this key it says “cannot store security data”. That means the browser can’t list or manage the credentials saved on it individually. This is because the Drive Clife Key speaks CTAP 2.0. With a CTAP 2.1 device (like the YubiKey) you would have been able to access the credentials and selectively remove the ones we no longer want. Unfortunately, with this key this is not possible, we’ll have to reset the whole key to free up slots (the Storage Drive is not affacted by the format! data is retained), which is quite annoying.

These are the limits:

  • discoverable credentials = “residential” keys (two terms for the same thing): the key stores up to 20 of these
  • non-discoverable credentials (U2F style): handled by the online service provider itself, nothing is saved on the key, so there’s an unlimited number of these

The trick I suggest

Since we have no way to browse what’s stored on the key, my suggestion is to create a text file on the drive itself (but not only) and write down where each resident key has been used, for example 1 - Runpod, 2 - Passkeys.io… You can never know when you’ll reach 20, so keep the list up to date!

The passkeys.io quick test

passkeys.io is a website made exactly to test passkeys: create a zero-friction account, attach your key as a passkey and sign in with it. It worked flawlessly with the Drive Clife Key… but be aware that it uses residential credentials, so it consumed one of my 20 slots! Luckily for me, at that moment I only had tutorial keys on the stick.

Which sites are which?

There’s a lot of confusion around this topic: unfortunately many websites write “passkey” when they really mean just an extra 2nd factor, and some do the opposite. Remember: a real passkey lets you log in without username/email AND without password. Also, whether a site uses resident or non-resident keys is decided by them, not by your key.

This is the list of websites I confirmed being residential with the YubiKey (CTAP 2.1), and the non-residential but I’m not 100% sure about them, as I’ve registered the key with them years ago, and things might have changed.

The list it’s far from complete, but it should help:

Residential credentials (count towards the 20 limit):

  • passkeys.io
  • fluxer.app
  • google.com (as main account login)
  • login.microsoft.com
  • login.nvgs.nvidia.com (NVIDIA developers)
  • projects.blender.org (Blender id + dev)
  • Notion.so
  • runpod.io
  • linkedin.com
  • amazon.it
  • superhivemarket.com
  • openrouter.ai

Non-residential credentials (unlimited):

  • google.com (when used as 2FA instead of login)
  • cloudflare.com
  • qoto.org
  • mastdn.social
  • coinbase.com
  • github.com
  • stripe.com
  • x.com
  • facebook.com
  • dropbox.com
  • discord.com
  • zoho.com
  • proton.me
  • eid.gov.it (eIDAS)
  • kraken.com
  • Vultr.com (via Yubico Cloud, only for YubiKeys)

For example: we could have 21 Google accounts and still register the 22nd and 23rd keys on the stick without problems! If you find other websites that are residential or non-residential, let me know so I can update this list!

Final thoughts and discount

I think it’s a good key! And since the drive part is IP68, my suggestion is: buy two - keep the Drive Clife Key always with you (water/dust proof) and put a regular Clife Key in your safe as backup (the non-drive one is unfortunately NOT water or dust proof).

SecuX kindly granted me a 10% discount for you to use: go to furayoshi.com/secux, add the key(s) to the cart and if you have cookies enabled the code should be applied automatically - otherwise type FRAYOSHI manually at checkout.


Help the author to continue publishing,
donate now or use an affiliate link.

⭐ Click here to choose ✨

You can also become an Affiliate for my content at this Link



  Made with Bulma   build with   Build with Hugo

  © 2026 Francesco Yoshi Gobbo - PGP 3FC5F028E7AFF594 - ISNI 0000000502954809 - P.IVA / VAT: IT-01572520052

privacy policy | cookie policy