Security is Kraken’s top priority and we are requiring clients with legacy Sign-in 2FA methods to update to a Passkey or Authenticator App to help prevent compromise.
If you have a Static Password enabled, you are using the least secure 2FA method. Because they do not change with each use, this makes them easy to be stolen by an attacker if the password is acquired.
If you currently have Yubico OTP enabled, you can use the same hardware security key and simply update it to a Passkey method. Passkeys are more secure because they are bound to a website or an app's identity and therefore are immune to phishing attacks. The browser and operating system ensure that a Passkey is used only with the website or app it was created for so you cannot be tricked into using your Passkey to sign into a fraudulent app or website.