if you’re using someone else’s computer, or a computer at a library, you have no security. TLS isn’t enough to be certain they haven’t intercepted the connection, installed their own root certs, or whatever else. I can’t think of any method to securely use someone else’s computer and connection unless you bring a live boot Linux USB or something, which I doubt applies to the intended audience here.
Sure, having a physical key makes it easy for a non-technical librarian to steal someone’s identity, but perhaps having some kind of yubikey safe deposit box would be an appropriate compromise.
Also consider that the yubikey is only the 2nd factor, the user still needs to enter the password. Obviously password resets are possible but might be a bit more of tip off to the user.
Sure, having a physical key makes it easy for a non-technical librarian to steal someone’s identity, but perhaps having some kind of yubikey safe deposit box would be an appropriate compromise.