I think to get a Yubikey and read that Keepass with OTP makes no sense No. Security remains the same + extra cognitive overhead.
I try to store all data local and use seldom cloud based services.
If I have a very bad SecOp and keep the dongle always plugged in the MacBook (or on the same table), does that dongle add a security benefit?
My thread model are remote attacks. If there is a security benefit, what Yubikey configuration I need to implement, to profit from improved security?