About this question
Along with a billion other people, I was also notified that my Yahoo! Account was potentially compromised yesterday. Although I'm not worried about that (I have changed my password since then, have a very long and complex password, and don't reuse it), they did take the time to point out the Yahoo Account Key feature. Yahoo Account Key is a feature that, when you log in, sends a notification to the Yahoo! app on your mobile phone, and you must approve that before the login can continue further.
You'll no longer need to remember those complicated passwords when you use Yahoo Account Key to access your account. To sign in, tap "Yes" on the notification we send to your mobile phone. With Account Key enabled, there's no password on your account, so no one other than you can sign in.
This is similar to Google’s two-factor Authentication option, Google Prompt, which is certainly better than just single-factor authentication. But the difference here is that while Google requires the password AND the prompt, Yahoo does not require the password: so this is single-factor authentication, just a different factor.
So Is Yahoo account key secure enough? How secure is this, compared to a good, complex, long, never reused password? Are there any known methods to subvert mobile phone notifications that could affect something like this?