openideurope.eu

Hardware security keys explained: how they work

A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.

Login securityPublished

A hardware security key is a small physical device, about the size of a car key, that you plug into a USB port or hold against your phone to confirm a login. Inside is a chip that holds a private key. When you sign in, the website sends a challenge, the key signs it after you touch it, and the site checks the signature. The key only responds to the genuine website address, so a fake login page gets nothing. This is why security keys are the benchmark for phishing-resistant authentication.

How it works

Hardware keys follow the FIDO2 standards, explained in more detail on our page on FIDO2 and WebAuthn. The older FIDO U2F protocol is still widely supported, too. In short:

  1. Registration. You add the key to an account. The key creates a key pair for that service and hands over only the public key.
  2. Login. The service sends a challenge. You touch the key (some models also ask for a PIN or fingerprint).
  3. Verification. The key signs the challenge with the private key. The service verifies the signature.

Because the private key never leaves the chip and the key checks the website address, the attack that defeats SMS and authenticator-app codes, a fake site relaying your code, does not work.

Two jobs: second factor and passkey store

  • As a second factor, the key is used after your password. It adds strong protection to existing logins.
  • As a passkey store, many FIDO2 keys can hold passkeys, so you can sign in without a password. Capacity is limited and depends on the model and firmware. Yubico documents that its YubiKey 5 series holds up to 25 discoverable credentials on earlier firmware and up to 100 with firmware 5.7 and later. Check the specification of the key you plan to buy. A passkey on a key is device-bound: it does not sync, so keep a spare.

For a broader introduction to passkeys, see passkeys explained.

What to look for when buying

Feature Why it matters
FIDO2 / WebAuthn support The standard that works with passkeys and modern services
Connector USB-A, USB-C, or both, plus NFC for phones
Passkey capacity Important if you want to replace passwords
PIN or fingerprint protection Protects the key if someone steals it
Open or audited firmware Helps trust, for example in open-source models
Maker and place of manufacture A personal preference for some, relevant to some organisations

Well-known makers include Yubico, Nitrokey (Germany), Token2 (Switzerland) and Google with its Titan key. We compare them in our best hardware security keys overview, and put two popular options head to head in YubiKey vs Nitrokey.

How to set one up

  1. Buy two keys from the same or different makers. One is for daily use, one is the spare.
  2. Register both in the security settings of each important account, usually under “Security keys”, “Two-step verification” or “Passkeys”.
  3. Set a PIN on the key when asked. This is a PIN for the key itself, not your account password.
  4. Store the spare somewhere safe and separate, such as a locked drawer or a safe.
  5. Save backup codes and keep them offline, in case both keys are lost. See backup codes.
  6. Test by signing in on a second device.

Many services, including Google, Microsoft and major platforms, support security keys for personal accounts. Some require the key to be registered after you have logged in with another method. If the site only supports keys as a second factor, keep a strong password and use a password manager.

Using a key day to day

For most people it quickly becomes routine. At a computer you plug the key in (or tap it, if it has NFC and the computer has a reader), touch the contact and you are in. On a phone you hold the key to the back of the device or plug it into the USB-C port. For regular use, many people keep one key on their key ring and the spare at home, and use passkeys on their phone for everything else. If you travel, take the spare along only if it is stored separately from the main key, so that one bag lost does not take both.

Limits and caveats

  • Not accepted everywhere. Smaller sites often have no support for keys or passkeys.
  • Easy to lose. Put it on your key ring, but register a spare anyway.
  • Not a cure for everything. A key protects the login. It cannot help if malware on your device controls your session after you log in, or if an attacker gets into your account through a weak recovery path. Review account recovery.
  • Shared computers. Keys are great for public machines, but remember to log out.
  • Phones. NFC and USB-C support varies. Check compatibility before you buy.

Who benefits most

  • People with a high-value email or platform account.
  • Business owners, administrators and anyone with access to sensitive systems.
  • Journalists, activists and others at higher personal risk. Google offers an Advanced Protection Program that requires security keys or passkeys.
  • Anyone who prefers a physical object they can hold to a code on a screen.

For the average user, a passkey on your phone plus an authenticator app is already a great setup. The key is the upgrade for the accounts you cannot afford to lose.

Frequently asked questions

Do I need a hardware security key?

Not necessarily. Passkeys on your phone or computer and authenticator apps are a big improvement for most people. A key is worth it for your most important accounts, for shared or public computers, and if you want the strongest protection against phishing.

What happens if I lose my security key?

Use your second registered key or the backup method you set up, then remove the lost key from your accounts. That is why you should always register two keys and keep recovery codes.

Can a security key be copied?

The private key is generated inside the device and is designed never to be exported. A key cannot be cloned in the way a card with a magnetic stripe can. If you lose it, you simply register a replacement.

Do security keys work with my phone?

Yes, keys with NFC work by tapping the phone, and keys with USB-C plug into modern Android phones and iPhones with USB-C. Check that your key has the right connector for your devices.

Are security keys expensive?

They cost more than an authenticator app, which is free, and you need two. Prices vary by model and maker, so check current prices on our comparison page.

More in Login security