Hardware-backed security

Security keys: phishing-resistant account protection

A security key is a physical authenticator that can prove account access with cryptography. Modern FIDO keys work with websites through WebAuthn and can resist phishing because the key verifies the website identity before responding. Keys may connect by USB, NFC, or another supported interface.

Last reviewed: 2026-08-20 · Report a change

What the key proves

When a key is registered, it creates a credential for that service. The service stores a public key, while the private key remains protected by the authenticator. During sign-in, the browser passes a challenge and the expected site identity to the key. The key answers only for the registered site.

Touching the key shows user presence. Some keys also ask for a PIN or support biometric verification, which can add user verification. The PIN is local to the authenticator; it is not the account password and should not be typed into a website field.

Why security keys stop common phishing

A lookalike page cannot simply collect a reusable code from the key for the real service. The domain binding is enforced by the browser and authenticator. CISA and NIST describe FIDO/WebAuthn as a practical phishing-resistant approach.

Keys do not stop every attack. Malware can target a signed-in session, and an attacker may abuse recovery or trick an administrator into changing account settings. Keep software updated, protect recovery routes, and review sessions and account changes.

Register two keys

The safest routine is to register at least two keys when the service allows it. Keep one available for daily use and store the backup in a separate secure location. Name the keys clearly in account settings so you can remove the correct one if it is lost.

Test both keys before signing out or traveling. A backup stored in the same bag as the primary can be lost at the same time, so physical separation matters. Some services also allow a synced passkey or recovery codes as an additional fallback.

Compatibility and connection choices

Check the ports and wireless features on the devices you actually use. USB-C is common on newer computers and phones, while some environments still need USB-A. NFC can make phone sign-in convenient. Organization-managed devices may restrict which authenticators are allowed.

Use a FIDO-certified product from a reputable seller and follow the manufacturer's official setup instructions. Avoid buying a used key for important accounts because you may not know how it was handled or configured.

Lost, damaged, or replaced keys

If a key is lost, use the registered backup or official recovery route, then remove the missing key from every account. A person who finds a key may still lack the account identifier and any required PIN, but removing it promptly reduces risk.

Maintain a simple inventory of important accounts that use each key. When retiring a key, add and test the replacement before deleting the old registration. Never mail or hand a key to someone claiming they need it for support.

If a provider or device change is also involved, map passkey portability and recovery boundaries before retiring a registered security key.

Practical checklist

How to put this into practice

  1. Choose a reputable FIDO-compatible key that fits your devices.
  2. Open the official service security settings.
  3. Register the first key and give it a clear name.
  4. Register and test a second key stored separately.
  5. Save any recovery codes in a secure offline location.
  6. Review the registered-key list after a loss or device change.

At a glance

Compare the options

OptionBest forStrengthPlanning need
USB/NFC FIDO keyBroad device usePhishing-resistantKeep a backup key
Biometric FIDO keyLocal user verificationPhishing-resistantEnroll and protect PIN
Synced passkeyConvenience across devicesPhishing-resistantProtect provider account
Authenticator codeWide compatibilityPhishableTransfer app and store recovery
SMS codeFallback availabilityPhishableProtect phone number

Decision guidance

Choosing the right approach

A security key is especially useful for administrators, developers, journalists, and anyone protecting an account that can reset many others. Register at least two keys when the service permits it. Keep the daily key convenient and the backup key in a separate protected location so loss, theft, or travel does not remove both at once.

Confirm what protocol and role the service supports. A modern FIDO2/WebAuthn key can provide phishing-resistant sign-in or a second factor. An older one-time-password mode may not have the same domain binding. Product documentation should state whether the key is a passkey, a security-key second factor, or only an emergency option.

Inventory keys by a recognizable nickname and review the list after device changes. Remove a missing key promptly, but only after another method works. An attacker who steals an unlocked session may try to register a new key, so enable security-change alerts and inspect unexpected enrollment notifications.

Operational test

Rehearse the moments when security usually fails

Start with an ordinary device change. Imagine the phone or computer used for this control is unavailable today, not after a carefully planned migration. Identify which trusted device, independent authenticator, recovery code, provider account, or administrator would restore access. Then verify that route without deleting the working method. For Security keys: phishing-resistant account protection, the practical starting action remains: Choose a reputable FIDO-compatible key that fits your devices. A recovery plan is only useful when the contact information is current and the required material can be reached without first unlocking the same account.

Next rehearse a suspected compromise. Do not answer the suspicious message or use its link to investigate. Open the known service independently, review recent sessions and security changes, and preserve evidence before removing anything. Rotate a reused password, revoke unfamiliar applications, and replace any exposed backup secret. If a second factor produced an unexpected prompt, deny it and assume the primary password may already be known. A strong authenticator helps prevent entry, but it does not clean up a stolen browser session, changed recovery address, malicious forwarding rule, or newly authorized application.

Finally, test the managed-account case. Workplaces, schools, families, and enterprise plans can place sign-in policy with an administrator or external identity provider instead of the service itself. Learn who can reset the control, what proof that person requires, and how an urgent request is authenticated. Never weaken the whole organization to solve one member's lockout. Record the official help route and an internal contact before a problem occurs, and separate administrative recovery from unsolicited support messages. This turns the comparison above—from USB/NFC FIDO key onward—into a maintainable choice rather than a one-time setup.

Common questions

Security keys: phishing-resistant account protection FAQ

Is a security key the same as a USB drive?

No. It uses an authentication protocol and does not expose a normal file-storage area for account secrets.

Can one key protect many accounts?

Yes. A FIDO key can hold credentials for many services, subject to the key and credential type.

What if the key is stolen?

Use a backup method, remove the key registration from accounts, and review sessions. A local PIN may provide additional protection.

Do I need two keys?

Two are strongly recommended for important accounts so one loss does not force emergency recovery.

Can I use a key on a phone?

Many phones support NFC or USB security keys. Check the phone, browser, service, and key compatibility.

Apply the idea

Representative service guides

Primary guidance

Sources and further reading

Product interfaces and available methods change. Re-check each service's official help before changing a security setting, and prepare recovery before removing an older authenticator.