Short answer

  • A security key is a small physical authenticator used to verify access to online accounts through USB or NFC.
  • FIDO2/WebAuthn security keys use public-key cryptography and bind each credential to the website that created it, making them substantially more resistant to phishing than SMS or one-time codes.
  • A security key can work as a second factor after a password or hold a device-bound passkey for passwordless sign-in when the service supports it.
  • Unlike OTP, a security key does not show the user a code that can be copied into a fake website.
  • Register at least two keys, store the backup separately, and configure account recovery before relying on security keys for critical accounts.

Email, cloud services, social networks, password managers, and business systems still commonly begin with a password. Even a long and unique password can be stolen through a fake login page, malware, or a breached database. Adding an OTP improves security, but a person can still be tricked into sending that code to an attacker in real time.

A security key moves the most important part of authentication into a physical device. The user plugs it into a USB port or taps it over NFC, then confirms the request by touching the key, entering a PIN, or using a fingerprint, depending on the service and key.

The important difference is not simply that another device is involved. The key cryptographically checks the website requesting authentication. A credential created for the legitimate website cannot normally be reused by a lookalike domain.

What is a security key?

A security key is an external authenticator that stores cryptographic credentials in hardware. It is usually shaped like a small USB drive or keyring tag and connects to computers and phones through USB-A, USB-C, or NFC.

Most modern security keys support FIDO2, which combines the W3C Web Authentication API, or WebAuthn, with the FIDO Alliance Client to Authenticator Protocol, or CTAP. FIDO2 supports passwordless, second-factor, and multi-factor sign-in experiences.

Security keys can be registered with compatible services such as Google, Microsoft, Apple, GitHub, password managers, and enterprise identity providers. Actual support depends on the service, operating system, browser, and key model, so compatibility should be checked before purchase.

How does a security key work?

When a security key is registered with a website, it creates a credential specifically for that service using asymmetric, or public-key, cryptography.

  1. The private key remains inside the security key and is not intended to leave the device.
  2. The public key is sent to the online service for signature verification.
  3. At sign-in, the service sends the browser a unique challenge.
  4. The security key checks the website context and signs the challenge with its private key.
  5. The service verifies the response with the public key and grants access if it is valid.

The service does not need to store a shared FIDO secret comparable to a password. If its database is breached, a stolen public key cannot be used to generate the signature produced by the private key inside the device.

What does touching the key prove?

Touching a standard key usually confirms user presence: a person is physically present and approves the request. It does not necessarily scan a fingerprint. Biometric models can verify a registered fingerprint, while non-biometric models may combine a touch with a FIDO2 PIN when user verification is required.

Why security keys resist phishing

An OTP is visible and transferable. A convincing fake website can ask for the code and immediately relay it to the real service before it expires. This is a common form of adversary-in-the-middle phishing.

A FIDO security key does not provide a code that can be typed elsewhere. Its credential is bound to the relying party and website domain. The browser and authenticator check the origin making the request. On a fake domain, the credential for the legitimate site does not match, so the key cannot produce a response accepted by the real service.

Phishing-resistant does not mean resistant to every attack. An attacker may still target an already authenticated session, compromise an endpoint, exploit a service vulnerability, or abuse a weak account-recovery process. Security keys should therefore be combined with software updates, session monitoring, and well-designed recovery policies.

Security keys vs OTP and passkeys

Method Primary purpose Phishing resistance Important consideration
SMS OTP Delivers a one-time code over the mobile network Low Exposed to code phishing and SIM-related attacks
Authenticator app Generates a time-based OTP on a phone Moderate Stronger than SMS, but the code can still be relayed
Synced passkey Stores a FIDO credential that may sync through a provider High Convenient and recoverable, but tied to a sync ecosystem
FIDO2 security key Stores a device-bound passkey or FIDO credential in a physical key High Requires a backup-key and recovery plan

Are a security key and a passkey the same thing?

Not exactly. A passkey is a FIDO credential. A security key is a physical authenticator that can store a device-bound passkey. Passkeys can also be held by a phone, computer, or password manager and may be synchronised across devices.

What is the difference between a security key and a YubiKey?

Security key is the product category; YubiKey is a Yubico product name. Yubico's Security Key Series focuses on FIDO2/WebAuthn and U2F. The YubiKey 5 Series adds protocols such as OATH, PIV, OpenPGP, and OTP for enterprise and legacy environments.

Who should use a security key?

  • Administrators and owners of critical accounts: cloud consoles, domains, source-code repositories, password managers, and privileged accounts.
  • Businesses and public-sector organisations: teams moving to phishing-resistant MFA or controlling the type of authenticator employees may use.
  • People exposed to targeted attacks: executives, journalists, activists, page administrators, and public figures.
  • Finance and approval teams: accounts that approve payments, access customer data, or change other users' permissions.
  • People who work across several devices: one compatible security key can be used across computers and phones without importing a shared secret into each device.

SIAMBC View

  • Protect the primary email account and password manager first, because they can often reset access to many other services.
  • Two security keys should be treated as the starting set, not one primary key followed by a backup purchase after the primary is lost.
  • FIDO-only keys cover many modern services. Organisations using PIV, OpenPGP, OATH, or legacy systems should evaluate multi-protocol models.
  • An SMS-only recovery path can undermine a strong security-key policy if it lets an attacker bypass the key.

How to choose a security key

1. Match the connector to your devices

USB-A remains common on older computers and office desktops. USB-C suits modern notebooks, Android phones, and USB-C iPhones. NFC is useful when the same key must work conveniently with both a phone and computer.

2. Decide between FIDO-only and multi-protocol

For compatible Google, Microsoft, Apple, social, and password-manager accounts, a FIDO-only key is often sufficient. Environments using smart card/PIV, OpenPGP, OATH-TOTP, challenge-response, or Yubico OTP should evaluate a multi-protocol YubiKey 5 model.

3. Consider PIN and biometric verification

FIDO2 keys can use a PIN for user verification. Bio models add fingerprint verification on the key, which can reduce PIN entry when supported. A standard touch key remains suitable when fingerprint verification is not required.

4. Verify standards and service support

Look for FIDO2/WebAuthn and FIDO U2F support, then check the vendor's compatibility list and the target service. Enterprise buyers may also need to assess FIDO certification, attestation, AAGUID policy, identity-provider controls, and inventory requirements.

5. Plan key quantity and recovery

The primary key should stay with the user, while a backup should be stored securely elsewhere. Apple requires at least two keys during setup, while other services have different requirements. Organisations need documented issuance, replacement, revocation, and identity-verification processes.

How to set up a security key safely

  1. Buy through a manufacturer or trusted supplier and inspect the product when it arrives.
  2. Update the operating system and browser before registration.
  3. Set a FIDO2 PIN through the vendor's recommended process and do not reuse a sensitive PIN.
  4. Register the primary and backup keys with the same accounts during the same setup session.
  5. Name each key in account settings, such as “daily key” and “home backup.”
  6. Store recovery codes offline and make sure recovery methods are not weaker than the intended policy.
  7. Test every key before signing out or removing an older authentication method.
  8. If a key is lost, use the backup to sign in and revoke the missing key immediately.

A security key is not a general-purpose USB storage device. Its credentials cannot be backed up by copying files. The correct backup is another key registered with each account, combined with a planned recovery process.

Recommended security keys by use case

Security Key NFC by Yubico: FIDO for USB-A and mobile

A cost-effective option for FIDO2/WebAuthn and U2F. It connects to computers over USB-A and taps compatible phones over NFC.

Security Key NFC by Yubico

Yubico

Security Key NFC by Yubico

฿1,390

  • USB-A and NFC
  • FIDO2/WebAuthn and FIDO U2F
  • Battery-free authentication for modern online accounts
Add to cart

Security Key C NFC by Yubico: FIDO for USB-C and mobile

Designed for modern USB-C notebooks and phones, with NFC for tap-based mobile authentication.

Security Key C NFC by Yubico

Yubico

Security Key C NFC by Yubico

฿1,790

  • USB-C and NFC
  • FIDO2/WebAuthn and FIDO U2F
  • Suitable for current computers and phones
Add to cart

YubiKey 5 NFC: Multi-protocol security with USB-A

For users and organisations that need FIDO plus OATH, PIV, OpenPGP, OTP, or other enterprise and legacy capabilities.

YubiKey 5 NFC

Yubico

YubiKey 5 NFC

฿2,490

  • USB-A and NFC
  • FIDO2, U2F, OATH, PIV, OpenPGP, and OTP
  • Suitable for multi-system and enterprise use
Add to cart

YubiKey 5C NFC: Multi-protocol security with USB-C

Combines multi-protocol YubiKey 5 capabilities with USB-C and NFC for modern desktop and mobile environments.

YubiKey 5C NFC

Yubico

YubiKey 5C NFC

฿2,690

  • USB-C and NFC
  • FIDO2, U2F, OATH, PIV, OpenPGP, and OTP
  • Works across modern desktop and mobile devices
Add to cart

Prices and availability may change. Check the product page before ordering. If an organisation is uncertain which protocols it requires, confirm with its administrator before selecting a model.

Frequently asked questions

Can a security key replace a password?

Yes, when a service supports passwordless sign-in or passkeys on a FIDO2 security key. Other services continue to use the key as a second factor after a password.

Can someone access my account immediately if they find my key?

They generally still need to know the account and may need its PIN or another verification step. Do not rely on that limitation: revoke a missing key from every account as soon as possible.

How many security keys should I buy?

At least two for most people: one for daily use and one stored separately as a backup. Some services, including Apple Account, require two keys at setup.

Does a security key need internet access or a battery?

Typical USB and NFC keys need neither their own internet connection nor a battery. The computer or phone still needs its normal network connection to reach the service.

Does a security key stop every type of account attack?

No. It substantially reduces password theft, credential replay, and phishing risk, but it cannot prevent every malware attack, session theft, service vulnerability, or recovery-process failure.

Can a security key work with a phone?

Yes, when the phone, operating system, and service support it. NFC and USB-C are usually the most convenient mobile connection methods.

Summary

A security key is a physical authenticator that requires possession of the device and a cryptographic response to sign in. With FIDO2/WebAuthn, credentials are bound to the registered website, making security keys much more resistant to fake login pages than SMS or OTP.

Choose based on the services, connectors, and protocols you actually need. A FIDO-only USB/NFC key covers many modern accounts, while organisations with smart-card, OpenPGP, or legacy OTP requirements may need a multi-protocol model.

Whatever the model, register at least two keys, test both, keep the backup and recovery codes separately, and ensure the account-recovery process does not create a weaker bypass.

Sources

  1. FIDO Alliance: User Authentication Specifications and FIDO2 overview
  2. FIDO Alliance: Passkeys and phishing-resistant authentication
  3. Google Account Help: Use a security key for 2-Step Verification
  4. Microsoft Learn: Sign in with a FIDO2 security key
  5. Apple Support: Security Keys for Apple Account
  6. Yubico: Security Key and YubiKey product families

This article references publicly available information checked on 22 August 2026. Standards support, operating systems, online services, firmware, prices, and product availability may change. Verify current information with the service provider and product page before setup or purchase.

Conclusion

A security key is a physical authenticator that uses FIDO2 and WebAuthn to protect online accounts from phishing. Learn how it works, how it differs from OTP and passkeys, and how to choose the right key.

Latest Stories

View all

Does Trezor Support USDT? How to Choose the Right Network

Trezor supports USDT on Ethereum, Tron, Solana and other networks. Learn how to choose the right network, receive funds safely and avoid costly transfer mistakes.

Read moreabout Does Trezor Support USDT? How to Choose the Right Network

Ledger Op3n 2026 with Ledger Stax, Ledger Flex and Ledger Nano Gen5 in Paris

Ledger Op3n 2026: What to Watch as AI, Blockchain and Quantum Converge

Ledger Op3n 2026 comes to Paris on October 15 with AI, blockchain and quantum security at the centre. Here is what hardware wallet users should watch.

Read moreabout Ledger Op3n 2026: What to Watch as AI, Blockchain and Quantum Converge

FTX logo and an analytical network linking Ren, Alameda and 3AC in a Thai parliamentary inquiry

Taiyang Zhang, Ren, Alameda, FTX and 3AC: What Is Known and What Still Needs Proof

A clear account of the questions surrounding Taiyang Zhang, Ren, Alameda, FTX and 3AC, separating public business history from allegations that remain unproven.

Read moreabout Taiyang Zhang, Ren, Alameda, FTX and 3AC: What Is Known and What Still Needs Proof