A password can leak. We can also enter it ourselves on a fake login page. Attackers can even intercept one-time codes from authenticator apps or text messages. That is why your most important accounts deserve protection that can resist this kind of fraud. A hardware security key is one effective option: a small device that recognises the legitimate website and will not approve a login on a fake copy. Who should use one, and what should you check before buying?
What is a hardware security key?
A hardware security key is a small physical device used to confirm that it is really you signing in. Depending on the model, you plug it into a USB-A or USB-C port, or hold it near an NFC-enabled phone to approve the login.
Before you can use a security key, you need to add it in the security settings of the account you want to protect. From that point on, the service knows that sign-ins should be approved with that key. One device can be registered with many services, including email, a password manager, hosting or an admin panel.
A hardware security key can work in two ways:
As a second factor – you first enter your login details, then connect the key or tap it against your phone. Someone who knows your password still cannot access the account without the key.
As a passkey – the device replaces a traditional password. You confirm the sign-in with the key and its PIN, or with your fingerprint if the model includes a biometric reader.
When you register a key, the service creates a unique pair of cryptographic credentials. The public part is stored by the service, while the private part stays on the key and never leaves it. Each sign-in generates a unique request that can be used only once. Depending on the model and settings, the key responds after you touch its button, enter a PIN or use your fingerprint.
That approval is valid only for a specific website and a single sign-in attempt. For example, if the key is registered with your Google account, a fake website impersonating Google will not receive a valid response. There is also no code for an attacker to view, copy or intercept. This is the key advantage of hardware security keys over traditional authentication methods.
How do hardware security keys protect against phishing?
A fake login page can look almost identical to the real one. If you enter your username and password by mistake, an attacker may immediately try to use them on the legitimate service.
A hardware security key works differently. As explained above, registering it with an account creates a separate credential tied to that specific service. The website address is checked, and the device approves the sign-in only for the correct domain. It simply will not work on a fake website.
Of course, a security key does not solve every security problem. It will not protect a computer from malware, revoke access granted to a suspicious application or prevent fraud when a user personally approves a transfer or a settings change. It does, however, make account takeover through stolen login details much harder.
When should you use a hardware security key?
Not every account needs this level of protection. For many accounts, a reliable password manager or biometric sign-in is enough. A hardware security key is most useful for services whose compromise could cause serious harm, such as banking or company resources. Start with:
your primary email account, which receives important messages and is used to reset passwords for other services,
administrator accounts for Google Workspace, Microsoft 365 and other business services,
your password manager,
hosting, your domain registrar and server control panels,
cloud services,
code repositories and tools used by the technical team,
company social media profiles and advertising platforms,
financial services.
Security keys are especially useful for employees with broad permissions or access to confidential information, as well as business owners, administrators and finance teams. They are also a sensible choice for public figures, journalists and activists who face a higher risk of targeted attacks.
For many personal accounts, a passkey stored on your phone or computer will be enough. A hardware security key gives you a separate way to sign in that you can use across compatible devices. If your smartphone is lost or stolen, a registered security key can also help you regain access.
How do you choose the right model?
The most expensive key is not always the best one. Compatibility with your services, the right connector and how you use your devices matter more.
1. Choose FIDO2 and WebAuthn
To protect modern online accounts, choose a model that supports FIDO2 and WebAuthn. This lets you use the key both as a second factor and for passkey sign-ins on services that support them.
The older FIDO U2F standard may still be enough to approve a sign-in after entering a password, but it does not support every newer authentication method. A FIDO2 model, preferably FIDO certified, is therefore the better choice.
2. Match the connection method to your devices
Before buying, check the ports and wireless standards supported by your computers and phones:
USB-A – available on many older desktop computers and laptops.
USB-C – standard on newer laptops and phones.
NFC – allows you to sign in on compatible smartphones by tapping the key against the phone.
If you normally use a USB-C laptop and an NFC-enabled phone, a model supporting both will be the most convenient. In a company, check the devices used by the whole team, not only the computer of the person ordering the keys.
3. Check compatibility with your most important services
FIDO is widely supported, but implementations vary. Before buying, review the security settings of your most important accounts and the providers’ documentation. Make sure each service allows you to register a hardware security key, use it on your operating system and add at least two keys.
In a business environment, the administrator should also review policies in Microsoft Entra ID, Google Workspace or another identity provider. Technical compatibility alone is not enough if the sign-in method has not been enabled for the organisation.
4. Do not pay for features you do not need
For email, social media accounts and popular cloud services, a FIDO2 security key is usually enough. More advanced models may also support smart cards, PIV, OpenPGP or older one-time password methods. These features can be useful in government, large organisations and specialist environments, but many users will never need them.
A fingerprint reader is another feature to consider. It can make identity verification more convenient, but it is not required for effective protection. Many models simply use a PIN instead. Think about which method you prefer and what you actually need.
5. Consider the shape, durability and manufacturer
A key carried every day alongside other objects should withstand ordinary knocks and remain convenient to use. A smaller model may be easier to carry but also easier to lose. A larger one is harder to overlook, although it sticks out further from the port and takes up more room in a backpack or laptop bag.
Choose a reputable manufacturer and buy from a trusted seller. The key may protect your most important accounts for several years, so buying the cheapest unknown device is not worth the risk. Avoid products without clear documentation or certification. We can recommend Yubico’s YubiKey models from our own experience at ZanReal.
Why is one hardware security key not enough?
If you lose the only key registered with an account, recovering access can be difficult. You may need emergency codes or have to complete an identity verification process. It is therefore best to buy two keys from the start and register both with your most important services during setup.
Carry one key with you for everyday use. Store the second in a secure place, such as a locked cabinet or safe. Do not keep them together, or you could lose both at the same time.
After setup, sign in with each key in turn. Simply buying a second key is not enough: if it has not already been registered with the account, it will not help you recover access.
Keep the emergency codes provided by the service as well. Do not store them only on the phone or computer you use to sign in. Keep a printout or handwritten copy in a secure location, and store an encrypted copy somewhere you can still reach if you lose your primary device.
A company should also decide where backup keys are kept, who may use them and whom employees should notify if their everyday key is lost.
How do you start using a hardware security key?
A key does not begin protecting your accounts as soon as you take it out of the box. You need to register it separately with each service.
Buy two compatible keys. Choose connectors that match the smartphones and computers you use every day.
Start with your primary email account. Open its security settings and look for options such as “security key”, “passkey” or “two-step verification”.
Register both keys. If you lose one, you will still be able to access the account with the other.
Test sign-in. Sign out and confirm that each key works. If you use both a computer and a smartphone, test the process on both devices.
Secure account recovery. Check that your recovery email address and phone number are current, save the emergency codes and remove outdated methods.
Add the keys to other important services. Your password manager, financial services, cloud accounts and administrator accounts can come next.
Do not remove your only working sign-in method until you have tested both keys. Check whether the account can still bypass the key through a weaker method such as SMS. If the service allows it, disable that fallback only after confirming that everything works correctly.
What should you do if you lose a hardware security key?
Losing a key does not automatically mean that someone has taken over your account. The person who finds it would still need to know which services it was registered with and, depending on the sign-in method, may also need your username, password or PIN. Even so, treat the loss seriously.
First, sign in to the affected accounts with your backup key or a recovery code, remove the lost device from the list of authentication methods and register a replacement if you already have one. If it is company equipment, report the loss to the administrator as soon as possible.
Do not label the key with details that clearly identify the company, email address or protected service. A discreet marking that helps you distinguish your own devices can be useful, but it should not help a stranger find the right account.
Is a hardware security key right for you?
A hardware security key is worth considering if losing control of your email, administrator account, domain or cloud services would cause significant costs or a long interruption to your work. It is also a strong choice when you want to reduce phishing risk without relying only on codes from an app or text message. You do not need to protect every online profile this way. Start with a few accounts that grant broad permissions, contain confidential information or can be used to recover access to other services. Buy a second key, test both and only then expand the setup.
For a company, purchasing the devices is only the beginning. You also need to decide who should use them, which systems support them and how keys will be issued, stored and revoked. If you want to introduce effective security controls in your organisation, contact us. We will help you choose measures that improve security without making everyday work unnecessarily difficult.