Hardware security keys: the strongest protection for your accounts

Breach / exposure. Updated 2026-09-13. About 5 minutes to read.

Always register two security keys on each account, keep the spare somewhere separate, and save recovery codes before you rely on the keys.

A hardware security key is a small USB or NFC device, often on a keyring, that proves who you are by doing a cryptographic check tied to the real website. A fake login page gets nothing it can use, so security keys are the strongest protection against phishing available to ordinary people.

Apple, Google, Microsoft and many other services support them. The catch is responsibility: Apple warns that if you lose all your trusted devices and security keys you could be locked out of your Apple Account permanently. This guide covers choosing keys, where to use them, setting up two, and what to do if one goes missing.

What a security key does that codes cannot

One-time codes from text messages or authenticator apps can be typed into a convincing fake site, and criminals relay them to the real site within seconds. A security key checks the website's address before it responds, so it simply will not sign in to the fake site.

Modern keys use the FIDO2 standard. They can act as a second step after your password, or hold device-bound passkeys so you can sign in without a password at all. You usually confirm by touching the key and sometimes entering a PIN for the key.

Choosing a key

  • Connector: match your devices. USB-C suits most new laptops and phones, USB-A suits older computers, and NFC lets you tap a phone.
  • Certification: pick a FIDO Certified key. Apple's security key feature requires them.
  • Features: FIDO-only keys cover websites and cost less. Yubico's Security Key series started from about US$30 on its store at the time of writing, while multi-protocol YubiKey 5 models cost more and add extras such as smart card support.
  • Brands: Yubico and Google's Titan are the best known, and other certified makers exist.
  • Where to buy: directly from the maker or an authorised reseller, never second-hand. Prices vary by country and change, so check the maker's site.

Where you can use a security key

  • Apple Account: requires at least two FIDO Certified keys, allows up to six, and needs iOS 16.3, iPadOS 16.3 or macOS Ventura 13.2 or later on all your signed-in devices. Child accounts and Managed Apple Accounts are not supported.
  • Google Account: supports security keys and passkeys, and Google's Advanced Protection Program for high-risk users is built around them.
  • Microsoft account: supports security keys as a sign-in method.
  • Discord: supports security keys and passkeys, up to 16 per account.
  • Many other major services, including Facebook, X, GitHub, Dropbox, and password managers such as 1Password and Bitwarden. Support changes, so check each account's security settings.

Set up two keys on your most important accounts

  1. Buy two keys and label them main and spare.
  2. Start with your email account. In a Google Account, open Security and find Passkeys and security keys, then add both keys one after the other.
  3. For an Apple Account on iPhone, open Settings, tap your name, then Sign-In and Security, then Security Keys, and follow the prompts to add both keys.
  4. Set a PIN on the key if the setup asks for one, and store it in your password manager.
  5. Add both keys to your password manager account, then your bank, social media and cloud storage where supported.
  6. Save each account's recovery or backup codes on paper or in a second secure place.
  7. Keep the spare key somewhere separate. Apple suggests one at home and one at work.

If you lose a key

  1. Sign in with your spare key or another trusted device.
  2. Remove the lost key from every account it was registered on. Keep a list of those accounts so you do not miss one.
  3. Buy a replacement and register it on each account, so you are back to two keys.
  4. If you lost both keys, use recovery codes or the account's recovery process straight away, before losing access to your trusted devices too.

A thief who finds your key still needs your password, or the key's PIN, on most accounts. The bigger risk is locking yourself out, which is why two keys and recovery codes are not optional.

Trade-offs to know before you commit

  • Some services still fall back to text message codes, which weakens the protection. Remove SMS where the service allows.
  • Older devices that cannot run supported software may no longer be able to sign in. Apple notes that Apple Watch paired to a family member's iPhone is not supported.
  • Apple signs you out of devices you have not used in more than 90 days when you turn on security keys.
  • Each key can store only a limited number of device-bound passkeys, so check capacity if you plan to go fully passwordless.
  • You need to carry the key or have a trusted device nearby whenever you sign in on something new.

Frequently asked questions

Is one security key enough?

No. Register at least two. Apple requires two, and every other service is safer with a spare, because losing your only key can lock you out.

Security key or passkey on my phone?

Both resist phishing. A phone passkey is more convenient and syncs. A security key is separate from your phone, cannot be copied and suits people at higher risk, such as journalists, executives and anyone targeted by stalkers.

Do security keys need batteries or charging?

No. They draw power from the USB port or from the phone during an NFC tap.

Can I use one key for many accounts?

Yes. A single key can be registered on as many services as you like for two-step sign-in. Only stored passkeys use up the key's limited storage.

Will a security key work with my iPhone?

Yes, with an NFC key you tap on the phone or a key whose connector matches your iPhone. Apple lists the YubiKey 5C NFC as working with most Mac and iPhone models.

Can someone copy my security key?

FIDO keys are designed so their private keys cannot be exported. The realistic risks are losing the key or touching it to approve a sign-in you did not start, so only tap it when you began the sign-in yourself.

Tools that help

Related guides

Sources