Hardware security key

Protection

The only second factor that cannot be phished. How it achieves that, who needs one and what it costs.

Every familiar confirmation method shares one weakness: it can be talked out of you. An SMS code gets read out over the phone; an app code gets typed into a fake page. A hardware key is the only one that cannot be tricked this way, and the reason is not the user's vigilance but the design of the protocol.

0cases
Successful phishing attacks against a properly configured hardware key

Not because the owner is more careful. Because the key physically cannot answer a fake site: it checks the address itself, before signing anything.

Why phishing does not work

This is the thing worth understanding, and it takes three steps to explain.

  1. The key is bound to the site's address

    At registration it remembers not the service's name but the exact domain. For a fake domain it simply has no matching record.

  2. The browser reports the address honestly

    The address is passed to the key by the browser, not by the page. A page cannot fake it: it has no way to say “I am really the bank”.

  3. No match, no signature

    The key does not produce a code you could type somewhere. It signs a specific request from a specific domain. There is nothing to intercept: the signature is useless on another site.

The methods compared

MethodPhishing resistanceIf the phone is lostCost
SMS codeNoLost along with the numberFree
App codeNo — the code can be typed anywhereLost without backup codesFree
Confirmation in a banking appPartly — you can see what is being confirmedLostFree
PasskeyYes — the same protocolMoves with the accountFree
Hardware keyYesDoes not depend on the phone at allThe price of the device
A passkey uses the same protocol and gives the same phishing resistance — covered separately. The difference is where the key lives: in an ecosystem, or in your pocket.

Who needs one

Worth it
  • The email through which everything else is recovered
  • Access to money and crypto assets
  • Public figures and journalists
  • Administrators of sites and systems
  • Anyone who has already fallen for phishing
Overkill
  • Forums and shops with a one-off purchase
  • Services holding neither money nor personal data
  • If your main accounts still have no second factor at all

The last point matters most: start not with a key but with making sure a second factor exists everywhere. A key on one account while the rest stand open gives little.

Choosing and setting up

  • Buy two at once. Carry one, keep the other at home as a spare. Keys get lost like house keys, and recovery without a second one is a matter of weeks.
  • A connector that fits your devices. USB-A, USB-C, wireless — check what your phone and computer take.
  • Register both keys straight away. On every service where you enable it. Adding the second later requires access, and if you had access you would not need the key.
  • Keep backup codes anyway. A key is no reason to give up a fallback route.
Copied