Safety key: when to use it

A small USB or NFC device confirms the login to the right page. See how to add the key and prepare to lose it.

2 min readFor execution: 10-15 minutes for registration and test
In this guide

The security key is similar to a small flash drive, but it is not used to copy files. When you log in, you connect it to a port or approach your phone. Then you confirm the operation according to the device message, such as the touch and PIN code.

This guide is about FIDO2/WebAuthn keys. The “token” itself is not enough: the device displaying the disposable code has different properties than the key that checks the login connection to the site.

What gives you an advantage over the application code?

The TOTP code can be copied to the fake form. The cheater can immediately use it on the real page. With FIDO2 the browser and key binds the operation to the right service. A similar domain will not receive the correct confirmation for the original site.

This is a good reason to protect your email key, code repository or administrative account. However, it does not mean protection against all threats: an active session or infected computer still requires a separate response.

Check match before purchase

Start by setting up important services. Do they allow you to register a security key or passkey on the key? Then check your computer ports, support your NFC phone and system requirements.

The USB-C key is not automatically compatible with every application on your phone with USB-C. It counts the whole set: service, browser, system and connection method. A list of supported configurations of the manufacturer is more useful than a photo of the connector itself.

If you want to use the key as the main login path, include a second copy or other independent recovery method.

Register the key in each account

  1. Sign in to the service and open the login method settings.
  2. Select adding the security key or saving passkey on the external key. Follow the browser messages.
  3. Give it a recognizable name, for example “Daily Key”.
  4. Check the new login, leaving the current session open.
  5. Repeat the registration for the spare key and test it separately.

The spare key does not become a copy of the first just because it comes from the same manufacturer. You have to add it separately in each service. Keep it in another place, not on the same keychain.

When the key dies or stops working

Log in with the backup method and remove the lost key from the settings of each account on which it was registered. Check the last activity. Add a new key before removing the last efficient method.

Do not reset the key blind with your PIN problem. Reset can remove saved credentials and require re-registration. First read the manufacturer's instructions and make sure you have another way in.