Resource icon

Security key: a physical sign-in method that can resist fake sites

A security key is a physical device used to prove a sign-in, commonly through FIDO2/WebAuthn. In that flow, the browser and key bind the response to the site's real domain, so a copied login page cannot simply relay the same proof to a different domain. Some keys also offer other modes; not every use of a hardware token has this protection.

A useful example​

You reach a fake webmail login and enter your password. The impostor asks for your security key. A FIDO sign-in should reject the wrong site origin instead of completing the genuine account login. The password may still be exposed, so change it on the real site.

Before you rely on one​

Check which key protocols your services support, register a backup method and store it safely. Losing your only registered key without recovery can lock you out. NIST explains phishing-resistant authentication; our authenticator migration guide covers the broader recovery planning.

Practical distinction​

A FIDO/WebAuthn sign-in is bound to the website origin. A one-time code displayed by a hardware token can still be typed into a fake site, so check which mode the service uses.
Posted by
Jack
Views
3
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack