{"id":71922,"date":"2026-09-11T02:05:49","date_gmt":"2026-09-10T23:05:49","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=71922"},"modified":"2026-09-12T15:42:57","modified_gmt":"2026-09-12T12:42:57","slug":"fido2-security-key","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/fido2-security-key\/","title":{"rendered":"FIDO2 Security Key: How to Protect Google and Other Accounts"},"content":{"rendered":"\n\n\n<p class=\"wp-block-paragraph\">We already have a <a href=\"https:\/\/lwallet.com.ua\/en\/best-fido2-keys\/\" target=\"_blank\" rel=\"noreferrer noopener\">separate guide<\/a> on choosing U2F\/FIDO security keys. Here, we\u2019ll focus on the practical side: <strong>you already have a FIDO2 security key<\/strong>, and you need to add it correctly to Google, GitHub, a crypto exchange, or a password manager, set up reliable backup access, and avoid locking yourself out of your accounts. We\u2019ll also explain the difference between a security key and a passkey, and where the protection of a physical key ends.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">FIDO2 security key: what it protects \u2014 and what it doesn\u2019t<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>FIDO2 security key<\/strong> is primarily designed to stop unauthorized sign-ins, even if your password or other login credentials have been stolen or intercepted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What it protects against:<\/strong><\/p>\n\n\n\n<ul class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>Phishing.<\/strong> WebAuthn binds authentication to a specific domain and origin. Even a convincing copy of a Google sign-in page on a lookalike domain cannot get a valid signature from your key. You can accidentally type an SMS or TOTP code into a phishing site; a FIDO key will not authenticate that site.<\/li>\n\n\n\n<li><strong>SIM swapping.<\/strong> If SMS is not left enabled as an alternative sign-in method or second factor, taking over your phone number will not let an attacker bypass the physical key.<\/li>\n\n\n\n<li><strong>A stolen or reused password.<\/strong> A password alone is not enough if the service requires confirmation with a FIDO security key.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What it does not protect against:<\/strong><\/p>\n\n\n\n<ul class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>It does not protect your seed phrase, private keys, or transactions in a self-custody wallet.<\/strong> FIDO2 protects online accounts such as email, password managers, and exchange accounts.<\/li>\n\n\n\n<li><strong>It does not save an already compromised session.<\/strong> Malware can steal a session cookie or token after you have successfully signed in.<\/li>\n\n\n\n<li><strong>It does not fix weak account recovery.<\/strong> If access can be restored through a poorly protected recovery email, phone number, or another fallback channel, an attacker may target that path instead.<\/li>\n\n\n\n<li><strong>It does not protect you from signing a malicious Web3 transaction.<\/strong> In self-custody, that is the job of your hardware wallet and careful verification of transaction details before approval.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A security key and a hardware wallet solve different security problems and do not replace each other.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">Second factor vs. passkey: two ways to use the same key<\/h2>\n\n\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-1024x573.jpg\" alt=\"FIDO2 security key: 2FA vs. passkey\" class=\"wp-image-71890\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">A physical security key can be used in two main ways, and it helps to understand the difference before you start setting it up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Security key as a second factor.<\/strong> You enter your username and password first, then the service asks you to confirm the sign-in with the physical key. Even an older U2F\/FIDO1 key may be enough for this setup: for example, Google accepts both FIDO1 and FIDO2 security keys for 2-Step Verification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Passkey stored on the security key.<\/strong> A FIDO2 key can store a discoverable credential \u2014 a hardware-bound passkey that may replace your password on a compatible service. Signing in usually requires user verification on the key itself, typically with a FIDO2 PIN or biometrics, followed by a touch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Registering a security key as a regular second factor generally does not use discoverable-credential slots. <strong>The storage limit matters specifically for passkeys saved on the key<\/strong>, and it depends on the model and firmware. Hardware-bound passkeys make the most sense for your primary email, password manager, GitHub, and other high-value accounts; where passwordless sign-in is not needed, the same key can simply remain a second factor.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">What to do before setting up your security key<\/h2>\n\n\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-1024x573.jpg\" alt=\"Preparing a FIDO2 security key for setup\" class=\"wp-image-71896\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Set up backup access before you start relying on a physical key as the main protection for your most important accounts.<\/p>\n\n\n\n<ol class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>Register two keys.<\/strong> Add both your primary and backup keys to critical services from the start. Store the backup key in a physically separate location.<\/li>\n\n\n\n<li><strong>Save your backup codes.<\/strong> Keep them offline or in another secure location that does not depend on the same account. A screenshot in your regular phone gallery is a poor backup.<\/li>\n\n\n\n<li><strong>Set a FIDO2 PIN.<\/strong> Passkeys stored on a physical key usually require user verification with a PIN; biometric models may also use a fingerprint. PIN requirements vary by key model and firmware.<\/li>\n\n\n\n<li><strong>Review account recovery.<\/strong> Your recovery email, phone number, and other fallback methods should be current and protected at least as well as the main account.<\/li>\n\n\n\n<li><strong>On a new NFC-enabled YubiKey, check Restricted NFC mode.<\/strong> On NFC models running firmware 5.7 or later, this mode is enabled during shipping. To enable normal NFC operation, connect the key to USB power for about 3 seconds.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">Google: three levels of protection<\/h2>\n\n\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1024x573.jpg\" alt=\"Setting up a FIDO2 security key for Google\" class=\"wp-image-71893\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Google lets you use the same physical key as a second factor, as a passkey, or as part of Advanced Protection.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Level 1. Security key as a second factor<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the basic setup, your password stays in place and the physical key becomes the second step of the sign-in process. Right after setup, <strong>add a backup key, save your backup codes, and review alternative 2FA methods<\/strong>. If SMS remains available as an alternative second factor, an attacker may try to target that weaker channel. A recovery phone number is a separate setting, so there is no need to remove it automatically just because you disable SMS as a 2FA method.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Level 2. Passkey stored on the key<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A FIDO2 security key can store a passkey and use it for passwordless sign-in. In your Google settings, open the passkeys and security keys section, choose to create a passkey on a security key, connect the key, and confirm registration with the key\u2019s PIN and a touch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your FIDO2 security key was added to your Google Account before May 2023, you may need to remove it from the account and add it again before you can create a passkey on that same key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Level 3. Advanced Protection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Advanced Protection is Google\u2019s strictest security mode for people at higher risk of targeted attacks.<\/strong> It requires a passkey or security key for sign-in, limits access by unverified third-party apps, adds stronger download checks, and makes account recovery more restrictive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Advanced Protection no longer requires two physical security keys: you can enroll with a passkey or a FIDO-compatible security key. Google still recommends keeping your recovery email and phone number up to date and having a separate backup passkey or physical key. Advanced Protection may be unnecessary for an ordinary personal account, but it can make sense for journalists, activists, administrators, executives, and anyone protecting especially valuable accounts.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">Other services<\/h2>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Microsoft<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Personal Microsoft accounts support passkeys and hardware security keys. In Microsoft Entra ID, administrators control which passkey types are allowed through authentication policies. <strong>Starting September 1, 2026, Microsoft automatically adds passkeys to the allowed authentication methods for Entra users who previously had SMS or voice calls enabled and prompts them to register a passkey during MFA sign-in<\/strong>; Microsoft does not create the passkey without the user completing registration.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Apple Account<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Apple requires <strong>at least two FIDO Certified security keys<\/strong>, and you can add up to six to your Apple Account. Devices already signed in to the account must be running iOS 16.3, iPadOS 16.3, macOS Ventura 13.2, or later, and two-factor authentication must already be enabled. Once configured, the physical key replaces the usual six-digit verification code during sign-in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Store your keys in different locations. If you lose access to all trusted devices and all security keys, <strong>Apple warns that you could permanently lose access to your account<\/strong>.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">GitHub<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub supports security keys as a second factor and passkeys for passwordless sign-in. <strong>A passkey can satisfy both the password and 2FA requirements at the same time<\/strong>. If your GitHub account gives access to repositories, CI\/CD, or tokens, it is worth adding a hardware-bound passkey or security key and keeping recovery methods separately.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Password managers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Your password manager is one of your most important accounts because compromising it can expose access to many other services. Bitwarden supports FIDO2 WebAuthn for two-step login for all users. After enabling 2FA, <strong>save your recovery code outside the vault itself<\/strong>: without it and without another available 2FA method, you may be unable to regain access.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Crypto exchanges<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On a crypto exchange, the key question is <strong>which actions FIDO2 actually protects<\/strong>: signing in, changing settings, adding a withdrawal address, or withdrawing funds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Binance<\/strong> lets you use a hardware FIDO2 key as a passkey; on compatible phones, the key can work over NFC or USB. Before setup, check the current options for your platform and app version.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Kraken<\/strong> configures sign-in 2FA, Master Key, and Funding 2FA separately. For withdrawals, Funding 2FA supports a Hardware Security Key or an authenticator app. It is also worth enabling Global Settings Lock: it blocks changes to critical settings and, among other things, helps prevent an attacker from adding new withdrawal addresses after taking over your account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other exchanges use different rules, so if you are buying a key for a specific service, check that service\u2019s current documentation first.<\/p>\n\n\n\n<h3 class=\"nm-block-heading wp-block-heading nm-block-heading\">Ukrainian services<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Universal USB\/NFC FIDO2 keys are still uncommon as a standard sign-in method in Ukrainian banking apps, which more often rely on their own approval flows and biometrics. Specialized systems such as DELTA are a separate use case. See our detailed guide to <strong><a href=\"https:\/\/lwallet.com.ua\/en\/fido2-keys-for-delta\/\">setting up FIDO2 security keys for DELTA<\/a><\/strong>.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">YubiKey FIDO2 PIN: 8 attempts and what happens after lockout<\/h2>\n\n\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-1024x573.jpg\" alt=\"YubiKey FIDO2 PIN: 8 attempts before lockout\" class=\"wp-image-71902\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">If you use a YubiKey, it is important to know the FIDO2 PIN retry limit, especially when passkeys are already stored on the key. <strong>Yubico allows 8 attempts in total.<\/strong> After three consecutive incorrect PIN entries, you must unplug and reconnect the key; the retry counter does not reset. In practice, that gives you 3+3+2 attempts. A correct PIN resets the counter back to eight.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After the eighth failed attempt, the FIDO2 function is locked and you must perform a FIDO reset to use it again. <strong>A FIDO reset deletes the FIDO2 PIN and all FIDO\/U2F credentials stored on the key<\/strong>, so you will need to register the key with your services again. There is no separate PUK code for FIDO2. Other authenticators may handle retry limits differently.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">How many passkeys can a security key store?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Capacity depends on the model and firmware. If you plan to use hardware-bound passkeys extensively, check the limit before you start.<\/p>\n\n\n\n<ul class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>YubiKey 5 Series and Security Key Series with firmware 5.7.x or later:<\/strong> up to 100 passkeys (discoverable credentials). YubiKey 5 Series also supports OATH, PIV, and OTP; Security Key Series remains FIDO-only.<\/li>\n\n\n\n<li><strong>YubiKey models with firmware 5.0\u20135.6.x:<\/strong> up to 25 passkeys (discoverable credentials).<\/li>\n\n\n\n<li><strong>OnlyKey:<\/strong> up to 12 FIDO2 resident credentials. Regular U2F\/FIDO2 use as a second factor without a resident credential does not have the same site-count limit.<\/li>\n\n\n\n<li><strong>Current-generation Google Titan Security Key:<\/strong> more than 250 passkeys.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">OnlyKey is different from a typical FIDO-only security key: it combines FIDO2 with a built-in password manager, OpenPGP, SSH, and encrypted backup and restore. That broader feature set can be useful for more advanced setups; if you mainly need FIDO2 for email, GitHub, and exchanges, a simpler security key is usually more convenient.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">How to set up a real backup key<\/h2>\n\n\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-1024x573.jpg\" alt=\"Primary and backup FIDO2 security keys\" class=\"wp-image-71905\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-fido2-keys-11-09-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>A key sitting unregistered in a drawer is not a real backup.<\/strong> On typical hardware-bound security keys, a passkey cannot be copied from one physical key to another, so each key must be registered separately with your critical services while you still have access to the accounts.<\/p>\n\n\n\n<ul class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>Primary key<\/strong> \u2014 keep it with you or near your workspace.<\/li>\n\n\n\n<li><strong>Backup key<\/strong> \u2014 store it somewhere physically separate, not in the same bag or on the same keychain.<\/li>\n\n\n\n<li><strong>Backup codes<\/strong> \u2014 keep them separate from the primary key and somewhere you can reach without signing in to the account they are meant to recover.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">About once every six months, use the backup key to complete a real sign-in to at least one critical service. This confirms that the key still works and that you remember the PIN and know where the backup is stored.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">What to do if you lose your security key<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you lose your primary key, follow these steps:<\/p>\n\n\n\n<ol class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>Sign in to your critical accounts<\/strong> with your backup key or another trusted method.<\/li>\n\n\n\n<li><strong>Remove the lost key<\/strong> from the list of registered security keys or passkeys in each service.<\/li>\n\n\n\n<li><strong>Review active sessions, recovery methods, and connected apps.<\/strong> Sign out unknown sessions and revoke any suspicious access.<\/li>\n\n\n\n<li><strong>Add a new backup key<\/strong> and register it with your critical services while you still have access.<\/li>\n\n\n\n<li><strong>Change your password if there are signs of a broader compromise.<\/strong> Losing a FIDO2 key by itself does not mean an attacker also knows your password.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If you do not have a backup, the recovery process depends on the service. Google warns that verification after losing a second factor can take <strong>3\u20135 business days<\/strong>. A crypto exchange may require you to verify your identity again. For Apple, the worst-case scenario is losing access to both every security key and every trusted device.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">Which security key should you choose?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your main goal is FIDO2 for Google, email, GitHub, password managers, and crypto exchanges, <strong>Security Key by Yubico with NFC<\/strong> is usually enough. It supports FIDO2\/WebAuthn and U2F, but not Yubico OTP, PIV, OpenPGP, or OATH, which makes it a simpler option than the multiprotocol YubiKey 5 Series.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>YubiKey 5 Series<\/strong> is the better choice if you also need Yubico OTP, OATH, PIV, or OpenPGP. Security Key Series can also be used for modern FIDO2-based SSH authentication, so SSH alone is not necessarily a reason to move up to a YubiKey 5.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>YubiKey Bio<\/strong> is a good fit if you want to approve FIDO2 sign-ins with a fingerprint: you can enroll up to five fingerprints, while the PIN remains a fallback verification method. <strong>OnlyKey<\/strong> is worth considering if you want a built-in password manager, FIDO2, OpenPGP, and SSH in one device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can buy a key directly from the manufacturer or from Lwallet. The Lwallet catalog includes Security Key by Yubico, YubiKey 5 Series, YubiKey Bio, the FIPS lineup, and OnlyKey, with local support and setup assistance.<\/p>\n\n\n\n<h2 class=\"nm-block-heading wp-block-heading nm-block-heading\">Final setup checklist<\/h2>\n\n\n\n<ol class=\"nm-block-list wp-block-list nm-block-list\">\n<li><strong>Two keys<\/strong> are registered with every critical service.<\/li>\n\n\n\n<li><strong>Your FIDO2 PIN<\/strong> is set and not stored together with the key.<\/li>\n\n\n\n<li><strong>Backup codes<\/strong> are accessible independently of the account they are meant to recover.<\/li>\n\n\n\n<li><strong>Weaker fallback 2FA methods<\/strong>, including SMS, are disabled where they are not needed; your recovery phone number has been reviewed separately.<\/li>\n\n\n\n<li><strong>Your backup key<\/strong> is stored in a physically separate location and periodically tested with a real sign-in.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>We already have a separate guide on choosing U2F\/FIDO security keys. Here, we\u2019ll focus on the practical side: you already have a FIDO2 security key, and you need to add it correctly to Google, GitHub, a crypto exchange, or a password manager, set up reliable backup access, and avoid locking yourself out of your accounts. &hellip;<\/p>\n","protected":false},"author":10,"featured_media":71888,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1006],"tags":[],"class_list":["post-71922","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-keys"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/71922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=71922"}],"version-history":[{"count":4,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/71922\/revisions"}],"predecessor-version":[{"id":71971,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/71922\/revisions\/71971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/71888"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=71922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=71922"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=71922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}