Device & account security

Do you need a security key? YubiKeys explained in plain English

Some links on this page may be affiliate links. If you buy through them we may earn a small commission, at no extra cost to you. We only recommend tools we believe are genuinely worth it. Learn more.

A security key is the strongest form of two-factor authentication you can buy. It is a small physical key, about the size of a USB stick, that proves it is really you by being physically present when you log in. Unlike a text message or an app code, it can’t be tricked into responding to a fake website, which is what makes it so hard to phish. Here is the honest version: it is the best account protection going, but not everyone needs one. This guide explains what a security key does, whether it is worth it for you, and which one to buy if you decide it is.

The short answer

  • A security key is the most secure 2FA there is, and the only kind phishing attacks essentially can’t get around.
  • Most people do not strictly need one. A proper authenticator app plus passkeys is already a big step up, and free.
  • If you want the strongest lock on your most important accounts, or you look after something valuable, a key is worth the money. Get two, and keep one as a backup.

What a security key actually is

It is a small physical device you either plug into your computer or tap against your phone. When an account asks you to prove it is you, you touch the key. Behind the scenes it uses an open standard called FIDO2 (you may also see U2F), which works with Google, Microsoft, Apple, Facebook, most password managers and a growing list of others.

The key never reveals a code you could accidentally hand over. There is nothing to type, nothing to read out, nothing to forward to the wrong person.

Why it beats codes from a text or an app

This is the part that matters. A text code or an app code can still be stolen if a convincing fake login page tricks you into typing it in. It happens to careful people every day. See how to spot a phishing email for how good those fakes have become.

A security key closes that door. It quietly checks the real web address for you before it responds, so a lookalike site gets nothing, even if you were fooled for a moment. That phishing resistance is the whole reason to own one.

So do you actually need one?

Be honest with yourself here. For most people, the free upgrade of an authenticator app (not text messages) plus passkeys already covers you well. Start there if you have not. Our guide to two-factor authentication walks through it.

A security key earns its place if any of these sound like you:

  • You look after something genuinely valuable online: a business, client data, or a crypto wallet.
  • You have been targeted or hacked before, or you are simply a bigger target than most.
  • You want the strongest possible lock on the account everything else hangs off: your main email. If someone owns your email, they can reset most of your other logins from it.

If none of that is you, a key is a nice-to-have, not a must.

Which security key should you buy?

Yubico’s YubiKeys are the ones I would point most people to, because they are well made, widely supported and easy to live with. Prices change, so treat these as a rough guide and check before you buy.

  • Best for most people: YubiKey 5 NFC. It plugs into a normal USB-A port and also taps against a phone over NFC, so it covers your laptop and your mobile. Around £50.
  • For USB-C laptops and phones: YubiKey 5C NFC. Same idea, USB-C instead of USB-A. Around £55.
  • Cheaper, does the essential job: Yubico Security Key C NFC. It handles the phishing-resistant logins that matter, without the extra features most people never touch. Often around £29.
  • Budget alternative: Thetis and Token2 keys do the core FIDO2 job for less, sometimes under £25. Less polished, but they work.

The tip people wish they had heard first: buy two. Register both on your accounts and keep the spare somewhere safe, like a drawer at home. If you own only one key and you lose it, you can lock yourself out of your own accounts. A backup key is not optional, it is the difference between a lost gadget and a very bad week.

How to set one up

It is easier than it sounds. In each important account, open the security settings, find the two-factor or security key option, and follow the prompt to touch your key. Do your email first, then your password manager, then anything else that holds money or personal data. Register your backup key the same way while you are there, so it is ready if you ever need it.

What about passkeys?

Security keys and passkeys are close cousins. Passkeys are the technology quietly replacing passwords, and a hardware key can act as a portable, phishing-resistant home for the important ones. If you are already moving to passkeys, a security key fits neatly alongside them rather than competing.

The bottom line

If you want the single strongest upgrade for your email and main accounts, and you do not mind spending somewhere around £25 to £55, a YubiKey is worth it. If money is tight, a free authenticator app plus passkeys still puts you ahead of most people. Either way, the real win is the same: stop relying on text-message codes, and make your logins something a fake website can’t simply trick out of you.

For more on locking down the accounts that matter, browse the device and account security guides.