Passkeys vs security keys, and the accounts where a $29 key still wins
Key takeaways
- Synced passkeys and hardware security keys both use FIDO2, so both stop phishing; the difference is where the private key lives and who can copy it.
- August 2026 research showed malware on a Windows PC could pull synced passkey private keys out of Google Password Manager in Chrome. A hardware key never hands its key to the computer.
- Use synced passkeys for everyday accounts and put a hardware key on the two or three accounts that can reset everything else, usually email, Apple or Google, and your password manager.
- For most people the $29 Yubico Security Key C NFC is enough. Pay $58 for a YubiKey 5 only if you need OTP, smart card or OpenPGP features.
This article contains affiliate links. We may earn a small commission if you make a purchase, at no extra cost to you.
Last updated: 2 October 2026
In August, Palo Alto's Unit 42 showed that malware already running on a Windows PC could recover the private keys behind a victim's synced passkeys in Google Password Manager. Not phish them. Recover them. The researchers called the worst version Golden Pass-ta-key, and Google's design currently offers no way to rotate the 32-byte master secret it targets.
That does not make passkeys bad. They are still the biggest upgrade to everyday login security in twenty years. But it settles a question people keep asking: if you have passkeys, do you still need a hardware security key like a YubiKey? For most of your accounts, no. For two or three of them, yes, and it costs less than you think.
Passkeys vs security keys: same standard, different vault
Both are built on FIDO2 and WebAuthn. When you sign in, the website sends a challenge, your device signs it with a private key, and the site checks the signature against a public key it stored when you registered. The signature is tied to the real domain, so a lookalike phishing page gets nothing useful. That part is identical.
The difference is where the private key sits.
- Synced passkeys live in iCloud Keychain, Google Password Manager, Microsoft's account, or a password manager like 1Password or Bitwarden. They copy themselves to every device you sign in on. Lose your phone and they are still there.
- Device-bound passkeys on a security key are generated inside a small piece of tamper-resistant hardware and never leave it. The computer asks the key to sign; the key does the maths and hands back only the signature.
So the trade is simple. Synced passkeys move the security boundary to your cloud account and every device signed into it. A hardware key keeps it on your keyring.
What the 2026 passkey attacks actually changed
Three research efforts landed in the same week in early August 2026. None broke the cryptography, and that is the point.
Unit 42's Pass-ta-key targeted Google Password Manager in Chrome on Windows. With malware on the machine, one path let attackers act as a legitimate client without a fresh unlock. The Golden variant grabbed the Security Domain Secret, the master key protecting synced passkeys, from Chrome's memory during device re-registration. Google removed it from the logs after the report, but the researchers say it still appears briefly in memory.
SpecterOps' Pass-the-Passkey, presented at Black Hat USA on 5 August, found Windows had been writing past YubiKey signatures to event logs in cleartext. Chained with weak challenge handling in Microsoft Entra ID, those old signatures could be replayed. Microsoft patched the Windows side as CVE-2026-34348 in its July updates, which SpecterOps says breaks the full chain.
Dirk-jan Mollema showed that malware inside a signed-in Windows session could use a Windows Hello for Business key without a new PIN prompt.
Read those carefully and a pattern appears. Every attack starts with malware already on your computer. Once that happens, synced passkeys can be copied out wholesale. A hardware key's private key cannot, though malware can still try to trick you into tapping it for a login you did not mean. That gap, between "steal the key forever" and "abuse one tap", is the whole argument for owning one.
Which accounts need a hardware key
You do not need a security key on your pizza delivery account. You need one on the accounts that can unlock or reset everything else. For most people that is a short list:
- Your main email. Every password reset lands here.
- Your Apple Account or Google Account. These hold your synced passkeys, so protecting them with a hardware key protects the vault itself.
- Your password manager, if it supports FIDO2 sign-in.
- Work admin accounts, cloud consoles, domain registrars and anything holding money.
Everything else can use synced passkeys. That combination is roughly what security teams recommend for companies too: hardware keys for admins and high-value roles, synced passkeys for everyone else.
This also matters at work. Microsoft started auto-enabling passkeys on 1 September 2026 for Entra ID users who currently sign in with SMS or voice codes, and Microsoft-provided SMS and voice delivery retires on 1 February 2027. If your employer uses Microsoft 365, expect a passkey prompt soon, and ask IT whether a hardware key is an option. If you manage your own home setup, our home network security settings guide covers the router side of the same problem.
Which security key to buy
Always buy two. Register both on every account that matters, keep one on your keys and the other somewhere safe at home. Apple will not even let you turn on security keys for an Apple Account with fewer than two.
Best for most people: Yubico Security Key C NFC
At $29 on Yubico's US store, this is the one I would hand a friend. USB-C for laptops and modern phones, NFC for tapping an iPhone. It does FIDO2 and the older U2F standard and nothing else, which is all a personal account needs. No one-time codes, no smart card mode, no PGP. You will not miss them.
Best if you need the extras: YubiKey 5C NFC or 5 NFC
The YubiKey 5 series lists at $58 on Yubico's store after early 2026 price rises. You pay double for OTP, PIV smart card support, OpenPGP and OATH codes. Those matter for developers signing commits, sysadmins using SSH with hardware-backed keys, and anyone whose employer uses smart card login.
One detail worth checking before you buy: keys on firmware 5.7 or later store up to 100 passkeys, up from 25 on older units. YubiKey firmware cannot be updated, so an old unit sitting in a warehouse stays at 25 forever. If you plan to store a lot of device-bound passkeys, buy from a seller with fresh stock.
Check price on Amazon: YubiKey 5C NFC (USB-C) →
Check price on Amazon: YubiKey 5 NFC (USB-A) →
The alternative: Google Titan Security Key
Google sells the USB-A plus NFC Titan for $30 and the USB-C plus NFC version for $35. Google says the current generation stores over 250 passkeys. It is FIDO-only like Yubico's basic key and a perfectly good pick if you live inside Google's ecosystem.
Prices above are US list prices as of October 2026. UK, EU, Indian and Australian pricing varies, and Amazon stock in some regions lags the latest firmware, so check the listing or ask the seller.
Setting it up without locking yourself out
- Step 1: Register both keys on your email and cloud account first, before anything else.
- Step 2: Generate and print backup codes for each of those accounts. Store them with your spare key.
- Step 3: Keep synced passkeys on your phone for daily use if you like. The hardware key is the root of trust, not the thing you tap fifty times a day.
- Step 4: Keep Windows, macOS and your browser patched. Every 2026 passkey attack needed something already on the machine. If you are not sure your devices are clean, our guides on checking whether your phone is monitored and the Android security checklist are a good start.
FAQ
Is a passkey as safe as a hardware security key?
Against phishing, yes. Both bind the login to the real website. Against malware already on your device, no. Synced passkeys can be copied out of a compromised cloud keychain; a hardware key's private key cannot be exported.
Can a YubiKey store passkeys?
Yes. YubiKeys and Security Key series keys store device-bound passkeys. Firmware 5.7 and later hold up to 100.
Do I still need a security key if I use a password manager?
If your password manager supports FIDO2 login, a hardware key is one of the best things you can put in front of it. It guards the account that guards everything else.
What happens if I lose my security key?
Use your second key or your backup codes, then remove the lost key from each account. That is why you buy two.
The short version
Turn on passkeys everywhere they are offered. They are a huge improvement on passwords and SMS codes. Then spend $58 on two basic keys and lock down the handful of accounts that can reset your entire digital life. If you want more on how attackers get onto a machine in the first place, read our piece on AI browser prompt injection, and keep our zero-day checklist bookmarked for the day your router makes the news.