Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Passkeys and compatible FIDO2 security keys are designed to resist fake sign-in pages; authenticator apps that display one-time codes are not. Passkeys and security keys use public-key credentials bound to the service’s domain. A time-based one-time password (TOTP) can be copied from a fake login and relayed to the real service while it is still valid. That makes TOTP replay-resistant, but not phishing-resistant.

What phishing resistance means

NIST defines phishing resistance as preventing authentication secrets or valid authentication outputs from being disclosed to an impostor verifier, without relying on the user to notice the deception. The key distinction is whether the sign-in method is bound to the legitimate service—not whether a code expires quickly or can be used only once.

WebAuthn, used by FIDO2 authenticators, is an example of verifier-name binding. NIST explains that it selects an authenticator secret based on the authenticated domain name of the verifier. NIST SP 800-63B-4

How the three methods compare

Method Phishing resistance Where the credential lives Convenience and recovery
Synced passkey Yes, when implemented as a correctly configured WebAuthn credential bound to the service domain. A cryptographic key synced across devices by an authenticator provider. NIST treats syncable keys as exportable. Cross-device access and recovery can be easier. The sync provider’s account security and sharing model matter.
Device-bound passkey Yes, when correctly implemented through WebAuthn. On one device or hardware authenticator; protections vary by device. Less portable. Losing the device makes the service’s replacement and recovery options important.
FIDO2 security key Yes, through WebAuthn verifier-name binding. A physical external authenticator, connected through a supported interface. Must be carried and protected. A spare can help if the service allows multiple keys.
Authenticator app with TOTP No, under NIST’s definition. It is replay-resistant, not phishing-resistant. A shared secret is held by the app and verifier; the app displays a code for manual entry. Common where offered, but codes can be relayed in real time. Plan how to migrate or recover the app.

The distinction between synced and device-bound passkeys is about control and portability, not whether the credential is inherently resistant to phishing. NIST notes that syncable credentials support cross-device use and recovery, but their keys are exportable and sharing may be possible in some implementations. Device-bound credentials may suit tighter key-control requirements, while making recovery less convenient. NIST SP 800-63B-4

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why passkeys and security keys resist fake login pages

FIDO authentication uses public-key cryptography. When a credential is registered, the service stores a public key and the authenticator retains the corresponding private key. At sign-in, the authenticator responds to a challenge from the service. Because the credential is tied to the service’s domain, a credential for the legitimate site should not work at an impostor domain.

Passkeys can be stored on a device or synced through an authenticator provider. A security key is an external authenticator: FIDO2 combines WebAuthn, the web authentication API, with CTAP, which enables communication with external authenticators. Depending on the device, browser, operating system, and service, CTAP2 connections can use USB, NFC, or Bluetooth Low Energy. Support varies, so check compatibility before relying on a particular key or connection. FIDO2 specifications overview

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

FIDO says biometric information used to unlock an authenticator stays on the user’s device; it is not sent to the online service as part of the passkey sign-in. FIDO Alliance passkeys overview

Why an authenticator-app code can still be phished

A TOTP app generates a short-lived code from a shared secret. NIST classifies this method as replay-resistant: a code that has already been used should not be accepted again. But the code is typed manually and is not bound to the genuine website or sign-in session. An attacker can show a convincing fake page, capture the code, and relay it to the real service before it expires. NIST SP 800-63B-4

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That is why “one-time” does not mean “phishing-resistant.” TOTP still adds a layer of protection if a password is compromised, and it is generally preferable to using a password alone when it is the only second-factor option available. But it should not be described as protection against real-time credential relay. NIST SP 800-63B-4

Which option fits your situation?

  • For protection against fake sign-in pages: use a passkey or security key when the account supports it. Check the account’s security settings and recovery process.
  • For access across personal devices: a synced passkey can make cross-device use and recovery easier. Secure the account that manages syncing, and understand whether its implementation allows credentials to be shared.
  • For a physical credential or independence from a particular phone platform: consider a compatible FIDO2 security key. Confirm that the service accepts security keys, that the connector or wireless interface works with your devices, and that the service lets you register a backup key.
  • If the service offers only an authenticator app: TOTP is useful additional protection, but treat it as vulnerable to real-time phishing. Plan app migration or recovery before replacing or losing the phone.
  • For higher-assurance organizational use: assess exportability, device management, attestation, and certification against the organization’s requirements. NIST requires non-exportable keys at AAL3; FIDO certification levels offer another way to compare authenticator protections. FIDO authenticator certification levels

What to check before choosing a security key

  • Does the account support FIDO2 security keys, and does it allow more than one credential?
  • Do your devices and browsers support the service’s security-key sign-in flow?
  • Does the key have an interface your devices can use, such as USB, NFC, or Bluetooth Low Energy?
  • What will you do if the key is lost? A spare helps only if you can register it with the service.

What phishing-resistant authentication does not prevent

Phishing-resistant authentication is designed to prevent theft and reuse of authentication secrets. It does not prevent malware installation, manipulation through another channel, or collection of personal information for later misuse. Organizations still need broader phishing-prevention measures, and individuals should treat unexpected requests and downloads cautiously. NIST SP 800-63B-4

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How widely available are passkeys?

NIST reported a FIDO Alliance estimate in 2024 that more than 8 billion user accounts had the option to use passkeys. This is a dated estimate attributed to FIDO, not a NIST measurement or a current count of passkey users. Availability and recovery options still depend on the specific service. NIST SP 800-63B-4

Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.