Guide

Why a USB Security Key Is No Longer Enough

USB Keys were step one. Token is the final step. The only way to stop phishing, spoofing, and relay attacks dead is biometric, proximity-based, phishing-proof hardware.

Frame 1991428526

USB security keys are a meaningful step forward from SMS codes and push notifications. They use FIDO2, which binds credentials to a specific domain and keeps the private key on the device.

A phishing site cannot intercept a USB key authentication the way it can intercept an SMS code. That is a real improvement and it is worth saying clearly. But a USB key is still a physical object with no biometric requirement. Anyone who possesses it can use it. That single fact opens a category of risks that do not exist with biometric-bound hardware. The sections below explain each of them.

What USB Security Keys Get Right

USB security keys implement FIDO2 authentication. That means two things.

  1. First, a unique key pair is generated for each service the user registers with. The private key stays on the device and never leaves it.

  2. Second, the authentication challenge is bound to the specific domain the user is logging into. A fake domain cannot produce a valid challenge. A relay attack cannot forward one that resolves correctly.

This eliminates the two most common attack vectors against legacy MFA: credential theft and phishing relay. For organisations moving away from SMS-based authentication, USB keys are a defensible and significant improvement.

The weaknesses below are not arguments against FIDO2. They are arguments for going further than a USB-based implementation of it.

1. Physical Device Attacks

The most direct attack against a USB security key is theft. A stolen key can be used anywhere the credentials are registered. There is no fingerprint check. There is no way for the device to verify that the person holding it is the person it was issued to. An attacker who finds a USB key left in a laptop has everything they need.

A subtler threat is the fake key swap. An attacker with brief physical access can replace a user’s key with an identical-looking malicious device. The user has no way to detect this. Every subsequent authentication goes through the attacker’s device.

There is also a hardware-level vulnerability in many deployed keys. A widely used cryptographic library found in a significant proportion of USB security keys contains a known flaw that allows private key material to be extracted with lab access. Most USB keys do not support over-the-air updates. The flaw cannot be patched. It exists permanently in devices already in the field.

2. Human Factor Exploits

USB security keys require possession and a tap. They do not require proof of who is tapping. Any person holding the device can authenticate. This is the core gap between a USB key and a biometric-bound authenticator.

The relay risk follows from this. FIDO2 provides origin binding, but a phishing site operating as a real-time proxy can still present a valid challenge to the victim. The victim taps their key. The tap is valid. The authentication succeeds on the legitimate site. The attacker captures the session. This works because the tap requires only possession, not identity. 

Helpdesk attacks are a related problem. A social engineer who convinces IT support to issue a replacement key or reset an account bypasses the hardware entirely. Without biometric verification at the point of recovery, the strength of the primary authenticator is irrelevant.

3. Protocol and Architectural Weaknesses

FIDO2 origin binding is only as strong as the enforcement layer above it. Malicious middleware on a compromised endpoint can sit between the browser and the key, presenting a modified challenge that the key signs without knowing the origin has changed. Browser-level exploits can achieve the same result. The key does what it is asked. It cannot detect that it is being deceived.

Many USB security keys include NFC for contactless authentication. NFC authentication can be relayed over significant distances with the right equipment. The key believes it is communicating with a nearby reader. It is not.

The absence of over-the-air update capability means that when a protocol vulnerability is discovered, there is no fix path for deployed devices. The only option is full hardware replacement. Most organisations cannot execute that quickly.

4. Recovery and Fallback Risks

The most reliable way to bypass a strong authenticator is to find the recovery path around it. USB key deployments almost always include a fallback. SMS backup codes, recovery links, email verification. Each fallback is a weaker authentication method that an attacker can target directly. The strength of the primary factor becomes irrelevant once there is a side door.

Shared device environments introduce a different problem. When multiple users authenticate with the same physical key, the identity binding the key is supposed to provide does not exist. The device proves that someone with access to it is logging in. It cannot prove who.

5. Advanced Threats

A compromised endpoint undermines authentication at the session level. If malware is present when a user authenticates with their USB key, the malware can capture the session token after authentication completes. The key is never interfered with. The authentication is never tampered with. The attacker simply waits for the user to log in and then takes what results.

Supply chain risk is less discussed but structurally significant. USB keys are manufactured at scale without per-user binding. A compromised production batch could include modified firmware. The user receiving the device has no practical way to verify its integrity before registering it.

6. Usability & Behavioral Gaps

The most consistent failure mode for USB keys is behavioural. Keys are left in laptops in meeting rooms, forgotten at home, dropped in bags. Users resolve the friction of carrying a separate device by keeping it permanently attached to their machine, which directly undermines the possession factor it is supposed to provide.

The USB connection itself creates inconsistency. Not every device has a port in a convenient position. NFC tap is more portable but introduces the relay risk covered above. The authentication experience varies by device in ways that invite workarounds.

Once a USB key authentication completes, access is granted until the session expires. There is no continuous trust check. A user who authenticates at their desk and then steps away leaves an open session the key cannot close.

Why Token Closes These Gaps

Biometric enforcement - no fingerprint = no login No fallback / no shared secrets - removes human loopholes
Proximity binding - must be next to the machine logging in Tamper-resistant - Useless if stolen
Cryptographic domain binding - no spoofed origins Immune to fake key swap attacks - no USB port exposure
OTA upgradeability - resilient against new discoveries and library flaws Wearable convenience - Token Ring = always with the user, not left behind
Wireless BLE - works everywhere without USB hassle  

 

Keep reading

More guides worth your time.

Identity assurance covers more ground than a single guide. Dig deeper into the frameworks, threats, and decisions that define modern access control.

Learn

Types of Cyber Security Threats Explained

Learn about the most common types of cybersecurity threats, including malware, phishing, ransomware, insider threats, and denial-of-service attacks, plus strategies to reduce cyber risk.

Learn

Understanding CISA's Phishing-Resistant MFA Recommendations

Learn what CISA recommends for phishing-resistant MFA, why FIDO2 authentication is the preferred approach, and how organizations can implement phishing-resistant identity security.

Learn

How FIDO2 Stops Phishing Attacks

Learn how FIDO2 stops phishing attacks using public key cryptography, origin binding, and passwordless authentication to deliver phishing-resistant MFA for enterprise security.

No resources found.

Make Identity Absolute

TokenCore™ proves the human behind every login. No exceptions.