Most FIDO2 Security Keys Ship Without a PIN, and That Changes How Safe They Really Are
A hardware security key feels like the ultimate account protection. It sits on your keyring, cannot be stolen by malware over the internet, and is widely promoted as one of the strongest defenses against phishing. FIDO2 and WebAuthn sign-ins are often described as phishing-resistant authentication, and for good reason: they can stop attackers from tricking users into handing over reusable passwords or one-time codes.
But there is an important detail many buyers miss.
A large number of FIDO2 security keys do not come with a PIN enabled by default. In many cases, simply holding the key and tapping it is enough to approve a login. No fingerprint. No PIN. No extra proof that the person touching the key is actually the owner.
That does not mean the key is broken or poorly made. It means the FIDO2 standard allows different security levels, and many services decide how much verification they want to require.
Two security keys can follow the same FIDO2 standard, cost roughly the same, and behave very differently. One may demand a PIN before login. Another may only require a tap. To the average user, both may look equally secure. In practice, the difference matters a lot if the key is lost, stolen, borrowed, or left plugged into a device.
The key difference: presence versus verification
FIDO2 authentication has two important concepts: User Presence and User Verification.
User Presence means the key detected that a person was physically there. Usually, that means someone touched the key or interacted with it. The problem is obvious: the key does not know who touched it. If an attacker has the key, a tap may be enough.
User Verification goes further. It requires the person using the key to prove they are the right user, usually with a PIN or fingerprint. This is the stronger form of authentication most people imagine when they think of a secure passkey or hardware security key.
Both approaches can exist under the FIDO2 umbrella. That is why the certification label alone does not always tell the full story for everyday account safety.
Some manufacturer documentation makes this distinction clear. Certain keys accept a basic operation after being connected or tapped, while more sensitive actions such as reset or configuration may require additional steps. On biometric keys, LED patterns may even indicate whether the device is asking for a simple tap or a fingerprint scan.
In other words, the same physical device can support both a lightweight “someone is here” check and a stronger “the correct user is here” check.
Why your security key may not ask for a PIN
One of the biggest surprises is that the website or online service often decides whether a PIN is requested.
During authentication, a service can tell the security key how strongly it wants the user to be verified. The FIDO2 setting involved is called userVerification, and it can generally be set in three ways:
Discouraged means the service does not want user verification. In this case, the key may not ask for a PIN even if one exists.
Preferred means the service would like user verification if available. This is common, but if no PIN has been set, the login may still continue with only a tap.
Required means the service demands user verification. In that case, the user must verify with a PIN or biometric method, and the key may force PIN setup during registration.
This means setting a PIN on your security key is important, but it is not always enough. If a website chooses not to request user verification, your key may still allow a tap-only login unless another setting overrides it.
Most keys do not ship with a PIN enabled
Documentation from several major hardware security key makers shows that most FIDO2 keys are shipped without a PIN set by default.
That matters because many users assume a new security key already protects them with two layers: possession of the device plus knowledge of a PIN or biometric verification. In reality, the default setup often protects only possession of the device unless the user or service enables stronger verification.
Some product lines are exceptions. Certain enhanced-PIN security keys and specific firmware versions are designed to require or enable stronger PIN behavior out of the box. But for many popular models, the user must manually set a PIN after purchase.
For anyone using a security key to protect email, banking, cloud storage, work accounts, cryptocurrency accounts, developer platforms, or password managers, this is a critical setup step.
The setting that can force PIN use: alwaysUV
There is a way to make a FIDO2 security key demand user verification even when a website does not ask for it. The setting is commonly called alwaysUV, short for “always require user verification.”
When alwaysUV is enabled, the key requires a PIN or biometric check for FIDO2 use regardless of the website’s preference. This can close the gap where a service sends a weak userVerification request.
However, availability and documentation vary widely by manufacturer and model. Some keys ship with alwaysUV enabled on newer firmware. Some require users to activate it manually through management tools. Others may not clearly document the setting for regular users.
This creates a usability problem: the people who would benefit most from alwaysUV may not know it exists, and enabling it may require technical steps such as using a command-line tool.
There have also been compatibility issues in some environments. Older Windows versions reportedly had trouble when alwaysUV was combined with services that discouraged user verification, causing repeated prompts between touching the security key and entering the PIN. Newer Windows builds are reported to handle this more reliably.
Still, for users who want the strongest practical protection, alwaysUV is one of the most important FIDO2 security key features to look for.
A PIN improves security, but forgetting it can be painful
Adding a PIN makes a stolen key much less useful to an attacker. But it also introduces a new risk: lockout.
Several security key makers state that users get up to eight incorrect PIN attempts. This limit is tied to the FIDO CTAP specification, which sets eight as a maximum. Some implementations may allow fewer attempts. In some cases, after several wrong tries, the key must be unplugged and reinserted before more attempts are allowed.
The counter usually resets after a correct PIN entry. But if the user has truly forgotten the PIN, there are only a limited number of chances.
After too many wrong attempts, resetting the key is often the only option. A reset does not merely remove the PIN. It also destroys the stored FIDO2 and U2F credentials on the key. That means every account registered with that key must be set up again.
For users who protect many accounts with one hardware security key, this can become a serious recovery headache.
The best PIN is not necessarily the most complicated one. It should be strong enough to resist guessing, but memorable enough that the owner will not lose access. Some security keys enforce additional PIN rules, such as minimum length, blocking simple sequences, rejecting repeated digits, or requiring alphanumeric characters.
Fingerprint security keys behave differently
Biometric security keys add another layer by using fingerprint verification instead of, or alongside, a PIN. But their behavior after failed fingerprint attempts varies by brand and model.
Some keys fall back to PIN entry after a small number of failed fingerprint scans. Others allow more biometric attempts before requiring another method. This makes it important to understand how a biometric key behaves before relying on it for critical accounts.
A fingerprint reader can make secure login faster and more convenient, but it does not eliminate the need for a recovery plan. Users should still know their FIDO2 PIN, keep backup access methods, and register more than one key where possible.
Certification levels matter when buying a security key
The presence of a PIN is only one part of the security picture. Build quality, hardware protection, and resistance to tampering also matter.
FIDO certification levels help explain what type of protection a device offers. The levels include L1, L1+, L2, L3, and L3+.
L1 is the baseline level. It focuses on phishing resistance and protection against service-side breaches, but it may be based on software and documentation checks.
L2 requires a protected hardware environment so that a compromised operating system cannot directly access the private keys.
L3 adds protection against physical tampering.
L3+ extends that protection deeper into chip-level attacks.
For many personal users, L2 is a sensible minimum because it means the key has dedicated hardware protection beyond basic software claims. Users with higher-risk profiles, such as administrators, executives, journalists, activists, developers, or cryptocurrency holders, may want to consider stronger certification levels and stricter PIN behavior.
How to choose and set up a FIDO2 security key safely
When buying a FIDO2 security key, do not assume that “FIDO2 certified” automatically means every login will require a PIN or fingerprint. Before choosing a model, check these points:
Does the key ship with a PIN already required?
Can you set a FIDO2 PIN easily?
Does the key support alwaysUV?
Is alwaysUV enabled by default, or must it be turned on manually?
What FIDO certification level does the device have?
How many wrong PIN attempts are allowed before reset?
How does the key handle failed fingerprint scans?
Is the firmware actively maintained?
Does the manufacturer clearly document FIDO2 PIN behavior?
Once the key arrives, users should set it up carefully. Create a memorable but not obvious PIN. Register at least two keys with important accounts, keeping one as a backup in a safe place. Review account recovery options before disabling other login methods. If the key supports alwaysUV and compatibility is not an issue, consider enabling it for stronger protection.
The bottom line
FIDO2 security keys remain one of the best ways to protect online accounts from phishing. They are far safer than passwords alone and usually stronger than SMS codes or app-based one-time passwords.
But the details matter.
Many security keys work without a PIN by default. Many websites do not require user verification. And unless alwaysUV is enabled, possession of the key may sometimes be enough to log in.
For real phishing-resistant multi-factor authentication, users should make sure their security key requires more than a tap. A hardware key is strongest when it combines possession with user verification: the device you have, plus the PIN or fingerprint that proves it is really you.Biometric security keys can lock you out faster than you think
Fingerprint-based FIDO2 security keys promise a simple upgrade: touch the key, verify your fingerprint, and sign in without typing a password. For passkeys and phishing-resistant multi-factor authentication, that sounds ideal. But there is one detail many users overlook until it is too late: failed biometric attempts can lock the key, and in some cases the only recovery option is a full factory reset that deletes stored credentials.
That matters because a FIDO2 security key is often used as the final gatekeeper for important accounts. If it is your only registered key and it gets blocked, you may lose access to every service tied to it unless you have another recovery method.
Some biometric keys are stricter than users expect. Certain Feitian models, including the K26, K27 and K45, can become locked after repeated failed fingerprint attempts. According to the manual, recovery may require a factory reset, which wipes the data on the key. For newer K49 and K50 models, listed by Feitian as BioPass FIDO2 Plus, the exact number of allowed failures is not clearly stated.
The YubiKey Bio has its own important limitation. When used with plain U2F sign-in, there may be no PIN fallback. After three failed biometric attempts, the key can enter a “biometrics blocked” state. Yubico has also warned developers that the Bio series may be a poor fit for some login tools that rely on this kind of sign-in flow. In other words, fingerprint login is convenient, but it should not be treated as a magic recovery-proof solution.
The good news is that a successful fingerprint entry can reset the failure counter. In some cases, one correct verification restores the counter back to eight attempts. But that does not help if the key has already entered a blocked state or if you are locked out of the account where the key is registered.
The most important step is to set a PIN. A PIN changes the security model and gives you a fallback that can prevent biometric failure from becoming a complete lockout. On Yubico devices, the PIN can be managed through Yubico Authenticator. On the Nitrokey 3, it can be configured with Nitrokey App 2 or nitropy. Older Nitrokey FIDO2 models may require PIN setup directly in the browser during first registration because the app does not support that model. Token2 users can configure the PIN through the company’s own tool.
A PIN also strengthens authentication. With a security key alone, possession of the device may be enough for some sign-ins. With a PIN, the key becomes a stronger two-factor method: you need the physical device and something only you know. For anyone using passkeys for banking, business accounts, cloud storage, email, password managers or developer platforms, that extra layer is worth the few seconds it takes to set up.
Another feature to check is alwaysUV, short for “always user verification.” When enabled, the key requires user verification, such as a PIN or biometric check, for supported FIDO2 operations. On Yubico keys, users can check and configure this with ykman commands such as ykman fido info and ykman fido config toggle-always-uv. On Token2 devices, alwaysUV is active from firmware R3.3. For other manufacturers, public documentation may not clearly state whether the feature is available, so it is worth contacting support before relying on it.
The next rule is simple: register a second key. If your main security key is blocked, lost, damaged or reset, a backup key may be the only thing standing between you and a painful account recovery process. Keep the second key somewhere safe, such as a locked drawer or safe, and register it with every important account that supports hardware security keys or passkeys.
Do not rely blindly on marketing numbers or a single specification sheet. Security key documentation can be inconsistent. For example, one Yubico document has stated one passkey storage figure for the 5 series in one section and a different figure in a capability matrix. Token2 has also shown different chip certification levels on the same page. The lesson is clear: check the exact model in your hand, verify its capabilities, and do not assume that all keys from the same brand behave the same way.
Firmware is another detail that deserves attention. On certified security keys from brands such as Token2 and Yubico, firmware often cannot be updated by the user. This is intentional. A fixed firmware design can be part of the security and certification model because it prevents unauthorized changes after manufacturing. But it also means the features present when you buy the key are the features you will have permanently.
Yubico firmware 5.8, released in July 2026, can support stronger reset behavior, such as blocking reset over NFC or requiring a five-second touch. However, these are factory programming options. On a normally purchased key, those protections may be disabled unless the device was specifically configured that way.
For everyday users, the takeaway is straightforward. Biometric FIDO2 security keys are useful, but they are not foolproof. A fingerprint sensor can fail because of dry skin, cuts, dirt, moisture, sensor issues or simple misreads. If enough attempts fail, the device may lock biometric authentication, and some models may require a destructive reset.
Before depending on a biometric security key for your most important accounts, take these precautions: set a PIN, check whether alwaysUV is supported, register at least one backup key, confirm the real storage and certification details for your exact device, and understand whether the firmware can ever be updated.
Hardware security keys remain one of the strongest defenses against phishing and account takeover. But the safest setup is not just buying a key and using it once. It is configuring it correctly, planning for failure, and making sure one blocked fingerprint sensor does not lock you out of your digital life.






