In an era where data breaches and phishing campaigns dominate the threat landscape, relying on a strong password alone has become a gamble. Even the most complex password offers no defense if it is stolen in a server breach, handed over on a convincing fake login page, or reset through a hijacked phone number. German cybersecurity authorities are now urging consumers to adopt stronger account protection, specifically through two-factor authentication and passkeys.

Weak Links Even Strong Passwords Cannot Fix

Passwords are vulnerable in three fundamental ways. When an online service is breached, millions of credentials often surface on illicit forums, instantly compromising every account where that password was reused. Phishing pages harvest passwords in real time from users who believe they are logging into a legitimate site. SIM swapping, where fraudsters hijack a mobile phone number to intercept text messages, remains a persistent threat. The FBI reported roughly $26 million in losses linked to SIM swapping in 2024 alone. A second authentication factor introduces an additional barrier that can block an attacker even when a password is lost.

How Different Security Layers Compare

Not all verification methods provide equal protection. Codes delivered by SMS or email, while widely used, represent the weakest form of two-factor authentication. An authenticator application that generates time-based one-time passwords locally on the device is a stronger alternative because it never touches the cellular network, making it immune to SIM interception.

Passkeys shift the paradigm further by replacing codes entirely. They store a cryptographic private key on the user’s device and are unlocked through a fingerprint, facial scan, or PIN. Crucially, the private key never leaves the device. Hardware security keys, such as a YubiKey, apply the same principle in a dedicated USB or NFC token. Germany’s federal cybersecurity office, the BSI, also highlights chipTAN and the national electronic identity card as highly resistant methods tailored for banking and government services.

What separates the strongest methods from the rest is real-time phishing resistance. When a victim types an SMS or app-generated code into a fraudulent website, an attacker can relay that code instantly. According to the BSI, authenticator apps do not reliably block such real-time relay attacks or data leaks. Passkeys and hardware tokens, however, bind authentication to the legitimate website’s domain. They refuse to operate on a fake site, neutralizing the phishing attempt. The BSI’s evaluation concludes that chipTAN and the national ID card are resilient against all currently considered attack vectors, assuming users maintain a strong password and operate across two separate devices.

Setting Up Passkeys and Hardware Tokens

Passkeys offer a particularly practical path to high-security login. Since they typically rely on biometrics or a device PIN, they work on iPhones running iOS 16 or later, Android devices on version 9 or newer, and Windows 10 and 11 across all major browsers. Support has expanded rapidly among providers including Google, Apple, Microsoft, Amazon, PayPal, and GitHub. The FIDO Alliance projects roughly five billion active passkeys globally by 2026, with user awareness already reaching 90 percent.

Enabling a passkey requires only a few steps. Google users can visit g.co/passkeys, Apple users can go to appleid.apple.com, and Microsoft users can navigate to account.microsoft.com to create a passkey within minutes. Once configured, logins are confirmed with a glance or a touch. On shared computers, an authenticator app such as Google Authenticator, Microsoft Authenticator, or the open-source Aegis application is a sensible alternative. After installing the app, scanning a QR code shown in the account’s security settings binds the account to the app instead of an SMS code.

For the highest-value accounts, especially an email inbox that receives all password-reset messages, a hardware key provides maximum security. FIDO2 tokens like the YubiKey or Google’s Titan Key are briefly plugged in or tapped against a phone via NFC during login. They match passkeys in phishing resistance while adding physical separation that prevents remote copying.

A 2024 research demonstration known as EUCLEAK showed that certain YubiKey 5 Series devices with firmware older than version 5.7 can be cloned. The attack requires extended physical possession, specialist laboratory tools, and is not executable remotely. Yubico has since resolved the flaw in firmware version 5.7. For most people, the practical takeaway is straightforward: purchase a current model and consider keeping two keys, with one stored securely as a backup.

The Recovery Gap and a Practical Recommendation

The most frequent point of failure is not the authentication technology itself but the account recovery route. If a service allows access via a simple email link after a device is lost, the added protection collapses. The BSI advises securing the backup codes provided during setup in a safe offline location or inside a password manager. When using hardware keys, the second key functions as this exact backup.

For the majority of accounts, passkeys deliver the strongest balance between security and ease, increasingly eliminating the need for a password altogether. Where passkeys are not yet supported, an authenticator app should replace SMS-based codes. The single most sensitive account should be anchored by a hardware key. The steps are minor, but the security uplift is substantial.

Filed under — Passkeys · YubiKey