Most security keys ship without a PIN, and websites rarely ask - Notebookcheck Review
Reviews<br>← exclude selected types<br>← exclude selected tags
A security key on your keyring looks like maximum security. A piece of hardware nobody can steal remotely. The US cybersecurity agency CISA calls phishing-resistant sign-in the "gold standard" in its October 2022 fact sheet and names FIDO and WebAuthn "the only widely available phishing-resistant authentication".
What few people know: on many of these keys, a tap is enough out of the box. No PIN, no fingerprint, nothing. Whoever holds the thing is, as far as the service behind it is concerned, the rightful owner.
This is not an oversight and not a cheap-product problem, it is in the manuals. Yubico puts it in its Technical Manual as a side note: "By default, no PIN is set." And a paragraph later: the stored credentials "can be left unlocked and used for strong single-factor authentication".
A single factor, in other words. Exactly what passkeys were meant to replace.
Tap or prove it, that is the difference
FIDO2 has two levels, and both carry the same certification seal. User Presence only means a human was there and touched the key. Who touched it, the key does not check. User Verification means that human proved who they are, by PIN or fingerprint.
How thin the first level is, of all makers Nitrokey documents. The Nitrokey FIDO2 guide states: "The first FIDO operation is automatically accepted within two seconds after connecting Nitrokey FIDO2." Plugging it in counts as proof of presence. The same page adds that configuration and reset operations are not accepted this way. The Nitrokey Passkey guide carries the same sentence without that limit, and for the Nitrokey 3 the maker does not document the behaviour at all.
On Feitian's BioPass models K26, K27 and K45 the LED gives it away: a slowly blinking green light means tap, a fast one means place your finger. One device, two security levels, told apart by a blink rate.
ⓘ Notebookcheck
Two levels of checking, one seal.
The website usually decides about your PIN
The second uncomfortable point: even a PIN that is set does not mean it will be requested.
Token2 explains this more plainly than any other maker: "The decision whether to authenticate with a security key with or without a PIN rests with each website or authentication service." At sign-in the service sets a parameter called userVerification, with three possible values. With discouraged it asks for no PIN. With preferred, the standard case, it only asks if one is set. Only required makes it mandatory, and the service then forces you to set one during enrolment.
For you that means: without a PIN set, even preferred will not ask. And even with a PIN you stay unasked if the service sends discouraged. There is a way to flip this, more on that shortly.
ⓘ Notebookcheck
PIN out of the box and permitted PIN length, side by side.
News<br>← exclude selected types<br>← exclude selected tags
What stands out is how small the group is that demands a PIN out of the box: Yubico's Enhanced PIN line and Token2's PIN+ with firmware R3.3. Everyone else ships without. The second half of the table shows what happens when the PIN does not fit after all.
ⓘ Notebookcheck
Wrong entries, fingerprint behaviour and passkey capacity, side by side.
How to spot quality when buying
The numbers in the table say nothing about how well a key is built. That is what the FIDO Alliance certification levels are for, and they appear in every maker's data sheet. There are five: L1, L1+, L2, L3 and L3+.
L1 is the baseline against phishing and against breaches at the service provider. It can be pure software and is checked by questionnaire. L2 additionally requires a walled-off execution environment in hardware, so a compromised operating system cannot reach the keys. From L3 the device must also withstand physical tampering, and L3+ extends that to the chip level. From L2 upwards an accredited laboratory tests, in part with source code access and penetration testing.
For most private users L2 is the sensible floor. Token2 advertises it for the PIN+ series, but on the biometric Bio3 the certification covers the firmware only. Certification of the fingerprint part is still under way, the maker says.
ⓘ Notebookcheck
For most private users L2 is the sensible floor.
The switch that overrules the website
There is a way out, and it is called alwaysUV, short for "always require user verification". With it active, the key demands a PIN no matter what the service asks for. Token2 describes the effect: "This setting enforces PIN request in all cases, irrespective of whether the RP requests it or not." So it also bites when a service sends discouraged.
Getting at that switch is another matter. Token2 ships it enabled from firmware R3.3 on. As of 5 August 2026 the PIN+ Bio3 still runs R3.2, and according to the maker it will never get R3.3, jumping straight to R3.4...