- Most security keys (FIDO2) do not require a PIN from the factory, initially operating as simple single-factor hardware.
- The decision on whether to request a PIN usually depends on the website in question and not solely on the key itself.
- After 8 incorrect PIN attempts, the key resets and all stored credentials are lost.
The trap of the simple tap
When you hold a security key in your hands, you believe you have stopped every possible attack vector. According to official CISA document, the Phishing-resistant sign-in is considered the golden age of identification.
What most users don't realize is that devices from leading manufacturers work out of the box with just a simple touch. According to its technical manuals, Yubico, by default there is no PIN set. Someone who finds or steals your key can gain access immediately.
This function corresponds to the User Presence level of the FIDO2 protocol. The key does not control who is touching it, but simply confirms that a person was in front of the device.
Who decides on the PIN?
Even if you manually set a PIN, requiring it at login is not universal. As the Token2 in its documentation, the decision belongs exclusively to the website or service that serves you.
During sign-in, the service sets a parameter called userVerification. If the value is set to discouraged, the system will never ask for a PIN, even if you have it enabled.
A few manufacturers, such as Yubico with the Enhanced PIN series and Token2 with firmware R3.3, require a mandatory PIN from the start. In other cases, security remains in your hands.
How to set your own rules
There is a way to bypass the website selection by enabling the alwaysUV (always require user verification) feature. This setting forces the key to ask for a PIN regardless of what the service asks for.
According to Yubico command guides, you can intervene via the command line using the corresponding management tools. Other manufacturers, such as Nitrokey, are gradually integrating the feature into their newer software versions.
However, there is a critical risk that is rarely discussed. If you enter your PIN incorrectly eight times in a row, the FIDO standard forces an automatic reset, deleting all stored credentials and cutting you off from your services.
Our opinion at TechNoid
Buying a security key without an active PIN is like buying a safe and leaving the door open. Manufacturers make the mistake of shipping keys ready for immediate use without prompting for stronger authentication, sacrificing security for the sake of User Experience.
Αν επενδύεις σε φυσική ασφάλεια, μην εμπιστεύεσαι τις εργοστασιακές ρυθμίσεις. Μπες αμέσως στο λογισμικό διαχείρισης της συσκευής σου, όρισε ένα αξιόπιστο PIN, ενεργοποίησε το alwaysUV όπου υποστηρίζεται και —το κυριότερο— αγόρασε οπωσδήποτε ένα δεύτερο κλειδί για backup. Μια αποτυχημένη προσπάθεια ανάκτησης χωρίς εφεδρεία σημαίνει ψηφιακή απομόνωση.
Frequently Asked Questions about Security Keys and Security PINs
Does a FIDO2 security key necessarily require a PIN?
Not by default, as many keys work with a simple touch out of the box unless you enable it.
Who decides whether a PIN will be required at login?
The website or authentication service itself determines whether User Verification is required when you log in.
What is the alwaysUV function?
It is the setting that forces the key to always request a PIN, bypassing the instructions of each website.
How many incorrect PIN attempts are allowed?
The limit is eight consecutive incorrect attempts before the key blocks and performs a total reset.
What happens if the security key is reset?
All saved credentials are permanently deleted and you must reconfigure your connections to the services.
What is the difference between User Presence and User Verification?
The former simply confirms that someone touched the key, while the latter requires proof of identity via PIN or biometrics.
Are biometric keys more secure than classic ones?
They provide convenience, but on some models, failure to read a fingerprint can directly lock the device.


