Security Tokens - Hardware Keys and OTP Devices
About 2 min read
A security token is a physical device or software used for authentication. Examples include hardware tokens that generate one-time passwords, USB-connected security keys (such as the YubiKey), and smartphone authenticator apps. It functions as the possession factor of multi-factor authentication added on top of a password, greatly strengthening account security.
When Proof of Possession Becomes Proof of Identity
What a security token verifies is that the device was in the hands of whoever was operating the system at the moment authentication took place. As long as the assumption holds that each device is tied to one specific person, that fact can be treated as support for a claim of identity. Once the assumption breaks down, what can be verified shrinks to something narrower: that someone was holding a registered device. Practices such as keeping a single unit in a department for several people to share, or passing a device collected from a departing employee to another owner while its registration stays in place, quietly break that assumption. Because the logs contain nothing but successful authentications, the problem does not surface as an anomaly; it becomes visible only later, when someone tries to trace who performed an action and finds that it cannot be determined. This is why assigning one device per person, and keeping issue and return in step with registration and de-registration, is the condition under which a token works as an authentication measure at all. A device that has been collected but left registered also leaves a path by which authentication can still succeed while the hardware sits outside the control of the organization.
Types of Security Tokens
Hardware tokens are physical devices, including a type that displays an OTP (one-time password) and FIDO2 security keys that connect via USB/NFC. Software tokens run as smartphone apps and generate TOTP. FIDO2 security keys are the most phishing-resistant authentication method; Google has reported that after rolling them out to all employees, phishing incidents dropped to zero. As of 2025, with the spread of passkeys, demand for FIDO2-compatible security keys is rising even further.
Deployment Scenarios and How to Choose
For personal use, a practical approach is to first introduce a TOTP app for your main accounts (email, bank, social media), and add a FIDO2 key for especially important accounts. In enterprise environments, more organizations are making hardware tokens mandatory for accessing VPNs and cloud services. To prepare for token loss, it is important to securely store backup recovery codes or register a spare security key in advance. Online banking also makes use of tokens for transaction authentication.
Putting Tokens to Use
By combining a strong random password with a security token, you achieve the highest level of account protection. Use our two-factor authentication setup guide as a reference and roll it out starting with your most important accounts. Because SMS authentication is vulnerable to SIM-swapping attacks, we recommend migrating to a TOTP app or hardware key wherever possible.
Was this article helpful?