Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What should I do with a hardware security key?

Preserve a hardware security key as an authentication device, not merely as USB storage. Do not connect it, press its controls or use it to test access to an account.

The key may unlock more than one service

Security keys can support multi-factor authentication, passwordless sign-in, account recovery or device unlocking. Depending on the model, they may communicate through USB, NFC or Bluetooth and may require a touch or PIN to approve an operation. They generally prove that a registered authenticator participated in a login, not who physically activated it.

Record where the key was found, who possessed or controlled it and any associated computer, phone, account details or paperwork. Photograph its make, model, connector, serial number, labels, packaging, attached tag and adapters, and note all visible communication methods.

Preserve any live authentication context

Connection can create host and service logs or expose an already authenticated account. If the key is attached when found, record the host, port, open application, account, prompts and visible session before considering removal. Removing it may interrupt authentication or lock access, although many established sessions can remain active without the key.

Keep recovery codes and instructions separately protected but clearly associated. Where important accounts or encrypted material may depend on the key, obtain specialist advice and preserve it against damage, loss and accidental activation.

Key takeaway

A hardware security key is evidence of an authentication capability and its context; preserve it without using possession or a successful login as automatic proof of the user.

Reference: FRP-154First Response & Preservation