FIDO2 passkeys and hardware keys: the practical Australian adoption guide
FIDO2 passkeys and hardware keys: the practical Australian adoption guide
In October 2026, the security conversation in Australia has settled into a familiar rhythm: monthly breach roundups, credential stuffing against super funds, and a national crackdown on SIM swapping. Each of these incidents shares one root cause — authentication that depends on a secret somebody can phish, replay, or transfer. FIDO2 authentication, whether as a sync-based passkey or a physical hardware key, removes that dependency class entirely. It is the single most practical security and privacy upgrade an Australian account holder can make this year, and this guide covers what it is, where it matters most, and how to adopt it without locking yourself out.
The problem FIDO2 solves
Phishing-resistant authentication works because the private key never leaves your device and the challenge is bound to the real origin of the website. A fake login page cannot complete the FIDO2 handshake even if it perfectly clones the real one, because the browser refuses to serve credentials to an origin that does not match. There is no code for a user to mistype, no OTP for an attacker to intercept mid-flow, and no shared secret stored on a server that a breach can leak.
That last point is where the Australian context gets sharp. The ACCC's Scamwatch statistics on remote access and phishing scams run to hundreds of millions of dollars in reported losses annually, and the ACSC's Annual Cyber Threat Report documents tens of thousands of incidents where a single credential or OTP was the entry point. Our own super funds credential-stuffing analysis covered why stored-password databases keep fuelling these attacks: the stored password is the attack surface, and every measure that reduces reliance on a stored secret shrinks it.
SMS-based MFA, the default most Australian banks and telcos still offer, addresses some of this but has a well-documented weakness: the code rides the same phone number an attacker can hijack. The ACMA's SIM-swap rules that came into effect in 2026 are a genuine improvement in telco-level checks — mandatory identity verification, swap cooling-off periods, and port-out protections — but they are a telco control, not an account control. They reduce the frequency of successful SIM swaps; they do not change the fact that your bank's security still transits the phone network.
FIDO2 changes the fact. The credential is generated on your device, bound to your device, and never transmitted in a form that transfers.
Passkeys versus hardware keys: two forms of the same idea
The FIDO2 standard supports two delivery models, and choosing between them matters for adoption:
Sync-based passkeys are credentials generated on your phone or computer and synced through your Apple, Google, or password-manager account. They are convenient — sign in to any device with the same account and the credential follows — and they cover the long tail of everyday accounts: retail, streaming, loyalty programs. They also depend on the integrity of the sync provider's account, which for most people means their Apple ID or Google account, and those accounts need their own strong protection (a strong password plus a hardware key, ideally).
Hardware security keys are physical USB or NFC devices that hold FIDO2 credentials in a secure element that cannot be exported. They work across all your devices — plug into a laptop, tap against a phone — and they require nothing else to function: no account with a specific vendor, no network connection, no reliance on a sync provider's goodwill. This is the model used by people who protect accounts whose compromise would be catastrophic: email, password managers, financial accounts, and domain registrar access. As the FIDO Alliance's own guidance on choosing security keys makes clear, hardware keys are the highest-assurance form of the standard.
Both forms are FIDO2. Both are phishing-resistant. The distinction is convenience versus independence, and the right answer for most people is both: hardware keys for the accounts that anchor everything else, passkeys for the rest.
Which accounts need hardware keys first
Adoption works best in priority order, not all-at-once order. Start at the top of this list and work down:
- Your primary email. Everything password-reset flows through email. A hardware key on your email account is the single highest-value FIDO2 enrolment, because it makes password-reset attacks — the mechanism behind most account takeovers — structurally impossible.
- Your password manager. If you use one, it holds the credentials to everything else, and its own master account should sit behind a hardware key.
- Financial accounts. Banks, brokers, super funds. Every credential-stuffing wave we have covered targets exactly these, and hardware keys shut them out.
- Your Apple ID or Google account — the sync provider behind your passkeys. If this account is compromised, the attacker gains access to every synced passkey.
- Registrar and domain accounts — the accounts that control your domain's DNS, and with it your email's mail flow. Low traffic, enormous consequence.
- Everything else. Retail, streaming, loyalty. Sync-based passkeys are convenient here and adequate.
A single FIDO2 hardware security key enrols in all of the above and costs about the same as a night out. Pair it with an RFID-blocking card wallet for the contactless cards that still ride the older 13.56 MHz infrastructure, and your day-to-day credential surface shrinks to almost nothing. Two keys — one primary, one backup stored separately — is the standard, because a lost key without an enrolment fallback is how lockouts happen.
The adoption workflow, without lockouts
The failure mode people fear is locking themselves out of their own email. It is preventable with a short checklist:
- Enrol two keys on every critical account before removing any other MFA method. Keep the backup key somewhere physically separate — a different building, a safe deposit box, a trusted relative's house.
- Keep at least one recovery path. Most services let you keep backup codes or a secondary recovery method alongside hardware keys. Print them, store them, and treat them like the keys themselves.
- Test the backup key by actually signing in with it, not by checking that it is registered. Enrolment and function are different things, and the night you need it is not the night to discover a dead NFC reader.
- Enrol before you need it. Set a calendar reminder for each critical account; the workflow takes five minutes per service once the keys are in hand.
For passkey sync accounts, the same discipline applies to the sync provider: your Apple ID or Google account should have its own hardware key, its own strong password, and its own recovery codes before you entrust it with the rest of your credentials.
What this does not fix
Honest limits, because a guide without them is marketing: hardware keys do not help if an attacker compromises your device while you are using it (session hijacking, malicious browser extensions), they do not protect accounts that simply do not offer FIDO2, and they do not stop social engineering that convinces you to authorise something you should not. They also require services to support the standard — a limitation that has narrowed significantly over the last two years, with major Australian banks and services now offering passkey or hardware-key support as the ACSC's passkey guidance documents.
But the core attack classes — phishing a fake login page, replaying an intercepted OTP, breaching a stored-password database — are all defeated by origin-bound, non-exportable credentials. That is not a partial improvement; it is a structural removal of the mechanism behind the majority of account-takeover incidents Australia has seen this decade.
The bottom line
A pair of FIDO2 hardware keys, backing a password manager and your primary email, with sync-based passkeys covering the everyday accounts, is roughly two hours of configuration and the strongest practical authentication posture available to an individual in Australia. It is not exotic. It is not expensive. And unlike most of the security measures we recommend, it is a one-time setup whose benefits compound for years — every phishing wave, every breach roundup, every credential-stuffing campaign in the news simply does not apply to you.
This article is general security information, not legal advice.