Safari Supports NFC, USB, and Lightning FIDO2-Compliant Security Keys in iOS 13.3 - MacRumors
Skip to Content

Safari Supports NFC, USB, and Lightning FIDO2-Compliant Security Keys in iOS 13.3

The iOS 13.3 update that is currently available to developers and public beta testers has a new Safari feature that supports NFC, USB, and Lightning FIDO2-compliant security keys.

This option was activated in the first beta of iOS 13.3, but in the second developer beta, Apple has added details about it in the release notes.

yubico1

Now supports NFC, USB, and Lightning FIDO2-compliant security keys in Safari, SFSafariViewController, and ASWebAuthenticationSession using the WebAuthn standard, on devices with the necessary hardware capabilities.

With the iOS 13.3 update, Safari will support physical security keys like the Lightning-equipped YubiKey, which can be used for more secure two-factor authentication.

Yubico announced the YubiKey 5Ci back in August, but at the time of launch, it was of limited usefulness because it did not work with Safari, Chrome, or other major browsers, though it was compatible with apps like 1Password.

With Safari support, the YubiKey 5Ci is a legitimately useful tool that can be more convenient than software-based two-factor authentication because there's no need to enter a security code -- you simply plug it in to an iPhone or Mac (there's also a USB-C connector) to authenticate. Support for FIDO2-compliant USB security keys using WebAuthn was previously added to Safari 13 in macOS.

Other NFC, USB, and Lightning-based security keys will also work with Safari following the iOS 13.3 update. There's no word yet on when iOS 13.3 will be released, but we may see it sometime in December after a few more weeks of beta testing.

Related Forum: iOS 13

Popular Stories

Apple TV Thumb 3

Everything Coming in the 2026 Apple TV 4K

Wednesday July 8, 2026 4:51 pm PDT by
The Apple TV 4K hasn't been updated since 2022, and it's due for a refresh. An update is planned for 2026, but Apple is likely going to wait to launch it after Siri AI launches in iOS 27. Design Apple TV design updates don't happen often, and that's not changing. The next Apple TV is going to have the same squircle shape as the current model, and it'll continue to be made from a black...
iphone 16 teal

'Siri AI' Lawsuit Update: Apple to Pay Owners of These iPhone Models

Thursday July 9, 2026 7:08 am PDT by
In May, Apple agreed to pay $250 million to settle a U.S. class action lawsuit over Siri AI's delayed launch, and eligible iPhone users could receive up to a $95 payout. This week, the California court overseeing the case held a hearing regarding preliminary approval of the settlement, but the judge has not yet issued a ruling. It will likely be at least a few more months before eligible...
iphone 16e usb c feature

Apple Begins Selling a $419 iPhone

Monday July 6, 2026 6:29 am PDT by
Apple recently added the iPhone 16e to its refurbished store, with U.S. pricing starting as low as $419 for a model with 128GB of storage. Originally released in February 2025, the iPhone 16e is a lower-end device with a 6.1-inch OLED display, an A18 chip with 8GB of RAM for Apple Intelligence support, a single 48-megapixel rear camera, a 12-megapixel front camera, a USB-C port, an Action...

Top Rated Comments

87 months ago

This is great news for the 8 people who will ever use this totally obscure feature.
Willing to bet you will eat these words by this time next year.

All our security standards are extremely weak and / or have been hacked so we need new ones desperately. 2FA is going to be the savior of doing anything wallet related on your computer.

The reason this is fantastic news is that it will allow mass adoption of way better, way more convenient, way more mass compatible security.
Score: 2 Votes (Like | Disagree)
FishyFish Avatar
87 months ago
I’m just loving this announcement. Nice job Apple!!
Score: 2 Votes (Like | Disagree)
87 months ago
"it has awesome security" -steve jobs
Score: 2 Votes (Like | Disagree)
87 months ago

FIDO is that wonky thing where where the site is what is actually storying your keypair, but with you having locally encrypted it so it can give it to you so you can decrypt it so you can use that to verify the public half of the keypair that the site is also keeping?

https://www.grc.com/sn/sn-445.htm

Should just do something sensible like SQRL, or really any other solution.
Seriously, Gibson is a hack and a charlatan, no one serious in the industry respects him. There were several sites that debunk what he spewed, but they just stopped being maintained over 15 years ago because there was already too much information. Gibson total made things up (Socketgate?).

U2F which FIDO2 is based off of is well reviewed, and now included in the W3C specification through WebAuthN.
Score: 1 Votes (Like | Disagree)
87 months ago

And notice how devoid of the usual comments ("about time!", "what could go wrong", "how about you fix your software, Tim.", "X dollars? that's insane!", "insert dad joke here") this thread is. People are more likely to complain about what they don't quite fully understand but not about what they know nothing about IMHO.
Hard to put a double standard on when you don't know what your supposed to hate about, I guess.
Score: 1 Votes (Like | Disagree)
robbysibrahim Avatar
87 months ago

This is great news for the 8 people who will ever use this totally obscure feature.
And notice how devoid of the usual comments ("about time!", "what could go wrong", "how about you fix your software, Tim.", "X dollars? that's insane!", "insert dad joke here") this thread is. People are more likely to complain about what they don't quite fully understand but not about what they know nothing about IMHO.
Score: 1 Votes (Like | Disagree)