With the launch of iOS 16.3 and macOS 13.2 Ventura, Apple added Security Keys for the Apple ID, offering a more robust way to protect your Apple account and everything associated with your Apple account.

yubico 5c nfc
A Security Key is a physical device that works with two-factor authentication. Instead of using a code generated by a secondary Apple device for authentication, when you log into your ‌Apple ID‌ on another device after setting up Security Keys, you need to authenticate through a physical key that's actually plugged in to your device.

You can use any FIDO Certified security key to activate the feature, and Apple recommends the YubiKey 5C NFC and the YubiKey 5Ci, two devices sold by Yubico. Yubico sent me a pair of its security keys so that I could try them out with Apple's Security Key function.

yubikey close up
The YubiKey 5Ci has a USB-C connector and a Lightning connector so that it can be plugged into iPhones, iPads, Macs, and other devices that use these connectors, while the YubiKey 5C NFC has a USB-C connector and the ability to interface with NFC-enabled devices.

With Apple eliminating the Lightning port in the iPhone this year and because I don't own any devices without NFC, I opted for the YubiKey 5C NFC for futureproofing, but if you plan to have an ‌iPhone‌ or an iPad with a Lightning port for an extended period of time, the 5Ci might be the better option if you're interested in using Security Keys.

yubikey in hand size
Security Keys can be set up on the ‌iPhone‌, ‌iPad‌, or Mac. Note that whatever security key product you pick, you have to have two, not just one. Apple requires dual security keys for redundancy purposes, and Yubico recommends a pair as well. The reason for this is because if you lose your physical security key, if you don't have another in a safe place, you're going to lose access to your ‌Apple ID‌. You're going to want to store the Security Keys in two separate locations.

On an iOS device or Mac, Security Keys can be enabled through the Password and Security section of the Settings app. Before you can add a Security Key, you need to sign out of all inactive devices, which includes devices that you have not used in the last 90 days. Older devices won't support Security Keys at all.

I had to go through this process, and I want to note that it didn't quite work properly (which is not the YubiKey's fault). Apple's process signed me out of the unsupported devices or devices I had not logged into, but then the Security Keys setup would not progress. I swapped over to the Mac to continue, and had better luck.

yubico 5c nfc
The setup process required me to connect the security key, which I did using USB-C, and then I had to press on the key to get the Mac to recognize it. Apple had me give it a name, and then repeat the process to add the second security key.

mac security key setup
After that, I was instructed to review my list of active devices and choose whether to sign out of any of them. There was an option to stay signed in to everything, which is what I selected. Following the setup process, Apple instructed me to store the keys separately and in a safe place, and clarified that I can add additional keys in the future.

apple security keys added mac
There's also a single line on the bottom of the setup screen that makes it clear Apple has no way to help access an account that is tied to a security key if both keys are lost, a warning that should probably be in bolder text. Apple sends an email about the Security Key setup process, and in both Mac and iOS settings, I can view my connected Security Keys and remove them.

apple security key login process mac
When I attempt to sign into my ‌Apple ID‌ on a device on the Mac, I'm instructed to insert and activate one of my security keys. This process requires inserting the key into a USB-C port and pressing on it to activate it. I receive notifications across all of my devices when a login attempt is made.

security key login apple id
On an ‌iPhone‌, the login process is similar, but the YubiKey needs to be held near the ‌iPhone‌'s NFC reader (the top of the device) and activated for authentication. In general, it's a simple process on every Mac, ‌iPhone‌, and ‌iPad‌ I've tested it with. All of my devices are running iOS 16.3 or later or macOS Ventura 13.2 or later, and they all support USB-C or NFC. On devices that are not updated or do not support USB-C/NFC, the process might not be as seamless and could require adapters.

apple id login warning
My major worry activating Security Keys is that I'm going to lose one. YubiKeys and other security keys are small, unobtrusive, and easy to lose since they're designed to be kept secret and hidden. The YubiKey has a hole at the top for a keyring, so I'm going to add a keyring to one that will remain in a secure place in my office, and the second will go somewhere safer.

Two-factor authentication with a physical security key is more secure than authentication with a digital code, according to Apple, but it's a little riskier. I can't track my YubiKeys if they're lost, but I can track down all my secondary Apple devices if I should lose one and need it for a code. That said, the authentication process is super easy, and it's even quicker than getting a code from another Apple device.

yubikey authenticator app
YubiKeys don't need to charge and seem to be durable so far based on anecdotal reports from YubiKey users, which is good because I'm also worried about breaking one. Ultimately, I think I may add a third key to my account just for another layer of protection, since there's little chance I'll lose or break three at one time. There's an IP68 water resistance rating so it can hold up to liquid immersion, and it has a storage temperature of -4 °F to 185 °F.

You won't need an app to use a YubiKey for some services (like with an ‌Apple ID‌ or Twitter), but for others, the Yubico Authenticator will need to be installed. The Yubico Authenticator is like Google Authenticator or Authy, generating a code that uses the YubiKey.

twitter security keys
I was not able to set up the YubiKey with Instagram because Instagram's authentication process plus the Yubico app simply would not work. The app would not recognize the key, so be aware that there may be some troubleshooting involved. There are limitations with the YubiKey in terms of supported accounts. It can store up to 25 FIDO2 credentials for password-free logins, two OTP credentials, 32 OATH credentials for one-time passwords (when paired with the Yubico Authenticator), and an unlimited number of U2F credentials. If you have more than 32 accounts where you need one-time passwords, the YubiKey might not be the best solution because it only works with 32 logins.

yubikey front and back
In addition to an ‌Apple ID‌, the YubiKey works with other websites and services with two-factor authentication. Google, Microsoft, 1Password, LastPass, Facebook, Twitter, Instagram, bitcoin wallets, government accounts, and a bunch more are all supported.

Bottom Line

If you're aiming to better secure your ‌Apple ID‌ through physical authentication using the Security Keys feature, the YubiKey series is worth looking at. It offers better protection than you'll get through digital codes, but it is expensive and there are some limitations to be aware of if you want a multi-purpose physical authenticator.

How to Buy

The YubiKey 5C NFC that I used in this review is priced at $55, and it can be purchased from the Yubico website. The YubiKey 5Ci with Lightning connector and USB-C connector is priced at $75.

Top Rated Comments

timestride Avatar
17 months ago
Recently got on the YubiKey train and they work great. One thing that continues to be a disappointment regarding Apple is how easy it is change your Apple ID password. While the physical hardware key keeps other people from logging into your account, it does not actually protect changing your Apple ID password on your actual device. All you need is your pin, and frankly that is not enough. I wish they would require at least your full Apple ID password or a 2nd factor like a YubiKey in order to change.
Score: 15 Votes (Like | Disagree)
MNGR Avatar
17 months ago
Why not attach AirTags to the keys
Score: 14 Votes (Like | Disagree)
Hogswarts Avatar
17 months ago
I tried the same yubikeys and went back to the old way of Apple’s 2FA. I kept getting prompted for a security key that was stashed in another part of the house. I don’t want to carry—and guard—yet another device when I travel. iPhone failure on the road? You’re going to need a key with you to activate a replacement iPhone. I’m sure keys are the best choice for Apple to control access to its intellectual property, but for average users I wouldn’t recommend.
Score: 10 Votes (Like | Disagree)
Tune Avatar
17 months ago

Apple is trying to get rid of your wallet and keyring. These keys seem like a step backwards.
What is this stupid obsession apple users have with not wanting to carry stuff? You really want to get rid of all your physical things and trade it for software based crap so that way apple can come along a few years down the road and monetize your access with yet another subscription. You know they will try at some point too!
Score: 9 Votes (Like | Disagree)
ZZ9pluralZalpha Avatar
17 months ago

What is this stupid obsession apple users have with not wanting to carry stuff? You really want to get rid of all your physical things and trade it for software based crap so that way apple can come along a few years down the road and monetize your access with yet another subscription. You know they will try at some point too!
Even setting aside the apparent preference for a George Costanza wallet, an iPhone or Apple Watch is a multi-purpose device that is locked with biometric authentication or wrist monitoring (with a very strong passcode) and can be remotely disabled or wiped if lost or stolen. A Yubikey is an additional item that does not have any built-in protection against use by unauthorized parties, visually announces that it is a key guarding something valuable, and is still dependent on software/services which could decide to introduce usage fees. In my view, having my existing devices act as 2FA for each other still wins out over adding a Yubikey to the mix, just as having my password manager app generate time-dependent passcodes is preferable to bringing back the old SecurID keychain fobs.
Score: 9 Votes (Like | Disagree)
Cristim74 Avatar
17 months ago

I had been considering getting a couple of these, but didn’t realise that they only work on the very latest macOS. I still have a 2025 12” MacBook that I use occasionally.
You have the future 2025 12" MacBook? :)
Score: 8 Votes (Like | Disagree)

Popular Stories

iPhone 15 Pro Cameras

iPhone 17 Pro Max Will Be First Model to Feature Three 48MP Cameras

Thursday July 11, 2024 12:20 am PDT by
Next year's iPhone 17 Pro Max will feature an upgraded 48-megapixel Tetraprism camera for enhanced photo quality and zoom functionality, according to Apple analyst Ming-Chi Kuo. In his n-iphone-tetraprism-upgrade-ca62dd37e364">latest investor note published to Medium, Kuo said the key specification change would be a 1/2.6" 48MP CIS sensor, up from the 1/3.1" 12MP sensor expected to be used...
Beyond iPhone 13 Better Blue Face ID Single Camera Hole

10 Reasons to Wait for Next Year's iPhone 17

Monday July 8, 2024 5:00 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different – already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
maxresdefault

Apple's AirPods Pro 2 vs. Samsung's Galaxy Buds3 Pro

Saturday July 13, 2024 8:00 am PDT by
Samsung this week introduced its latest earbuds, the Galaxy Buds3 Pro, which look quite a bit like Apple's AirPods Pro 2. Given the similarities, we thought we'd compare Samsung's new earbuds to the AirPods Pro. Subscribe to the MacRumors YouTube channel for more videos. Design wise, you could potentially mistake Samsung's Galaxy Buds3 Pro for the AirPods Pro. The Buds3 Pro have the same...
primeday2020 feature3

The Best Early Prime Day Deals on Apple Products

Saturday July 13, 2024 6:23 am PDT by
Amazon is soon to be back with its annual summertime Prime Day event, lasting for just two days from July 16-17. As it does every year, Prime Day offers shoppers a huge selection of deals across Amazon's storefront, and there are already many deals you can get on sale ahead of the event. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...