Used Security Keys: The Device May Be Reset, But Can You Trust It?

Used Security Keys: It Looks New. That's the Problem.

Used Security Keys: It Looks New. That’s the Problem.

Aug 16, 2026

A security key is supposed to solve one of the oldest problems in digital security: trust. Instead of trusting a password that can be stolen, phished or reused, you authenticate with something you physically possess, usually a FIDO2 or U2F hardware key that uses cryptographic credentials rather than handing a secret to a website.

That creates an interesting paradox. The technology is designed to reduce the amount of trust you place in passwords, yet the moment you buy the physical device, you introduce another question: how much do you trust the device itself?

That is why the argument that you should never buy a used security key is too simplistic. A second-hand key is not automatically compromised, and in some circumstances a genuine, properly reset device can function perfectly well. The real issue is not simply whether somebody owned it before you. The issue is provenance.

The Previous Owner Is Not Necessarily the Threat

The first misconception is that buying a used FIDO security key is like buying a used hard drive containing somebody else’s passwords. It isn’t. FIDO2 credentials stored on supported YubiKeys can be removed through a FIDO2 reset, and Yubico states that the reset deletes the existing FIDO2 credentials and PIN. Its documentation also explains that passkeys and other FIDO2 credentials are removed from the device during the reset process. (Yubico Docs)

That means the previous owner’s credentials are not simply waiting inside the key for the next person to discover them. Once properly reset, the FIDO2 application can be returned to a state in which the new owner registers the device with their own accounts and creates their own credentials.

There is, however, a subtle distinction that matters enormously: resetting the credentials does not automatically establish the history or integrity of the physical device. You have solved one problem, but you have not necessarily answered the more interesting one.

  1. Who made this device?
  2. Where did it come from?
  3. Who handled it?
  4. And has anything happened to it before it reached you?
  5. That is where the story changes.

The Thing You Are Really Buying Is Provenance

When you purchase a genuine security key through a trusted supply chain, the trust relationship is relatively straightforward: manufacturer, controlled production, distribution, device, user. When you purchase a used or refurbished key from an unknown marketplace seller, you insert an unknown variable into that chain.

That does not mean the device has been compromised. It means you cannot confidently establish that it hasn’t been. FIDO itself recognises this problem. Its attestation documentation explains that authenticator attestation can provide verifiable evidence about an authenticator’s properties and can help defend against supply-chain attacks involving substitute or counterfeit authenticators.

That is an important detail because physical appearance proves very little. A device can say YubiKey on the casing, but that does not by itself prove that you received the genuine device you thought you purchased.

The deeper security question is therefore not, “Was this key used?” It is, “Can I establish enough confidence in what this key actually is?” That is a much harder question.

A Cheap Genuine Key Can Be Safer Than an Expensive Mystery Key

This is where price creates another psychological trap. People often assume that more expensive means more secure, while others assume that the cheapest device offering FIDO2 support must be the best value because the underlying protocol is secure.

Neither assumption is particularly useful. A relatively inexpensive security key from an established manufacturer can be attractive precisely because it performs a narrow function using a mature authentication standard. The price does not need to be high simply because the security is important.

The danger appears when cheap becomes synonymous with unknown. A $30 genuine security key from an established manufacturer and a $7 device from an unknown marketplace seller may look similar in a photograph, but they represent completely different trust models. FIDO’s certification and authenticator security requirements exist partly because security depends on more than the protocol itself; the manufacturing environment, handling of sensitive attestation material and protection against counterfeit devices also matter. (FIDO Alliance)

This is the part consumers often miss. Security is not just mathematics. It is mathematics plus provenance.

The Supply Chain Is Part of the Attack Surface

Most people imagine a hacker sitting somewhere behind a computer trying to steal credentials. That is only one part of the threat landscape.

FIDO’s security requirements specifically address the protection of authenticator manufacturing and the handling of attestation key material. The requirements even consider the possibility of counterfeit devices being introduced into a manufacturing environment and receiving legitimate attestation material. (FIDO Alliance)

That tells you something important about modern security.

The attack does not alwhttps://fidoalliance.org/specs/fido-security-requirements/fido-authenticator-security-requirements-v1.5.1-fd-20251016.htmlays begin after the product reaches the consumer.

Sometimes the interesting question is what happened before it arrived.

This is why supply-chain security has become such a significant part of cybersecurity. Software can be inspected, signed and updated, but physical devices also have histories, and those histories are rarely visible to the person opening the package.

A used security key therefore presents a peculiar asymmetry: the cryptographic system may be extremely strong, while your knowledge about the device’s history may be extremely weak.

That is where the risk lives.

The Paradox of the Reset

There is another fascinating distinction.

A proper FIDO2 reset is powerful because it destroys the credentials stored on the device. Yubico documents that resetting the FIDO2 application removes the PIN and credentials, after which the key must be registered again with the relevant services. (Yubico Docs)

But the reset does not magically transform an unknown device into a known device.

  1. It clears the past inside the credential system.
  2. It does not give you a complete history of the hardware.
  3. That distinction is easy to overlook because users naturally think in terms of data: If I wiped it, it’s clean.
  4. But hardware security is not merely about whether old data remains.
  5. It is also about whether the thing performing the cryptography is the thing you believe it is.

That is the enigma hiding underneath the apparently simple question of whether a used security key is safe.

So Should You Buy a Used Security Key?

For something protecting your primary financial accounts, email, password manager or other high-value identities, I would not make a used, unknown-provenance key the first choice when a genuine new key is affordable.

The reason is not that every used key is dangerous. The reason is that the potential saving is usually tiny compared with the value of the accounts being protected.

The calculation becomes even clearer when the price difference is small. Saving a few dollars while introducing uncertainty into the physical trust chain is a poor trade when the device may ultimately protect thousands of dollars, business credentials or your entire digital identity.

A used key from a known source is a different proposition from a random marketplace purchase. If the provenance is strong, the device is genuine, the supported applications can be reset appropriately and the device can be independently verified, the risk profile changes. But the less you know about the history, the less attractive the bargain becomes.

The Real Lesson Is Bigger Than YubiKey

The most important lesson has little to do with one manufacturer. It is about how people evaluate security. We tend to focus on the visible component: the password, the app, the security key, the encryption. We rarely examine the invisible chain underneath it, because invisible systems are psychologically difficult to value until something goes wrong.

That is precisely why supply-chain attacks are so interesting. The weakest point may not be the technology. It may be the assumption surrounding the technology.

A security key can dramatically reduce phishing risk and protect credentials with strong public-key cryptography, but none of that means you should blindly trust an unknown device simply because it supports FIDO2. The protocol can be sound while the provenance is questionable, just as a perfectly engineered lock becomes less reassuring when you have no idea who previously had the keys.

The best security decision is therefore not necessarily buy the most expensive key or never buy refurbished hardware.  It is simpler and more demanding: Know what you are trusting.

If you buy new from a reputable manufacturer or authorised channel, you are buying both a device and a clearer chain of trust. If you buy used, you are buying a device whose history becomes part of the security equation. And that is the part most people never calculate.  They think they are buying a key, but they should understand is that they are actually buying trust.

 

Thought-Provoking Reads