At CCPCREPAIR in Tahlequah we clean a lot of malware that started with a convincing fake login page. The user typed a password into the wrong site. Multi-factor authentication helps - unless the second factor is a text message a SIM-swap or mail-forward can intercept. Hardware security keys (FIDO2 / WebAuthn) change the game: the browser proves you have a registered authenticator that only answers the real domain. Phishing sites cannot complete that handshake.
What a hardware key actually is
It is a small USB (and often NFC) device that holds cryptographic credentials. When a site or app supports passkeys / security keys, your computer asks the key to sign a challenge. You touch the key (and may enter a PIN). No shared secret is sent across the wire the way a password is. That is why FIDO2 is called phishing-resistant when implemented correctly.
Why we use Swissbit iShield Key 2
CCPCREPAIR works with Swissbit under a B2B arrangement for the iShield Key 2 series - industrial-grade FIDO2 authenticators, not novelty tokens. We recommend what we run: durable hardware, FIDO-certified flows, and a clear model identity for organizations that want to allow-list only company-issued devices.
Model AAGUID: 7787a482-13e8-4784-8a06-c7ed49a7aaf4 - the Authenticator Attestation Globally Unique Identifier for this iShield Key 2 class. Relying parties can use it to accept only that model family when enterprise attestation is enabled. It is not your personal serial number; it identifies the authenticator type.
What we set up for customers
- Owner / admin accounts - Microsoft 365, Google Workspace, Apple ID where supported, password managers, domain registrars, hosting panels.
- Staff keys - who holds which key, spare keys in a sealed process, offboarding when someone leaves.
- Recovery design - lost-key procedures before you need them; backup keys registered while things are calm.
- Complementary hardening - malware cleanup, unique passwords, and removing SMS as the only second factor on high-value accounts.
What hardware keys do not replace
They do not fix a dead hard drive. They do not stop ransomware that already runs as you after you approved a bad installer. They shine at the identity layer: keeping attackers who stole a password from walking into the account. Pair them with backups (backup basics) and sane software habits (malware signs).
DIY first steps (safe)
- List accounts that would ruin your week if hijacked (email first - it resets everything else).
- Prefer services that list “security key” or “passkey” under 2-step verification.
- Register two keys when you can (primary + backup in a separate place).
- Store recovery codes offline; do not screenshot them into cloud photos only.
- Stop when an employer portal needs admin policy or attestation - that is a shop job.
When to book CCPCREPAIR
Book a security scope if you want keys issued and enrolled correctly, staff trained in five minutes of real workflow, Microsoft/Google admin policies tightened, or an allow-list of Swissbit iShield Key 2 devices only. Pricing is quoted per environment; residential labor rates apply to simple enrollments, business rates to multi-user and policy work. Start on the contact form - list the platforms (e.g. “M365 admin + bank + 1Password”).
← All guides · Services: Swissbit path · About the partnership