{
 "edition": "005",
 "date": "2026-08-06",
 "claim": "Security keys stop 100% of phishing.",
 "verdict": "Overstated",
 "score": 61,
 "components": [
  {
   "name": "Source quality",
   "score": 3,
   "note": "Rubric 0 to 4: peer reviewed at the 2019 World Wide Web Conference with New York University and UC San Diego, and the full text is openly available. The research is not the problem here."
  },
  {
   "name": "Sample and method",
   "score": 15,
   "note": "Rubric 15 to 17: the paper covers over 350,000 real hijacking attempts, but the security key cells carry margins of plus or minus 25 and 28 points, and the targeted-attack cell for security keys is not reported at all."
  },
  {
   "name": "Independence",
   "score": 15,
   "note": "Rubric 15 to 17: the publisher sells security keys and the paper names them as the best immediate solution for at-risk users. That is a direct interest in the conclusion, which is this band. Peer review and two university co-authors are why it sits at the bottom of it."
  },
  {
   "name": "Replication",
   "score": 12,
   "note": "Rubric 10 to 14: not independently reproduced. Supporting reports exist but come from companies describing their own deployments."
  },
  {
   "name": "Drift",
   "score": 16,
   "note": "Rubric 15 to 17: a hundred percent with a plus or minus 28 point margin becomes a flat hundred percent, and a cell the paper leaves empty becomes a claim about targeted phishing."
  }
 ],
 "call": "Within the window, at least one publicly disclosed account-takeover incident at an organization with a hardware security key deployment will be attributed by that organization or by a credible independent technical analysis to a non-key authentication path that was left enabled.",
 "resolves": "January 2027",
 "resolution_criteria": "Resolves HELD if, by January 31, 2027, at least one such incident is documented in a vendor disclosure, regulatory filing, or technical analysis by a named security research team, and the stated entry path is a non-key method such as SMS, a one-time code, a recovery flow, a help-desk reset, or an exempted account. Resolves MISSED if the only documented incidents in that window are attributed to a cryptographic or protocol defeat of the key itself. Resolves VOID if no qualifying incident is documented either way by that date.",
 "source": {
  "title": "Evaluating Login Challenges as a Defense Against Account Takeover",
  "publisher": "Proceedings of the 2019 World Wide Web Conference, ACM",
  "date": "May 2019",
  "url": "https://damonmccoy.com/papers/loginchallenges.pdf"
 },
 "scored_by": "Mark Lynd",
 "url": "https://thehypeindex.com/edition/005-security-keys-stop-100-percent-of-phishing/",
 "method": "https://thehypeindex.com/method/",
 "rubric_version": "v1.0",
 "rubric_effective": "July 26, 2026",
 "corrections": [
  {
   "date": "July 26, 2026",
   "text": "Source changed from the Google Security Blog post to the peer-reviewed WWW 2019 paper it summarizes, which is now linked in three places including an open full text. Source quality moved from 5 to 3 and Sample and method from 11 to 8 as a result, and the total moved from 52 to 47. The headline friction figure was changed to the paper's own 52% sign-in failure rate. The blog's 38% and 34% figures remain in the body, where they are now labelled as consumer measurements reported alongside the study rather than presented as enterprise numbers. SUPERSEDED by the July 26 rewrite below, which removed that section entirely. Left here because the policy is that nothing disappears.",
   "superseded": true
  },
  {
   "date": "July 26, 2026",
   "text": "Independence lowered from 11 to 8. The note argued the 5 to 9 band, which covers an indirect interest offset by independent co-authors and external review, while citing 10 to 14. The band now matches the reasoning. Total moved from 47 to 44. The verdict is unchanged at Half True."
  },
  {
   "date": "July 26, 2026",
   "text": "Substantially rewritten after reading the paper's Table 3 rather than the blog post summarizing it. The security key row reports 100% plus or minus 25 for bots and 100% plus or minus 28 for bulk phishing, and reports nothing at all for targeted attacks. Earlier versions of this edition repeated the blog's figures, including a recovery-phone line that does not match any row in the paper, and described a missing cell as a published zero with an unpublished denominator. Sample and method moved from 8 to 15, Independence from 8 to 15, and Drift from 13 to 16. Total moved from 44 to 61 and the verdict from Half True to Overstated. This is the most serious correction on the site and it was found by a reviewer checking our sources against the original, which is exactly the process we ask readers to run on us."
  },
  {
   "date": "July 26, 2026",
   "text": "Challenge C-007. Independence moved from 8 to 15. C-005 had lowered it to 8 on the reasoning that independent co-authors and peer review put it in the 5 to 9 band. That was wrong and we upheld it wrongly. Selling the remedy a finding recommends is the 15 to 17 band, and the rubric contains no mechanic by which co-authorship pulls a direct interest below it. Peer review is why this sits at the bottom of 15 to 17 rather than the top. C-005 is marked superseded in the challenge log."
  }
 ],
 "words": 725,
 "reading_minutes": 3,
 "published_web": "2026-07-26",
 "emailed": "2026-08-06"
}