Say you click on a link that looks like Google but it's not. You enter your credentials -> these are now in possession of the attacker. If you have 2FA enabled AND you use a security key, the key digitally signs the hostname of the site you're browsing. This second factor won't be valid on the real google.com site because it was created on the phishing site.
Phishing protection is a core feature unique to security keys, and it's completely independent whether you keep the key in your laptop or you bring it with you.
How does this work? Does the browser talk with the key? I thought the key is primarily an input device.
https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-cl...
At the extreme case, when you're asked to sign in with a Security Key you could have an authenticator with dedicated flash storage, screen and fingerprint reader so it can display like:
"Site news.ycombinator.com is prompting you to authenticate as blueblisters [484D2A8BBF] blueblisters@example.com - You last used this credential 16 hours 41 minutes ago. Touch the fingerprint reader to continue"
But in the real world the cheapest options have zero flash, zero display, just a push button and an LED. The LED flashes to indicate that you're being asked to press the button, your pressing it means you signify that you're present. All the data is still sent to them, but they can't display it, you have to trust your browser to validate what was sent.
This means it's unsafe to "press the button" when plugged into a general purpose computer unless prompted by an application you trust with your credentials, like a web browser you're using to sign in to sites
If the authenticator has no storage it can only really act as a Second Factor this way. But a device with storage can replace all steps of logging in if you want. No need to enter a password, an email address, anything, just one tap to get in. Apple is promoting this for the new iOS. A current Yubikey does have storage, and so it can do this, but the storage is very limited, unlike an iPhone with gigabytes of Flash memory.
Browser and security keys implement one side of the protocol called CTAP (client to authenticator protocol).
Then, browsers expose WebAuthn to web developers that can interact with security keys (create credentials, make assertions = signatures, ...).
I have a second one on my keychain.
I would highly recommend to have two keys: one for backup one for daily use.
In situations where laptop is not under your control, you can remove it.