A friend has got a U2F device (forgot its name) which has six buttons that serves to enter a PIN and the PIN to authenticate and the PIN to register are different ones.
Or the Ledger Nano S hardware wallet (and probably the X too) have a U2F app (so the "older" standard only atm) but there it's even better: the device not only tells you if you're registering the key for the first time or authenticating but it also displays the name of the site you're authenticating to.
This is one notch above many other authenticating methods: it doesn't just protect the server versus malicious users, it also protects honest users logging into malicious servers/websites.