Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is true for all 2FA methods but not for FIDO security keys. With FIDO, the hostname of the site you're browsing is signed in the assertion, therefore the attacker -even with automation- can't reuse it on the target site.

This is why FIDO claims protection against phishing.

What the author says is that the attacker, when you're using a FIDO security key, can simply say it's not working and force the user to switch to a different 2FA method, therefore in the end phishing the user.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: