Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Secure enclaves as a second factor break the assumptions of 2FA threat models. If I compromise a single factor (your device) then I can gain both your password and your second factor.

The best second factors are separate devices with their own screens that indicate what you are authenticating to/for before you provide your authentication.

Of course, nothing ever stops a user from deputizing malware.



I guess I'm not seeing the difference between the secure enclave in a phone and the secure chip in a Yubikey in regards to threat models.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: