4 ms·
That's why yubikey is important - it does it's own verification of the site. You can't MITM it.
by ryanobjc 10y ago
That's why yubikey is important - it does it's own verification of the site. You can't MITM it.
- wfunction 10y agoDid not know! Thanks for mentioning!
- mackmgg 10y agoNewer Yubikeys support U2F, which I haven't seen any way to phish yet, but the Yubikey protocol is still possible to phish. To do this, the fake login page says that the token was incorrect the first time (which would possibly alert some people, but certainly not everyone), and then when the user submits a second token, the phishing site sends the first one to the real site. They now have an unused token which can be used up until the user logs into another website (thus invalidating the 'unused' one).