3 ms·
Uh excuse me?? SQRL provides excellent anti-phishing protection. There are no reusable credentials across domains, and the domain can be displayed on your authe
by floatboth 9y ago
Uh excuse me?? SQRL provides excellent anti-phishing protection. There are no reusable credentials across domains, and the domain can be displayed on your authenticator.
https://www.grc.com/sqrl/phishing.htm https://www.grc.com/sqrl/phishing.htm
- nickik 9y agoCool, I did not see that. However, the limitation are there, FIDO goes further.
- hdhzy 9y agoDomain displayed is no real protection, actually its weakness is what drives phishing. But the link you provided contains some interesting info: > How SQRL changes things > When using SQRL, users do not identify and authenticate themselves with a username and password. Instead, their unique user identity is derived from their secret master key and the website's full domain name. So that's similar to what U2F does - domain name (origin) is part of the protocol.