5 ms·
This is mostly against phishing. A phisher can get users to insert a token from a USB device or a text into evil.com. But U2F uses public key crypto, so your to
by bugmen0t 9y ago
This is mostly against phishing.
A phisher can get users to insert a token from a USB device or a text into evil.com.
But U2F uses public key crypto, so your token derived for evil.com is not the same as for github.com
- madamelic 9y agoAhhhh. That makes a lot more sense. Thank you.
- anfedorov 9y agoAlso, if your machine is compromised, your the cookies used to authenticate you post-login can be stolen just as well. RTFA.
- StavrosK 9y agoThis is a brilliant idea to use as a third factor. Instead of TOTP or the hardware U2F key, just create keys for all your browsers. That way, you're more protected against phishing, but still have a way to log in if you lose your keyfile.
- Emilie_ 9y agoBenjamin answered I'm in shock that some one can make $4929 in 1 month on the internet . ___________http://bit.do/dnRs5 http://bit.do/dnRs5
- Harmony_ 9y agoAre you boring your life for pocket money.if u don’t worry for your pocket money I share my home profit system to everyone.i enjoy my life because I using this easy online jobs and earning $25986 daily wovrk for only 3 hours a day online for doing thivs easiest online home jobz.for more details visit this link… ᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵᴵhttp://usawork.cn.to http://usawork.cn.to
- subway 9y agoMy knee jerk reaction was 'sounds an awful lot like a cookie', but maybe that's an indicator that the problem could be slightly generalized to offering a 'secure' version of localstorage.
- Harley454 9y agoI got paid $10438 last month by working online. Its an easy online job to do and earning is more and better than the regular office job. I have found this job six months ago and starts earning in my first month easily. Everybody can do this job from home by just follow this web. go to this site home media tech tab for more detail thank you . ►►►https://is.gd/qKRnJt https://is.gd/qKRnJt
- StavrosK 9y agoIt's almost like a cookie, yes, in that you could say "trust this browser". However, the problem comes when you ask for the second factor for a new computer. A TOTP approach would give the second factor to the phisher, whereas U2F does not. Come to think of it, I'm not sure that's a problem with the cookie and not with TOTP.