3 ms·It also seems that would help with not giving out passwords to spoofing sitesby cjwhite 9y agoIt also seems that would help with not giving out passwords to spoofing sitesStavrosK 9y agoThe spoofing site could just pretend your U2F was valid and get your password, although it couldn't really do anything with it anyway.u801e 9y agoThe spoofing site wouldn't/shouldn't be able to pass the browser validation of the TLS server side certificate.StavrosK 9y agoWhy not? How hard is it to get a cert for a domain that looks like paypal-businesscenter.com?cjwhite 9y agoMoreover, the browser could remember the expected shared secret based on its and the server's RSA exchange.