3 ms·
Hardware keys are not great. You use a company laptop and they have disabled usb or set off an alarm when you plug something in. It should be based on phone h
by dpweb 9y ago
Hardware keys are not great.
You use a company laptop and they have disabled usb or set off an alarm when you plug something in.
It should be based on phone however, since thats the one thing everybody cant live without and usually have on them.
It would be nice to see goog and msft make their authenticator apps interoperable, or a global standard all svcs can use, as authenticator apps seem to be the best thing going.
- Rafert 9y agoU2F does NOT require a hardware key - only a secure cryptographic processor. It could be built into your laptop. There were some rumours floating around that Chromebooks would receive fingerprint scanner that would enable this. It would make sense since U2F originated from Google. The W3C is working on the Web Authentication spec: https://www.w3.org/TR/webauthn/ https://www.w3.org/TR/webauthn/ with (among others) Google and Microsoft contributing. Wide support for this would be the endgame OP mentioned.
- Piskvorrr 9y agoHow is that "not hardware"? If you meant a separate physical key, I think that's actually a Good Thing: you can have it on you and it's tiny in features - reducing the likelihood it would get tampered with, unnoticed; one integrated into a laptop is a part of a huge blackbox that you just need to blindly trust.