3 ms·
Your example would be valid if U2F simulated a keyboard, but it doesn’t. The U2F key is a non-keyboard USB-HID device. The browser has special code embedded to
by LammyL 8y ago
Your example would be valid if U2F simulated a keyboard, but it doesn’t. The U2F key is a non-keyboard USB-HID device. The browser has special code embedded to identify and communicate with U2F keys using low level operating system USB api calls. The authentication process is a challenge response mechanism where the site challenges and the key signs and responds to the request. The browser adds an additional piece of information to the challenge and embeds the actual URL (and tls session id if supported) and the server verifies this additional information. Phishing and mitm are prevented because the server is validating the actual URL of their own site when checking the signed response. The whole process is really cool when you get into the details and is very well designed for security.