5 ms·
Just curious, what are the domain registrars currently support U2F? Also, just to be sure U2F is an additional methods of 2FA, not the only method of 2-step, s
by devy 8y ago
Just curious, what are the domain registrars currently support U2F?
Also, just to be sure U2F is an additional methods of 2FA, not the only method of 2-step, so to me having U2F is not necessarily making accessing your account securer.
- Jerry2 8y ago>Just curious, what are the domain registrars currently support U2F? Google, Amazon, Gandi (and some others I can't remember off the top of my head) support U2F. >having U2F is not necessarily making accessing your account securer. I don't agree with that at all. There are numerous cases of various 2FA methods being taken advantage of. No one has yet managed to crack U2F.
- regecks 8y agoI think devy means that you usually cannot add a U2F as the only second factor - you usually need to first add TOTP or phone number as backup. So, an attacker can just target the weaker factor and ignore U2F. I certainly had the same thought.
- AdamGibbins 8y agoThe prime thing U2F mitigates is phishing attacks. You literally cannot be phished with U2F, you try to auth against the wrong domain and you get a different secret - so they can't then pass that on the backend (i.e. the real site) and login as you. Sure your TOTP might remain, but you're not using it, so it's not liable to be taken.
- regecks 8y agoConstruct a phishing site that gives some vague error message about being unable to connect to your device, and offer the TOTP fallback. How many people will fall for it? "Literally cannot get phished" is woefully far away, because the phishing-resistant property of U2F has a giant hole in the side of it (fallback factors) and therefore still relies on human vigilance. I do use U2F though, because it is pretty convenient.
- regecks 8y agoNamecheap support U2F as well.