4 ms·
Fully agree that a physical attack is much less likely. Also, the use of a PIN or fingerprint[1] to authenticate the yubikey itself and not sent over the netwo
by Ottolay 6y ago
Fully agree that a physical attack is much less likely.
Also, the use of a PIN or fingerprint[1] to authenticate the yubikey itself and not sent over the network, mitigates the stolen key scenario. [2]
[1] https://www.yubico.com/blog/getting-a-biometric-security-key-right/ https://www.yubico.com/blog/getting-a-biometric-security-key...
[2] https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Guide/FAQ.html https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Gu...