4 ms·
Huh, so I'm stupid I guess, but how is MFA phish proof? Why did Kurt's commit access get revoked?
by 0xdeadbeefbabe 1y ago
Huh, so I'm stupid I guess, but how is MFA phish proof? Why did Kurt's commit access get revoked?
- tptacek 1y agoThe commit access thing is a joke. I think it's a joke. It's mostly a joke. MFA is not in general phish-resistant. But Passkeys, U2F, and FIDO2 generally are, because they mutually authenticate; they're not just "one time passwords" you type into a field, but rather a cryptographic protocol running between you and the site.
- 0xdeadbeefbabe 1y agoWell he must be punished somehow!