Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.


One login is enough to authorize an Oauth app.


Require second login to transfer chrome apps to alternate account + 24 hour timer on transfer that sends an email to recovery email/everyone else relevant when extension is transferring.


That still allows them to log in though.


SMS and TOTP (Google Authenticator) can both be phished.

U2F cannot be phished.


Can't it?

What if I control the user's computer and can let my own code interact with U2F? Or does the protocol somehow prevent that?


If you control the user's computer, that isn't phishing. That's keylogging/credential theft.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: