Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you are not careful, you'll enter the random chains of characters into a phishing site.

But a phishing site can't steal your passkey and forward it to the real site, the passkey will just not work with the phishing site if you try using it there, it's locked to the authentic domain.



That's mumbo jumbo to me so far.

What's an authentic domain?

How is my passkey locked to it?


The domain that the verifier (the site trying to authenticate you) is at is part of the cryptographic process. If the domain doesn't match (ie you're at a phishing site) then the results of the cryptography won't be valid for the actual correct site, only the phishing site (which gets the phishing site nothing it can use).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: