Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Malware running on your computer is a game-over scenario even with hardware tokens. The main difference here is that you'll need to revoke the device key after a compromise.

Password reuse and phishing are probably the most common threats users face. This addresses both with a (for most users) negligible security trade-off. If it increases U2F adoption, I'm all for it. I'd like to see U2F (or webauthn) become a browser/OS feature, backed by TPMs or things like TouchID, but this is a good first step.



Jinx :-)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: