|
|
|
|
|
by spydum
3444 days ago
|
|
Incorrect: U2F would prevent this, but simple 2FA challenge could simply be displayed at the next screen of the form, and once you submit, the malicious server could immediately use the token you provide.
U2F does mutual auth of the u2f service, so it should fail. |
|
2FA is a great way to know when you have to look at all the data to decide wether or not to give the token. For instance, I always double check the URL when I'm about to hand out a 2FA code.