Hacker News new | ask | show | jobs
by mike-cardwell 3447 days ago
Yes. With U2F the recipient of the token is verified by a machine. With TOTP/HOTP it is verified by the user looking at the browser address bar.