|
|
|
|
|
by tomfitz
3220 days ago
|
|
U2F keys are linked to the associated domain (e.g. google.com or dropbox.com), so your U2F would not present your google.com key to a U2F prompt on googlehax.com This stops the proxy attack you describe getting a session key, but not getting your password. Of course, the password alone is insufficient. |
|
In what sense are the keys linked? I'm assuming it requires the browser to pass the actual domain requesting the auth?