Hacker News new | ask | show | jobs
by Buge 3026 days ago
How would that help? Couldn't the webusb simply lie to the u2f device about what the channel is?
1 comments

Go take a look at token bound channels. It sure could but it'd be completely useless to do so.
I know a bit about token bound channels. But the u2f device only talks to Chrome via usb. So anything that the legitimate chrome could say to the u2f device (negotiating tokens, channels, etc) can now be done by the attacker via webusb. So I would think the attacker can get the u2f device's signature on the attacker's channel.

It should be just as if you unplugged your u2f device from your machine and plugged it into the attacker's machine.