Hacker News new | ask | show | jobs
by thekeyper 1773 days ago
That's a similar concept, though despite their claims of unphishability, it is phishable, since the QR code is portable, and that is the only item that the authenticating device reads. The contents of the QR code simply don't matter as long as it's portable (it always will be) and is the only item that the authenticator reads. Keyri reads stuff other than the QR code.
1 comments

It's unphishable because the keys used for each domain are different.