|
|
|
|
|
by necovek
1580 days ago
|
|
I think phishing is an entirely different matter. Any access is easily "phished" with pliable people (which is not necessarily a set of people, but also a question of timing and circumstances: everyone is sometimes more or less pliable): "please log in with your U2F device, download that document and upload it to this URL https://your-company-confidential.s3.amazonaws.myurl.com/, before we can reinstate your access to company systems". |
|
The advantage of U2F is that it isn’t phishable. You can only sign the message for the pre enrolled URL.
Yes, you can still fall for more elaborate instructions but you cannot simply give the attacker your credentials through a normal looking flow.