|
|
|
|
|
by UncleMeat
1580 days ago
|
|
It isn’t a different matter. It is the core matter. Phishing and stuffing completely dominate the actual attack space. SIM swapping and other theft of SMS messages is tiny in comparison. The advantage of U2F is that it isn’t phishable. You can only sign the message for the pre enrolled URL. Yes, you can still fall for more elaborate instructions but you cannot simply give the attacker your credentials through a normal looking flow. |
|
I also disagree it's that far fetched to get people who'd do that to also do whatever else you want them to.
And while SMS swapping is miniscule in comparison, the big difference there is that there is no signal at all that you are under attack. With phishing, there is no way you are not feeling something is at least a bit off, so you know to check soon after, even if you've been compromised.