Hacker News new | ask | show | jobs
by snadal 1366 days ago
So if your device is compromised, the attacker could trick you into entering 2FA for some minor action while it actually is transferring all your funds.

If your PC or smartphone is compromised nothing will prevent you from losing control of your accounts.

2 comments

Which gives you more chance at detecting such an attack. Without 2fa, the funds are already gone.
That's kinda problem of many 2FA systems, my bank's send me the reason for 2FA and amount + last few digits of account if it is money transactions.
Yes, that is what I was trying to point out. With Yubikey or other 2FA devices you can not see the transaction details of what are you signing unless the device has a screen so a screenless device does not protect much more than this virtual yubikey.