|
|
|
|
|
by RaisingSpear
807 days ago
|
|
> I don't think phishing is such an obscure scenario. For a typical person, maybe, but for a tech-minded individual who understands security, data entropy and what /dev/random is? And I don't see how MFA stops phishing - it can get you to enter a token like it can get you to enter a password. I'm also looking at this from the perspective of an individual, not a service provider, so the activities of the greater percentage of users is of little interest to me. |
|
That's why I qualified it with "certificate-based". The private key never leaves the device, ideally a yubikey-type device.