|
|
|
|
|
by mr_mitm
811 days ago
|
|
> And I don't see how MFA stops phishing - it can get you to enter a token like it can get you to enter a password. That's why I qualified it with "certificate-based". The private key never leaves the device, ideally a yubikey-type device. |
|
Except that phishing doesn't require the private key - it just needs to echo back the generated token. And even if that isn't possible, what stops it obtaining the session token that's sent back?