Hacker News new | ask | show | jobs
by grizzles 272 days ago
Seems perfect for a YubiKey type of device. Know where your authenticating to.
2 comments

Crypto hardware wallets have had little screens on them for ages now, for this same reason. Rather than trusting the app to tell you the truth about the tx it's presenting your key to sign, your key shows you the tx hash / amount to be transferred / etc, and asks you to make sure the details match before approving.
yubikeys already know who they are authenticating to. the relying party is verified as part of the FIDO2/CTAP2 protocol