|
|
|
|
|
by 3RTB297
10 days ago
|
|
My issue is that they're touted to the consumer as secure, and they're not really doing much more than a complex password. How do you generate a new key if you need one? Same process as a password reset. Does it prevent session stealers? Not at all. Its "benefit" is grandma can't read it to an attacker. OK, well can grandma click a link and have a session stealer bork her life instead? Yeah, and attackers know that and just shift methods. Session stealing isn't a sophisticated attack, and so all that's being done is shaving a cost on PW resets in the interest of shareholder value, at the cost of security theater and locking up your keys in a single domain that holds control over our access to everything. |
|