Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

OTP based 2FA is susceptible to phishing and MITM attacks. U2F is phish-proof and makes MITM more difficult.

For computers you frequently use, you can get multiple keys and leave them in the port (Yubico makes a small one that stays in the port and only sticks out enough for you to be able to touch it, but it's a bit pricey).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: