Hacker News new | past | comments | ask | show | jobs | submit login

Allowing access to FIDO U2F devices via this would fundamentally break the security model of U2F. It relies on websites being forced to go through a U2F-specific layer in the browser that ensures websites can only request authentication to that site. Without that, any website could do a forwarding attack where it forwarded the authentication request from any other website to the device and used the response to authenticate as you. In order for this to be used for a second factor, you'd basically have a separate authentication dongle for every website.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: