Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I want warn people about U2F.

U2F is only an authentication tool, not security/encryption one.

If you have your smartphone/browser/pc pwned, you are even more screwed than with offline key table/token.

For something truly security critical, you need security against MITM on your own device, which only leaves smartcards as an option.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: