Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not if the phising site asks for the 2FA token.


The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.


One login is enough to authorize an Oauth app.


Require second login to transfer chrome apps to alternate account + 24 hour timer on transfer that sends an email to recovery email/everyone else relevant when extension is transferring.


That still allows them to log in though.


SMS and TOTP (Google Authenticator) can both be phished.

U2F cannot be phished.


Can't it?

What if I control the user's computer and can let my own code interact with U2F? Or does the protocol somehow prevent that?


If you control the user's computer, that isn't phishing. That's keylogging/credential theft.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: