Skip to content

Comment on You don’t need SMS-2FAparent

Comments

Web sites can all just do WebAuthn. The browser will securely manage the relationship between each site and the USB key ensuring that sites can't lie to the key about who they are (which would enable phishing).

If you are happy to use this only as a second factor, the USB key can handle any number of sites without constraint. If you want "resident credentials" where the USB key can sign you in spontaneously (no need to even enter a username or email address) the key needs storage for each such credential, those on the market today hold only a relatively small number, fine for your bank but not for say Hacker News and other forum sites you might join dozens of.

For other application software it's trickier but possible, you can see that OpenSSH did this for example.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.