U2F-enabled Security Key, such as the YubiKey, user login is bound to the origin, meaning that only the real site can authenticate with the key. The authentication will fail on the fake site even if the user was fooled into thinking it was real. This greatly mitigates against the increasing volume and sophistication of phishing attacks and stops account takeovers.
Standard https://www.yubico.com/authentication-standards/fido-u2f-standard/
Please authenticate to join the conversation.
Feature Requests
5 months ago

William K Santiago
Get notified by email when there are changes.
Feature Requests
5 months ago

William K Santiago
Get notified by email when there are changes.