This low-cost device may be the world’s best hope against account takeovers

Discussion in 'privacy technology' started by Minimalist, Dec 23, 2016.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    http://arstechnica.com/security/201...e-worlds-best-hope-against-account-takeovers/
     
  2. kronckew

    kronckew Registered Member

    Joined:
    Aug 27, 2006
    Posts:
    455
    Location:
    CSA Consulate, Glos., UK
    sadly u2f only works with chrome. i use thunderbird for my gmail, and occasionally firefox for webmail. dislike chrome passionately.
     
  3. deBoetie

    deBoetie Registered Member

    Joined:
    Aug 7, 2013
    Posts:
    1,832
    Location:
    UK
    It's dismal how glacial the progress has been with U2F - which reflects, in my opinion, the lack of sanctions against the website owners. Where they do offer 2FA, it's often on the basis of smartphone authentication which is terrible for privacy.

    U2F is relatively good from a privacy point of view (and as a cheap dongle), because it allows identity-per-site (which of course the site owners don't like because they want to back-end monetise you). That combined with no adequate liability means that they are not incentivised to offer U2F support.

    Here's a summary from 2 years ago, not a lot has changed.

    https://www.wilderssecurity.com/thr...on-first-look-with-google-and-yubikey.369913/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.