Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Passkeys or FIDO hardware tokens are the solution, as written up by Google ages ago, because they only enter the TOTP code when the URL matches the right site, it wouldn't enter the code for the phishing URL


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: