logoalt Hacker News

mwwaterstoday at 12:44 AM1 replyview on HN

The far bigger benefit is phishing resistance (with hardware-contained keys themselves being phishing-proof on a non-compromised system).

It moves to the account recovery flows, but that can be much more difficult to phish.


Replies

inigyoutoday at 2:41 AM

Why would a key need to be "hardware-contained" to be difficult to phish? My SSH private key is unphishable and it's right there in a file. It's unphishable because I know there's never ever a reason to send it to someone - in a scenario where that would be needed, I'd generate a new key just for that situation.