A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult'
IMHO, soft token u2f is only useful for testing, development, and personal entertainment
A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult'
IMHO, soft token u2f is only useful for testing, development, and personal entertainment
The soft U2F solution presented here still prompts you, but it is easier to imagine the software being modified/owned on a compromised machine than then hardware token being hacked in such a way as to hand over the keys without a physical press.
It also shows parts of the public key (or so I believe, it is a unique identifier) per website.
My bank, for example, has both your password entry and the private keys on the token. All you ever enter onto a computer or smartphone is the one time password, even when using their smartphone app.
I like my bank.
The best an attacker can do at that point is access whatever account-specific token that was 'intercepted', and use that until it expires on whatever site...which if implemented correctly won't let you make any major changes without your token press - aka, software-token just gave up your account, where hardware would have stopped it.
Github isn't too cheap to buy the token. The token they want to buy simply doesn't exist.
Yubikey 4C definitely does not qualify.
Password reuse and phishing are probably the most common threats users face. This addresses both with a (for most users) negligible security trade-off. If it increases U2F adoption, I'm all for it. I'd like to see U2F (or webauthn) become a browser/OS feature, backed by TPMs or things like TouchID, but this is a good first step.