> Sigh... totally agree. I could add a longer story why just this account had no 2FA enabled, but the lesson learned is simple: From now on, we enable 2FA for every account that offers it.
So they won't make this mistake again.
This whole 2FA thing has been really jarring for me, because I always treated my phone like a public space: no password, no private data (that I know of), ready for inspection by foreign authorities. Of all the things the world could ask me to trust, why the phone?
[1] https://en.wikipedia.org/wiki/Security_token#/media/File:Cry...
Because it's the only instance of a computer that you can expect majority of users to own and always have on them.
2FA as a thing would not get any reasonable adoption if you required people to buy hardware keys to use it. Not to mention, hardware keys do not work on every device one would like to log in from (AFAIK you can't plug in a Yubikey to an Android tablet, and it may not have NFC built in).
Using an USB OTG adapter, it should be possible. However, even the flagship tablets of Samsung don't carry NFC, only the phones do - and even there it's a hit and miss if you have NFC.
Apple, on the other hand, doesn't have developer-accessible NFC anywhere.
This is a real shame.
U2F cannot be phished.
What if I control the user's computer and can let my own code interact with U2F? Or does the protocol somehow prevent that?