Unfortunately though, as with any phishing attack, this flaw is most likely to be effective against uninformed users, and those users are the least likely to take proactive measures to protect themselves beforehand.
Fortunately:
> "We will have a short term mitigation in place in the upcoming version of Chrome, and we're working closely with the FIDO Alliance to develop a longer-term solution as well."
I supposed you could trick them by saying that the login process has changed and they need to enable WebUSB to let their YubiKey work
https://www.yubico.com/about/reference-customers/department-...
There is an enormous need for some solution resistant to users who aren't good at identifying legitimate vs phishing sites. U2F as it stands is the only practical and deployed solution to that problem. It's infuriating that chrome broke this security promise to compete with microsoft.
This phishing attack removes the benefit that Yubikeys provided.
Sure a smart users can decline the permission prompt. But a smart user can also simply not enter their password into phishing pages.