What kind of uniformed user uses a YubiKey?
I supposed you could trick them by saying that the login process has changed and they need to enable WebUSB to let their YubiKey work
I supposed you could trick them by saying that the login process has changed and they need to enable WebUSB to let their YubiKey work
https://www.yubico.com/about/reference-customers/department-...
This phishing attack removes the benefit that Yubikeys provided.
Sure a smart users can decline the permission prompt. But a smart user can also simply not enter their password into phishing pages.
There is an enormous need for some solution resistant to users who aren't good at identifying legitimate vs phishing sites. U2F as it stands is the only practical and deployed solution to that problem. It's infuriating that chrome broke this security promise to compete with microsoft.