back

by anderspitman·7y ago·view on hn ↗
I agree, but maybe encourage a U2F key option instead. I really like the idea of completely removing the possibility of password phishing.
1 comments
Relying on a U2F key alone is single factor authentication. If a user is going through the very real/significant effort of using a U2F key, they presumably want/need real two factor authentication. That requires two forms of authentication, generally something you know (a password) and something you have (a key).