Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

U2F does NOT require a hardware key - only a secure cryptographic processor. It could be built into your laptop. There were some rumours floating around that Chromebooks would receive fingerprint scanner that would enable this. It would make sense since U2F originated from Google.

The W3C is working on the Web Authentication spec: https://www.w3.org/TR/webauthn/ with (among others) Google and Microsoft contributing. Wide support for this would be the endgame OP mentioned.



How is that "not hardware"? If you meant a separate physical key, I think that's actually a Good Thing: you can have it on you and it's tiny in features - reducing the likelihood it would get tampered with, unnoticed; one integrated into a laptop is a part of a huge blackbox that you just need to blindly trust.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: