Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When I said "auto-fill", I was referring to auto-fill with a browser extension where the website is checked. Yes, the FIDO method is even nicer from a technical perspective, but from a security perspective they are similar.

But of course, you can be phished into copying your password into a phishing site. So there are benefits, but it's not a huge difference in this one specific context (no physical token, using a password manager with a browser-extension-based auto-fill).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: