Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Huh, so I'm stupid I guess, but how is MFA phish proof? Why did Kurt's commit access get revoked?


The commit access thing is a joke. I think it's a joke. It's mostly a joke.

MFA is not in general phish-resistant. But Passkeys, U2F, and FIDO2 generally are, because they mutually authenticate; they're not just "one time passwords" you type into a field, but rather a cryptographic protocol running between you and the site.


Well he must be punished somehow!




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: