| ▲ | mwwaters 2 days ago | ||||||||||||||||
The far bigger benefit is phishing resistance (with hardware-contained keys themselves being phishing-proof on a non-compromised system). It moves to the account recovery flows, but that can be much more difficult to phish. | |||||||||||||||||
| ▲ | inigyou 2 days ago | parent [-] | ||||||||||||||||
Why would a key need to be "hardware-contained" to be difficult to phish? My SSH private key is unphishable and it's right there in a file. It's unphishable because I know there's never ever a reason to send it to someone - in a scenario where that would be needed, I'd generate a new key just for that situation. | |||||||||||||||||
| |||||||||||||||||