Chrome lets hackers phish even ‘Unphishable’ Yubikey users

Posted on Mar 3, 2018

Chrome lets hackers phish even ‘Unphishable’ Yubikey users

Two weeks ago, in a little-noticed presentation at the Offensive Con security conference in Berlin, security researchers Markus Vervier and Michele Orrù detailed a method that exploits a new and obscure feature of Google’s Chrome browser to potentially bypass the account protections of any victim using the Yubikey Neo, one of the most popular of the so-called Universal Two-Factor, or U2F, tokens that security experts recommend as the strongest form of protection against phishing attacks.

Source: wired.com