Hacker News new | past | comments | ask | show | jobs | submit login

It's very easy to fall prey to an Evilginx or similar AITM phishing attack. Passkeys or TLS client certificates are the only guaranteed defense. Relying on the user noticing the different domain or the lack of autofill by the password manager, not so much.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: