Hacker News new | past | comments | ask | show | jobs | submit login

Honestly, I don't know why Apple don't implement U2F on the secure enclave (activated via the TouchId sensor); it seems like such an obvious move.

Maybe they're trying to get iCloud and Safari support all ready to release at-once?




Wow, great idea!

I think Web Authentication will slowly make U2F obsolete, in a sense that U2F will become one of many authentication methods, others could also be implemented. Checking WebAuth specs one can see references to Android attestation, TPM attestation so generally secure hardware elements. Implementing a U2F solution would require emulating USB exchange I guess.

Of course U2F still has an advantage that you can take your token and authenticate on a different device but unfortunately newer Yubikeys do not support U2F over NFC and there are not so many other solutions.


¡Hola 2018!




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: