On Wed, 2022-09-14 at 02:46 -0400, Demi Marie Obenour wrote: > Because FIDO2 is not phishable. TOTP and HOTP are. The only other > non-phishable authentication method is TLS client certificates and > I would be fine with those. I'm not entirely convinced. See this paper: https://eprint.iacr.org/2020/1298.pdf _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue