Dark | Light
[GUEST ACCESS MODE: Data is scrambled or limited to provide examples. Make requests using your API key to unlock full data. Check https://lunarcrush.ai/auth for authentication information.]

![TheHackersNews Avatar](https://lunarcrush.com/gi/w:24/cr:twitter::209811713.png) The Hacker News [@TheHackersNews](/creator/twitter/TheHackersNews) on x 926.7K followers
Created: 2025-07-21 07:04:59 UTC

Just to clarify: this attack doesn’t work everywhere β€” here's when you're safe πŸ‘‡

The phishing trick targets cross-device sign-in flows without strict proximity checks (like Bluetooth or local attestation).

If your org enforces:
βœ… Hardware keys plugged into the login device
βœ… Platform-bound authenticators (e.g. Face ID in browser)

...then the attack fails.

Why? Because those setups prevent remote QR code hijacking.

Bottom line: phishing-resistant auth still works β€” if deployed right.


XXXXXX engagements

![Engagements Line Chart](https://lunarcrush.com/gi/w:600/p:tweet::1947191054341714311/c:line.svg)

**Related Topics**
[login](/topic/login)

[Post Link](https://x.com/TheHackersNews/status/1947191054341714311)

[GUEST ACCESS MODE: Data is scrambled or limited to provide examples. Make requests using your API key to unlock full data. Check https://lunarcrush.ai/auth for authentication information.]

TheHackersNews Avatar The Hacker News @TheHackersNews on x 926.7K followers Created: 2025-07-21 07:04:59 UTC

Just to clarify: this attack doesn’t work everywhere β€” here's when you're safe πŸ‘‡

The phishing trick targets cross-device sign-in flows without strict proximity checks (like Bluetooth or local attestation).

If your org enforces: βœ… Hardware keys plugged into the login device βœ… Platform-bound authenticators (e.g. Face ID in browser)

...then the attack fails.

Why? Because those setups prevent remote QR code hijacking.

Bottom line: phishing-resistant auth still works β€” if deployed right.

XXXXXX engagements

Engagements Line Chart

Related Topics login

Post Link

post/tweet::1947191054341714311
/post/tweet::1947191054341714311