Earlier quoted context omitted.
How does a U2F key even solve the problem of knowing that a website associates with a real identity? It may stop a phishing attack, but where do you get the initial trust to begin with? I think the issue is that we need to know that google.com can be shown to clearly be owned by Google, LLC, and not GoogleCo in a small African nation. (And also, presumably, that google.com is actually google.com, and not some weird s…
> I think the issue is that we need to know that google.com can be shown to clearly be owned by Google, LLC, and not GoogleCo in a small African nation. Google, LLC? Why not Google, Inc.? Wait, is it Alphabet, Inc.? Why do I trust companies from Palo Alto (or Delaware?) more than I trust companies from small African nations? I don't trust google.com because they're run by some Delaware corporation named "Alphabet." I…
And what about https://www.xn--80ak6aa92e.com/? How is the average user supposed to keep up with the latest and greatest ways to pretend to be someone else's URL? I mean, goog1e.com is likely to still be a reasonably effective deception to the average user. Should nobody ever click a link from anywhere, and solely find websites by memorizing the URLs and typing them in?