Live data from Hacker News

Google Titan Security Key

cloud.google.com

21–30 of 36 posts

Re: Google Titan Security Key

#21

The thing that makes me a bit jumpy about hardware 2FA with things like this or a Yubikey is around what happens if I lose it or it breaks. It's not so much a problem in a corporate setup (like internally at Google) where you could go to a central admin team to revoke/replace the key. But if you're a home user using this for a wide variety of sites and the token fails then the failure mode seems to be "go figure out…

See https://twofactorauth.org/ . I thought there was an ongoing effort to add backup/restore steps to this informative site.

Indeed, I was recently locked out of some of my accounts: I used some "one-shot backup codes", but some sites didn't deliver them (and so, required involvment of admin/support by mail+phone).

Re: Google Titan Security Key

#22
post #14
post #8

Why Google 'sell' this as an advantage over 2FA over mobile phone? In this case it works on computer only, or you have to be at some computer, with mobile app, you can be anywhere? I see that as huge disadvantage.

Security tokens are more secure and can't be as easily fished as phone-based 2FA solutions. It's not about using the key on a mobile phone, it's about replacing phone-based 2FA. You're right however that their key doesn't seem to have any interface other than USB so it won't be practically usable on smartphones. Yubico has NFC tokens[1] for that use case but it doesn't seem that Google's version offers that yet. [1]…

The page Using Security Key links to mentions that Titan supports Bluetooth & USB, with NFC support in a future update.

https://support.google.com/accounts/answer/6103523

Re: Google Titan Security Key

#23
Quite neat. Though I'm still dissapointed in the U2F/Security Key market.

The Yubico's cost 50€ the piece or 20€ for the U2F key only. And to get NFC usage you have to buy a worse variant of the other keys that doesn't support 4096bit RSA and some other features.

There is not much competition either, Nitro is just as expensive and doesn't feature a good and cheap key either.

Open Source variants are also fairly rare, I would love to DIY some Yubikey 4-like stick with the same or similar/comparable function set. Only thing so far I found is the U2F zero but that didn't offer RSA.

Quite annoying, maybe some competitor other than Yubikey and Nitro can solve this. (It doesn't seem Google is selling the Titan, I see no pricetag)

Re: Google Titan Security Key

#24
post #8

Why Google 'sell' this as an advantage over 2FA over mobile phone? In this case it works on computer only, or you have to be at some computer, with mobile app, you can be anywhere? I see that as huge disadvantage.

> 2FA over mobile phone

Still vulnerable to phishing. If you include a convincing iframe, your attacker can store your TOTP, and use it from their machine.

U2F relies on the domain of the page you are currently browsing, so the code can't be used by another party on the real site.

And if you were thinking about SMS... vulnerable to any attack on the mobile network + phishing + ...

Re: Google Titan Security Key

#25

The thing that makes me a bit jumpy about hardware 2FA with things like this or a Yubikey is around what happens if I lose it or it breaks. It's not so much a problem in a corporate setup (like internally at Google) where you could go to a central admin team to revoke/replace the key. But if you're a home user using this for a wide variety of sites and the token fails then the failure mode seems to be "go figure out…

With yubikeys, you can effectively clone them when setting them up initially. So you carry one and keep another spare in a safe location. If your primary fails, you can buy another and promote your hot standby to primary having set the new one up to be a clone.

Re: Google Titan Security Key

#26
post #4

I think Google uses this same Titan chip for it: https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-... I'm not sure if this is the "hardware security module" they've been touting for Pixel 2 devices, too. I assume this project was spun-off from Project Vault, or at least they re-used some of the ideas/code from that, but it's still a shame we won't be getting the microSD "HSM" anymore. I guess that idea die…

Meh... "open" https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...

Re: Google Titan Security Key

#27
post #26
post #4

I think Google uses this same Titan chip for it: https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-... I'm not sure if this is the "hardware security module" they've been touting for Pixel 2 devices, too. I assume this project was spun-off from Project Vault, or at least they re-used some of the ideas/code from that, but it's still a shame we won't be getting the microSD "HSM" anymore. I guess that idea die…

Meh... "open" https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...

You might like Nitrokey: https://www.nitrokey.com/

Re: Google Titan Security Key

#28

The thing that makes me a bit jumpy about hardware 2FA with things like this or a Yubikey is around what happens if I lose it or it breaks. It's not so much a problem in a corporate setup (like internally at Google) where you could go to a central admin team to revoke/replace the key. But if you're a home user using this for a wide variety of sites and the token fails then the failure mode seems to be "go figure out…

umm, buy two, enroll both and keep one safe somewhere?

I'm very surprised when people voice this concern. These keys cost a mere $20 or so. There's no limit to how many website you can set them up with. So $40 or even $60 is all you need to invest in.

Re: Google Titan Security Key

#29
post #26
post #4

I think Google uses this same Titan chip for it: https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-... I'm not sure if this is the "hardware security module" they've been touting for Pixel 2 devices, too. I assume this project was spun-off from Project Vault, or at least they re-used some of the ideas/code from that, but it's still a shame we won't be getting the microSD "HSM" anymore. I guess that idea die…

Meh... "open" https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...

Yeah, that stood out to me, too. It's kind of funny that they're using the "open" as a competitive advantage against Google, when they no longer have that competitive advantage.

I bet they wish they had stayed open right about now.

Re: Google Titan Security Key

#30
post #28

The thing that makes me a bit jumpy about hardware 2FA with things like this or a Yubikey is around what happens if I lose it or it breaks. It's not so much a problem in a corporate setup (like internally at Google) where you could go to a central admin team to revoke/replace the key. But if you're a home user using this for a wide variety of sites and the token fails then the failure mode seems to be "go figure out…

umm, buy two, enroll both and keep one safe somewhere? I'm very surprised when people voice this concern. These keys cost a mere $20 or so. There's no limit to how many website you can set them up with. So $40 or even $60 is all you need to invest in.

It's interesting you say that, does that not mean you need to enroll both keys on every site you use them on?

This makes having one in a safe location somewhere kind of tricky, as it has to be accessible when you're signing up. so for example if you're travelling/working from another site, you won't have your "safe" key to hand.

Also you need to remember to do the enroll twice for every service, forget one, and you're back to trying to see if there's a fallback procedure.

Post reply on HN