Live data from Hacker News

Google Titan Security Key

cloud.google.com

31–36 of 36 posts

Re: Google Titan Security Key

#31

The thing that makes me a bit jumpy about hardware 2FA with things like this or a Yubikey is around what happens if I lose it or it breaks. It's not so much a problem in a corporate setup (like internally at Google) where you could go to a central admin team to revoke/replace the key. But if you're a home user using this for a wide variety of sites and the token fails then the failure mode seems to be "go figure out…

With yubikeys, you can effectively clone them when setting them up initially. So you carry one and keep another spare in a safe location. If your primary fails, you can buy another and promote your hot standby to primary having set the new one up to be a clone.

Ahh that is interesting! Do you know is there a doc. on how that's done? Also does that mean that once the clone is done you can effectively just register once with your "live" key and if it fails seemlessly use the "backup" key or do you need to register with both for that to work?

Re: Google Titan Security Key

#33

Earlier quoted context omitted.

With yubikeys, you can effectively clone them when setting them up initially. So you carry one and keep another spare in a safe location. If your primary fails, you can buy another and promote your hot standby to primary having set the new one up to be a clone.

Ahh that is interesting! Do you know is there a doc. on how that's done? Also does that mean that once the clone is done you can effectively just register once with your "live" key and if it fails seemlessly use the "backup" key or do you need to register with both for that to work?

When you buy one and follow the basic setup steps it tells you how. Always buy them in pairs.

Re: Google Titan Security Key

#34
post #23

Quite neat. Though I'm still dissapointed in the U2F/Security Key market. The Yubico's cost 50€ the piece or 20€ for the U2F key only. And to get NFC usage you have to buy a worse variant of the other keys that doesn't support 4096bit RSA and some other features. There is not much competition either, Nitro is just as expensive and doesn't feature a good and cheap key either. Open Source variants are also fairly rare,…

To be fair for home usage a soft-token is just as good and you can back it up by backing up the seed.

If your phone is compromised by someone who can exploit it then your adversarial outlook is pretty dire to begin with.

Re: Google Titan Security Key

#35
post #23

Quite neat. Though I'm still dissapointed in the U2F/Security Key market. The Yubico's cost 50€ the piece or 20€ for the U2F key only. And to get NFC usage you have to buy a worse variant of the other keys that doesn't support 4096bit RSA and some other features. There is not much competition either, Nitro is just as expensive and doesn't feature a good and cheap key either. Open Source variants are also fairly rare,…

To be fair for home usage a soft-token is just as good and you can back it up by backing up the seed. If your phone is compromised by someone who can exploit it then your adversarial outlook is pretty dire to begin with.

I'd rather have a hardware solution tbh, I don't think software U2F or smartcard is what I want or fits my threatmodel.

Re: Google Titan Security Key

#36
post #7

Earlier quoted context omitted.

regarding yubico: they talk open, global standards, but then say security can only be met by producing in the USA (and Sweden!). Why should I trust USA produced products?

Looking at the list of IC exports[0], where should they be produced that will be trusted by the vast majority of those who care? [0]: https://en.wikipedia.org/wiki/List_of_countries_by_integrate...

Now I'm wondering how Malta made the top-20 list of IC export countries.
Post reply on HN