Live data from Hacker News

Your Android Phone Is a Security Key

blog.google

11–20 of 144 posts

Re: Your Android Phone Is a Security Key

#11
post #9

My phone already prompts me when I login to a google account on another device. Is this new / different?

I thought that. AFAICT it's local via Bluetooth, as opposed to through Google servers and push messaging. Good idea, but better if it's open.

Of course their motivation as normal may be to have users have their wifi/bluetooth on all the time so they can reliably collect more location data.

Re: Your Android Phone Is a Security Key

#12
post #8
post #6

Earlier quoted context omitted.

I'd argue using Authenticator is better than simply not using 2FA. Which is probably the choice for a lot of people for whom always carrying some dedicated hardware device is not really a realistic option.

In what way is carrying a dedicated device not realistic? My second factor lives on my keyring and is only a bit larger than a typical door key. Everyone carries keys.

I don't carry my keys when I'm traveling if I'm not driving my own car. So, no, not everyone carries keys.

ADDED: I do have other 2FA hardware as well. But I assume I'm not guaranteed to have it with me when I need it.

Re: Your Android Phone Is a Security Key

#13
post #2

I don't know how I feel about making a device so endlessly hackable a "security key".

All Android devices certified by Google will have a hardware security module which should keep the keys secure. Some cheap non-certified devices (mostly Chinese) might not have hardware backed keystores, but I doubt those devices would be able to run this Google app.

Re: Your Android Phone Is a Security Key

#14
They don't make this very obvious but this only works in Chrome. So you'll have to use SMS codes, the Authenticator app, or backup codes everywhere else. (edit: they explicitly say so when activating it but not as clearly in the docs)

Re: Your Android Phone Is a Security Key

#15
post #9

My phone already prompts me when I login to a google account on another device. Is this new / different?

I think the difference is that the prompt you describe still travels over the wire to get to your device, while this new thing used Bluetooth based on FIDO standards.

So the access key the client logging in passes to the server is from the local device you trust.

Re: Your Android Phone Is a Security Key

#16
post #8
post #6

Earlier quoted context omitted.

I'd argue using Authenticator is better than simply not using 2FA. Which is probably the choice for a lot of people for whom always carrying some dedicated hardware device is not really a realistic option.

In what way is carrying a dedicated device not realistic? My second factor lives on my keyring and is only a bit larger than a typical door key. Everyone carries keys.

> In what way is carrying a dedicated device not realistic?

For most people, it's so far outside what they're familiar with that it feels alien and incomprehensible. It makes absolutely no sense to them. So they're not going to do it or adopt it quickly.

User education will catch up in time, but that will take quite a long time.

Re: Your Android Phone Is a Security Key

#18
post #9

My phone already prompts me when I login to a google account on another device. Is this new / different?

I think the difference is that the prompt you describe still travels over the wire to get to your device, while this new thing used Bluetooth based on FIDO standards. So the access key the client logging in passes to the server is from the local device you trust.

Ah thank you!

Sometimes google's announcements really make it hard to understand their products when there is overlap or similarities or what.

Re: Your Android Phone Is a Security Key

#19
I like the idea behind it in principle, since it will simplify 2FA for the masses and may lead more people to adopt it.

But, apart from that: 1. It's only on Chrome (for now(?)) 2. It's only for Google products (for now (?)) 3. It's only on Android that Google fully controls remotely (and probably it will stay there).

All these give even more power to Google at the expense of convenience and allows a single company to define "how things should be done".

And I should clarify that I am not against this tech specifically. If anything, I think Google has some of the brightest minds, so technically I'm sure that the product will be great.

The problem is that with great power comes something that Google (as a company) seems to be lacking lately.

Post reply on HN