Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

101–110 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#101
post #93
post #92

Earlier quoted context omitted.

It has radios. Bluetooth Low Energy support, plus a near-field transponder. Seeing those functions in a security key is troublesome. It offers a lot of attack surface.

Right, but that's not really my question. I'm asking, do you really think Google is backdooring security tokens? Google's security team is basically at the vanguard of getting those things deployed.

Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4].

[1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.com/2016/11/hacking-android-smartphone...

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#102

Earlier quoted context omitted.

They could market it not because they want money, but because they want to make everybody secure.

I think that's what most of us think they're trying to do.

The article makes the product look to be directed at Google Cloud customers, thus increasing its unique selling proposition over AWS and Azure.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#103
post #102

Earlier quoted context omitted.

I think that's what most of us think they're trying to do.

The article makes the product look to be directed at Google Cloud customers, thus increasing its unique selling proposition over AWS and Azure.

AWS and Azure should provide direct support for U2F, too. It's an open standard; nothing stops either provider from doing that.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#104
post #93

Earlier quoted context omitted.

Right, but that's not really my question. I'm asking, do you really think Google is backdooring security tokens? Google's security team is basically at the vanguard of getting those things deployed.

Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…

Why would you trust a Yubikey, then?

To my snarky interlocutor: congratulations, you pried the plastic off a Yubikey and found a pair of NXP MCUs. Now what? Can you even get the data sheets for those things without signing an NDA?

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#105
post #102

Earlier quoted context omitted.

The article makes the product look to be directed at Google Cloud customers, thus increasing its unique selling proposition over AWS and Azure.

AWS and Azure should provide direct support for U2F, too. It's an open standard; nothing stops either provider from doing that.

Sure. But the message I get is, "Now I can use Google's phishing resistant 2FA device to protect my Google Cloud account". It's like accessing Gmail via Chrome: you know, that it's the "official way".

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#106
post #105

Earlier quoted context omitted.

AWS and Azure should provide direct support for U2F, too. It's an open standard; nothing stops either provider from doing that.

Sure. But the message I get is, "Now I can use Google's phishing resistant 2FA device to protect my Google Cloud account". It's like accessing Gmail via Chrome: you know, that it's the "official way".

It's a U2F token. It should be the official way. It's kind of a travesty if AWS doesn't have native support for it.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#107

Earlier quoted context omitted.

You get a device (like those in the pictures), which you then connect to your computer, and insert your debit card. When you do an online operation (e.g. bank transfer), the bank site requires the transaction to be digitally signed by your card (and which requires your PIN).

Ah OK I didn't look closely enough as I thought the picture were of POS terminal devices. I was confusing CAP with "chip and pin" - the tech used inside debit cards.

It is chip and pin :) it's the same cards, just not a POS device.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#108
post #105

Earlier quoted context omitted.

Sure. But the message I get is, "Now I can use Google's phishing resistant 2FA device to protect my Google Cloud account". It's like accessing Gmail via Chrome: you know, that it's the "official way".

It's a U2F token. It should be the official way. It's kind of a travesty if AWS doesn't have native support for it.

Fairly sure it doesn't unless it's really well hidden. In fact, if someone at Google really did happen to think 'doing initial rollout to GCP customers is going to make AWS look lame' and AWS stops dragging their feet on this, it would also be a good thing for everyone.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#109

I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…

Charles Schwab supports authenticator codes with Symantec VIP, or they'll send you a hardware token that generates codes.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#110

Earlier quoted context omitted.

Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…

Why would you trust a Yubikey, then? To my snarky interlocutor: congratulations, you pried the plastic off a Yubikey and found a pair of NXP MCUs. Now what? Can you even get the data sheets for those things without signing an NDA?

http://lmgtfy.com/?q=yubikey+teardown
Post reply on HN