Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

111–120 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#111
I remember hearing that Google's main critique with yubikeys is that the newer keys' firmware is no longer open source (and thus, no longer independently verifiable). And that was, apparently, a primary motivation for breaking away from Yubico.

I wonder if its firmware will be open source? The marketing page makes no mention of that

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#112
post #108

Earlier quoted context omitted.

It's a U2F token. It should be the official way. It's kind of a travesty if AWS doesn't have native support for it.

Fairly sure it doesn't unless it's really well hidden. In fact, if someone at Google really did happen to think 'doing initial rollout to GCP customers is going to make AWS look lame' and AWS stops dragging their feet on this, it would also be a good thing for everyone.

I would argue, that the entire GCP development model, as the late entrant's to the cloud market, is about making AWS look lame in comparison.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#113
post #93

Earlier quoted context omitted.

Right, but that's not really my question. I'm asking, do you really think Google is backdooring security tokens? Google's security team is basically at the vanguard of getting those things deployed.

Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…

But you apparently trust the computer you'd be plugging this key into?

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#114
post #105

Earlier quoted context omitted.

AWS and Azure should provide direct support for U2F, too. It's an open standard; nothing stops either provider from doing that.

Sure. But the message I get is, "Now I can use Google's phishing resistant 2FA device to protect my Google Cloud account". It's like accessing Gmail via Chrome: you know, that it's the "official way".

or are you saying "Hey, what a handy way to keep people invested in our Googleverse?"

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#115
post #105

Earlier quoted context omitted.

Sure. But the message I get is, "Now I can use Google's phishing resistant 2FA device to protect my Google Cloud account". It's like accessing Gmail via Chrome: you know, that it's the "official way".

or are you saying "Hey, what a handy way to keep people invested in our Googleverse?"

How do U2F tokens accomplish that? It's an open standard; it is basically the open standard for modern multi-factor authentication.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#116
post #95
post #48

Earlier quoted context omitted.

> I can't speak for the US, but most European banks I've seen require 2FA for almost any non-read-only action. You need either an app, or a tiny machine that authenticates against your (chip) debit card. I have multiple US bank accounts and none of them have anything approaching that, it's kind of pathetic.

Vanguard supports U2F.

Note that Vanguard requires you to enable SMS two-factor authentication first. Security is only as strong as the weakest link - even if you use U2F for the security challenges, an attacker can still hijack your phone number and use that to answer the challenge.

It's still a good sign, but not good enough IMO. Unfortunately other places aren't any better.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#117
Stupid and slightly unrelated point but: Yubikey need some serious work getting their product available in major retailers. I've been checking Amazon for several months looking for a Yubikey Nano on USB-C (rather than USB-A) and they still don't have them available.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#119

For those of us with Mac laptops, is there a reason that the laptop itself with TouchID and Secure Enclave can't act as a U2F security key? Maybe that is what this is? https://github.com/github/SoftU2F

Chrome is doing this:

https://lists.w3.org/Archives/Public/public-webauthn/2018Jun...

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#120

I feel stupid for asking this, but what if you lose your key?

It's not a stupid question. When setting these up, you have four layers to fall back on:

1. Any other keys you added to the account (like a coworker's)

2. TOTP app like Google Authenticator

3. Printed one-time backup codes

4. Onerous account recovery process through support.

Post reply on HN