I feel stupid for asking this, but what if you lose your key?
Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
121–130 of 147 posts
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#122Earlier quoted context omitted.
> I can't speak for the US, but most European banks I've seen require 2FA for almost any non-read-only action. You need either an app, or a tiny machine that authenticates against your (chip) debit card. I have multiple US bank accounts and none of them have anything approaching that, it's kind of pathetic.
Vanguard supports U2F.
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#123Earlier quoted context omitted.
That's an unusually low-substance comment coming from you. Do you really believe a Google U2F key would somehow phone home to Google?
It has radios. Bluetooth Low Energy support, plus a near-field transponder. Seeing those functions in a security key is troublesome. It offers a lot of attack surface.
Yes, more surface, but it is a trade-off that means protecting more devices (users' phones; not just their laptops).
Personally, I would also like to see a USB-C security key that also works with phones and doesn't have the wireless antennas. (Not sure how to make something like that work with an iPhone, though.)
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#124Earlier quoted context omitted.
Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…
Why would you trust a Yubikey, then? To my snarky interlocutor: congratulations, you pried the plastic off a Yubikey and found a pair of NXP MCUs. Now what? Can you even get the data sheets for those things without signing an NDA?
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#125I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…
Google claims to have written the firmware, so it's more than "rebranded" certainly.
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#126It sure would be nice if AWS would support FIDO U2F. Currently, only TOTP codes are supported. I guess most orgs are implementing that in their SSO solution, but for those of us that still have regular IAM users, U2F would be a big improvement in usability.
You can add your voice to the comments there, but I don't think they plan to implement any time soon.
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#127Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#128Earlier quoted context omitted.
How does CAP provide protection when logging into your bank account online?
You get a device (like those in the pictures), which you then connect to your computer, and insert your debit card. When you do an online operation (e.g. bank transfer), the bank site requires the transaction to be digitally signed by your card (and which requires your PIN).
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#129Earlier quoted context omitted.
Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…
Why would you trust a Yubikey, then? To my snarky interlocutor: congratulations, you pried the plastic off a Yubikey and found a pair of NXP MCUs. Now what? Can you even get the data sheets for those things without signing an NDA?
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#130I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…