Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

121–130 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#122
post #95
post #48

Earlier quoted context omitted.

> I can't speak for the US, but most European banks I've seen require 2FA for almost any non-read-only action. You need either an app, or a tiny machine that authenticates against your (chip) debit card. I have multiple US bank accounts and none of them have anything approaching that, it's kind of pathetic.

Vanguard supports U2F.

I was under the impression that Vanguard's U2F fails open if your password is over eight characters long. Is that still true?

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#123
post #92
post #86

Earlier quoted context omitted.

That's an unusually low-substance comment coming from you. Do you really believe a Google U2F key would somehow phone home to Google?

It has radios. Bluetooth Low Energy support, plus a near-field transponder. Seeing those functions in a security key is troublesome. It offers a lot of attack surface.

Those are so that you can use a security key with an iPhone or Android.

Yes, more surface, but it is a trade-off that means protecting more devices (users' phones; not just their laptops).

Personally, I would also like to see a USB-C security key that also works with phones and doesn't have the wireless antennas. (Not sure how to make something like that work with an iPhone, though.)

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#124

Earlier quoted context omitted.

Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…

Why would you trust a Yubikey, then? To my snarky interlocutor: congratulations, you pried the plastic off a Yubikey and found a pair of NXP MCUs. Now what? Can you even get the data sheets for those things without signing an NDA?

[deleted]

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#125

I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…

> just a cheaply made Feitian Key though rebranded for Google Cloud

Google claims to have written the firmware, so it's more than "rebranded" certainly.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#126
post #5

It sure would be nice if AWS would support FIDO U2F. Currently, only TOTP codes are supported. I guess most orgs are implementing that in their SSO solution, but for those of us that still have regular IAM users, U2F would be a big improvement in usability.

It looks like they were going to and then backed off. See here: https://forums.aws.amazon.com/thread.jspa?threadID=163777&st...

You can add your voice to the comments there, but I don't think they plan to implement any time soon.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#128

Earlier quoted context omitted.

How does CAP provide protection when logging into your bank account online?

You get a device (like those in the pictures), which you then connect to your computer, and insert your debit card. When you do an online operation (e.g. bank transfer), the bank site requires the transaction to be digitally signed by your card (and which requires your PIN).

That's sick, and also what I want out of the open crypto networks.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#129

Earlier quoted context omitted.

Until there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.co…

Why would you trust a Yubikey, then? To my snarky interlocutor: congratulations, you pried the plastic off a Yubikey and found a pair of NXP MCUs. Now what? Can you even get the data sheets for those things without signing an NDA?

You've gotten quiet, but are posting on other threads (apologies, but you're someone whose comments I follow here on HN). I'm genuinely curious to hear out the logic you brought to this comment about Google backdooring U2F tokens, and also about what security hardware you do trust.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#130

I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…

I still hope Google will not be the most powerful influencer at W3C and that Firefox implements support for U2F/FIDO/WebAuthn as well, to continue keeping the web free (Google-free let's say)
Post reply on HN