Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

131–140 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#131

I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…

I wish banks just got out of the business of logins and let you SSO through a Gmail or another provider that has 2FA support.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#132
post #63

Earlier quoted context omitted.

I found the CyberScoop article confusing. CNET, of all places, has a pretty good hands-on preview: https://www.cnet.com/news/google-made-the-titan-key-to-tough... It makes clear that there will in fact be two separate styles. It also includes a comment from Yubico that Bluetooth "does not provide the security assurance levels of NFC and USB, and requires batteries and pairing that offer a poor user experience."

They're not wrong on the poor UX. I have the Feitan BLE key, along with about three Yubico U2F keys (I'm paranoid about losing them). You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a MicroUSB cord to the bottom of the key, plug it into your computer, and use it like you would a USB key. While I could pair the key with my iPad and my Pixel phone, I couldn't wit…

> I keep the BLE key in a desk drawer for the purpose of authing my mobile devices as it's pretty much the only way to auth on iOS

Krypton Authenticator [1] is another option for iOS. It can turn an iPhone (or Android smartphone) into virtual U2F key.

[1] https://krypt.co/

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#133

If you like your hardware and software free and open (or like to support smaller businesses) there's also the NitroKey: https://www.nitrokey.com/ Not quite as slim, but to me at least, cooler. Made in Berlin!

Being open is really important in this case - I can't be sure there isn't some government backdoor in Google's keys, for example.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#134
post #2

This looks similar to the Feitan Bluetooth LE-compatible key they also recommend that you purchase if you enable their Advanced Protection feature on your Google account: https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d...

The other looks like the Feitan ePass NFC U2F Security Key. https://www.amazon.com/Feitian-ePass-NFC-FIDO-Security/dp/B0...

I have one of these and I can strongly recommend it.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#135

Earlier quoted context omitted.

Its not atypical for Google to do this, for instance Google Hangouts is actually a licensed software deal and not something in-house (albeit not the greatest example).

I'm not really sure what this is referring to - did you mean the Vidyo codec deal (which was subsequently dropped in favor of VP8)? https://vsee.com/blog/google-hangouts-dropped-vidyo/

No, but I can see why you would think I meant that. I didn't cite my sources, probably why I got downvoted a bunch; Racking my brain to remember that company's name but it essentially looked like a whitelabel version of hangouts (minus the google-y/material-design feel of the app).

I'll shut up now till I figure out the company I was thinking of.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#136
post #26
post #21

Earlier quoted context omitted.

Especially for USB-C, Yubico is the only game in town. Based on the pic it's a USB A plug. Seems like a missed opportunity.

USB-C is not backward compatible to USB-A. There's no way to plug a USB-C key into a computer with only USB-A ports. If you need to work with both ports, USB-A is the only game in town. The C to A adapters are not compliant with USB-C spec (see Benson Leung) and are dangerous to use with your USB-C devices.

I can see why a passive adapter could be dangerous.

I don't see, though, why a self-powered hub could not be built that connects to the host over USB-A and provides USB-C ports for peripherals. But I can't find anyone selling such a thing.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#137
post #95

Earlier quoted context omitted.

Vanguard supports U2F.

Note that Vanguard requires you to enable SMS two-factor authentication first. Security is only as strong as the weakest link - even if you use U2F for the security challenges, an attacker can still hijack your phone number and use that to answer the challenge. It's still a good sign, but not good enough IMO. Unfortunately other places aren't any better.

In theory, if you're worried about SIM hijacking, you could use something like Skype SMS, and secure your access to Skype by 2FA on the associated Live account.

Perhaps there are services to choose from as well, but, I'd take great care in determining trust here.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#139
post #82

Earlier quoted context omitted.

I didn't realize that the Neo was so outdated. I wonder why 2FA with NFC hasn't caught on more.

No idea, since the NFC was actually pretty convenient. Considering the Yubico authenticator has a relatively small amount of downloads on the play store (50k), I'm guessing that feature wasn't used that much. If you're thinking of getting the USB C versions of Yubikeys and using them with your phone, it does work but since the Yubikey appears as a keyboard, it disables the Android keyboard while it's plugged in. If I…

Interesting. Didn't realize you could use that with Android. Sounds like the YubiKey 4C may be the best option for me since it looks like I could plug it directly into my phone and laptop.

Edit

Perhaps not as it seems it doesn't work with 2FA in Chrome. https://forum.yubico.com/viewtopic31fc.html?f=35&t=2798

Post reply on HN