Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

141–147 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#141
post #90

Uh, so was that last article about how these keys prevented phishing attempts at google just marketting for this product?

What exactly would warrant such 'marketing'? You think Google is going to make mad money selling little USB doodads to uber-nerds?

Cost.

This tech should be bread-and-butter security for enterprises and consumers alike, just like TLS is today. The main reason why it's not is the crazy device cost.

And like the early CAs with SSL in the 90s, Yubico is charging way more for entry than the underlying cost would justify. Based on the teardowns, it looks like they have a 10x or higher markup above standard "profitable" hardware patterns on these devices. Like 90s Verisign charging more for key length, Yubico is selling the security delta. They're free to set their own prices, of course, but that pattern makes real security a luxury rather than an expectation.

What eventually made SSL more than just an enterprise luxury was competition, driving the price down to only $100/cert initially, and eventually lower as volume became a factor.

If Google can bootstrap adoption by bootstrapping price competition, that will encourage more manufacturers to build u2f devices, driving prices lower still. Eventually this tech will become an expectation rather than a luxury.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#142
post #39

Earlier quoted context omitted.

Wrong! I use the following: Yubikey 4C https://www.yubico.com/product/yubikey-4-series/#yubikey-4c USB C-A Adapter https://www.amazon.ca/gp/product/B01C43FUIW/ref=oh_aui_searc...

>Wrong! No, sorry, you are wrong. https://plus.google.com/+BensonLeung/posts/UFCHbSDRa2o

>If C receptacle to A plug adapters exist, they allow the user to plug one in on both ends of the cable, creating an invalid cable that devolves into a USB A-to-A cable. This is why the specification specifically forbids all legacy adapters that have a C receptacle on one end.

I don't understand this statement; If an adapter for USB-C to USB-A exists, then the usage of it would force the USB-C operations to be limited to USB-A specs?

Isn't that exactly what you want? USB 2.0 is slower than 3.0, so interaction between the two devolves to USB 2.0; USB-A is slower than USB-C, so interaction devolves, and now you're backwards compatible (omitting whatever benefits of USB-C, but still a working setup nonetheless)

In fact, I'd imagine thats what adapters do in general.. if they're between non-equivalent things, it naturally devolves to the maximum commonly supported

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#143

My main concern about that - I'm not 100% sure that Google will not discontinue that in couple of years. And for example: recently they've announced that 'Save to Google' extension will be discontinued in nearest weeks, without easy ways to exporting saved stuff.

Not sure how this new Google Titan key works but Yubico doesn't rely on anything other than sites that support it. If Yubico goes under tomorrow my key will continue to work for probably many years.

It's different than buying a device that needs update or server side controls.

This argument doesn't really matter here.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#144
post #141
post #90

Earlier quoted context omitted.

What exactly would warrant such 'marketing'? You think Google is going to make mad money selling little USB doodads to uber-nerds?

Cost. This tech should be bread-and-butter security for enterprises and consumers alike, just like TLS is today. The main reason why it's not is the crazy device cost. And like the early CAs with SSL in the 90s, Yubico is charging way more for entry than the underlying cost would justify. Based on the teardowns, it looks like they have a 10x or higher markup above standard "profitable" hardware patterns on these devi…

It's a little frustrating to read analyses like these, which sort of seem like they're premised on the COGS cost of the parts they sell.

In fact, the marginal cost of one U2F token has probably not much to do with the price Yubikey assigns to its tokens. Yubi has to pay not just for the hardware, but for their engineering team and for the cost of educating the market about using these things, which remain super-niche products that we're barely even able to get Congressional campaigns to adopt, let alone a significant fraction of the Github user base.

Also, I don't know what teardown you're looking at, but it sounds like you're saying you can buy an NXP MCU that can do ECC operations for under $2, which sounds... low... to me. The one-off BOM cost for the NXP MCUs they apparently use for the Neos looks to be something like $40.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#145
post #122
post #95

Earlier quoted context omitted.

Vanguard supports U2F.

I was under the impression that Vanguard's U2F fails open if your password is over eight characters long. Is that still true?

This is not true.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#146

Earlier quoted context omitted.

or are you saying "Hey, what a handy way to keep people invested in our Googleverse?"

How do U2F tokens accomplish that? It's an open standard; it is basically the open standard for modern multi-factor authentication.

I did not realize they were using an open standard.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#147
post #15

I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…

>Google's entry and dominance in the security key industry could be detrimental overtime by limiting the actual implementation of FIDO U2F My hope is that this is the sort of thing that just becomes a standard built-in feature in computers going forward. If my computer is going to have a biometric reader and a trusted secure element, then let that do U2F, too.

What if the computer is somehow compromised, before or after manufacture?
Post reply on HN