Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

51–60 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#51
post #47
post #39

Earlier quoted context omitted.

>Wrong! No, sorry, you are wrong. https://plus.google.com/+BensonLeung/posts/UFCHbSDRa2o

99% of people do not care what the USB spec says is allowed, if the thing works they will buy and use it. See: every phone charger that outputs more than 500mA over a USB-A port. Doesn't comply with the spec, nobody cares, everyone does it. Even the post says the only reason C-A adapters aren't allowed in the spec is that they can be chained with a C-C cable to make an A-A cable. They work fine if you don't do stupid…

Buyers may not know or care, but retailers do. Anyone can report that Amazon link shared earlier and Amazon will remove it as it is not spec compliant. Those type adapters are also non-existent at basically every electronics brick-and-mortar store I've visited.

https://www.androidpolice.com/2016/03/29/amazon-updates-its-...

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#52
post #2

This looks similar to the Feitan Bluetooth LE-compatible key they also recommend that you purchase if you enable their Advanced Protection feature on your Google account: https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d...

I found the CyberScoop article confusing. CNET, of all places, has a pretty good hands-on preview:

https://www.cnet.com/news/google-made-the-titan-key-to-tough...

It makes clear that there will in fact be two separate styles. It also includes a comment from Yubico that Bluetooth "does not provide the security assurance levels of NFC and USB, and requires batteries and pairing that offer a poor user experience."

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#53

I feel stupid for asking this, but what if you lose your key?

It’s not as big of a deal as you might expect because:

- The spec requires providers to allow independent addition / removal of multiple keys per account, so it’s easy to manage backup U2F keys.

- Providers can use any backup authentication method they want. This includes SMS codes, TOTP / HOTP apps, email resets, or maybe VCing in to tech support.

And even if the backup method is less awesome (e.g. sms codes) it still reduces your risk because because you use it less often.

[edit for formatting]

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#54

I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…

My guess is that it's related to support costs. If you lose your hardware key and fail Google's automated account recovery, that's a feature! If you lose your Dropbox hardware key, I'm guessing they have a proprietary recovery procedure that's not regulated by a government. If you lose a key that's associated with your bank account, that bank by law must still give you access to your account, and support costs to do that are likely higher than the systems they already have in place. Or maybe it's just hard to add this to aging infrastructure held together by duct tape, dunno.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#57
post #6

Can someone explain this? > “Yubikey cost Google less than their own authenticator app,” Ehrensvärd said, and there have been no account takeovers since the program was implemented, Google says.

Perhaps he is factoring is the human cost. Yubikeys save a couple of minutes multiple times per day.

Could also be the security benefit. Authenticator-style apps are still vulnerable to MITM attacks, where physical keys are not.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#58

Given how much 'Titan' sounds like 'Feitian', I'm a little bit surprised their upstream hardware vendor would be ok with them using the brand.

They're probably OK with it because of the profit they stand to make from the increased visibility/marketing. To Americans, I'd guess "Feitian" sounds like "some foreign thing I've never heard of" whereas "Google Titan" feels warm and fuzzy.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#59
post #39

Earlier quoted context omitted.

>Wrong! No, sorry, you are wrong. https://plus.google.com/+BensonLeung/posts/UFCHbSDRa2o

Doesn't that mean that 99.99% of all USB chargers for phones violate the spec? Since the spec says USB A only outputs 500mA ? Holy shit!

IIRC since at least 2.0 the USB spec is very liberal in what current can A port source and the 500mA is relevant only as maximum that can device with B port negotiate as it's sink current.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#60
post #51
post #47

Earlier quoted context omitted.

99% of people do not care what the USB spec says is allowed, if the thing works they will buy and use it. See: every phone charger that outputs more than 500mA over a USB-A port. Doesn't comply with the spec, nobody cares, everyone does it. Even the post says the only reason C-A adapters aren't allowed in the spec is that they can be chained with a C-C cable to make an A-A cable. They work fine if you don't do stupid…

Buyers may not know or care, but retailers do. Anyone can report that Amazon link shared earlier and Amazon will remove it as it is not spec compliant. Those type adapters are also non-existent at basically every electronics brick-and-mortar store I've visited. https://www.androidpolice.com/2016/03/29/amazon-updates-its-...

Amazon has had this policy for years but unfortunately enforcement is a complete joke and they remain full of noncompliant hardware.

I do find it interesting that they ban noncompliant Type C devices but not noncompliant Type A devices. Probably because the Type A current spec has got to be among the world's most-violated standards.

Post reply on HN