Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

61–70 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#61

Earlier quoted context omitted.

No, there's no reason. CAP has been around for over a decade, and my bank has supported that and/or SMS as 2nd factor since at least 2008. https://en.wikipedia.org/wiki/Chip_Authentication_Program

How does CAP provide protection when logging into your bank account online?

You get a device (like those in the pictures), which you then connect to your computer, and insert your debit card. When you do an online operation (e.g. bank transfer), the bank site requires the transaction to be digitally signed by your card (and which requires your PIN).

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#62

I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…

I use Fidelity (in the US) because they have a TOTP implementation. Its unfortunately Symantec VIP and not Google Authenticator standard so I need yet another app, but it gives me some extra security and I am happy with it. PayPal can also use the same authenticator, in lieu of the known broken SMS.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#63
post #2

This looks similar to the Feitan Bluetooth LE-compatible key they also recommend that you purchase if you enable their Advanced Protection feature on your Google account: https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d...

I found the CyberScoop article confusing. CNET, of all places, has a pretty good hands-on preview: https://www.cnet.com/news/google-made-the-titan-key-to-tough... It makes clear that there will in fact be two separate styles. It also includes a comment from Yubico that Bluetooth "does not provide the security assurance levels of NFC and USB, and requires batteries and pairing that offer a poor user experience."

They're not wrong on the poor UX. I have the Feitan BLE key, along with about three Yubico U2F keys (I'm paranoid about losing them).

You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a MicroUSB cord to the bottom of the key, plug it into your computer, and use it like you would a USB key.

While I could pair the key with my iPad and my Pixel phone, I couldn't with my Mac. So keeping the BLE key on my keychain rather than a USB version is kind of pointless, because I would need a cord lying around.

I keep the BLE key in a desk drawer for the purpose of authing my mobile devices as it's pretty much the only way to auth on iOS, and once you've used the key with Google's Smart Lock iOS app to add your Google account you don't need the key again. I don't take it anywhere with me.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#64
This is definitely threadjacking, but curious if anyone here has tried the Yubikey Neo? I'd like to purchase a 2FA device and it seems like this is the only option with NFC which I would appreciate given how often I find I'm logging into things on my phone these days.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#65
post #49
post #43

Earlier quoted context omitted.

Webauthn and WebUSB UIs are very different. Additionally, Chrome has banned WebUSB from claiming Security Keys. However, it remains the case that if the user downloads and runs exes, or otherwise grants the attacker direct access to the Security Key, then they can ask it to sign an authentication request for a given website. Such an attacker could also compromise the browser and wait for the user to login themselves…

>Chrome has banned WebUSB from claiming Security Keys Since when? Is this extension now broken? https://chrome.google.com/webstore/detail/smart-card-connect...

I don't know about the specific extension, but see https://groups.google.com/a/chromium.org/d/msg/blink-dev/LZX...

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#66
post #49
post #43

Earlier quoted context omitted.

Webauthn and WebUSB UIs are very different. Additionally, Chrome has banned WebUSB from claiming Security Keys. However, it remains the case that if the user downloads and runs exes, or otherwise grants the attacker direct access to the Security Key, then they can ask it to sign an authentication request for a given website. Such an attacker could also compromise the browser and wait for the user to login themselves…

>Chrome has banned WebUSB from claiming Security Keys Since when? Is this extension now broken? https://chrome.google.com/webstore/detail/smart-card-connect...

Since webusb broke u2f: https://pwnaccelerator.github.io/2018/webusb-yubico-disclosu...

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#67
post #33
post #13

Earlier quoted context omitted.

I own a Yubikey, and I can see why it has a virtual monopoly. It may look flimsy, but it is on my keychain and I do not bother to baby it. It has lasted for well over two years with little signs of wear. It is also very thin and adds little more footprint to my keychain then another house key. While I do not have it, they also have another one that almost fits completely within a USB slot. The size of that security k…

Totally agree on the USB-A models. On the other hand, my USB-C Yubikey only lasted a month in my pocket before the case fractured and flaked apart. Whatever plastic they encased it in was not up the job of being on keyring. Additionally the plastic sleeve inside the USB-C plug broke and the thing became trash. Yubikey shipped me a new one, but looks to be of the same design. That was last summer. The photos on the we…

Interesting, I have both in my keychain, I destroy all things consumer product usually, but both are fine. 1-2 yrs straight. I do wish other companies would compete in the space.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#68
post #33
post #13

Earlier quoted context omitted.

I own a Yubikey, and I can see why it has a virtual monopoly. It may look flimsy, but it is on my keychain and I do not bother to baby it. It has lasted for well over two years with little signs of wear. It is also very thin and adds little more footprint to my keychain then another house key. While I do not have it, they also have another one that almost fits completely within a USB slot. The size of that security k…

Totally agree on the USB-A models. On the other hand, my USB-C Yubikey only lasted a month in my pocket before the case fractured and flaked apart. Whatever plastic they encased it in was not up the job of being on keyring. Additionally the plastic sleeve inside the USB-C plug broke and the thing became trash. Yubikey shipped me a new one, but looks to be of the same design. That was last summer. The photos on the we…

Same happened to me with the USB-C key. Meanwhile, my three year old USB-A key that has lived on my keyring continuously shows some obvious wear, but no signs of damage.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#69
post #27

I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…

> Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. The article implies otherwise: """ “It’s built with a secure element including firmware we built ourselves,” Google’s Rob Sadowski said. “It provides a ton of security with very little interaction and effort on the part of the user.” """

Its not atypical for Google to do this, for instance Google Hangouts is actually a licensed software deal and not something in-house (albeit not the greatest example).

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#70

I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…

No, there's no reason. CAP has been around for over a decade, and my bank has supported that and/or SMS as 2nd factor since at least 2008. https://en.wikipedia.org/wiki/Chip_Authentication_Program

American Express provided something similar to this with the first iteration of the Amex Blue card, though the implementation details were probably different since that was back in the early 2000s. They gave each cardholder a card reader that plugged into your PC, along with other handy stuff like software that could generate one-time use card numbers linked to your account. It was all pretty whizzy, though Amex dropped it like a hot rock when it failed to get much traction.
Post reply on HN