Earlier quoted context omitted.
No, there's no reason. CAP has been around for over a decade, and my bank has supported that and/or SMS as 2nd factor since at least 2008. https://en.wikipedia.org/wiki/Chip_Authentication_Program
How does CAP provide protection when logging into your bank account online?
Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
61–70 of 147 posts
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#62I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#63This looks similar to the Feitan Bluetooth LE-compatible key they also recommend that you purchase if you enable their Advanced Protection feature on your Google account: https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d...
I found the CyberScoop article confusing. CNET, of all places, has a pretty good hands-on preview: https://www.cnet.com/news/google-made-the-titan-key-to-tough... It makes clear that there will in fact be two separate styles. It also includes a comment from Yubico that Bluetooth "does not provide the security assurance levels of NFC and USB, and requires batteries and pairing that offer a poor user experience."
You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a MicroUSB cord to the bottom of the key, plug it into your computer, and use it like you would a USB key.
While I could pair the key with my iPad and my Pixel phone, I couldn't with my Mac. So keeping the BLE key on my keychain rather than a USB version is kind of pointless, because I would need a cord lying around.
I keep the BLE key in a desk drawer for the purpose of authing my mobile devices as it's pretty much the only way to auth on iOS, and once you've used the key with Google's Smart Lock iOS app to add your Google account you don't need the key again. I don't take it anywhere with me.
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#64Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#65Earlier quoted context omitted.
Webauthn and WebUSB UIs are very different. Additionally, Chrome has banned WebUSB from claiming Security Keys. However, it remains the case that if the user downloads and runs exes, or otherwise grants the attacker direct access to the Security Key, then they can ask it to sign an authentication request for a given website. Such an attacker could also compromise the browser and wait for the user to login themselves…
>Chrome has banned WebUSB from claiming Security Keys Since when? Is this extension now broken? https://chrome.google.com/webstore/detail/smart-card-connect...
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#66Earlier quoted context omitted.
Webauthn and WebUSB UIs are very different. Additionally, Chrome has banned WebUSB from claiming Security Keys. However, it remains the case that if the user downloads and runs exes, or otherwise grants the attacker direct access to the Security Key, then they can ask it to sign an authentication request for a given website. Such an attacker could also compromise the browser and wait for the user to login themselves…
>Chrome has banned WebUSB from claiming Security Keys Since when? Is this extension now broken? https://chrome.google.com/webstore/detail/smart-card-connect...
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#67Earlier quoted context omitted.
I own a Yubikey, and I can see why it has a virtual monopoly. It may look flimsy, but it is on my keychain and I do not bother to baby it. It has lasted for well over two years with little signs of wear. It is also very thin and adds little more footprint to my keychain then another house key. While I do not have it, they also have another one that almost fits completely within a USB slot. The size of that security k…
Totally agree on the USB-A models. On the other hand, my USB-C Yubikey only lasted a month in my pocket before the case fractured and flaked apart. Whatever plastic they encased it in was not up the job of being on keyring. Additionally the plastic sleeve inside the USB-C plug broke and the thing became trash. Yubikey shipped me a new one, but looks to be of the same design. That was last summer. The photos on the we…
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#68Earlier quoted context omitted.
I own a Yubikey, and I can see why it has a virtual monopoly. It may look flimsy, but it is on my keychain and I do not bother to baby it. It has lasted for well over two years with little signs of wear. It is also very thin and adds little more footprint to my keychain then another house key. While I do not have it, they also have another one that almost fits completely within a USB slot. The size of that security k…
Totally agree on the USB-A models. On the other hand, my USB-C Yubikey only lasted a month in my pocket before the case fractured and flaked apart. Whatever plastic they encased it in was not up the job of being on keyring. Additionally the plastic sleeve inside the USB-C plug broke and the thing became trash. Yubikey shipped me a new one, but looks to be of the same design. That was last summer. The photos on the we…
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#69I don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F impleme…
> Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. The article implies otherwise: """ “It’s built with a secure element including firmware we built ourselves,” Google’s Rob Sadowski said. “It provides a ton of security with very little interaction and effort on the part of the user.” """
Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
#70I have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offe…
No, there's no reason. CAP has been around for over a decade, and my bank has supported that and/or SMS as 2nd factor since at least 2008. https://en.wikipedia.org/wiki/Chip_Authentication_Program