Live data from Hacker News

Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

cyberscoop.com

91–100 of 147 posts

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#91
Here's the thing. I don't want a device with a usb interface. Some environments are so locked down, the ability to plug in a usb device is completely unfeasible. Similarly, cell phones are not a good option in these restricted environments (one time password apps or text messages would not work).

It's these types of environments where security is the most restricted that we need better two factor options. RSA SecureId tokens are a reasonable solution for local logins, but can't be used to authenticate with external resources like Google.

I want to access Google, AWS (and friends) without a network (phone) or plugged (usb) device. Let me register a SecureId token or something similar with them. We need to be able to bring our own devices.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#92
post #86
post #55

It's a Google product. Does it phone home to Google, or what?

That's an unusually low-substance comment coming from you. Do you really believe a Google U2F key would somehow phone home to Google?

It has radios. Bluetooth Low Energy support, plus a near-field transponder. Seeing those functions in a security key is troublesome. It offers a lot of attack surface.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#93
post #92
post #86

Earlier quoted context omitted.

That's an unusually low-substance comment coming from you. Do you really believe a Google U2F key would somehow phone home to Google?

It has radios. Bluetooth Low Energy support, plus a near-field transponder. Seeing those functions in a security key is troublesome. It offers a lot of attack surface.

Right, but that's not really my question. I'm asking, do you really think Google is backdooring security tokens? Google's security team is basically at the vanguard of getting those things deployed.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#94

Here's the thing. I don't want a device with a usb interface. Some environments are so locked down, the ability to plug in a usb device is completely unfeasible. Similarly, cell phones are not a good option in these restricted environments (one time password apps or text messages would not work). It's these types of environments where security is the most restricted that we need better two factor options. RSA SecureI…

BLE security keys also exist:

https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d...

SecureId is a TOTP device last time I checked, which is phishable and significantly less secure than U2F devices. The sooner TOTP is phased out the better.

If BLE and NFC are unacceptable, well, I guess you are stuck trying to use TPMs in some way to do U2F. Some phones already support something like that and I assume newer desktops and laptops will be capable of doing that some day.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#95
post #48

Earlier quoted context omitted.

I can't speak for the US, but most European banks I've seen require 2FA for almost any non-read-only action. You need either an app, or a tiny machine that authenticates against your (chip) debit card. Login is still just password, though, but there's only so much damage you can do.

> I can't speak for the US, but most European banks I've seen require 2FA for almost any non-read-only action. You need either an app, or a tiny machine that authenticates against your (chip) debit card. I have multiple US bank accounts and none of them have anything approaching that, it's kind of pathetic.

Vanguard supports U2F.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#96
post #74
post #59

Earlier quoted context omitted.

IIRC since at least 2.0 the USB spec is very liberal in what current can A port source and the 500mA is relevant only as maximum that can device with B port negotiate as it's sink current.

The spec is not liberal. See Section 7.2.1 for power delivery information. "A unit load is defined to be 100 mA. The number of unit loads a device can draw is an absolute maximum, not an average over time. A device may be either low-power at one unit load or high- power, consuming up to five unit loads." http://sdphca.ucsd.edu/Lab_Equip_Manuals/usb_20.pdf

Liberal in exactly the sense that you describe, that is it describes and limits behavior of the current sink (ie. USB function) and does not constrain the current that downstream port (in traditional USB topolgy an A port, ie. host or hub's downstream port) can source apart from specifing minimum of one load unit and maximum as something IIRC safety related (and not exactly defined).

Originally (1.0, 1.1...) downstream USB ports were supposed to measure and limit downstream VBUS with the unit load precission, but this idea was shelved very early on and replaced with recommendation of placing fuses or polyswitches and sensing their state.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#97
post #27

Earlier quoted context omitted.

> Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. The article implies otherwise: """ “It’s built with a secure element including firmware we built ourselves,” Google’s Rob Sadowski said. “It provides a ton of security with very little interaction and effort on the part of the user.” """

Its not atypical for Google to do this, for instance Google Hangouts is actually a licensed software deal and not something in-house (albeit not the greatest example).

What's the source platform for Google Hangouts? I would be interested using them internally for our video chat needs, a link would be useful to see their pricing.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#99
post #90

Uh, so was that last article about how these keys prevented phishing attempts at google just marketting for this product?

What exactly would warrant such 'marketing'? You think Google is going to make mad money selling little USB doodads to uber-nerds?

They could market it not because they want money, but because they want to make everybody secure.

Re: Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device

#100
post #90

Earlier quoted context omitted.

What exactly would warrant such 'marketing'? You think Google is going to make mad money selling little USB doodads to uber-nerds?

They could market it not because they want money, but because they want to make everybody secure.

I think that's what most of us think they're trying to do.
Post reply on HN