11 ms·
Google Unveils Titan Security Key, a Yubico-Like Phishing Resistant 2FA Device
- ghostly_s 8y agoTitle is clickbait and should be changed. The article mentions no features that make this more or less 'phishing-resistant' than any other physical security key product.
- ben1040 8y agoThis looks similar to the Feitan Bluetooth LE-compatible key they also recommend that you purchase if you enable their Advanced Protection feature on your Google account: https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/dp/B01LYV6TQM https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d...
- rhencke 8y agoDang. That's more than similar - that's nearly identical form factor, for both that and the USB key.
- ianburrell 8y agoThe other looks like the Feitan ePass NFC U2F Security Key. https://www.amazon.com/Feitian-ePass-NFC-FIDO-Security/dp/B01M1R5LRD https://www.amazon.com/Feitian-ePass-NFC-FIDO-Security/dp/B0...
- chaz6 8y agoI have one of these and I can strongly recommend it.
- SloopJon 8y agoI found the CyberScoop article confusing. CNET, of all places, has a pretty good hands-on preview: https://www.cnet.com/news/google-made-the-titan-key-to-toughen-up-your-online-security/ https://www.cnet.com/news/google-made-the-titan-key-to-tough... It makes clear that there will in fact be two separate styles. It also includes a comment from Yubico that Bluetooth "does not provide the security assurance levels of NFC and USB, and requires batteries and pairing that offer a poor user experience."
- ben1040 8y agoThey're not wrong on the poor UX. I have the Feitan BLE key, along with about three Yubico U2F keys (I'm paranoid about losing them). You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a MicroUSB cord to the bottom of the key, plug it into your computer, and use it like you would a USB key. While I could pair the key with my iPad and my Pixel phone, I couldn't with my Mac. So keeping the BLE key on my keychain rather than a USB version is kind of pointless, because I would need a cord lying around. I keep the BLE key in a desk drawer for the purpose of authing my mobile devices as it's pretty much the only way to auth on iOS, and once you've used the key with Google's Smart Lock iOS app to add your Google account you don't need the key again. I don't take it anywhere with me.
- arthurfm 8y ago> I keep the BLE key in a desk drawer for the purpose of authing my mobile devices as it's pretty much the only way to auth on iOS Krypton Authenticator [1] is another option for iOS. It can turn an iPhone (or Android smartphone) into virtual U2F key. [1] https://krypt.co/ https://krypt.co/
- ridgewell 8y agoI don't think I'm all that opposed to competition in this space. Yubico has a virtual monopoly on high-quality Fido U2F keys at the moment. Google is a giant admittedly, and could crush Yubico overtime though. Not sure if this is just a cheaply made Feitian Key though rebranded for Google Cloud, or if it is a new product in itself. However, I've heard that Google is kind of going on a tangent with its own U2F implementations, emphasizing an old-school implementation instead of the Web Authentication Standard that's pushed by the W3C. Google's entry and dominance in the security key industry could be detrimental overtime by limiting the actual implementation of FIDO U2F, or it could push security keys into the mainstream too, and with that, open the floodgates for supply.
- agl 8y ago> However, I've heard that Google is kind of going on a tangent with its own U2F implementations, emphasizing an old-school implementation instead of the Web Authentication Standard that's pushed by the W3C. Chrome has supported "U2F" (the first FIDO spec) for a while and all support for Security Keys in the last few years has been via this protocol. But we're implementing the W3C Web Authentication (webauthn) spec and you can already use it in Chrome in place of U2F. All effort is going into webauthn now and the U2F code is frozen. At some point I'll announce a sunset date for U2F support in Chrome and happily delete that code. (Just the API, U2F keys will continue to work via webauthn.)
- puzzle 8y agoCan you use local storage and upload local applets to these new keys? The main use case is authenticating under Secure Shell on a Chromebook without having to configure the key on e.g. Linux first: https://groups.google.com/a/chromium.org/forum/#!topic/chromium-hterm/LuDVJ67Q4BE https://groups.google.com/a/chromium.org/forum/#!topic/chrom... https://chromium.googlesource.com/apps/libapps/+/HEAD/nassh/doc/hardware-keys.md https://chromium.googlesource.com/apps/libapps/+/HEAD/nassh/...
- scott00 8y agoDon't know anything about the Google Titan keys, but they are most likely Feitian hardware with custom firmware, and you can buy unlocked versions of Feitian security keys by contacting them. On unlocked keys you can install your own javacard applets.
- masonhensley 8y agoCan someone explain this? > “Yubikey cost Google less than their own authenticator app,” Ehrensvärd said, and there have been no account takeovers since the program was implemented, Google says.
- tln 8y agoPerhaps he is factoring is the human cost. Yubikeys save a couple of minutes multiple times per day.
- pc86 8y agoI took it as the cost of just purchasing Yubikeys for everyone was less than the payroll and associated costs of developing the Authenticator app. But I could either interpretation (or both) being correct.
- organsnyder 8y agoCould also be the security benefit. Authenticator-style apps are still vulnerable to MITM attacks, where physical keys are not.
- ReidZB 8y agoIt sure would be nice if AWS would support FIDO U2F. Currently, only TOTP codes are supported. I guess most orgs are implementing that in their SSO solution, but for those of us that still have regular IAM users, U2F would be a big improvement in usability.
- cjcampbell 8y agoYes! I don't understand why it has taken so long. The benefit for protecting root accounts and scenarios where federation is not applicable is significant. I find the usability to be a particular drag during local development.
- eggsome 8y agoIt looks like they were going to and then backed off. See here: https://forums.aws.amazon.com/thread.jspa?threadID=163777&start=50&tstart=0 https://forums.aws.amazon.com/thread.jspa?threadID=163777&st... You can add your voice to the comments there, but I don't think they plan to implement any time soon.
- bogomipz 8y agoI have a tangential question about 2FA since there's been a couple of articles recently on HN about U2F/FIDO/2FA. Is there a reason almost no banks offer 2FA? I really seems absurd that in 2018 a person's gmail/dropbox/github etc has better security practices than an online bank account. EDIT. Some people assumed this was a US-centric question/perspective. If you look at this list. The number of checks for banks offering either hardware/software 2FA is pretty dismal: https://twofactorauth.org/#banking https://twofactorauth.org/#banking
- whitepoplar 8y agoMy guess is that it's related to support costs. If you lose your hardware key and fail Google's automated account recovery, that's a feature! If you lose your Dropbox hardware key, I'm guessing they have a proprietary recovery procedure that's not regulated by a government. If you lose a key that's associated with your bank account, that bank by law must still give you access to your account, and support costs to do that are likely higher than the systems they already have in place. Or maybe it's just hard to add this to aging infrastructure held together by duct tape, dunno.
- thezilch 8y agoWhy do many US banks and CUs have bad password hygiene? Length limits (and really short ones)? Character restrictions? Makes you really think how bad the tech behind it all is protecting your security.
- bogomipz 8y agoAnd of course many(most?) still use security questions - "whats your favorite food?", "what was the name of your first employer" etc.
- icebraining 8y agoNo, there's no reason. CAP has been around for over a decade, and my bank has supported that and/or SMS as 2nd factor since at least 2008. https://en.wikipedia.org/wiki/Chip_Authentication_Program https://en.wikipedia.org/wiki/Chip_Authentication_Program
- kxyvr 8y agoCould someone explain the difference between FIDO and FIDO2 compliant keys? For example, is new hardware required or will existing FIDO/U2F keys work with FIDO2? It looks like Yubico is advertising a new FIDO2 key under the brand name "Security Key by Yubico". Personally, I've been meaning to pick up a U2F key, but if sites are going to start rolling out WebAuthn support, I'd rather have a key that supports both FIDO and FIDO2. Does anyone have a recommendation?
- agl 8y agoWebauthn works with both FIDO1 and FIDO2 keys. (Unless you have the new, FIDO2 key from Yubico then you have a FIDO1 key). You might also see them called CTAP1 and CTAP2 keys because CTAP is the bit of FIDO that defines the interface to the hardware tokens. (CTAP: "Client to Authenticator Protocol". See https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-client-to-authenticator-protocol-v2.0-id-20180227.html https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-cl...) FIDO2 keys talk a different protocol and do everything that FIDO1 keys do, and (potentially) more. For example, they may operate in "resident key" mode where the key remembers both your username and private key. They can also support things like PIN activation. I've only briefly poked the Yubico FIDO2 key. I think it supports a limited form of resident keys and it advertises PIN support, although I didn't exercise that.
- zxcvgm 8y agoFIDO2 is an improvement over the U2F standard, mainly with the ability to now perform password-less logins [1][2]. This had to do with a shortcoming in the U2F protocol and/or devices such that they didn't need to have much storage on these devices [3]. To address this, the new FIDO2 devices are now required to persist your username(s) for a particular site. The new CTAP2 protocol has also been extended to accommodate more sophisticated authenticators, like those crypto-currency wallets with a display. If you are looking for devices, check out reviews of various devices by agl [4] and Brad Hill [5]. [1] https://www.yubico.com/2018/04/yubico-and-microsoft-introduce-passwordless-login/ https://www.yubico.com/2018/04/yubico-and-microsoft-introduc... [2] https://fidoalliance.org/fido2/ https://fidoalliance.org/fido2/ [3] https://www.yubico.com/2014/11/yubicos-u2f-key-wrapping/ https://www.yubico.com/2014/11/yubicos-u2f-key-wrapping/ [4] https://www.imperialviolet.org/2017/10/08/securitykeytest.html https://www.imperialviolet.org/2017/10/08/securitykeytest.ht... [5] https://github.com/hillbrad/U2FReviews https://github.com/hillbrad/U2FReviews
- gandhium 8y agoMy main concern about that - I'm not 100% sure that Google will not discontinue that in couple of years. And for example: recently they've announced that 'Save to Google' extension will be discontinued in nearest weeks, without easy ways to exporting saved stuff.
- dudus 8y agoNot sure how this new Google Titan key works but Yubico doesn't rely on anything other than sites that support it. If Yubico goes under tomorrow my key will continue to work for probably many years. It's different than buying a device that needs update or server side controls. This argument doesn't really matter here.
- 394549 8y agoWhat's the difference between this and other U2F security keys? Are these just a Google-branded U2F keys, functionally identical to those from Yubico?
- w9r09eridlk 8y agoI feel stupid for asking this, but what if you lose your key?
- sonaltr 8y agoYou are supposed to have 2 keys - that way you can loose one and still have a backup.
- mimming 8y agoIt’s not as big of a deal as you might expect because: - The spec requires providers to allow independent addition / removal of multiple keys per account, so it’s easy to manage backup U2F keys. - Providers can use any backup authentication method they want. This includes SMS codes, TOTP / HOTP apps, email resets, or maybe VCing in to tech support. And even if the backup method is less awesome (e.g. sms codes) it still reduces your risk because because you use it less often. [edit for formatting]
- steve19 8y agoIs it a good way to store SSH keys? Looking at the company website is seems a little hacky.
- idlewords 8y agoIt's not a stupid question. When setting these up, you have four layers to fall back on: 1. Any other keys you added to the account (like a coworker's) 2. TOTP app like Google Authenticator 3. Printed one-time backup codes 4. Onerous account recovery process through support.
- deleted 8y ago[deleted]
- sonaltr 8y agoI am a bit disappointed they didn't add some of the features of the OnlyKey - such as passcodes (and having the ability to self destruct the contents). Those would be awesome to have if someone decides to steal your keys (yes I am aware you need your key + password -> but if someone goes through the effort to steal your keys - I'm sure a hammer can get the password out of you).
- kerng 8y agoThis really should be just part of future phones - everyone carries a phone with them. Just some creative ideas needed on how to integrate it. You heard it here first. :)
- Animats 8y agoIt's a Google product. Does it phone home to Google, or what?
- pg_bot 8y agoNo, it is a security key for universal second factor authentication. Read the spec[0] before you put on your tinfoil hat John. [0]: https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/FIDO-U2F-COMPLETE-v1.2-ps-20170411.pdf https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/FID...
- tptacek 8y agoThat's an unusually low-substance comment coming from you. Do you really believe a Google U2F key would somehow phone home to Google?
- Animats 8y agoIt has radios. Bluetooth Low Energy support, plus a near-field transponder. Seeing those functions in a security key is troublesome. It offers a lot of attack surface.
- tptacek 8y agoRight, but that's not really my question. I'm asking, do you really think Google is backdooring security tokens? Google's security team is basically at the vanguard of getting those things deployed.
- Animats 8y agoUntil there's a solid third party teardown, you just don't know. Look how many backdoors in major products have been discovered in recent years. Juniper Networks.[1] Cisco.[2] Dell.[3] ZTE.[4]. [1] https://arstechnica.com/information-technology/2016/01/juniper-drops-nsa-developed-code-following-new-backdoor-revelations/ https://arstechnica.com/information-technology/2016/01/junip... [2] https://www.bleepingcomputer.com/news/security/cisco-removes-backdoor-account-fourth-in-the-last-four-months/ https://www.bleepingcomputer.com/news/security/cisco-removes... [3] https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ https://www.theregister.co.uk/2015/11/25/dsdtestprovider/ [4] https://thehackernews.com/2016/11/hacking-android-smartphone.html https://thehackernews.com/2016/11/hacking-android-smartphone...
- obrajesse 8y agoGiven how much 'Titan' sounds like 'Feitian', I'm a little bit surprised their upstream hardware vendor would be ok with them using the brand.
- antsar 8y agoThey're probably OK with it because of the profit they stand to make from the increased visibility/marketing. To Americans, I'd guess "Feitian" sounds like "some foreign thing I've never heard of" whereas "Google Titan" feels warm and fuzzy.
- michaelmior 8y agoThis is definitely threadjacking, but curious if anyone here has tried the Yubikey Neo? I'd like to purchase a 2FA device and it seems like this is the only option with NFC which I would appreciate given how often I find I'm logging into things on my phone these days.
- jfim 8y agoThe NEO is pretty nice, especially when combined with the Yubico authenticator app for TOTP codes. One issue with the authenticator apps (eg. Google authenticator) is that if you reset your phone, you lose all your secrets and need to reset 2FA for all your accounts. With the Yubico authenticator, the secret is stored in the key and the phone only gives a time signal and authenticates to the key over NFC. The app is also available for desktops, making it pretty easy to use 2FA without having your phone. The NEO is older unfortunately, so it's only available in USB A form factor and has weaker crypto than newer Yubikeys (2048 bit vs 4096, iirc) for private keys stored in it if you're planning to use GPG (for email encryption or signing git commits). In practice, that's not a real limitation. However, it also does not support signing Docker images, which is unfortunate.
- michaelmior 8y agoI didn't realize that the Neo was so outdated. I wonder why 2FA with NFC hasn't caught on more.
- jfim 8y agoNo idea, since the NFC was actually pretty convenient. Considering the Yubico authenticator has a relatively small amount of downloads on the play store (50k), I'm guessing that feature wasn't used that much. If you're thinking of getting the USB C versions of Yubikeys and using them with your phone, it does work but since the Yubikey appears as a keyboard, it disables the Android keyboard while it's plugged in. If I remember correctly, U2F support on Android also requires installing the Google authenticator app even though you might not store any codes in it. You'd think it would be easier to have these things working.
- jrochkind1 8y agoUh, so was that last article about how these keys prevented phishing attempts at google just marketting for this product?
- pvg 8y agoWhat exactly would warrant such 'marketing'? You think Google is going to make mad money selling little USB doodads to uber-nerds?
- yjftsjthsd-h 8y agoThey could market it not because they want money, but because they want to make everybody secure.
- tptacek 8y agoI think that's what most of us think they're trying to do.
- krn 8y agoThe article makes the product look to be directed at Google Cloud customers, thus increasing its unique selling proposition over AWS and Azure.
- tptacek 8y agoAWS and Azure should provide direct support for U2F, too. It's an open standard; nothing stops either provider from doing that.
- krn 8y agoSure. But the message I get is, "Now I can use Google's phishing resistant 2FA device to protect my Google Cloud account". It's like accessing Gmail via Chrome: you know, that it's the "official way".
- taftster 8y agoHere's the thing. I don't want a device with a usb interface. Some environments are so locked down, the ability to plug in a usb device is completely unfeasible. Similarly, cell phones are not a good option in these restricted environments (one time password apps or text messages would not work). It's these types of environments where security is the most restricted that we need better two factor options. RSA SecureId tokens are a reasonable solution for local logins, but can't be used to authenticate with external resources like Google. I want to access Google, AWS (and friends) without a network (phone) or plugged (usb) device. Let me register a SecureId token or something similar with them. We need to be able to bring our own devices.
- betterunix2 8y agoBLE security keys also exist: https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/dp/B01LYV6TQM https://www.amazon.com/Feitian-MultiPass-FIDO-Security-Key/d... SecureId is a TOTP device last time I checked, which is phishable and significantly less secure than U2F devices. The sooner TOTP is phased out the better. If BLE and NFC are unacceptable, well, I guess you are stuck trying to use TPMs in some way to do U2F. Some phones already support something like that and I assume newer desktops and laptops will be capable of doing that some day.
- haberman 8y agoFor those of us with Mac laptops, is there a reason that the laptop itself with TouchID and Secure Enclave can't act as a U2F security key? Maybe that is what this is? https://github.com/github/SoftU2F https://github.com/github/SoftU2F
- veeti 8y agoChrome is doing this: https://lists.w3.org/Archives/Public/public-webauthn/2018Jun/0472.html https://lists.w3.org/Archives/Public/public-webauthn/2018Jun...
- nevir 8y agoI remember hearing that Google's main critique with yubikeys is that the newer keys' firmware is no longer open source (and thus, no longer independently verifiable). And that was, apparently, a primary motivation for breaking away from Yubico. I wonder if its firmware will be open source? The marketing page makes no mention of that
- alasdair_ 8y agoStupid and slightly unrelated point but: Yubikey need some serious work getting their product available in major retailers. I've been checking Amazon for several months looking for a Yubikey Nano on USB-C (rather than USB-A) and they still don't have them available.
- confounded 8y agoIf you like your hardware and software free and open (or like to support smaller businesses) there's also the NitroKey: https://www.nitrokey.com/ https://www.nitrokey.com/ Not quite as slim, but to me at least, cooler. Made in Berlin!
- Cthulhu_ 8y agoBeing open is really important in this case - I can't be sure there isn't some government backdoor in Google's keys, for example.
- BooneJS 8y agoIf the Google Titan Security Key is a rebadged Feitian key, why does it share a name with this piece of custom security silicon they announced a year ago? https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-security-in-plaintext.html https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-...
- bdz 8y agoWill this be available to normal Google users?