20 ms·
Google Titan Security Key now available
- sschueller 8y agoI only see Chromecast and Chromecast Audio on this page.
- jeeva 8y agoUK, same issue. Possibly only available on the US store, or similar?
- squaredpants 8y agoUS only, it seems.
- breakingcups 8y agoI don't see them either, it might be region-bound.
- buzer 8y agoLikely US only. I can access the page via https://store.google.com/us/product/titan_security_key_kit https://store.google.com/us/product/titan_security_key_kit, but ordering would likely require US address.
- ktta 8y agoHere's a wayback machine link: http://web.archive.org/web/20180830111650/https://store.google.com/product/titan_security_key_kit/ http://web.archive.org/web/20180830111650/https://store.goog...
- pjmlp 8y agoAlso not visible in Germany.
- desdiv 8y agoSame here. Use this link to force-redirect to the US product page: https://store.google.com/us/product/titan_security_key_kit?hl=en-US https://store.google.com/us/product/titan_security_key_kit?h... (mods, can we please change the story URL to the above one? It should show the correct item globally and thus leaving less people confused.)
- throwawaymath 8y agoAm I correct in my understanding that this will only work for Google devices? It states that, but at least for the physical U2F key I don’t see why that wouldn’t also work on a non-Google device. EDIT: Revisting, it states anything running Google Chrome should also work. So I guess macOS should be fine, what about iOS?
- dgacmu 8y agoThe Bluetooth one works for iOS. I'm not sure about connecting a USB one in some way - haven't tried.
- Ded7xSEoPKYNsDd 8y ago(I got these at a Google thing at DEF CON.) Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google software on Android (Lineage) that can talk to them.
- __float 8y agoI asked at DEF CON about these, but they said they were not the same as the Titan. Hardware looks to be the same, but they may not have the Titan firmware, but rather the original Feitian one. I...don't actually know how to verify that claim though.
- grepthisab 8y agoPretty cool, I like that it comes with two keys at the start so you have a backup, unlike Yubi where I have to buy two before I can even get started in earnest. Still living the dongle life though, but it appears to come with its own usb a -> c adapter at least.
- h8trswana8 8y agoIt’s so big. Couldn’t they have come up with a more subtle form factor?
- deleted 8y ago[deleted]
- craftyguy 8y agoTBF, it does have 'titan' in the name.
- scrrr 8y agoIsn't this the same as a code app like Authy? Why carry the extra dongle?
- matharmin 8y agoSimilar use case (2FA), but different implementation. Instead of typing in a code, you press a button. It also protects against phishing by validating the URL of the site you're authenticating on (with a code-based 2FA you can still enter your code on a phishing site, which then forwards it to the real one).
- scrrr 8y agoGood reasons, thanks!
- m_eiman 8y agoThere are apps that also validate the source and can automatically sign you in (or require a button press), e.g. https://www.kryptco.com https://www.kryptco.com Seems like it might be useful, but haven't had the time to try it out yet.
- tialaramex 8y agoAIUI Krypton is basically doing the same thing as these FIDO2 Security Keys, but their software substitutes an app on your Phone for the Security Key. So a web site offering WebAuthn can't tell the difference (unless you allow it to interrogate the "Security Key" to ask who made it, which you probably shouldn't) I personally would rather have Security Keys, but a solution like Krypton is definitely easier for a lot of users and obviously the price differential is hard to argue with.
- ZiiS 8y agoAn app has a much larger attack surface (for instance from malware on the phone). TOTP has to use short easy to enter codes (six digit numbers), Titan is doing a full handshake using modern cryptography with sensable key lengths. In many use cases pushing the button on the key is quicker/easier then using the app.
- Someone1234 8y agoThe wireless key is the "Feitian MultiPass FIDO Security Key" I'd caution people to read the Amazon reviews (specifically people found it unreliable and it would break if dropped/roughly handled). They both seem to be re-branded Feitian, which cost less ($25 + $17 = $42) when purchased under that brand from Amazon than the Google Titan moniker.
- rahimnathwani 8y ago"Firmware for Titan Security Keys is engineered by Google, to verify the key’s integrity."
- Someone1234 8y agoThat won't resolve many of the negative reviews of the MultiPass key, since they're complaints over the physical design and usage.
- rahimnathwani 8y agoYes. Sorry I should have made it clear I was addressing the second part of your comment, i.e. a reason to pay $50 for hardware you can get for $42 elsewhere
- amelius 8y agoGiven the recent amount of reports of counterfeiting on Amazon (not specifically this product), I'd buy my security keys elsewhere.
- frockington 8y agoI assume everything on Amazon is a counterfeit and plan accordingly. Have you heard anything about Walmart? They have free two day shipping and I haven't heard any counterfeit horror stories (yet)
- felix_nagaand 8y ago
- kennydude 8y agoIs that a dongle to use it on the surface-style-thing? Whyyyyyyy
- dewey 8y agoIt's a USB C Adapter
- therealmarv 8y ago1. why not going from usb-c to usb A with adapter than the other way round (this laptop photo looks so ugly with the usb-c->usb A adapter). 2. this link does not work outside US
- fredley 8y agoCan't see the page, but that there is not a USB C variant is bonkers. All Google engineers I know use mac devices.
- jrockway 8y agoI use a Mac at work. It has 0 USB Type C ports. The only computer I own that has a USB Type C port is my homebuilt desktop, and it's on the back, and I don't think the Windows driver actually works.
- fredley 8y agoI'm not suggesting they should only produce a USB C variant, I'm suggesting that they produce a USB C variant.
- psychometry 8y agoYou should know that Apple moved to USB-C only for its Macbook line years ago.
- mikelward 8y agoMost of the Google engineers I know use Chromebooks and Linux laptops. Most Chromebooks also only have USB C.
- desdiv 8y agoThis link should work everywhere: https://store.google.com/us/product/titan_security_key_kit?hl=en-US https://store.google.com/us/product/titan_security_key_kit?h...
- ryukafalz 8y ago
- Operyl 8y agoAre both keys configured with the same underlying keys? Each key bundle comes with a physical USB security key and a Bluetooth security key—one for your primary use and one for safe keeping.
- suprfsat 8y agoEach key is unique. You add both of them to your account.
- ekingr 8y agoThe description doesn't say if the keys are compatible with FIDO2 / Webauthn, which seem to be the new standard superseding FIDO (namely with password-less and multi-factor auth). It would be disappointing if not...
- spuz 8y ago$50 seems very expensive. The actual hardware probably does not cost more than $10 and I can't see adoption of FIDO keys becoming widespread unless companies are willing to sell keys at or below cost.
- 16bytes 8y agoYubikeys are about the same cost: https://www.yubico.com/product/yubikey-4-series/ https://www.yubico.com/product/yubikey-4-series/ What makes you think that the cost to produce the hardware is less than $10? And what reason would companies have to offer keys below cost?
- MikeKusold 8y agoThe Yubikey 4 also provide more functionality such as PGP. This is more like the Yubikey Security Key ($20): https://www.yubico.com/product/security-key-by-yubico/#security-key https://www.yubico.com/product/security-key-by-yubico/#secur...
- spuz 8y agoIf a bluetooth locator tag is only about £3.34 [1], then a tag with an encryption chip should not be 10x the cost. Google has an incentive for their keys to become widespread and well adopted because people will associate their brand with "high security". It also actually helps Google if they don't have to deal with support requests from users who've had their accounts compromised. [1]http://amzn.eu/d/bMowBkS http://amzn.eu/d/bMowBkS
- michaelt 8y agoThe open-source U2F Zero claims ~$3 of parts and a ~$2 PCB [1] ordering a single unit. Making a large volume, that price is only going to come down. Admittedly you'd have to pay for a plastic case, assembly costs, an envelope and stamps. But if I can get a 16GB flash drive for $8 with free shipping [2] the plastic case, assembly etc can't be that expensive! [1] https://github.com/conorpp/u2f-zero https://github.com/conorpp/u2f-zero [2] https://www.amazon.com/SanDisk-Cruzer-Low-Profile-Drive-SDCZ33-016G-B35/dp/B005FYNSZA/ https://www.amazon.com/SanDisk-Cruzer-Low-Profile-Drive-SDCZ...
- locusm 8y agoWhat does this offer over Yubi?
- ekingr 8y agoThe wireless one has Bluetooth - which is the only way to go on iOS for now.
- carc1n0gen 8y agoYou may be interested in some yubikey iOS news that came out in may https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-mobile-sdk-for-ios-and-lastpass-support/ https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-...
- ekingr 8y agoYes. Unfortunately it is still only OTP (vulnerable to fishing). Let’s hope that one day Apple opens full access to the NFC chip.
- stephengillie 8y agoHow secure is Bluetooth - how do we know snoopers aren't stealing keys wirelessly?
- mkj 8y agoThe most likely snoopers are far far away, probably even a different timezone. If you have local burglars around they'll just break your windows and doors to get things anyway. (And Bluetooth isn't that bad either?)
- numbsafari 8y agoOr just sit down next to you for a few minutes until you use your device and then walk away? I'd rather force them to smash my windows and doors rather than just give them what they want in passing.
- floor_ 8y agoThe countdown starts and runs until some 12 year old breaks it wide open.
- deleted 8y ago[deleted]
- estomagordo 8y agoIs it sort of a ubikey?
- amelius 8y agoCan I use it for my bank too?
- mkj 8y agoMaybe in a few years time
- moviuro 8y agoHaha, probably not[0]. [0] https://twofactorauth.org/#banking https://twofactorauth.org/#banking
- Postosuchus 8y agoNot really if your bank doesn't support U2F and/or TOTP.
- jrockway 8y agoVanguard lets you use a security key as a second factor. It is the only finance-related website I've ever seen that does so. (And it's probably because Google made them, as that's where my Google 401k was.)
- the-peter 8y agoVanguard? That's a laugh. There's a link on the login page "I don't have my device with me, send me an SMS instead". This cannot be disabled.
- zaarn 8y agoFor 50$ I don't really see the point in this, Yubikey already asks this much. I'll probably wait out for the FIDO2 upgrade on the u2fzero...
- amelius 8y agoNice for humans, but these dongles don't solve the problem of automated background services having to log in to machines to complete their tasks. How do people solve this problem?
- moviuro 8y agoPer-purpose passwords. https://support.google.com/accounts/answer/185833?hl=en https://support.google.com/accounts/answer/185833?hl=en Per-purpose users (with very limited rights) on machines, inside per-purpose VMs (with very limited network if any)... etc.
- jrockway 8y agoA persistent token like OAuth. Generally, you want these to be time-limited, scope-limited, and traceable to a human (probably issued by touching a security key). Part of the idea behind the security key is to prove that a human is requesting access and that is why there is a button to press. If your application is designed to give privileges to robots, then a security key is completely orthogonal to that.
- Postosuchus 8y agoThe store page sucks balls - no details whatsoever! Does anyone know how these keys could be used for TOTP? In case of Yubikey one could use an app which effectively acted as a proxy between the TOTP-based system and a hardware key. Does the Google key support the same functionality?
- anilakar 8y agoThese devices don't have a real-time clock, so TOTP is out of the question. A Yubikey by itself is incapable of doing TOTP, too – it just acts as a hardware authenticator for the actual password generator. HOTP/counter mode doesn't have this requirement.
- helper 8y agoYubikey does support storing TOTP secrets. It requires you use their app (desktop or android) which then provides the time component.
- anilakar 8y agoIs it possible to use the Bluetooth dongle with a desktop computer without a cable? Having to carry both on your keyring kind of defeats the purpose, because even Google's own guidelines tell you to store one in a safe place and keep the other one in daily use.
- hesdeadjim 8y agoYea I was wondering this too.
- meanmartine 8y agoYeah, no thanks
- Demoneeri 8y agoExcuse my ignorance (I'm trying to understand by googling). I know it's not the same technology but is it the same concept (public/private key) as for example the Estonian government uses for identity and accessing government services?
- jameskegel 8y agoHow would Google Titan improve the 2F experience for someone who already uses a dongle-key device like a Yubikey, for example?
- ecesena 8y agoIt's pretty much the same. One of these keys has bluetooth so it also works with iphone without any cable.
- amingilani 8y agoThe Feitan key's Bluetooth works with Android and iPhone but it won't work with your Mac or Windows. I own one, that bit was an unexpected pain for me.
- ecesena 8y agoThe problem I think is the browser, e.g. Chrome only implements CTAP over USB. The Secure Click (yet another security key) is sold with a usb2ble dongle, so you can use it wirelessly also with your laptop/desktop.
- amingilani 8y agoIt won't. Stick with what you have, it's essentially a bundle to help non-U2F owners start with their Advanced Protection Program.
- deleted 8y ago[deleted]
- amingilani 8y agoQuestion for Advanced Protection and Mac users. Have you managed to authenticate your Google account with your U2F keys on your Mac? If you have, please help the rest of us out, I get an error: > You can only use your Security Keys with Google Chrome. Here's a StackExchange question for some karma: https://apple.stackexchange.com/questions/327491/how-do-i-use-a-u2f-token-when-adding-a-google-account-to-my-macbook-pro https://apple.stackexchange.com/questions/327491/how-do-i-us...
- steven2012 8y agoI would prefer one from Apple. I don't trust Google as much as I do Apple, simply because I know they don't make money from my data. The fact that the FBI couldn't get into an iPhone makes me trust Apple much more. If I start using this Google key, I'm not sure how far in bed they are with the government and if they can crack my accounts.
- guessmyname 8y agoI would prefer one from Apple as well, but mostly because my laptop (which was built by Apple) only has USB-C ports, so carrying an USB-A adapter, like the one shown in the picture [1], would be a deal breaker for me and many others. Something like the YubiKey 4C Nano [2] would be good. [1] https://i.imgur.com/79ojvAK.jpg https://i.imgur.com/79ojvAK.jpg [2] https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-nano https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-...
- toyg 8y agoIsn't it incredibly risky to leave it in-port? If the laptop is stolen, the thief also gets all your logins...
- patejam 8y agoIf someone has physical access, isn't it considered compromised anyway?
- ufmace 8y agoIf it gets stolen, and the thief is actually trying to take over your accounts, then the process of proving that you are the rightful owner is probably easier if you have the key than if the thief has both the laptop and the key.
- jonahhorowitz 8y agoIf you're clever about it, you can do U2F using the secure enclave built into touchID. You don't even need a separate device.
- alecbenzer 8y agoWhat's the summary on how security keys compare to Google's tap-to-sign-in flow? https://support.google.com/accounts/answer/7026266?co=GENIE.Platform%3DAndroid&hl=en https://support.google.com/accounts/answer/7026266?co=GENIE....
- nikolay 8y ago"Available" just like Google One is? I hate when people make things "available" this way! Don't they know the meaning of the word?!
- jamesgeck0 8y agoThat's on the person who submitted, not Google. The word "available" doesn't appear on the page in regards to this product.
- nikolay 8y agoI already gave my email to Google that I'm interested and now I need to be added to yet another waiting list? What's the point? All this buzz is actually hurting Google as people become aware of these products and services and because Titan is not immediately available, they will end up with alternatives such as YubiKey.
- nikolay 8y agoAnd, for the record, Google sent me an email that Google One is available, but it is not.
- extrapolate 8y agoAnyone able to actually purchase one? I'm just seeing a "Join waitlist" button.
- mitchtbaum 8y agoI would rather use something like this: https://www.thingiverse.com/thing:1970583 https://www.thingiverse.com/thing:1970583
- Thriptic 8y agoIs it possible to set up advanced protection on the ipad using the camera adapter and a yubikey, or a bluetooth key required?
- johntash 8y agoJust to make sure.. these don't provide GPG/PGP smartcard support, right?