Google Physical Authenticator (Titan) Recall

Questions on how we spend our money and our time - consumer goods and services, home and vehicle, leisure and recreational activities
Post Reply
Topic Author
mhalley
Posts: 6856
Joined: Tue Nov 20, 2007 6:02 am

Google Physical Authenticator (Titan) Recall

Post by mhalley » Wed May 15, 2019 5:22 pm

2 fa is discussed fairly frequently here, heads up on Article on a vulnerability of physical google authenticators.
https://gizmodo.com/google-recalls-phys ... 1834788835
. Titan—the physical security Google rolled out last summer—was built to “protect high-value users.” Now those users who bought in on Titan are all eligible for free replacements of this $50 device suite after the company discovered a vulnerability in the way it operates.
Due to a misconfiguration in the Titan Security Keys’ Bluetooth pairing protocols, it is possible for an attacker who is physically close to you at the moment you use your security key — within approximately 30 feet — to (a) communicate with your security key, or (b) communicate with the device to which your key is paired.
Lots of things have to line up just right for this exploit to be effective, and Google is not aware of this exploit being used to gain access to user data in the wild.

HEDGEFUNDIE
Posts: 2397
Joined: Sun Oct 22, 2017 2:06 pm

Re: Google Physical Authenticator (Titan) Recall

Post by HEDGEFUNDIE » Wed May 15, 2019 5:36 pm

Switched from Google to Authy years ago and haven’t had a problem.

Whakamole
Posts: 911
Joined: Wed Jan 13, 2016 9:59 pm

Re: Google Physical Authenticator (Titan) Recall

Post by Whakamole » Wed May 15, 2019 5:41 pm

HEDGEFUNDIE wrote:
Wed May 15, 2019 5:36 pm
Switched from Google to Authy years ago and haven’t had a problem.
This story is referring to a physical device similar to a Yubikey, not an app-based authenticator.

User avatar
catalina355
Posts: 162
Joined: Sun Jun 10, 2018 6:46 pm

Re: Google Physical Authenticator (Titan) Recall

Post by catalina355 » Wed May 15, 2019 5:44 pm

HEDGEFUNDIE wrote:
Wed May 15, 2019 5:36 pm
Switched from Google to Authy years ago and haven’t had a problem.
Just because you have not had a "problem" does not mean there is not a security issue.

bluquark
Posts: 445
Joined: Mon Oct 22, 2018 2:30 pm

Re: Google Physical Authenticator (Titan) Recall

Post by bluquark » Wed May 15, 2019 10:26 pm

Vanguard did not support this type of security key anyway.

Post Reply