Google Turns All Android 7.0+ Phones into 2-Factor Security Keys

You should always use 2-factor authentication, or 2-step verification as Google calls it. This is the best way to keep unauthorized people from getting into your accounts, but it can be a pain to set up and use. That’s why Google has worked to make 2-step verification easier to use with devices like the Titan Security Key. That costs money, and you might already have an Android phone. Starting now, most Android phones have magically become 2-factor security keys.
Most 2-factor security keys are USB dongles, so you need to find a free port on a device and plug the hardware in. As we move from USB-A to Type-C, you may or not have the right kind of port available. Google’s Titan key solves that with Bluetooth support, and now Android phones operate in a similar fashion. You need Bluetooth and location services enabled, though.
Phone security keys can be configured on any device running Android 7.0 Nougat or higher. This feature was delivered by a Google Play Services update, so you don’t need any system OTAs. When you attempt to log into Google, your phone will generate a confirmation prompt. The Pixel 3 and 3 XL have a hardware Titan M security chip inside, so you have to press the volume down button to physically engage the chip. All other phones have a button on the screen to authorize.
Currently, you can use your phone authenticator over Bluetooth with a computer running Chrome OS, macOS, or Windows 10 with the latest stable version of Chrome (v72 as of this writing). You also need the same Google account signed in on both devices. Google is working to get the industry to standardize around the FIDO and WebAuthn standards, but support is somewhat narrow at this time.
The argument could be made that using your phone as an authenticator is a bit less secure than using an app like Google Authenticator to generate one-time codes. After all, someone just needs to tap a button within Bluetooth range of the login. However, Google only lets you set up phones as authenticators as long as you have a secure lock screen enabled. Turning on trusted locations or devices that can bypass the lock screen (a long-time feature of Android) reduced your security.
Continue reading

Intel Launches AMD Radeon-Powered CPUs
Intel's new Radeon+Kaby Lake hybrid CPUs are headed for store shelves. Here's how the SKUs break down and what you need to know.

NASA’s OSIRIS-REx Asteroid Sample Is Leaking into Space
NASA reports the probe grabbed so much regolith from the asteroid that it's leaking out of the collector. The team is now working to determine how best to keep the precious cargo from escaping.

Chromebooks Gain Market Share as Education Goes Online
Chromebook sales have exploded in the pandemic, with sales up 90 percent and future growth expected. This poses some challenges to companies like Microsoft.

Intel’s Raja Koduri to Present at Samsung Foundry’s Upcoming Conference
Intel's Raja Koduri will speak at a Samsung foundry event this week — and that's not something that would happen if Intel didn't have something to say.