Google Turns All Android 7.0+ Phones into 2-Factor Security Keys

Google Turns All Android 7.0+ Phones into 2-Factor Security Keys

You should always use 2-factor authentication, or 2-step verification as Google calls it. This is the best way to keep unauthorized people from getting into your accounts, but it can be a pain to set up and use. That’s why Google has worked to make 2-step verification easier to use with devices like the Titan Security Key. That costs money, and you might already have an Android phone. Starting now, most Android phones have magically become 2-factor security keys.

Most 2-factor security keys are USB dongles, so you need to find a free port on a device and plug the hardware in. As we move from USB-A to Type-C, you may or not have the right kind of port available. Google’s Titan key solves that with Bluetooth support, and now Android phones operate in a similar fashion. You need Bluetooth and location services enabled, though.

Phone security keys can be configured on any device running Android 7.0 Nougat or higher. This feature was delivered by a Google Play Services update, so you don’t need any system OTAs. When you attempt to log into Google, your phone will generate a confirmation prompt. The Pixel 3 and 3 XL have a hardware Titan M security chip inside, so you have to press the volume down button to physically engage the chip. All other phones have a button on the screen to authorize.

Currently, you can use your phone authenticator over Bluetooth with a computer running Chrome OS, macOS, or Windows 10 with the latest stable version of Chrome (v72 as of this writing). You also need the same Google account signed in on both devices. Google is working to get the industry to standardize around the FIDO and WebAuthn standards, but support is somewhat narrow at this time.

The argument could be made that using your phone as an authenticator is a bit less secure than using an app like Google Authenticator to generate one-time codes. After all, someone just needs to tap a button within Bluetooth range of the login. However, Google only lets you set up phones as authenticators as long as you have a secure lock screen enabled. Turning on trusted locations or devices that can bypass the lock screen (a long-time feature of Android) reduced your security.

Continue reading

The Best Smart Home Security Systems
The Best Smart Home Security Systems

Once a niche business with a few traditional players and some startups, home security systems are now a major battleground for not just security companies, but several internet giants. We round up highlights of the most popular options for 2020.

Microsoft: Pluton Chip Will Bring Xbox-Like Security to Windows PCs
Microsoft: Pluton Chip Will Bring Xbox-Like Security to Windows PCs

Intel, AMD, and Qualcomm are working to make Pluton part of their upcoming designs, which should make PCs more difficult to hack, but it also bakes Microsoft technology into your hardware.

Security Researcher: ‘solarwinds123’ Password Left Firm Vulnerable in 2019
Security Researcher: ‘solarwinds123’ Password Left Firm Vulnerable in 2019

SolarWinds, the company at the center of the massive hack that hit US government agencies and corporations, doesn't exactly use cutting-edge password techniques.

A File Sharing App With 1 Billion Downloads Has a Major Security Flaw
A File Sharing App With 1 Billion Downloads Has a Major Security Flaw

Trend Micro says SHAREit is a security nightmare that could allow intruders to sneak a peek at your data or even install malware. Perhaps most troublingly, the developers have not responded to Trend Micro's warnings.