Google Replaces Titan Security Keys Due to Vulnerability

Google Replaces Titan Security Keys Due to Vulnerability

Google announced its Bluetooth security keys could be vulnerable to attack.

Google has discovered a security vulnerability so serious that it is telling users it will replace their Bluetooth Titan Security Keys for free. 

In a press release, the company said that there is a "misconfiguration in the Titan Security Keys' Bluetooth pairing protocols" that could potentially allow an attacker to gain access to your account  or device though some very specific circumstances.

One of the vulnerabilities described by Google allows an attacker within a 30-foot Bluetooth Low Energy range of your key when you press the button to authenticate a login, they could connect heir device to your security key. If they have your password, they could gain access to your account. 

Another way a bad actor could make their way into your account is when you pair your device for the first time. An attacker could "masquerade as your affected security key and connect to your device," and then do the same things on your device that other Bluetooth devices can do, like act as a keyboard or a mouse.

Google has been leading the charge in two-factor authentication (2FA) for a long time now. It has been pushing its Titan Security Keys as a more secure way to enable 2FA than simply an authentication app, or SMS. Google is not wrong about trying to add another layer of security, but there is going to be a higher level of scrutiny on any potential vulnerabilities. 

Google has made it know that if you have a "T1" or "T2" on your Titan Key, you are eligible for a replacement.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.