Google Replaces Titan Security Keys Due to Vulnerability

Google Replaces Titan Security Keys Due to Vulnerability

Google announced its Bluetooth security keys could be vulnerable to attack.

Google has discovered a security vulnerability so serious that it is telling users it will replace their Bluetooth Titan Security Keys for free. 

In a press release, the company said that there is a "misconfiguration in the Titan Security Keys' Bluetooth pairing protocols" that could potentially allow an attacker to gain access to your account  or device though some very specific circumstances.

One of the vulnerabilities described by Google allows an attacker within a 30-foot Bluetooth Low Energy range of your key when you press the button to authenticate a login, they could connect heir device to your security key. If they have your password, they could gain access to your account. 

Another way a bad actor could make their way into your account is when you pair your device for the first time. An attacker could "masquerade as your affected security key and connect to your device," and then do the same things on your device that other Bluetooth devices can do, like act as a keyboard or a mouse.

Google has been leading the charge in two-factor authentication (2FA) for a long time now. It has been pushing its Titan Security Keys as a more secure way to enable 2FA than simply an authentication app, or SMS. Google is not wrong about trying to add another layer of security, but there is going to be a higher level of scrutiny on any potential vulnerabilities. 

Google has made it know that if you have a "T1" or "T2" on your Titan Key, you are eligible for a replacement.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • Research: Cybersecurity Success Hinges on Full Organizational Support

    Cybersecurity is the top technology priority for the vast majority of organizations, but moving from aspiration to reality requires a top-to-bottom commitment that many companies have yet to make, according to new research released today by CompTIA, the nonprofit association for the technology industry and workforce. Read Now

  • Live from GSX 2024: Day 3 Recap

    And GSX 2024 in Orlando, is officially in the books! I’d like to extend a hearty congratulations and a sincere thank-you to our partners in this year’s Live From program—NAPCO, Eagle Eye Networks, Hirsch, and LVT. Even though the show’s over, keep an eye on our GSX 2024 Live landing page for continued news and developments related to this year’s vast array of exhibitors and products. And if you’d like to learn more about our Live From program, please drop us a line—we’d love to work with you in Las Vegas at ISC West 2025. Read Now

    • Industry Events
    • GSX
  • Bringing New Goods to Market

    The 2024 version of GSX brought with it a race to outrun incoming hurricane Helene. With it’s eye on Orlando, it seems to have shifted and those security professionals still in Orlando now have a fighting chance to get out town. Read Now

    • Industry Events
    • GSX
  • Live from GSX 2024: Day 2 Recap

    Day 2 was another winner at GSX 2024 in Orlando. Aisles and booths were packed with attendees looking at some of the new and latest security technology. Remember to follow the GSX Live page from Security Today, as well as SecurToday on X and Security Today on LinkedIn to find out more about what’s happening on the show floor during tomorrow’s final day. Here’s what was happening with all four of our partners during the event on Tuesday. Read Now

    • Industry Events
    • GSX

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3