Google Boosts Cybersecurity with Security Key Requirement

Google Boosts Cybersecurity with Security Key Requirement

Google employees have successfully dodged phishing attempts for over a year thanks security keys and two-factor authentication.

One of the biggest ways companies are infiltrated by hackers is through phishing. Attackers craft an email that looks just like something you'd normally click on, like a bill or an email telling you to change your password but instead the user is giving their information away - making their account vulnerable.

Google seems to have solved this phishing problem with a $20 security key it requires all its employees to use.

None of Google's 85,000 employees have successfully been phished on their work accounts since it started requiring the extra security to log in, the company said.

"We have had no reported or confirmed account takeovers since implementing security keys at Google," the company told Business Insider.

Google took the security of their employee's accounts to the extreme. Usually when employees sign on using two-factor authentication, you put in your username and password and then enter a code that comes through a text or app. Google requires that employees insert a security key instead of the code, bolstering the security of the accounts.

In October, Google launched an advanced protection program involving security keys for people at the highest risk of being phished, including journalists, business leaders and activists. Google has worked with several industry groups, such as the FIDO Alliance, to develop security-key technology called U2F.

A 2016 Google study found that text-message or app-based two-factor authentication, sometimes called "one-time password," had an average failure rate of 3%, while the U2F or security-key approach had a 0% failure rate.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.