Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Friday May 17 2019, @10:47PM   Printer-friendly
from the when-an-air-gap-is-NOT-your-friend dept.

Google is warning that the Bluetooth Low Energy version of the Titan security key it sells for two-factor authentication can be hijacked by nearby attackers, and the company is advising users to get a free replacement device that fixes the vulnerability.

A misconfiguration in the key's Bluetooth pairing protocols makes it possible for attackers within 30 feet to either communicate with the key or with the device it's paired with, Google Cloud Product Manager Christiaan Brand wrote in a post published on Wednesday.

[...] To tell if a Titan key is vulnerable, check the back of the device. If it has a "T1" or "T2," it's susceptible to the attack and is eligible for a free replacement. Brand said that security keys continued to represent one of the most meaningful ways to protect accounts and advised that people continue to use the keys while waiting for a new one. Titan security keys sell for $50 in the Google Store.

While people wait for a replacement, Brand recommended that users use keys in a private place that's not within 30 feet of a potential attacker. After signing in, users should immediately unpair the security key. An Android update scheduled for next month will automatically unpair Bluetooth security keys so users won't have to do it manually.

Source: ArsTechnica

[Note: Though it cautions about attackers within 30 feet (approximately 10 meters), the distance could be potentially much greater than that depending on the design of the antenna used by the attacker; cf an analogous technique described in How To Make a Wi-Fi Antenna Out Of a Pringles Can. --Ed.]


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 5, Touché) by Anonymous Coward on Friday May 17 2019, @11:04PM (1 child)

    by Anonymous Coward on Friday May 17 2019, @11:04PM (#844870)

    Using a Google device to protect your privacy... LOL!

    • (Score: -1, Troll) by Ethanol-fueled on Saturday May 18 2019, @02:18AM

      by Ethanol-fueled (2792) on Saturday May 18 2019, @02:18AM (#844904) Homepage

      Hey, Chinaman, lay off my IP camera. It's not like you and the Jews have stolen all our military secrets or anything.

      " Because we can live with it. We will live with it. We will learn..."

  • (Score: 1, Funny) by Anonymous Coward on Friday May 17 2019, @11:22PM

    by Anonymous Coward on Friday May 17 2019, @11:22PM (#844874)

    Blimps are the solution. Have it hover exactly 30 feet above the device so that no hacker can get closer than that.

(1)