TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security Issue with Bluetooth Low Energy (BLE) Titan Security Keys

80 点作者 agrinman大约 6 年前

9 条评论

sisk大约 6 年前
For anyone else who has to go through the process:<p>Go to the replacement page: <a href="https:&#x2F;&#x2F;myaccount.google.com&#x2F;replacemykey" rel="nofollow">https:&#x2F;&#x2F;myaccount.google.com&#x2F;replacemykey</a><p>If you qualify for the return, there will be a box displaying the key you purchased (in my case it says &quot;Titan Security Key Bundle&quot;). If you do not see this box and you have multiple Google accounts, make sure you&#x27;ve selected the one in which you placed the order (and is paired to your account—thanks programd) by clicking on your avatar in the top right. If you&#x27;re not simply in the wrong account, Google doesn&#x27;t think you qualify.<p>At that point, you&#x27;ll end up on the shopping page. Add the replacement key (it will tell you the full price of the item but don&#x27;t worry). Proceed to checkout. On the final checkout screen, you should find a promo applied which brings your total down to $0. If you don&#x27;t, you&#x27;re probably buying another one so don&#x27;t confirm.
评论 #19922594 未加载
评论 #19922130 未加载
turtlegrids大约 6 年前
Not the most user-friendly replacement process here, Google.<p>First I had to chat with a representative, which wasn&#x27;t terrible but still took time.<p>Now I need to place a &quot;replacement order&quot; for a new set of keys. And it&#x27;s charging me $1.00 for the replacement key plus $0.07 tax.<p>And on top of all that I need to print labels for fedex, box up the old keys, and drive the ewaste box to a fedex&#x2F;kinkos&#x2F;whatever.<p>Maybe Yubikey wasn&#x27;t so terrible after all...
评论 #19922622 未加载
kevin_b_er大约 6 年前
&quot;Once paired, an attacker in close physical proximity to you could use their device to masquerade as your affected security key and connect to your device at the moment you are asked to press the button on your key. After that, they could attempt to change their device to appear as a Bluetooth keyboard or mouse and potentially take actions on your device.&quot;<p>Why is a bluetooth device allowed to spontaneously change its type and suddenly become an authenticated keyboard and&#x2F;or mouise? Could this be done to insecure BT headphones or is something specific to a security key? Is the security key actually a keyboard?
评论 #19922971 未加载
评论 #19926249 未加载
janekm大约 6 年前
Has anyone seen a description of the &quot;misconfiguration&quot;? It appears that both iOS (is) and Android (will) ship mitigations which disable the existing keys, but I can&#x27;t find a description of the actual issue.
r3bl大约 6 年前
Is this issue applicable to Feitian MultiPass key[0]? As far as I can tell, Google rebranded them as Titan Key. Ones with the Feitian&#x27;s labels were handed out by Google to activists at various conferences. I assume there&#x27;s no way they&#x27;ll be replacing those (since they were handed out for free), but it would be nice to know if they&#x27;re affected or not.<p>[0] <a href="https:&#x2F;&#x2F;www.ftsafe.com&#x2F;products&#x2F;FIDO&#x2F;Multi" rel="nofollow">https:&#x2F;&#x2F;www.ftsafe.com&#x2F;products&#x2F;FIDO&#x2F;Multi</a>
评论 #19922337 未加载
评论 #19922066 未加载
评论 #19922068 未加载
finiteloops大约 6 年前
Quick link to replacement: <a href="https:&#x2F;&#x2F;myaccount.google.com&#x2F;replacemykey" rel="nofollow">https:&#x2F;&#x2F;myaccount.google.com&#x2F;replacemykey</a>
CaliforniaKarl大约 6 年前
I’m curious, what did Apple fix in 12.3 that makes the older Titans unusable? It sounds like something Bluetooth-related.
评论 #19923859 未加载
paulie_a大约 6 年前
I wonder if the key I just ordered two hours ago will be effected. Google sent out an email they were back in stock.
hsk823大约 6 年前
The interesting tidbit here is around iOS 12.2 and 12.3 (and I assume also affects macOS 10.14.5 but people generally use USB based U2F hardware keys). In the 10.14.5 what&#x27;s new page, it says &quot;Disables accessories with insecure Bluetooth connections.&quot;