Connect with us

Google

Google’s super secure Titan Security keys have a major security issue, imagine that

A security vulnerability was found in the T1 and T2 versions.

google titan security key on blue table
Image: Joe Rice-Jones / KnowTechie
Giveaway: Enter to win a BLUETTI Charger 1 ($399 value): Enter Here

Just a heads up, if you buy something through our links, we may get a small share of the sale. It’s one of the ways we keep the lights on here. Click here for more.

If you own Google Bluetooth Titan Security Key, you might want to head on over to Replace My Key and see if your device is part of a replacement program. That’s because of a security bug in the device that Google disclosed yesterday. This affects all Bluetooth models of the security key marked with a T1 or T2 on the back.

The keys were sold for $50 as part of a two-pack, with a standard USB/NFC key inside the same package. Google also gave them out free to journalists and other targets of online attacks to protect themselves.

The bug in the Bluetooth versions of the Titan Security Keys is a “misconfiguration in the Bluetooth pairing protocols”

That could mean an attacker taking over your device, although they’d need the stars to align to pull it off.

For the exploit to happen, an attacker would need:

  1. Your login name and password
  2. To be within 30 feet of you
  3. Pair to your device as soon as you press the button on the Titan Key

As you can see, that’s not going to happen unless it’s a very determined attacker, so the chances of it happening are slim. Still, Google is taking the proactive route and offering free replacements for anyone who has one of the affected Titan Security Keys. Check if your key has a T1 or T2 on the back, and then go to the site Google set up to get a replacement.

In the blog post announcing the bug, Google makes the case that it doesn’t affect the main reason to have a security key – namely phishing protection. The company says to keep on using the key until the replacement arrives, as “it is much safer to use the affected key than no key at all.”

Phew, I thought I was going to have to replace yet another Google device but mine is a version 3.

What do you think? Do you have one of the models affected by the issue? Let us know down below in the comments or carry the discussion over to our Twitter or Facebook.

Editors’ Recommendations:

Follow us on Flipboard, Google News, or Apple News

Maker, meme-r, and unabashed geek with nearly half a decade of blogging experience at KnowTechie, SlashGear and XDA Developers. If it runs on electricity (or even if it doesn't), Joe probably has one around his office somewhere, with particular focus in gadgetry and handheld gaming. Shoot him an email at joe@knowtechie.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

More in Google