Connect with us

Google

Google’s super secure Titan Security keys have a major security issue, imagine that

A security vulnerability was found in the T1 and T2 versions.

google titan security key on blue table
Image: Joe Rice-Jones / KnowTechie

If you own Google Bluetooth Titan Security Key, you might want to head on over to Replace My Key and see if your device is part of a replacement program. That’s because of a security bug in the device that Google disclosed yesterday. This affects all Bluetooth models of the security key marked with a T1 or T2 on the back.

The keys were sold for $50 as part of a two-pack, with a standard USB/NFC key inside the same package. Google also gave them out free to journalists and other targets of online attacks to protect themselves.

The bug in the Bluetooth versions of the Titan Security Keys is a “misconfiguration in the Bluetooth pairing protocols”

That could mean an attacker taking over your device, although they’d need the stars to align to pull it off.

For the exploit to happen, an attacker would need:

  1. Your login name and password
  2. To be within 30 feet of you
  3. Pair to your device as soon as you press the button on the Titan Key

As you can see, that’s not going to happen unless it’s a very determined attacker, so the chances of it happening are slim. Still, Google is taking the proactive route and offering free replacements for anyone who has one of the affected Titan Security Keys. Check if your key has a T1 or T2 on the back, and then go to the site Google set up to get a replacement.

In the blog post announcing the bug, Google makes the case that it doesn’t affect the main reason to have a security key – namely phishing protection. The company says to keep on using the key until the replacement arrives, as “it is much safer to use the affected key than no key at all.”

Phew, I thought I was going to have to replace yet another Google device but mine is a version 3.

What do you think? Do you have one of the models affected by the issue? Let us know down below in the comments or carry the discussion over to our Twitter or Facebook.

Editors’ Recommendations:

Maker, meme-r and unabashed geek. Hardware guy here at KnowTechie, if it runs on electricity (or even if it doesn't) I probably have one around here somewhere. My hobbies include photography, animation and hoarding Reddit gold.

Comments

More in Google