Google issues USB keys for Chrome users to log into Google accounts and any other websites that support FIDO universal two-factor authentication -- but it's no help to mobile users.
Google today expanded two-factor authentication (2FA) for Google account users and opened the door for other websites to offer 2FA to customers who visit their sites through Google Chrome.
Google launched support for Security Key, making Chrome the first browser to implement support for Fast Identity Online (FIDO) Universal Two-Factor (U2F) Authentication -- an open-source standard that lets users log in with a password and a variety of physical devices. Those devices may include USB keys, Bluetooth devices, NFC, biometrics, and smartcards, but for now Google only supports USB keys that are "FIDO-ready."
Google will continue to offer Google account holders its existing two-factor authentication method, in which a user manually enters a six-digit code sent to their mobile phone. However, as the company explains:
...sophisticated attackers could set up lookalike sites that ask you to provide your verification codes to them, instead of Google. Security Key offers better protection against this kind of attack, because it uses cryptography instead of verification codes and automatically works only with the website it's supposed to work with.
The drawback of Security Key, of course, is that it only works on devices that have USB ports -- thereby counting out most mobile phones and Apple devices.
Several companies recently released new lines of FIDO-ready devices -- including Duo Security, Entersekt, Infineon, NXP, Nok Nok Labs, Plug-up International, ST Microelectronics, Sonavation, StrongAuth, SurePassID, and Yubico.
About the Author(s)
You May Also Like
Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024