Google makes safe logins more convenient by allowing smartphones to be security keys
Full article551 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It's the latest anti-phishing effort from Google's Advanced Protection team.
Google users can now use an iPhone or Android device as a security key to sign into their accounts, utilizing a technique that improves their defense against phishing attacks, the company announced Wednesday.
In a blog post, a product manager for Google’s Advanced Protection Program wrote that people who exclusively use security keys when logging in to their accounts “never fell victim to targeted phishing attacks.” Yet security keys, which are more secure than text-based authentication, typically are available in the form of a standalone physical device, an inconvenience that may discourage adoption.
Google’s update Wednesday is a significant step toward solving that problem. Instead of plugging a key into a USB slot, users just need to have their phones close to their machines.
“Everything becomes much simpler when the things we’re already carrying around — our smartphones — have a built-in security key,” Shuvo Chatterjee said in the post. “That’s been the case on Android since last year, and starting today you can activate a security key on your iPhone as well. Millions of people around the world — many high-risk users among them — use iPhones, and this new capability makes Advanced Protection significantly easier for them.”
It works like this: A user connects their phone to their computer via Bluetooth. A Google login attempt on a computer triggers a push notification to the phone, and they’re required to press a button on Google’s Smart Lock app to complete the authentication process.
The effort coincides with other security initiatives from Google, such as the expansion of “predictive phishing” tools meant to protect credentials in Chrome.
The upgrade comes amid a growing recognition that, while text-based two-factor authentication provides more security than only a username and password, that technique is not the most secure option. Security hardware options like Yubico’s Yubikey have made advancements, while other technologies like password management tools also are experiencing new interest.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/google-smartphone-security-key-hardware/