Google Adds Physical Security Key Support to 2-Step Verification

Advertisement
By Ketan Pratap | Updated: 22 October 2014 13:23 IST
Google has beefed up its 2-step Verification process by enabling support for a Security Key, a physical USB second factor.

The company details that the physical USB second factor only works after it verifies the site the user is attempting to log in to is a Google website and not a fake site attempting a phishing attack.

(Also see: How to Enable Two-Factor Authentication For Gmail, Facebook, Apple, Twitter, Outlook, Yahoo Accounts)

Advertisement

Google in a blog post titled "Strengthening 2-Step Verification with Security Key" announced the new Security Key support, saying, "Today we're adding even stronger protection for particularly security-sensitive individuals. Security Key is a physical USB second factor that only works after verifying the login site is truly a Google website, not a fake site pretending to be Google."

The company details that the Security Key and Chrome incorporate the open Universal 2nd Factor (U2F) protocol from the FIDO Alliance. This means websites that use the same U2F protocol can access Security Key's features in Chrome.

Advertisement

Google reveals that the Security Key works with Google Accounts at no charge, but users are required to buy a compatible USB device directly from a U2F participating vendor. The Mountain View giant also provided a link to online retail giant Amazon that lists FIDO U2F Security Key USB devices, with prices starting as low as $5.99 (roughly Rs. 370), and warned users to look for the 'FIDO U2F Ready' logo.

The search giant says users will be able to log in safely by just inserting the Security Key into the computer's USB port as a second factor for verification when prompted in Chrome; rather than by typing a code. "When you sign into your Google Account using Chrome and Security Key, you can be sure that the cryptographic signature cannot be phished," it added.

Advertisement

Google claims that the Security Key offers "protection even beyond what using verification codes sent to your phone gives" and details few examples of phishing attacks. It notes, "With 2-Step Verification, Google requires something you know (your password) and something you have (like your phone) to sign in. Google sends a verification code to your phone when you try to sign in to confirm it's you. However, sophisticated attackers could set up lookalike sites that ask you to provide your verification codes to them, instead of Google. Security Key offers better protection against this kind of attack, because it uses cryptography instead of verification codes and automatically works only with the website it's supposed to work with."

The search engine giant also lists some limitations of the Security Key in 2-step Verification, such as the requirement of a USB port to use the Security Key, and that the feature does not work on browsers other than Chrome.

Advertisement

Last month, a stash of roughly 5 million usernames and passwords of Google accounts (including Gmail, Google+) was reported to have been found on a Russian forum for Bitcoin security. The company responded on the claims and said, "We found that less than 2 percent of the username and password combinations might have worked, and our automated anti-hijacking systems would have blocked many of those login attempts. We've protected the affected accounts and have required those users to reset their passwords."

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Won't Start After Battery Runs Out? Apple Says iOS 26.5.1 Fixes It
  2. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  3. Moto G37 Power Review: Covers All the Bases and More
  4. Apple's First Foldable iPhone May Get White Colourway, VC Cooling
  5. MSI's First RTX Spark Laptop Targets AI Workloads, Creators and Developers
  6. Hisense Launches U7SE 144Hz ULED Mini-LED TV Series in India
  7. Nothing Ear 3a, CMF Buds Neo Visit Regulatory Databases, Might Launch Soon
  8. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  1. Nothing Ear 3a, CMF Buds Neo Spotted on Regulatory Databases Ahead of Anticipated Debut
  2. Samsung Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra Could Feature Vastly Different Designs, Leaked Dummy Units Suggest
  3. Hisense U7SE 144Hz ULED Mini-LED TV Series With Up to 100-Inch Screens Launched in India: Price, Features
  4. Vivo Y500 Surfaces on Bluetooth SIG Database With Multiple Model Numbers, Could Launch Soon
  5. Asus Ascent QN10 Mini PC With Snapdragon X2 Elite Chipset Showcased at Computex 2026
  6. MSI Showcases New Katana, Venture Laptops and Crosshair A16 HX MLG Edition at Computex 2026
  7. Acer TravelMate P6 14 AI and P2 Spin 14 Unveiled, Acer TravelMate X2 15 and X2 14 Tag Along
  8. Sony Bravia 7II 4K TVs Launched in India With Cognitive Processor XR, Dolby Vision: Price, Features
  9. Asus TUF 16 (2026) Gaming Laptop Unveiled Alongside ExpertBook B5 Flip G2 (2026) at Computex 2026
  10. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.