HomeSecurityGoogle security vulnerability locks iOS users out of their accounts

Google security vulnerability locks iOS users out of their accounts

vulnerability

A vulnerability in the Bluetooth Low Energy (BLE) Titan Security Key, which provides two-factor authentication for accessing Google, is preventing some iOS from accessing their accounts. Christiaan Brand, a product manager at Google Cloud, wrote on the Google Security Blog yesterday that “due to a misconfiguration in the Bluetooth pairing protocols of Titan Security Keys, it is possible for an attacker who is in close proximity to you at the time you are using your security key to communicate with your security key or the device to which your key is paired.”

Of course, the attacker would have to be very close to their victim, and it’s pretty difficult to pull off such an attack unless the attacker had your username and password. Titan Security Keys are used by Google employees for internal access and are sold as two-factor authentication hardware devices to the public. The company says the security issue “does not affect the primary purpose of security keys, which is to protect you from a remote attacker,” and says that “it’s safer to use a key that has this issue than to disable two-factor authentication on your Google account.”

Which keys are affected by the vulnerability?

USB and NFC security keys are not affected by the aforementioned vulnerability. However, if you are using a BLE version of the Titan Security Key, you should check the back of the device and if it has T1 or T2 printed on it, then it is affected and Google will offer a free replacement.

What's the problem with iOS 12.3?

Google advises users of iOS 12.2 or earlier to simply use the key “in a private place where a potential attacker is not nearby” and then sign out. However, things are different for iOS 12.3. Google says that such users will not be able to use the key to sign in to a Google Account or any other account protected by the key. Additionally, Google confirms that “if you are already signed in to your Google Account on your iOS device, you should not sign out as you will not be able to sign in again until you receive a new key.” If you do not have access to your account, Google provides instructions for regaining access to it.

Nadir Israel, CTO at Armis, says that Bluetooth is a complex protocol and that he is not surprised by the issue that has arisen. “This vulnerability highlights the importance of checks to ensure that there are no vulnerabilities or misconfigurations when implementing the Bluetooth protocol.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS