Security News

GoSecure Titan MDR portal offers customizable dashboard for its customers
2021-08-04 02:10

The GoSecure Titan MDR portal delivers a customizable dashboard for GoSecure Titan MDR customers to view all aspects of their MDR service. The GoSecure Titan MDR portal takes this service visibility to unprecedented levels.

Fashion titan French Connection says 'FCUK' as REvil-linked ransomware makes off with data
2021-06-24 08:30

Cheeky clothing firm French Connection, also known as FCUK, has become the latest victim of ransomware, with a gang understood to be linked to REvil having penetrated its back-end - making off with a selection of private internal data. Founded in 1972 by current chief executive Stephen Marks, French Connection made a name for itself when it adopted the not-actually-rude-honest slogan "FCUK" in its advertising in the early 2000s.

GoSecure Titan update enhances MDR service to speed up ransomware and malware detection
2021-06-03 01:15

GoSecure announced the release of the latest update to the GoSecure Titan platform. The Spring update illustrates the continued evolution of the GoSecure Titan platform.

S3 Ep15: Titan keys, Mimecast certs and Solarwinds [Podcast]
2021-01-14 16:21

We explain how two French researchers hacked the Google Titan security key product, and dig into the Mimecast certificate compromise story to see what we can all learn from it. WHERE TO FIND THE PODCAST ONLINE. You can listen to us on Soundcloud, Apple Podcasts, Google Podcasts, Spotify, Stitcher, Overcast and anywhere that good podcasts are found.

Cloning Google Titan 2FA keys
2021-01-12 12:16

The cloning works by using a hot air gun and a scalpel to remove the plastic key casing and expose the NXP A700X chip, which acts as a secure element that stores the cryptographic secrets. The exploit allows an attacker to obtain the long-term elliptic curve digital signal algorithm private key designated for a given account.

Google Titan security keys hacked by French researchers
2021-01-11 14:09

In July 2018, after many years of using Yubico security key products for two-factor authentication, Google announced that it was entering the market as a competitor with a product of its own, called Google Titan. Security keys of this sort are often known as FIDO keys after the Fast IDentity Online Alliance, which curates the technical specifications of a range of authentication technologies that "[p]romote the development of, use of, and compliance with standards for authentication and device attestation".

Researchers Show Google's Titan Security Keys Can Be Cloned
2021-01-11 12:33

Researchers have found a way to clone Google's Titan Security Keys through a side-channel attack, but conducting an attack requires physical access to a device for several hours, as well as technical skills, custom software, and relatively expensive equipment. A new attack method against such devices was described by researchers from NinjaLab, a France-based company that specializes in the security of cryptographic implementations.

New Attack Could Let Hackers Clone Your Google Titan 2FA Security Keys
2021-01-08 11:59

The vulnerability allows the bad actor to extract the encryption key or the ECDSA private key linked to a victim's account from a FIDO Universal 2nd Factor device like Google Titan Key or YubiKey, thus completely undermining the 2FA protections. An actor will have first to steal the target's login and password of an account secured by the physical key, then stealthily gain access to Titan Security Key in question, not to mention acquire expensive equipment costing north of $12,000, and have enough expertise to build custom software to extract the key linked to the account.

Remember the Titans: Yubico jangles new NFC and USB-C touting security key
2020-09-09 12:00

Security token biz Yubico has a new key out today, its latest-generation two-factor encryption authentication unit, the Yubico 5C NFC, which includes support for PCs and mobile devices using USB-C, as well as a built-in NFC radio. The last model offering USB-C lacked NFC - although it did come with a built-in Lightning plug, effectively covering all the bases of the mobile market.

Google rolls out Titan keys to Europe, Japan. Plus: Group Policy bug is a feature, not a flaw, says Microsoft
2020-02-24 06:08

Bug disclosure service HackerOne was in the rare position of publicizing one of its own security holes this week after a researcher discovered a flaw that was exposing some user email addresses. Tenable says Microsoft won't fix Group Policy bug.