Jump to content

Google's New High-Security Option for Google Accounts

Fetzie

 

Secure-Gmail.jpg

 

Google has introduced a new, increased security option for Google Accounts.

 

Quote

The Advanced Protection Program safeguards the personal Google Accounts of those most at risk of targeted attacks—like journalists, business leaders, and political campaign teams.

 

Phishing is one of the most common techniques hackers use to gain access to your account or personal information. For example, phishing emails or fake sign-in pages could trick you into revealing critical information, like your password.

To provide the strongest defense against phishing, Advanced Protection goes beyond traditional 2-Step Verification. You will need to sign into your account with a password and a physical Security Key. Other authentication factors, like codes sent via SMS or the Google Authenticator app, will no longer work.

 

Essentially, it adds an additional level of protection to your Google account - a physical key. You can register a physical key as well as a bluetooth dongle with your account. This code generator key will be required to log in on a new device. Codes from software authenticators and mobile phone verification attempts will no longer be valid.

 

Advanced Protection bans all third party applications from accessing your account.

 

Quote

Accessing Gmail & Drive

  • Third-party apps that want access to Gmail or Drive will no longer have permission. For secure access, you will need to use the Gmail app or Inbox by Gmail.

Google services on the web

  • You will only be able to use the Chrome browser to access signed-in services like Gmail or Photos.

iOS Support

  • Apple Mail, Contacts, and Calendar apps do not currently support Security Keys and will not be able to access your Google data. Instead, you can use the Gmail, Inbox, or Google calendar apps on iOS.

 

This means that third party applications, for example honey pots placed by security services or criminals, will no longer be able to access your Google account. It unfortunately also means no more importing of your Google calendar to Outlook, using the default Mail app on your iPhone or even logging into Gmail on a browser that isn't Chrome.

 

Additionally, there are more hoops to jump through to recover your account than usual if you lose your Security Keys and your account credentials.

Quote

A common way that hackers try to gain access to your account is by impersonating you and pretending they have been locked out of your account.

To provide you with the strongest safeguards against this type of fraudulent account access, Advanced Protection adds extra steps to verify your identity. If you ever lose access to your account and both of your Security Keys, these added verification requirements will take a few days to restore access to your account.

 

Advanced Protection is available as of today at the link below.

 

I think this is an important tool for people who need to keep their correspondence and correspondents away from prying eyes. Journalists, political activists and victims of domestic abuse are all potential users of this feature. However, it will of course mean more inconvenience (not to mention the money you will have to spend on hardware code tokens), so I think that most people won't turn it on. It will also be interesting to see what happens when the first law enforcement agency tries to gain access to a protected account by force, and whether Google is willing or even capable of helping in this case if the security tokens are destroyed.

 

Sources:

primary source: https://landing.google.com/advancedprotection/

secondary source: https://www.wired.com/story/google-advanced-protection-locks-down-accounts/

 

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

So they're just telling you that FIDO keys are acceptable for google 2FA, which has been a thing for like, quite a while now? Additionally, locking Google Apps access to Chrome.

 

 

[FS][US] Corsair H115i 280mm AIO-AMD $60+shipping

 

 

System specs:
Asus Prime X370 Pro - Custom EKWB CPU/GPU 2x360 1x240 soft loop - Ryzen 1700X - Corsair Vengeance RGB 2x16GB - Plextor 512 NVMe + 2TB SU800 - EVGA GTX1080ti - LianLi PC11 Dynamic
 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, knightslugger said:

So they're just telling you that FIDO keys are acceptable for google 2FA, which has been a thing for like, quite a while now? Additionally, locking Google Apps access to Chrome.

 

 

And if you need to recover the account, you will have to go through a more extensive verification process to make sure it is you and not somebody else.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

Pretty good move , But remember , To those in power this isn't an issue.

Details separate people.

Link to comment
Share on other sites

Link to post
Share on other sites

feels like i might actiually do this, but not right now. i switch google account and shit all the time and haveing this would probably be a bit of a pain for me, but i like the physical key aspect of it all to be honest

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×