{"id":4388,"date":"2024-07-10T05:00:00","date_gmt":"2024-07-10T10:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint-security\/google-targets-passkey-support-high-risk-execs-civil-society"},"modified":"2024-07-10T05:00:00","modified_gmt":"2024-07-10T10:00:00","slug":"google-targets-passkey-support-to-high-risk-execs-civil-society","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/10\/google-targets-passkey-support-to-high-risk-execs-civil-society\/","title":{"rendered":"Google Targets Passkey Support to High-Risk Execs, Civil Society"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0be5f9acf3355d4d\/668478b50e577156a2061601\/Passkey%281800%29_ArtemisDiana_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the latest push to move people to strong authentication mechanisms for online accounts, Google is adding passkey support to its Advanced Protection Program (APP).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">APP is a cyber defense effort meant to protect the accounts of high-risk targets such as top executives, government employees, and members of civil society. The move means that people at high risk of cyberattacks can forgo easy-to-steal\/easy-to-guess passwords in favor of a passkey, which is a virtual form of the FIDO2 hardware security key scheme.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Passkeys are straightforward to use: Users store a private key on a hardware endpoint using a secure hardware enclave or password manager, which is then used to authenticate to cloud services and websites by solving a cryptographic challenge. That solve takes place in the background, and for the user, it&#8217;s just a matter of using a thumbprint, face scan, or PIN to sign in.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Passkeys can also thwart phishing and adversary-in-the-middle (AitM) attacks because they verify that websites the user is trying to access are legitimate.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the case of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.google\/technology\/safety-security\/google-passkeys-advanced-protection-program\/\" rel=\"noopener\">Google APP<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, it includes support for any passkeys that support FIDO standards, including those stored on devices the users already own, or external security keys that contain passkeys (like many of today&#8217;s FIDO2 security keys). Users can use passkeys to secure any Google account, including Google Cloud Platform, Gmail, and Google Workspace.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Individuals have been targeted by sophisticated adversaries forever, and this continues to grow,&#8221; Shuvo Chatterjee, product lead for Google&#8217;s APP, tells Dark Reading. &#8220;Google introduced the APP as a protective product for high-risk individuals long before anyone else did, because of our continued work to protect those who face these elevated threats.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the program has supported hardware FIDO2 keys from the beginning, &#8220;this announcement of supporting passkeys as an option for enrollment is important for the many high-risk individuals we&#8217;ve heard from who simply cannot access hardware security keys,&#8221; Chatterjee explains. He cites examples of a journalist covering a war zone who physically can&#8217;t take the time to attach a bulky key, or a lower-level campaign staffer hopping across the country who might be operating on a grassroots budget and can&#8217;t afford to go the hardware route.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We&#8217;ve seen the global struggles of people wanting an extra layer of protection but unable to enroll for various reasons,&#8221; he says. &#8220;For journalists, activists, politicians, business leaders, and others at higher risk of being targeted, this potentially removes one more obstacle in their way.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In tandem with the passkey announcement, Google launched a partnership with Internews to provide journalists and human rights workers with security support around the world through Internews&#8217; global network of security trainers. The program will span 10 countries, including Brazil, Mexico, and Poland.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Passkeys Inch Into Public's Consciousness\">Passkeys Inch Into Public&#8217;s Consciousness<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Despite moves by major service providers including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/amazon-quietly-wades-into-passkey-waters\" rel=\"noopener\">Amazon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/microsoft-apple-and-google-promise-to-expand-passwordless-features\" rel=\"noopener\">Apple<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/google-expands-passkey-support-with-passwordless-authentication\" rel=\"noopener\">Google&#8217;s consumer business<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/microsoft-adds-passkeys-to-windows-11\" rel=\"noopener\">Microsoft<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to roll out the technology, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/new-developer-tools-necessary-passkey-adoption\" rel=\"noopener\">passkey awareness and use<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> remain low. That&#8217;s something that Google&#8217;s Chatterjee expects to change.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;One advantage is that passkeys are something the industry as a whole is pushing together,&#8221; he says. &#8220;Whether it&#8217;s Google, Apple, or Microsoft, or individual websites who support passkeys, this will become more common for people. It takes time to make that transition.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He said that in less than a year since passkeys have been available to Google users, they&#8217;ve been used to authenticate people more than 1 billion times across over 400 million Google accounts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It should be noted that the technology is not infallible and can be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/passkey-redaction-attacks-subvert-github-microsoft-authentication\" rel=\"noopener\">vulnerable to passkey redaction attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, as eSentire detailed last week. In this case, that type of gambit is rendered moot for anyone using their Google passkeys in a normal authentication setting, Chatterjee stresses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The main chokepoint for that attack vector was stripping the passkey option from websites, forcing users to use a downgraded authentication method,&#8221; he explains. &#8220;If you&#8217;re in APP, you\u2019re not able to sign in with a downgraded authentication method, so a security key or passkey will be required for sign-ins on a new device.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In general, it&#8217;s also a good idea to harden account recovery methods. APP&#8217;s particular implementation of passkeys, for instance, allows Google account users to add recovery options during enrollment in case the device the passkey is stored in is lost. The options include using a phone number, email, or another passkey or security key to recover the account; the latter two are certainly the more secure options.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/google-targets-passkey-support-high-risk-execs-civil-society\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the latest push to move people to strong authentication<\/p>\n","protected":false},"author":12,"featured_media":4389,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4388","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/google-targets-passkey-support-to-high-risk-execs-civil-society.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4388"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4388\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4389"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}