https://www.zdnet.com/article/google-launches-titan-security...
https://www.zdnet.com/article/google-launches-titan-security...
2. The threat model makes no sense. Why would Google send you to a compromised vendor of cheap devices with weak radios to falsely secure logins to your Google account, when Google already has control over your Google account?
There's a simpler answer, which is that the only vendors that have Android NFC U2F devices are China-based. The YubiKey doesn't support U2F over NFC (at least last I checked). That's why they previously had you get one YubiKey and one Feitian. On that assumption, the most rational thing for Google to do if they have good intentions is to suggest the leading Chinese security key in the short term, and in the medium term, white-label that key's hardware and flash their own firmware (or at least firmware they've audited) onto it and rebrand it, which appears to be exactly what they've done.
Unfortunately my anecdotal experience biases me to believe it. After getting hundreds of Microsoft product keys from Dell, and having 20 to 50÷ of them from China being compromised even with the security scratch off intact. Have not ran into an issue with a single us printed one. Ya, no faith here.
The Yubikey NEO has since 2015, and I use it with Advanced Protection.
Brad Hill's author choice here: https://github.com/hillbrad/U2FReviews#neo
Personally, I prefer the flat key profile over something bulbous on the keychain.
I think that this is a terribly naive assumption. Privacy is cheap if not meaningless in China. The government can request access to server private keys and it often does. Anyone that has tried to deploy a service in China knows that it is an absolute security nightmare because of the security allowances you have to make for the government.
And it's not fear of Google accessing your account, which they already do. Is the Chinese state actor doing so. Which they will.
Is the claim here that Google is wilfully facilitating China accessing your account? If so, those fears are the same.
(If the claim is that Google is unintentionally facilitating this, I think we need a bit more of a story about why Google - which wrote the U2F protocol with Yubico in the first place, and is generally seen to be competent at this - would make this mistake. "They want to make China happy" is the beginning of such a story but not nearly enough.)
[I bought half a dozen yubikeys with NFC last year for my family, setup and tested lastpass, extensively tested my android and PC... when it all fell flat on their iPhone. Whopsie!]
https://www.ftsafe.com/products/FIDO/Multi
The case design shape and LED positions are identical. You'll need to check the USB VID and Bluetooth MAC vendor ID's to be sure the hardware inside is the same.