Tuesday, March 4, 2025
HomeAndroidNow Use Your Android Phone as a Physical Security Key - Google's...

Now Use Your Android Phone as a Physical Security Key – Google’s New Advanced Two-factor Authentication

Published on

SIEM as a Service

Follow Us on Google News

Google announced a new Two-factor authentication method let Android Phone to be used as a physical security key when users log into a Google account with the Chrome browser.

This is a new era for 2-factor authentication which is one of the very effective and the most secure ways to log in your Google accounts.

Android that running with version 7.0 and higher can be used as a physical security key for the Google services that required 2 Factor Authentication.

Two Factor authentication makes the attack harder when an attacker tries to trick users to steal online credentials and prevent users from the most common security breaches.

According to Google, “While any form of 2SV, like SMS text message codes and push notifications, improves the security of your account, sophisticated attackers can skirt around them by targeting you with a fake sign-in page to steal your credentials.”

Other Form of two-factor verification like pushing the one time password, Google prompts the SMS verification code and Google service on your computer directly communicate over the internet.

This new Android Phone as a Security Key for 2 Factor Authentication, pushing the same notification, but it required your Android phone physically nearby your computer and ask you to confirm the sign in verification from your Android phone.

To activate your phone’s built-in security key, all you need is an Android 7.0+ phone and a Bluetooth-enabled Chrome OS, macOS X or Windows 10 computer with a Chrome browser. Here’s how to do it:

  1. Add your Google Account to your Android phone.
  2. Make sure you’re enrolled in 2SV.
  3. On your computer, visit the 2SV settings and click “Add security key”.
  4. Choose your Android phone from the list of available devices—and you’re done!

“This makes it easier and more convenient for you to unlock this powerful protection, without having to carry around additional security keys. Use it to protect your personal Google Account, as well as your Google Cloud Accounts at work” Google Said.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

TOP 11 Deep Web Search Engine Alternative for Google and Bing 2019

How Does Worlds Highly Secured Google Network Works ? Google’s Effort & Dedication

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Pathfinder AI – Hunters Announces New AI Capabilities for Smarter SOC Automation

Pathfinder AI expands Hunters' vision for AI-driven SOCs, introducing Agentic AI for autonomous investigation...

Google Secretly Tracks Android Devices Even Without User-Opened Apps

A recent technical study conducted by researchers at Trinity College Dublin has revealed that...

LLMjacking – Hackers Abuse GenAI With AWS NHIs to Hijack Cloud LLMs

In a concerning development, cybercriminals are increasingly targeting cloud-based generative AI (GenAI) services in...

Microsoft Strengthens Trust Boundary for VBS Enclaves

Microsoft has introduced a series of technical recommendations to bolster the security of Virtualization-Based...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Google Secretly Tracks Android Devices Even Without User-Opened Apps

A recent technical study conducted by researchers at Trinity College Dublin has revealed that...

Google, Meta, and Apple Power the World’s Biggest Surveillance System

Imagine a government that tracks your daily movements, monitors your communications, and catalogs your...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...