How Google’s Physical Keys Will Protect Your Password

Minh Uong/The New York Times
Minh Uong/The New York Times
TT

How Google’s Physical Keys Will Protect Your Password

Minh Uong/The New York Times
Minh Uong/The New York Times

Why won’t the password just go away? The silly pet names, movie titles or sports teams that many people punch in to get into their online accounts are a weak spot that hackers continue to puncture.

Yet passwords remain the primary way we log in to online accounts containing our personal and financial information. Google has a new pragmatic solution: Embrace the password, but lock it down with extra physical security.

The company this month released its Advanced Protection Program, which is meant to make stealing your password pointless. To use it, you’ll need two inexpensive physical keys to log in to your Google account on your computer and smartphone.

This way, even if hackers stole your password in a data breach or successfully phished for it, by tempting you to hand over your credentials on a fake login page, they couldn’t do anything unless they got their hands on the keys as well. And minimizing risk with minimal effort is a boon to anyone who cares about online security.

“I am a big fan of this,” said John Sabin, a former hacker for the National Security Agency. “It’s probably the easiest and most secure multifactor for the masses.”

The physical keys are an evolution of two-factor authentication, an extra security layer to ensure that your password is being entered by you. Google was one of the first companies to start offering two-factor authentication back in 2010, not long after it learned that it had been hacked by state-sponsored Chinese hackers.

After the attack, Google’s security team came up with a motto: “Never again.” The company later rolled out two-factor authentication for Google customers’ Gmail accounts. It involved text messaging a unique code to your phone that you must type in after entering your password in order to log in.

Unfortunately, those text messages can be hijacked. Last month, security researchers at Positive Technologies, a security firm, demonstrated how they could use vulnerabilities in the cellular network to intercept text messages for a set period of time.

The idea of Google’s Advanced Protection Program is to provide people with a physical device that is much harder to steal than a text message. Google is marketing the program as a tool for a tiny set of people who are at high risk of online attacks, like victims of stalking, dissidents inside authoritarian countries or journalists who need to protect their sources.

But why should extra-tough security benefit such a small group? Everyone should be able to enjoy stronger security.

So we tested Google’s Advanced Protection Program and vetted it with security researchers to see if the program could be used by the masses. The verdict: Many people should consider signing up for the security system and buying a pair of keys. But if you are married to some non-Google apps that are not yet compatible with the keys, you should wait and see if the program matures.

Setting Up Advanced Protection

Anyone with a Google account can sign up for the security program on Google’s Advanced Protection webpage. To get started, you will have to buy two physical keys for about $20 each. Google recommends buying one from Feitian and another from Yubico.

The keys, which look like thumb drives and can fit on your key chain, contain digital signatures that prove you are you. To set one up, you plug the key into a computer USB port, tap a button and name it. (The Feitian key wirelessly communicates with your smartphone to authenticate the login.) This process takes a few minutes.

On a computer and a smartphone, you need to log in with the key only once, and Google will remember the devices for future logins. That is more convenient than traditional two-factor authentication, which requires entering a unique code each time you log in.

But there are trade-offs. Google’s Advanced Protection cuts off all third-party access by default, allowing only applications that support its security keys. For the time being, that means only Google’s Gmail mail app, Google’s Backup and Sync app, and Google’s Chrome browser.

On an iPhone, for example, you will have to use Google’s Gmail or Inbox apps for email, and on a computer, you can use only the Chrome browser when signing in with a browser. So if you rely on Apple Mail to gain access to your Gmail on an iPhone, or if you use Microsoft Outlook for getting into Gmail on a PC, you’re out of luck. Google says its goal is to eventually allow third-party apps to work with the program, but it is also up to other companies to update their apps to support the keys.

Testing the Security

Despite the drawbacks, security researchers agree that the Advanced Protection Program is a solid piece of security and relatively painless to use, even for everyday use for people outside high-security jobs.

Mr. Sabin, the former N.S.A. hacker, who is now a director of network security at GRA Quantum, a security consulting firm, said the physical keys had pros and cons. On one hand, if you lose a key, a hacker would have a hard time figuring out which account it was associated with.

On the other hand, if you lose the keys or don’t have the keys around when you need to log in to a new device, it takes longer to regain access to your account. Google has put in place more elaborate recovery steps for Advanced Protection users, including additional reviews and requests for details about why users have lost access to their account. In our test, we answered security questions to try to recover an account, and Google said it would review the recovery request and respond within a few days.

Runa Sandvik, the director of information security at The New York Times, said the keys were not much of a hassle. She said Google’s requirement of using two keys meant you essentially had a spare: If you lose one key, you can get into your account with the remaining key.

But she noted that the keys could get annoying if you used many devices and constantly needed to carry the keys around to log in to your account. That may be an issue for people who work in the technology industry, but most people probably use only one computer and one phone.

Ms. Sandvik, who has been testing Google’s program to assess whether to recommend it to the newsroom, said she had not yet discovered vulnerabilities in the security key system outside of the slim possibility that a hacker gained possession of both your password and your key.

“It’s something that is relatively easy to set up once you have both keys,” Ms. Sandvik said. “I don’t see a reason you shouldn’t turn this on.”

The Bottom Line

While the security keys are easy to set up and provide tough security, they may be disruptive to your productivity if you rely on apps that are incompatible with the keys.

It took a few minutes for us to migrate to Google’s apps from Apple’s and integrate them into our newsroom workflow, which already relies on Google’s mail, messaging and cloud storage services. But using the keys required sacrificing an important feature — Apple’s V.I.P. alerts, which notify you when people you deem important email you. Google’s iOS apps for Gmail and Inbox lack a similar feature. For people with flooded inboxes, lacking V.I.P. alerts makes sifting through emails time-consuming.

Another example of how the keys can stifle productivity: Many employers still require using the Microsoft Outlook app for email, which won’t work with the keys.

If using Google’s security program would disrupt your work, you may want to wait for more companies to update their apps to support the keys, which rely on a standard called FIDO, for Fast Identity Online. Mr. Sabin predicts that many apps will follow Google’s lead.

If you decide to wait, don’t procrastinate on turning on traditional two-factor authentication that relies on text messages. While it is hackable, it is still much safer than relying on a password alone to protect you.

The question is how long it will take security researchers to find a way to hack the physical keys as well. When asked if he had already circumvented physical multifactor authentication devices like Google’s keys, Mr. Sabin would offer only: “No comment.”

The New York Times



India Eyes $200B in Data Center Investments as It Ramps Up Its AI Hub Ambitions

FILE -Google CEO Sundar Pichai, right, interacts with India's Minister for Information and Technology Ashwini Vaishnaw during Google for India 2022 event in New Delhi, Dec. 19, 2022. (AP Photo/Manish Swarup), File)
FILE -Google CEO Sundar Pichai, right, interacts with India's Minister for Information and Technology Ashwini Vaishnaw during Google for India 2022 event in New Delhi, Dec. 19, 2022. (AP Photo/Manish Swarup), File)
TT

India Eyes $200B in Data Center Investments as It Ramps Up Its AI Hub Ambitions

FILE -Google CEO Sundar Pichai, right, interacts with India's Minister for Information and Technology Ashwini Vaishnaw during Google for India 2022 event in New Delhi, Dec. 19, 2022. (AP Photo/Manish Swarup), File)
FILE -Google CEO Sundar Pichai, right, interacts with India's Minister for Information and Technology Ashwini Vaishnaw during Google for India 2022 event in New Delhi, Dec. 19, 2022. (AP Photo/Manish Swarup), File)

India is hoping to garner as much as $200 billion in investments for data centers over the next few years as it scales up its ambitions to become a hub for artificial intelligence, the country’s minister for electronics and information technology said Tuesday.

The investments underscore the reliance of tech titans on India as a key technology and talent base in the global race for AI dominance. For New Delhi, they bring in high-value infrastructure and foreign capital at a scale that can accelerate its digital transformation ambitions.

The push comes as governments worldwide race to harness AI's economic potential while grappling with job disruption, regulation and the growing concentration of computing power in a few rich countries and companies.

“Today, India is being seen as a trusted AI partner to the Global South nations seeking open, affordable and development-focused solutions,” Ashwini Vaishnaw told The Associated Press in an email interview, as New Delhi hosts a major AI Impact Summit this week drawing participation from at least 20 global leaders and a who’s who of the tech industry.

In October, Google announced a $15 billion investment plan in India over the next five years to establish its first artificial intelligence hub in the South Asian country. Microsoft followed two months later with its biggest-ever Asia investment announcement of $17.5 billion to advance India’s cloud and artificial intelligence infrastructure over the next four years.

Amazon too has committed $35 billion investment in India by 2030 to expand its business, specifically targeting AI-driven digitization. The cumulative investments are part of $200 billion in investments that are in the pipeline and New Delhi hopes would flow in.

Vaishnaw said India’s pitch is that artificial intelligence must deliver measurable impacts at scale rather than remain an elite technology.

“A trusted AI ecosystem will attract investment and accelerate adoption,” he said, adding that a central pillar of India’s strategy to capitalize on the use of AI is building infrastructure.

The government recently announced a long-term tax holiday for data centers as it hopes to provide policy certainty and attract global capital.

Vaishnaw said the government has already operationalized a shared computing facility with more than 38,000 graphics processing units, or GPUs, allowing startups, researchers and public institutions to access high-end computing without heavy upfront costs.

“AI must not become exclusive. It must remain widely accessible,” he said.

Alongside the infrastructure drive, India is backing the development of sovereign foundational AI models trained on Indian languages and local contexts. Some of these models meet global benchmarks and in certain tasks rival widely used large language models, Vaishnaw said.

India is also seeking a larger role in shaping how AI is built and deployed globally as the country doesn’t see itself strictly as a “rule maker or rule taker,” according to Vaishnaw, but an active participant in setting practical, workable norms while expanding its AI services footprint worldwide.

“India will become a major provider of AI services in the near future,” he said, describing a strategy that is “self-reliant yet globally integrated” across applications, models, chips, infrastructure and energy.

Investor confidence is another focus area for New Delhi as global tech funding becomes more cautious.

Vaishnaw said the technology’s push is backed by execution, pointing to the Indian government's AI Mission program which emphasizes sector specific solutions through public-private partnerships.

The government is also betting on reskilling its workforce as global concerns grow that AI could disrupt white collar and technology jobs. New Delhi is scaling AI education across universities, skilling programs and online platforms to build a large AI-ready talent pool, the minister said.

Widespread 5G connectivity across the country and a young, tech-savvy population are expected to help with the adoption of AI at a faster pace, he added.

Balancing innovation with safeguards remains a challenge though, as AI expands into sensitive sectors such as governance, health care and finance.

Vaishnaw outlined a fourfold strategy that includes implementable global frameworks, trusted AI infrastructure, regulation of harmful misinformation and stronger human and technical capacity to hedge the impact.

“The future of AI should be inclusive, distributed and development-focused,” he said.


Report: SpaceX Competing to Produce Autonomous Drone Tech for Pentagon 

The SpaceX logo is seen in this illustration taken, March 10, 2025. (Reuters)
The SpaceX logo is seen in this illustration taken, March 10, 2025. (Reuters)
TT

Report: SpaceX Competing to Produce Autonomous Drone Tech for Pentagon 

The SpaceX logo is seen in this illustration taken, March 10, 2025. (Reuters)
The SpaceX logo is seen in this illustration taken, March 10, 2025. (Reuters)

Elon Musk's SpaceX and its wholly-owned subsidiary xAI are competing in a secret new Pentagon contest to produce voice-controlled, autonomous drone swarming technology, Bloomberg News reported on Monday, citing people familiar with the matter.

SpaceX, xAI and the Pentagon's defense innovation unit did not immediately respond to requests for comment. Reuters could not independently verify the report.

Texas-based SpaceX recently acquired xAI in a deal that combined Musk's major space and defense contractor with the billionaire entrepreneur's artificial intelligence startup. It occurred ahead of SpaceX's planned initial public offering this year.

Musk's companies are reportedly among a select few chosen to participate in the $100 million prize challenge initiated in January, according to the Bloomberg report.

The six-month competition aims to produce advanced swarming technology that can translate voice commands into digital instructions and run multiple drones, the report said.

Musk was among a group of AI and robotics researchers who wrote an open letter in 2015 that advocated a global ban on “offensive autonomous weapons,” arguing against making “new tools for killing people.”

The US also has been seeking safe and cost-effective ways to neutralize drones, particularly around airports and large sporting events - a concern that has become more urgent ahead of the FIFA World Cup and America250 anniversary celebrations this summer.

The US military, along with its allies, is now racing to deploy the so-called “loyal wingman” drones, an AI-powered aircraft designed to integrate with manned aircraft and anti-drone systems to neutralize enemy drones.

In June 2025, US President Donald Trump issued the Executive Order (EO) “Unleashing American Drone Dominance” which accelerated the development and commercialization of drone and AI technologies.


SVC Develops AI Intelligence Platform to Strengthen Private Capital Ecosystem

The platform offers customizable analytical dashboards that deliver frequent updates and predictive insights- SPA
The platform offers customizable analytical dashboards that deliver frequent updates and predictive insights- SPA
TT

SVC Develops AI Intelligence Platform to Strengthen Private Capital Ecosystem

The platform offers customizable analytical dashboards that deliver frequent updates and predictive insights- SPA
The platform offers customizable analytical dashboards that deliver frequent updates and predictive insights- SPA

Saudi Venture Capital Company (SVC) announced the launch of its proprietary intelligence platform, Aian, developed in-house using Saudi national expertise to enhance its institutional role in developing the Kingdom’s private capital ecosystem and supporting its mandate as a market maker guided by data-driven growth principles.

According to a press release issued by the SVC today, Aian is a custom-built AI-powered market intelligence capability that transforms SVC’s accumulated institutional expertise and detailed private market data into structured, actionable insights on market dynamics, sector evolution, and capital formation. The platform converts institutional memory into compounding intelligence, enabling decisions that integrate both current market signals and long-term historical trends, SPA reported.

Deputy CEO and Chief Investment Officer Nora Alsarhan stated that as Saudi Arabia’s private capital market expands, clarity, transparency, and data integrity become as critical as capital itself. She noted that Aian represents a new layer of national market infrastructure, strengthening institutional confidence, enabling evidence-based decision-making, and supporting sustainable growth.

By transforming data into actionable intelligence, she said, the platform reinforces the Kingdom’s position as a leading regional private capital hub under Vision 2030.

She added that market making extends beyond capital deployment to shaping the conditions under which capital flows efficiently, emphasizing that the next phase of market development will be driven by intelligence and analytical insight alongside investment.

Through Aian, SVC is building the knowledge backbone of Saudi Arabia’s private capital ecosystem, enabling clearer visibility, greater precision in decision-making, and capital formation guided by insight rather than assumption.

Chief Strategy Officer Athary Almubarak said that in private capital markets, access to reliable insight increasingly represents the primary constraint, particularly in emerging and fast-scaling markets where disclosures vary and institutional knowledge is fragmented.

She explained that for development-focused investment institutions, inconsistent data presents a structural challenge that directly impacts capital allocation efficiency and the ability to crowd in private investment at scale.

She noted that SVC was established to address such market frictions and that, as a government-backed investor with an explicit market-making mandate, its role extends beyond financing to building the enabling environment in which private capital can grow sustainably.

By integrating SVC’s proprietary portfolio data with selected external market sources, Aian enables continuous consolidation and validation of market activity, producing a dynamic representation of capital deployment over time rather than relying solely on static reporting.

The platform offers customizable analytical dashboards that deliver frequent updates and predictive insights, enabling SVC to identify priority market gaps, recalibrate capital allocation, design targeted ecosystem interventions, and anchor policy dialogue in evidence.

The release added that Aian also features predictive analytics capabilities that anticipate upcoming funding activity, including projected investment rounds and estimated ticket sizes. In addition, it incorporates institutional benchmarking tools that enable structured comparisons across peers, sectors, and interventions, supporting more precise, data-driven ecosystem development.