Google confirms its Titan Security Keys are made by a Chinese company, but says the firmware ensures security, as security experts call for more transparency
Google's Titan Security Keys, used to lock down accounts, are produced in China. Several experts want more answers on that supply chain process …
Context & Ripple Effects
When Google unveiled the Titan Security Key in July 2018 as a Yubico-style phishing-resistant 2FA device for Google Cloud customers, the pitch was trust in the hardware itself. This report undercuts part of that story: the keys are manufactured by a Chinese company, and Google's defense rests entirely on the firmware rather than the factory.
The disclosure lands awkwardly because Google has spent years building a tamper-detection narrative around the Titan name, starting with the Titan chip designed to scan cloud hardware for evidence of tampering. Security experts' call for supply-chain transparency tests whether 'firmware guarantees security' is an answer or a deflection.
First-order effects
- Google Cloud customers and other buyers weighing the Titan key against alternatives like Yubico now have to price in an unverified manufacturing chain, with Google offering only its firmware assurance as reassurance.
- Security researchers gain leverage: their demand for transparency puts Google in the position of either disclosing supplier and verification details or defending a black-box claim about its own flagship security product.
Second-order effects
- Transparency pressure pushes Google toward verifiability it controls — weeks later it committed to open source the Titan M firmware in Pixel phones, a move consistent with answering supply-chain distrust by making the code auditable rather than relocating production.
- Rivals positioned outside the contested supply chain get a marketing opening, letting buyers who balk at Chinese manufacture default to competing keys even where Google's firmware argument may be technically sound.
Third-order effects
- If the pattern holds, hardware security vendors converge on 'trust the firmware, not the factory': auditability of code becomes the substitute for control over geography, and firms that publish verifiable firmware will be structurally better placed to sell security hardware across borders.
- Supply-chain disclosure shifts from optional PR to a baseline expectation for security products, with procurement decisions increasingly hinging on whether manufacturers can demonstrate custody over what ships inside the device.
The trend: Security hardware makers are responding to geopolitical supply-chain scrutiny with verifiable, openable firmware rather than manufacturing relocation, making code auditability the new trust anchor for physical security tokens.