Here's Why I Moved to Security Keys for 2FA

Поділитися
Вставка
  • Опубліковано 31 жов 2024

КОМЕНТАРІ • 185

  • @techlore
    @techlore  Рік тому +31

    Really funny because 'U2F' is one of those words you only read and never have to say - well I just consistently said it wrong the whole video :P Enjoy the review/coverage!
    *➡If you like our content, join our Patreon, it's one of the best ways you can help us spread privacy & security to the masses:* patreon.com/techlore

    • @user-xl5kd6il6c
      @user-xl5kd6il6c Рік тому +1

      U2F is terrible, easy to steal, easy to make so you lose access to your accounts forever
      TOTP solves all of this in better ways, I can have a backup somewhere online and no one would know. Even if the glowies raided my house and destroyed all my equipment, I would still have access to my accounts and data.
      The same just isn't the case for U2F

    • @bryceknight-ryder3239
      @bryceknight-ryder3239 Рік тому

      Merch!

    • @kpieckiel
      @kpieckiel Рік тому +2

      It would be really nice if you actually said what U2F stands for. I know MFA is multi-factor auth, 2FA is two-factor auth, but I actually had to look up U2F because I haven't encountered it before.
      (For those reading this that don't know, it's Universal 2nd Factor.)

    • @3nertia
      @3nertia 2 місяці тому

      @@kpieckiel 🙏

  • @tATuCentral
    @tATuCentral Рік тому +87

    Absolutely love security keys and the peace of mind they provide. However it baffles me that every bank I have only allows SMS verification 😒

    • @AV8R767
      @AV8R767 Рік тому +9

      Yes, banks need to get their act together. Problem is people wont pay the money for a security key.

    • @victoriaryan1509
      @victoriaryan1509 Рік тому

      A couple of banks in the UK still use the key where they send out a 6 digit code to a little plastic thing that you put your pin into, but they're reluctant to use them. like a little mini pocket bank. I'm totally up for getting security keys

    • @epytaffskitchenstink
      @epytaffskitchenstink 8 місяців тому +2

      In case you haven't noticed, banks are pros at placing the blame for their sloppy security on you. Everyone who has had their account hacked receives nothing but blame from the banks. It costs money to put real security on your accounts, it's cheaper to take the loss and have the banks lawyers find a reason you're at fault. Kind of like the Ford Pinto scenario Ford knew how many people would likely die from their poor design but took the risk (with the purchasers life) instead of fixing the safety issue.

    • @synthwave7
      @synthwave7 8 місяців тому +1

      Not the banks in South Africa - they use App Authentication etc. no SMS

    • @3nertia
      @3nertia 2 місяці тому

      Banks are the bedrock of capitalism so it only makes sense that they won't spend money doing something unless it makes them more money back than they spent ...

  • @lexshizumdot2115
    @lexshizumdot2115 Рік тому +26

    I bought 2 Security Yubikeys , because they fit my threat model. I still struggle with the "management" part but I'll get there, it's just a matter of finding the more intuitive arrangement, but overall I like this solution a lot. The irony is the few services I use that accept hardweare keys are the (only) ones that accept TOTP. It's all or nothing, so I've decided, whenever it's possible, to delete accounts or services that don't offer at least SMS 2FA.
    Thanks a lot for your video, and all your work :)

  • @z0rden_
    @z0rden_ Рік тому +102

    well u2f is so expensive so aegis 2fa is still a chad for security

    • @phukhue289
      @phukhue289 Рік тому +13

      also Aegis you can back up at will and the DB is encrypted. If someone has your password and manages to steal the Db files without that PW they are SOL. With this if someone has your PW and they steal this device , one tap and they are golden. I will be sticking with Aegis

    • @notafbihoneypot8487
      @notafbihoneypot8487 Рік тому

      Def aegis is based and I also have a Yubikey and have used my fliperzero also as a hardwear key, I can also put a password on the key as well
      Is based but I understand that it can be expensive for some

    • @notafbihoneypot8487
      @notafbihoneypot8487 Рік тому

      ​@@phukhue289 yes v based

    • @mkglo
      @mkglo Рік тому

      definitely a chad

    • @dinhductien2005
      @dinhductien2005 Рік тому

      But then Aegis is Android only, so... Sorry

  • @gotoastal
    @gotoastal Рік тому +31

    I appreciate the usage of the term “hardware key” all over this video instead of saying a singular brand like many do.

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому +6

      Yeah absolutley we got to keep competion alive and well there is more than one security key manafacturer 😀

    • @3nertia
      @3nertia 2 місяці тому

      @@DEFECTEDSTREETRACER Which ones? I've literally only ever heard of Yubikey lol

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER 2 місяці тому +1

      @@3nertia
      solo security keys
      Nitro security keys
      Titan security keys
      Onlykey security keys
      Personal reccomendation is nitrokeys specifically the nitrokey 3a nfc open source and future proofed 👍

    • @3nertia
      @3nertia 2 місяці тому +1

      @@DEFECTEDSTREETRACER Thank you

  • @redeyesdrogon786
    @redeyesdrogon786 Рік тому +16

    This is a great video. I was not fully aware of how U2F/Hardware keys work. After watching this, I would seriously start considering them. Thank you!

  • @hugoedelarosa
    @hugoedelarosa Рік тому +14

    I wish their keys were made of durable materials or that they were honest with clients and tell them: “don’t store these with your keys in your pocket”

    • @sibu7
      @sibu7 Рік тому

      Why should you not keep them with your keys?

    • @hugoedelarosa
      @hugoedelarosa Рік тому +3

      @@sibu7 because the Yubico keys are easily scratched. The USB type A keys do not have a shield and over time they wear out and have to be replaced, and they aren’t cheap. Mine doesn’t work reliably, I have to get a new one.

    • @Darkk6969
      @Darkk6969 4 місяці тому

      @@hugoedelarosa Amazon sells covers for the keys.

  • @mukkaar
    @mukkaar Рік тому +10

    U2f is nice, but personally I would only recommend it for business, including working for yourself. TOTP is frankly more than enough.

  • @penultimatename6677
    @penultimatename6677 Рік тому +10

    Yubikey has a 2fa app. The info is kept on the key. If someone can open the app they will find nothing.

  • @notreallyme425
    @notreallyme425 Рік тому +12

    4:53 limitation #3, this is the main reason why I haven’t switched to these. I’m thinking of the disaster scenario where my house (and Yubikey) gets destroyed in a tornado. Keeping a backup key at a friends house isn’t a good idea because that would require having a friend, you’d have to retrieve it every time you update or create a new credential, and what if the tornado hits his house too? I’ve setup as many of my credentials using zero trust, like my password manager. So if I lose the password or 2FA there’s no way the service can let me back in. Having a weaker backup authentication method defeats the purpose of using the Yubikey in the 1st place. So, I’ve stuck with TOTP codes that I have encrypted backups of in the cloud. If an asteroid destroys my house and the cloud, then I’ve got bigger problems.

    • @soy_terrible
      @soy_terrible Рік тому +3

      Back-up #1 stays in our fireproof safe (~$75), Back-up #2 stays in my Mom's safe (~100 miles away), Back-up #3 stays on my wife's keyring.
      The hassle of updating back-up #2 (at my mom's) is definitely something to contend with, but... security > convenience

    • @heymaumaumau
      @heymaumaumau Рік тому

      ​@@soy_terrible And remember that everytime you create a new account for another website you need to manually add the backups to the account as well (hopefully supported). And whenever you lose one of the keys you'll need to add the replacement to each of the existing accounts. I can only imagine how painful this would become in terms of support requirements to help people get back access to their accounts if this were to be embraced by the general public in terms of support required as barely anyone would even consider going to the lengths you describe.

    • @soy_terrible
      @soy_terrible Рік тому +1

      @@heymaumaumau You're completely right, but I stated your mindset has to be security > convenience. Most people don't care enough about security to even enable 2fa SMS - until they are forced to. And even then, they moan and grown about it. How do I know? I work IT for a private school and cover multiple trainings about privacy and security. Of the ~300 employees, less than 10% have actually made changes to the way they manage online accounts. And I'm giving them free and easy to implement tools. Your scenario of "support requirements to help people get back access to their accounts" is a nonstarter because people watching this video or actively seeking this information that decide to use hardware security keys are very unlikely to be people who need help recovering accounts. Hardware keys will never be embraced by the general public, at least not in this current iteration because it's too inconvenient.

    • @heymaumaumau
      @heymaumaumau Рік тому

      @@soy_terrible I agree with you as well for the most part, I guess the difference might just be determining where "security > convenience". And in my case whether the inconvenience of the steps one must take to avoid getting locked out of an account in the event of losing a hardware token is worth it compared with the additional security of having those hardware tokens in the first place. At least now, with standardization of these hardware tokens, hopefully each org that starts requiring their use doesn't require people to carry their unique one anymore and allowing people to avoid having to carry separate tokens for each of the important accounts they may want to be able to access on a daily basis, if they want or need to rely on these tokens for additional security.
      In my personal case I already use a security key for work, but I'm still on the fence about whether it's worth it using for my personal accounts as well. I guess I'll wait a bit more and see how this ends up being adopted by the services where I have accounts and how they handle loss of keys.

    • @cipher893
      @cipher893 3 місяці тому

      @@heymaumaumauI’m going to use Proton Pass where I keep all my passwords and accounts. There’s also a 2FA baked in as well as ability to register passkeys directly to the accounts that support it. To login to my Proton Pass I use my Yubikey. Problem solved, at least for me.

  • @galaxytrio
    @galaxytrio Рік тому +9

    Henry, you are GREAT at this. Thanks for this helpful info. I look forward to your review(s) of the open source alternatives to Yubikeys.

  • @oooo0O0oooo
    @oooo0O0oooo Рік тому +6

    Biggest obstacle is that it's not widely available in most of the countries ! Moreover, govt. in those places can ask operators to share SMS or force you legally to unlock your phone :)

    • @oooo0O0oooo
      @oooo0O0oooo Рік тому

      @BlackLivesMatter we can't refuse legally. that's why u2f is very important for us yet it's availability is close to zero. even if we order online, the price goes very high because of the shipment cost and unbelievable tax rate.

  • @manny7886
    @manny7886 Рік тому +5

    Great video. I use mine with my password manager Bitwarden. I wish financial institutions (i.e. banks, credit card companies) support hardware 2FA.

    • @Darkk6969
      @Darkk6969 4 місяці тому +1

      Bank of America supports it now.

  • @capn
    @capn Рік тому +3

    People with security keys: "Wow look at me, my security is impenetrable!"
    People with fingers: "yoink that real quick thanks"

    • @-_Somebody_
      @-_Somebody_ Рік тому

      This is why I’m hesitant to make the switch…I need my security to be discrete. Besides I’m too worried I’ll misplace it on a busy day I can’t keep up with putting it back in its rightful place.

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому +1

      that's a fair point nothing is foolproof the reality is if someone wants to get you no matter what walls you put up, they will find a way around, but we should at least step back reflect and make an effort to prioritize security because we may not know what threats lies ahead and we should weigh up the pros and cons for each setup based on our threat models in our heads to ensure our safety

  • @Pewafamath
    @Pewafamath Рік тому +6

    Switching off a phone entirely for a year has been difficult. Arguing with the bank to remove the cell number they have on my account or disable 2fa and they just wouldn't and ultimately left with just freezing the account entirely.

    • @-_Somebody_
      @-_Somebody_ Рік тому +1

      @Not Me I’ve done exactly this after I learned that for myself several years back with a yahoo account I tried to get rid of.

  • @JohnSmith-zl8rz
    @JohnSmith-zl8rz Рік тому +5

    You should do a yubikey guide, is a pain in the ass understand everything about it, just open the Manager (PIV, FIDO, OTP) pin, passwords and open the Auth App more stuff, is a mess!!! understand the two yubikey apps. This video is useless until you explain all that showing that two apps.

    • @benwika3714
      @benwika3714 Рік тому +3

      I got a Yubikey 5 NFC recently, really just out of curiosity and your comment really hits home. It's remarkable how complicated the learning curve is to using it. Here I was thinking the whole point was to make 2FA easier. And given it was potentially going to be a critical link in my security processes, I feel like I need to absolutely understand every aspect of how it works before I could ever really use it for real world security. Following just the simplified guides for basic usage felt like I was trying to set up a home network server accessible to the outside internet without the faintest understanding of all the security implications.
      Then I thought, maybe I'll just use it for TOTP only, but couldn't get Yubikey's authenticator app to work on my custom rom due to some missing os function.
      So then I thought, maybe I'll just use it to unlock my keepass. And that became a massive learning curve in itself and couldn't get the same functionality working on both desktop and mobile so that the same database could be used. At this point it's really just gathering dust until one day perhaps I'll investigate again - maybe on a new phone or a new keepass app or some other situation. At this point I'm kind of thinking it's only purpose could be to just store it somewhere as kind of a key to some master set of instructions on how to decrypt my life that I can leave to my loved ones in my will.

  • @sammydepresso
    @sammydepresso Рік тому +6

    I have 2 yubikeys, best 80 bucks I ever spent.

  • @Torpps
    @Torpps Рік тому +4

    Great video like always. I’m looking forward to the reviews on the other hardware keys

  • @myentertainment55
    @myentertainment55 Рік тому +7

    Yeah, Laptops should put more than 3 USB ports!
    Less than 3 is just embarrassing

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому

      My acer predator helios 300 2018 has 3 usb a ports so its not impossible it also has Ethernet USB C and SD Card slots plus a feature apple removed much to many dismay although im not to fussed the beloved headphone jack 😁

    • @myentertainment55
      @myentertainment55 Рік тому

      @BlackLivesMatter my condolences : (

  • @bradyy0rk
    @bradyy0rk Рік тому +11

    What I really don't like about the Yubikeys and basically all of the of the other U2F devices is that you cannot back them up. So you have to buy and register multiple devices for each service to be safe. Which is both annoying and expensive. With Trezor I can use it for U2F and restore it with the seed phrase if needed. But for that I have to carry around a bigger and more complex crpyto wallet.
    Why is no dedicated hardware key doing something like that?
    Is there any other device that supports backup and restoring? Preferably some small one dedicated hardware key like the Yubikey Nanos. I did not find any so far.

  • @TadeoVance
    @TadeoVance Місяць тому

    Appreciate the detailed breakdown! 🧐 Just a small off-topic question: 😅 I have a set of words 🤷‍♂️. (behave today finger ski upon boy assault summer exhaust beauty stereo over). How do I use this? 🤨

  • @RitzyBusiness
    @RitzyBusiness Рік тому

    I've been using yubikeys for over a decade now. While I am not particularly a security enthusiast, I find them to be extremely convenient. Especially when traveling to countries where you might not have your phone number. Getting locked out of your email because you don't have your phone # is not a good time.
    But also have a key that only I have access to makes things quite nice. I wish banking institutions would allow me to use it. As of now, my banks are my weakest links when it comes to 2fa

  • @TonyPadgett
    @TonyPadgett Рік тому +3

    Woudn't leaving that key in your laptop be a risk? For example, what if someone stole your laptop with it in it?

    • @techlore
      @techlore  Рік тому +1

      ua-cam.com/video/epiduqAStlE/v-deo.htmlm59s
      We directly touched on this on our recent Techlore Talks if you want to see our thoughts 🫡

    • @TonyPadgett
      @TonyPadgett Рік тому

      @@techlore Points taken. I just think though that leaving it in raises the risk.

  • @gmmxn
    @gmmxn Рік тому +1

    I have been using yubikeys for years, I even give them as a birthday present sometimes to friends and family....

  • @HalfwayHikes
    @HalfwayHikes Рік тому +5

    What is the risk of leaving one in your laptop if, say, the laptop was stolen? Do you remove the nano when not using?

    • @techlore
      @techlore  Рік тому +8

      Good question! Ahead are my personal takes on this. The key is meant to be something you 'have' - and then passwords and usernames/emails are something you 'know'
      On paper, because you need both forms of authentication for 2FA, there's no inherent risk if someone only obtains one. If someone steals your laptop with your key inside it, assuming your laptop has a strong password + Full disk encryption, there's very little anyone could do as they wouldn't be able to retrieve your passwords, emails, and/or session cookies from your browsers. (which are required alongside your security key)
      Even if someone bypasses your computer login, there are further precautions in place for the above risks, like clearing data from your browsers on exit, and ensuring you're using a safe password manager with a strong master password.
      TLDR:
      - In my eyes, keeping the key plugged in is every so slightly less secure, in exchange for a massive bump to convenience - which for me means it stays in my laptop - but this'll depend on your threat model 👍
      - It's much more important for most people to layer up their security, than to be stressed about where their Yubikeys are being kept. This means: Full disk encryption, being aware of data being stored by your browser(s), ensuring you have a strong login password, having a backup security key in the event the one in the device is stolen, and using a strong password manager with a strong master password!
      - Do your best to ensure that something you 'have' and 'know' are not easily obtained at the same time from the same incident, and be ready to layer up to ensure this.
      A fun game to play is to think over scenarios of people gaining access to certain things. Example:
      - IF an attacker steals my security key with my laptop, THEN I will be safe because they'll need to bypass my device login and full disk encryption
      - IF an attacker manages to bypass my login and gain access to my OS, THEN I will be safe because my browsers clear data on exit, and my password manager is locked behind a secure password
      - IF an attacker manages to gain access to my password vault, etc.
      Just keep in mind the more 'ifs' you implement, the less likely it is to happen, but hopefully this comment adds some perspective on the question you're asking. No, I keep the nano plugged in all the time.
      Another tidbit: You can set up a PIN for your security key that some sites will respect. So even if someone steals your key and your laptop and they have your creds, you can still require a PIN to use the key.
      Edit: Yubikey also offers biometric keys as well to kind of address this problem.
      -H

    • @HalfwayHikes
      @HalfwayHikes Рік тому +2

      @@techlore - thank you for the detailed response. I agree. They would need physical access to the device AND know the login to that device.
      For me, I’m less concerned about the device itself and more about stopping access to information/data like my Microsoft, google, 1Password, proton account settings. The goal would be to stop account take over or even worse, permanent lockout even if a device is stolen or compromised.

    • @kruegdude
      @kruegdude Рік тому +1

      @@techlore The hardware key is the thing you have to secure some service, not your laptop. It seems like if they have your key it would be like they have your sim from your phone.

    • @techlore
      @techlore  Рік тому +1

      ua-cam.com/video/epiduqAStlE/v-deo.htmlm59s
      We directly touched on this on our recent Techlore Talks if you want to see more of our thoughts 🫡

    • @HalfwayHikes
      @HalfwayHikes Рік тому +1

      @@techlore thank you so much. Watching now. I’m definitely buying some yubikeys. I’ve been wanting to do it for awhile now and it’s good to hear your thoughts on it.

  • @Riclaval
    @Riclaval Рік тому +2

    First thought after first few seconds was "again?"
    These hackers ain't getting anymore out of an emptied account and widely abused and banned user profiles, so just like artists losing to A.I. they better adapt.

  • @Waltaere
    @Waltaere 7 місяців тому

    Thanks for putting in the effort and extra demonstration in this fairly informative video, as i added it to the top my 2fa topic playlist i might show my sister later.
    Anyways, Liked and subscribeds 👍

  • @alicethegrinsecatz6011
    @alicethegrinsecatz6011 Рік тому +3

    You don't need to plug them in. You can use NFC on some models

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому

      My Nitrokey 3A has nfc support it works but you have to take your phone cover off still it works

    • @hellouser5498
      @hellouser5498 8 місяців тому

      Cant they integrate U2F NFC into phones, no need for separate device

    • @alicethegrinsecatz6011
      @alicethegrinsecatz6011 8 місяців тому

      @@hellouser5498 Phones have a similar feature called Passkey but Passkey is a software solution. When your phone is infected, the keys could be stolen. This can't happen with a physical security key.

  • @vmobile890
    @vmobile890 2 місяці тому

    Where is a website with all the information needed explaining this information . See many videos of parts but not all . One video seem to say non compliant devices will be locked out but using the key on a compliant device will give all devices access ?

  • @michaelunderwood6298
    @michaelunderwood6298 Рік тому +1

    I recently updated my phone since it forced me to do so, but when it finished updating it, all of my photos, videos and apps I have downloaded were all gone including the authenticator. I used the authenticator for roblox for my account log in, but now that it has been deleted, i can't log in nor find the exact authenticator i used. I tried setting back up the log in code on other authenticator apps, but it didn't work. So now i can't log in to my account anymore. Can someone help me?

  • @ryak2
    @ryak2 9 місяців тому +1

    All this security is a nightmare.

  • @rashidismail9537
    @rashidismail9537 Рік тому +3

    Is it open or close sourced...I mean the hardware firmware.

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому +3

      YubiKeys demonstrated in the video are closed source security keys however you can buy an open-source alternative such as nitrokeys and solokeys for around the same money.

    • @rashidismail9537
      @rashidismail9537 Рік тому +1

      @@DEFECTEDSTREETRACER Thoughts on Onlykey and Google Titan? Are they any good?

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому

      @@rashidismail9537 so for google titan they are great very well put together and established security keys work well with android devices, but I believe they are closed source (someone correct me if I'm wrong) I was looking at them for purchase when I was shopping around for U2F keys however shipping options outside of the US are spotty at best meaning to get a hold of one outside of google store you would need to purchase it of eBay for example and we all know how sketchy that can be in relation to tampering as for only key I researched it as I had no prior knowledge of them but they seem to be more geared towards tech professionals like developer types features include pin code u2f with self-destruct pin code as a pose to just tap and in so that's pretty sweet however they cost nearly 200$ USD that being said though they are open source and store passwords too so it's not all bad news

    • @rashidismail9537
      @rashidismail9537 Рік тому +1

      Thanks bro.Really appreciate it.

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому

      @@rashidismail9537 no problem happy to help happy shopping 8)

  • @TheWhiteLotuss
    @TheWhiteLotuss 8 місяців тому +1

    Can you use adapter USB C to USB A Please If you want the tinny one Techlore 🤗Thanks in advance

  • @Skyman12808
    @Skyman12808 Рік тому +1

    Thanks for your video Mr Henry

  • @CrittingOut
    @CrittingOut Рік тому +2

    been thinking of getting a yubikey too honestly, but I don't really have anything to warrant it.

    • @gotoastal
      @gotoastal Рік тому +5

      Get an open source alternative

  • @johnnny9
    @johnnny9 Рік тому +2

    whats the life span of a yubi key ?

    • @stratvar
      @stratvar Рік тому +1

      Just like with most electronics, lifespan is a combination of how you re using/treating them and luck.

  • @rydmerlin
    @rydmerlin Рік тому +2

    If you keep it with your laptop you lose it and your laptop together.

  • @mountainslopes
    @mountainslopes Рік тому

    What’s weird here to me is why you would use an external security key over something like Passkeys. I have multiple security keys which I use weekly, but I use biometrically protected Passkeys wherever supported

  • @gidi1899
    @gidi1899 Рік тому

    @Techlore - Thanks for another great assistance in security management :)
    One Question:
    About software updates - Does the HW key or the OS service require updates? since it's also a security vulnerability?
    OS service - I mean - the code that transport the "public key" and the "location of the private key on the HW-Key"
    between the App/Site and the USB connector, on registration and login sequences.

  • @gregvanpaassen
    @gregvanpaassen 7 місяців тому

    I tried the most well known brand of hardware key ten years ago. The main key failed after three weeks of being carried around on my key-ring. Just failed, for no reason.That is not reliable enough. Never had a phone fail on me.

  • @San_Dee
    @San_Dee Рік тому

    Do you have a video on having multiple 2FA and using the others as backup? Say hardware keys are your active 2FA, meaning the only one you use, and you lost your hardware keys, but fortunately you’ve got your TOTP Authenticator code backed up in a location that doesn’t require the use of that hardware key. My thought being that you have multiple 2FA, which seems less secure, but if you aren’t using the other ones it lessens the possibility they are compromised. Instead just have them stored on an encrypted USB or in a veracrypt folder on the cloud (your thoughts on the security of this too?) for the day all your hardware keys are lost. Realistically I don’t see why having more than one backup 2FA is necessary if you would be storing that 3rd 2FA backup in the same secure place. Or any other thoughts on this, best alternative backup 2FA (might depend on the 2FA offered by each service).
    Basically any video you can point to where you talk about using multiple 2FA and your security thoughts on this. Thanks!

  • @Translogiced
    @Translogiced Рік тому +2

    I bought my 2 Yubikeys back in 2021 and I love them
    I really wish BANKS WOULD GET ON THEM MOST OF ALL it boggles my mind how this is not a thing
    I use them everywhere I can and I always disable all other methods like SMS and TOTP if I am allowed to like on Twitter
    UA-cam should also force you to Authenticate with 2FA when making important account changes like changing the channel name or modifying 2FA itself
    Coinbase does this it is strict about it too like even changing my password I have to Authenticate the change with my Yubikey and I love it
    Same thing happens with changing your email for Coinbase

  • @herbglub5831
    @herbglub5831 Рік тому +4

    Love this channel and the podcast

  • @Saadlatif92
    @Saadlatif92 Рік тому

    Why does Instagram not have the option for Yubikey or for any physical hardware token form of 2FA?
    It’s very weird considering that Facebook has this option and both companies are part of Meta.

  • @bronkolie
    @bronkolie Рік тому

    Why would you keep one key in your wallet and another in your laptop? Surely if the one in your laptop breaks you wouldn't need the backup that urgently? Also wouldn't that be a problem if you fall into water? You'd think you should just keep one at home. idk tho

  • @petergon3613
    @petergon3613 15 днів тому

    Do you know how I can set on amazon to use myr authentication harware key as the primary, and not have to keep receiving codes to my phone.

  • @justincase5272
    @justincase5272 9 місяців тому

    Security requires something know, have and are -- each and every time. Authenticating apps and keys are only as secure as your phone and key. Therefore, you MUST enable a solid 6-digit PIN to use every time you log in to each and every account. Otherwise, you're short-circuiting your own security.
    Know: PIN
    Have: phone, key
    Are: fingerprint (record multiple from both hands)
    SMS is absolutely NOT secure
    TOTP is not as secure as you think! If someone were to sit down at an unlocked computer with TOTP, they would have access to the authenticator.

  • @sijonda
    @sijonda 10 місяців тому

    I'll look into these more. I use a password generator and have generated passwords for every account I have but everything is on one encrypted file across 3 of my devices. It it supports having a security key but it's a digital file you can put in a flash drive so it's not as convenient as just tapping the end of the key.

  • @pperrinuk
    @pperrinuk Рік тому

    I have three fido devices I got years ago get them out now and then for another shot... always too much of a pita. Now if there were a password manager that used U2F to effectively U2F enable all the sites I use, I guess it may be ok.
    A couple of mine do bluetooth, NFC and USB, but never really worked with android - and I only recently got a phone that does NFC....
    Maybe time to dig the out again!

  • @lucious455
    @lucious455 Рік тому +1

    I don’t know if I fully trust these keys … see they could Install a keylogger and still be hacked.

  • @alphatech__
    @alphatech__ Рік тому +2

    Meanwhile Cookies Session Hijack 😶

  • @Eeeeejjejsud7372
    @Eeeeejjejsud7372 2 місяці тому

    I have a different method for 2FA. I currently use my Authenticator app via 2FAS as backup and I use my security key as my default key.

  • @asishreddy7729
    @asishreddy7729 Рік тому

    If I lose my hardware key is there an option to switch over your old credentials from the lost key to a new hardware key over the internet? Otherwise, revoking the old key and adding a new one in all my websites will be a tremendous headache. I know we will have a backup key as well, but we still have to revoke the lost key on all the websites.

  • @pmauriciomm
    @pmauriciomm 7 місяців тому

    and where passkeys goes in all this?
    better or worse?

  • @gothducks
    @gothducks 8 місяців тому

    Best option but just another thing for me to lose. It and the backup, which is barely useful since many sites don't support it and just forget any financial institution.

  • @wolixoriginal
    @wolixoriginal Рік тому

    Do you know now security keys now integrit on phones to say your fingerprint be your utf

  • @Geothy
    @Geothy Рік тому +1

    5:11 55 dollars? Here in the netherlands they are 95 euro's.

  • @Spiralnebel_GB
    @Spiralnebel_GB Рік тому

    @Techlore: The Nano can be used in a Pixel 6a, right? Plugin in with the sensor up or down, right?
    Can someone tell me if it fits into the cutout at the USB-C Port of the Otterbox Commute?
    Otterbox can not tell me even i provided the exact dimensions 🙄

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому

      Since the nano is usb a You can use a usb a to c connector thats the size of a small phone charger cable and it should fit through thats what i use for my 2fa keys

    • @Spiralnebel_GB
      @Spiralnebel_GB Рік тому +1

      @@DEFECTEDSTREETRACER There is also a Nano 5C i would line to use with the Pixel ;)

  • @Imperfect_Mom
    @Imperfect_Mom Рік тому

    Is it safe to leave it in your PC all the time?

  • @Gy_279
    @Gy_279 10 місяців тому

    Bro.. I flashed my phone... I used my fingerprint as security key.. Now my fingerprint is required to open discord.. What should I do please help

  • @portman8909
    @portman8909 8 місяців тому

    Can you not use authenticator app on your phone as a bakcup to get on the account if you lose your key?

    • @rblythin
      @rblythin 8 місяців тому

      No, the yubico app merely displays what is on the key. Without the physical key the app has no information to bring up. Nothing is saved on the app itself

  • @someoneoncesaid6978
    @someoneoncesaid6978 Рік тому +2

    If you keep it plugged into your laptop, and someone steals your laptop, you've provided them (literally) the key to hacking all of your accounts.

    • @techlore
      @techlore  Рік тому

      ua-cam.com/video/epiduqAStlE/v-deo.htmlm59s
      We directly touched on this on our recent Techlore Talks if you want to see our thoughts. It's not that simple. 🫡

    • @tjgdddfcn
      @tjgdddfcn Рік тому +1

      wouldn't that also require them to have the password?

    • @someoneoncesaid6978
      @someoneoncesaid6978 Рік тому +3

      @@tjgdddfcn - It would, but the point of 2FA is that passwords are hackable, hence the need for the second physical layer of security. But, when you're providing the physical layer to the thief, then you might as well just use a password and not bother using the physical layer.
      It's like having a security door that uses a keypad, and you go "That's not secure enough, because someone could figure out the security code, so I'm going to add a physical key lock to it too, so that you have to have the physical key and the security code to get in." Then, it becomes inconvenient to keep the key on your keychain and digging it out every time you want to open the door, so you just start leaving the key in the lock. You've effectively downgraded your 2FA back to just needing a security code to get in.

  • @Techkomsan
    @Techkomsan Рік тому

    I prefer to security key better than 2FA

  • @vitalis
    @vitalis 5 місяців тому

    There is a maximum of 32 TOPT key limit btw

  • @LionRoars918
    @LionRoars918 Рік тому +1

    Or your bank has no 2FA. Yes truly these days thats sad.

  • @ErnstNoel-i5y
    @ErnstNoel-i5y Рік тому

    can your employer track your location with this key?

  • @comically
    @comically Рік тому

    ☝🏼Unfortunately, they don’t work with Windows Hello (apart from Azure Active Directory), if I’m not mistaken. 🤔
    🤷🏼‍♂️

    • @HalfwayHikes
      @HalfwayHikes Рік тому

      I think they do. Security key is an option for signing in with Microsoft Account

  • @_modiX
    @_modiX Рік тому +1

    Do they work on Android phones?

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому +2

      Yes it does still work if you have a usb c key and even a usb a to c adapter to plug in however support depends on the service you are using and how well they have set it up

    • @comically
      @comically Рік тому +4

      ​@@DEFECTEDSTREETRACER Keys with NFC are also an option, if supported by your phone/tablet. 🤓

    • @_modiX
      @_modiX Рік тому +1

      @@DEFECTEDSTREETRACER Thanks!

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому +1

      @@comically yes absolutley i forgot to mention NFC support for security keys and phones 😅

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому

      @@_modiX no problem happy to help if you need a personal reccomendation on security keys im running nitrokey 3A NFC for my accounts that support it in comparison to yubikeys they are open source if you value checking the code and are also fido2 certified plus you can attach them to a keychain as well 😁

  • @Kaleb-lf8kf
    @Kaleb-lf8kf Рік тому

    surprised you didn't redo the video with how many mistakes there are, other then that great advice

  • @handicappuccino8491
    @handicappuccino8491 Рік тому

    They should make these with security cameras on them so you wouldn’t have to buy multiple ones maybe they can team up with us security camera company

  • @immortalcyanogen779
    @immortalcyanogen779 Рік тому

    What about onlykey?

  • @addy7445
    @addy7445 Рік тому

    Bro got confused between u2f and dablu tee eff😂🤣

  • @ThomasAndersonPhD
    @ThomasAndersonPhD Рік тому +6

    This is a nice summary, but I'm surprised that you felt comfortable releasing a video of this quality. The consistently repeated speech-errors are unprofessional. Given that it is such a short video, it seems like a candidate for re-recording. Just say all the same things, but "U2F".

  • @bernardmueller5676
    @bernardmueller5676 8 місяців тому

    What a joke. My company is completely moving away from FidoKey and YubiKey to MS Authenticator. Nobody wants those keys.

  • @DiSiBijo
    @DiSiBijo Рік тому

    good luck with carrying that around

  • @recklessroges
    @recklessroges Рік тому

    rfc6238 should be mandatory for all websites.

  • @naromekram
    @naromekram 6 місяців тому

    Chase bank doesn’t use yubikeys.

  • @TheMegaOddly
    @TheMegaOddly 11 місяців тому

    I would love if my bank would give me a way to use 2FA to use hardware key over app or sms

    • @Eeeeejjejsud7372
      @Eeeeejjejsud7372 2 місяці тому +1

      As long as your authenticator app is secure via E2EE and isn't collecting data, you would most likely be fine.

    • @TheMegaOddly
      @TheMegaOddly 2 місяці тому

      @@Eeeeejjejsud7372 My issue is my bank is either SMS or their own proprietary software authentication app. I dont want to have so amy Auth apps on my phone id rather either a physical key or it be companiable with other apps and not force me into their own

  • @MysticMylesZ
    @MysticMylesZ Рік тому

    3:50 USBc?

  • @TheSolderingGuy007
    @TheSolderingGuy007 8 місяців тому

    I don't get it.
    1. If you are still entering password, how it better than password ?
    2. If a touch is all it takes (and not fingerprint/pin), whats prevents it from being stolen and used ?

    • @TheSolderingGuy007
      @TheSolderingGuy007 7 місяців тому

      No that's not correct reasoning for number 2. I found the correct answer elsewhere. A touch of the HW key alone is not sufficient to use the key. The key has an associated pin which you need to enter on every use. So even if a bad actor steals your key, they cannot use it since they wont know the associated PIN.

  • @AUDIO2AUTO
    @AUDIO2AUTO Рік тому +1

    Let me see you sim swap my email. Just send the code to the email instead of a phone company not smart enough to not swap you with someone thats not you.

  • @An.Individual
    @An.Individual Рік тому

    Leaving the yubikey plugged into the laptop sounds like a terrible idea.

  • @DigitalDissident
    @DigitalDissident Рік тому

    how much you get paid for this sponsorship

  • @electricz3045
    @electricz3045 Рік тому

    Yubikey is actually 3fa so the title you've chose make little sense...

  • @byrd203
    @byrd203 Рік тому +2

    ok break your 2fa key all of them can you get in your accounts no loose your iPhone otp you just sign in to your iPhone plus the iPhone version in settings more secure you must have your face id unlocked first to use it then it auto fills boom much better plus Apple locks otp down great

    • @DEFECTEDSTREETRACER
      @DEFECTEDSTREETRACER Рік тому +3

      They did mention those disadvantages of 2fa keys in the video i guess like anything do so at your own risk

    • @stratvar
      @stratvar Рік тому

      It is one of the main disadvantages of Yubikeys. However, most if not all services that give a 2FA option, also give you back-up codes in case you lose your 2FA authentication method.

  • @TomNook.
    @TomNook. Рік тому

    UTF lol

  • @AUDIO2AUTO
    @AUDIO2AUTO Рік тому

    Until you lose or the key gets stolen.. lol

  • @epytaffskitchenstink
    @epytaffskitchenstink 8 місяців тому

    I'm hoping Proton will at the security key for the phone as well. Currently you can only use the key to the computer. And yes you need extra keys, we have 4 in our household.

  • @BD4-ManchesterIsRed
    @BD4-ManchesterIsRed Рік тому

    👍

  • @ISCARI0T
    @ISCARI0T Рік тому +1

    people who care about security as randoms are insanely delusional. narcissism + low knowledge in computer science, happens i guess..

    • @tjgdddfcn
      @tjgdddfcn Рік тому

      It's better to overestimate than to underestimate

  • @5lothamLovesPedos
    @5lothamLovesPedos Рік тому

    I always thought 2fa was stupid.