Why Usernames Are Just As Bad As Passwords - Identity and Access Management

Поділитися
Вставка
  • Опубліковано 15 кві 2020
  • SUBSCRIBE! 🌸 ua-cam.com/users/ShannonMorse?s...
    TWITTER 🌸 / snubs
    Patreon 🌸 / shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    ⭐IN TODAY'S VIDEO ⭐
    Working from home comes with new complications with regards to Identity and Access Management, or IAM. In this new 6 part series, I'll share what current "best practices" we use for security and how we can work to make "best practices" in IAM even better.
    This episode is sponsored by WWPass! Learn more about WWPass here: www.wwpass.com/
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    SUPPORT MY WORK
    Patreon 💛 / shannonmorse
    Buy Me a Coffee 💛 www.buymeacoffee.com/snubs
    Shop 💛 snubsie.com/shop
    Coupon Codes 💛 snubsie.com/support
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    FOLLOW THE SOCIALS THINGS
    Twitter 🌸 / snubs
    Instagram 🌸 / snubs
    UA-cam 🌸 ua-cam.com/users/ShannonMorse?s...
    Website 🌸 www.shannonrmorse.com
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    TECH I USE AND RECOMMEND
    Amazon Associates ✨ amzn.to/2pHgf8T
    My Amazon Influencer Page ✨ www.amazon.com/shop/shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    MY OTHER SHOWS
    ThreatWire 🌙 ua-cam.com/users/hak5?sub_confi...
    Sailor Snubs 🌙 ua-cam.com/users/sailorsnubs?s...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    GET IN TOUCH
    Mail ✈
    SHANNON MORSE
    558 CASTLE PINES PKWY UNIT B-4 #198
    CASTLE PINES CO 80108
    UNITED STATES
    Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com
    My Media Kit ✈ tinyurl.com/qmoz4sk
    Music from Pond5 🎵 www.pond5.com/?ref=snubsie and UA-cam's Music Library
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    😍 FTC DISCLAIMER 😍
    Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Thank you for your support!
  • Наука та технологія

КОМЕНТАРІ • 23

  • @johntaylor7020
    @johntaylor7020 3 роки тому

    I remember a comment I heard around Y2K, paraphrasing. "When you share your username, your halfway to being hacked."

  • @weirdler
    @weirdler 4 роки тому +8

    You can tell it has been a long lockdown as Shannon’s hair has lost almost all its purple.

  • @kianoa193
    @kianoa193 4 роки тому

    Thank you Shannon very interesting! :)

  • @RoniRachmani
    @RoniRachmani 4 роки тому +1

    Shannon: " I am introducing a X part series.."
    My face: 😍
    *turning on all notifications*

  • @praecorloth
    @praecorloth 4 роки тому +2

    My own personal recommendation I make whenever I can:
    Do NOT tie internal facing usernames with external facing usernames. E.g. Do NOT tie your fancy Cisco remote access VPN to your company Active Directory/LDAP. Generally I am on the side of "It is the administrator's job to help make technology useful, available, and usable for their users." This is one of the very few cases where I make an exception. It absolutely kills me when I see a person's company email address have the same username as their desktop/laptop login which is the same as their VPN login. This setup means that usernames to connect to your network, and to move around within your network are knowable by the filthy, unwashed internet at large.
    This is the lowest hanging fruit. I know this video is getting us started moving away from the whole username/password model. But separating your users' VPN credentials from their internal network credentials is a pretty easy change to enforce.

    • @ShannonMorse
      @ShannonMorse  4 роки тому

      💯 agree with you. Great comment!

  • @joejamescat4126
    @joejamescat4126 4 роки тому

    Very good video. Really enjoyed the style of your presentation. Security is such a hot topic. Thank you for making my working from home safer.

  • @hardversesthesebibleverses9926
    @hardversesthesebibleverses9926 4 роки тому

    Before video...patting self on back for good password protocol.
    After video...hunched over, back to the drawing board.

  • @janokartal5690
    @janokartal5690 4 роки тому

    Nice one shannon 🙂🙂

  • @bothellkenmore
    @bothellkenmore 4 роки тому

    I worked for a medical company that was governed by HIPAA so we already had a pretty strict VPN procedure back in 2012. The few of us that had decent PC's back then really enjoyed kicking in a few hours of OT. The security loophole was the documents we had in hand from the office.

  • @jr4062
    @jr4062 4 роки тому

    Great information. For myself with a horrible memory, I would like to see a book or list of ways to protest my identity on the internet. Something like “IAM for Dummies” like me.

  • @aaronperl
    @aaronperl 4 роки тому

    Very nice, thanks. I'm still crossing my fingers for SQRL, but anything to get rid of usernames and passwords will be great

  • @0bscura
    @0bscura 4 роки тому +1

    I work in technology services and the number one problem that I see is users who forget or lose their passwords. There's no good answer here like you said folks want things to be easy. Personally I use a password manager and have a different password for every account and they're long and they're difficult. I've put my wife on the same password manager with the family plan so that she can gain access to our accounts if something were to happen to me. The problem is after months of trying she still is still having a hard time using the password manager.

  • @JoshyDaMan08
    @JoshyDaMan08 4 роки тому

    Shannon, I've done with same password on every sites for years. Shame on me. Unfortunately, one of my account hacked but I've changed quickly til' my lesson learned. That suck. I'm thinking about getting the Yubi keys and how reliable are they now? I've seen for years but still on Amazon. I really needs to step up security in near future. Possible get worst later. Excellent content 👌🏼

  • @Eva-gg3kx
    @Eva-gg3kx 4 роки тому +1

    Heyo! ❤️👋

  • @brayden4740
    @brayden4740 4 роки тому

    Hey just curious if you have any recommendations for good file encryption software, and if you're planning on making a video about encryption?

    • @ShannonMorse
      @ShannonMorse  4 роки тому +1

      I've used Veracrypt over the years for file encryption. It's a fork of TrueCrypt and works really well I can do a video about it.

    • @brayden4740
      @brayden4740 4 роки тому

      @@ShannonMorse that would be great because I feel like more people need to start using encryption!

    • @brayden4740
      @brayden4740 4 роки тому

      @@ShannonMorse and thanks for the recommendation I'm definitely going to check it out.

  • @jedimindtrickonyou3692
    @jedimindtrickonyou3692 4 роки тому

    What do you think about services like 33mail and anonaddy? I use them to obscure my true email for lots of services and they let you make an individual email for each site, all flowing back into your main email inbox. I just worry about using it for important, sensitive accounts. Let me know if you think that’s a good strategy for “junk” accounts. Maybe you could touch on that in a video and which services are most trustworthy. I think blur allows for some of the same type of thing. Anyway, looking forward to the series!

    • @ShannonMorse
      @ShannonMorse  4 роки тому

      It's convoluted to have to sign up for a third party service just to create aliases or to hide your email address. To me, these services are putting a bandaid on the problem, not fixing the problem of usernames and passwords.

    • @jedimindtrickonyou3692
      @jedimindtrickonyou3692 4 роки тому

      Until all these online services allow for something better, it’s all I know to do to protect myself. And it is too much work for the general user, but I just don’t see an alternative if I want to have online accounts and not give these websites my email address. I think that until they have to change, they won’t. Same goes for the critical mass of users, but I do think the fire has been lit. Thanks for helping it grow!

  • @myownsite
    @myownsite 4 роки тому

    Wow, throwing some shade in the thumbnail. :(