Why You Should Turn On Two Factor Authentication

Поділитися
Вставка
  • Опубліковано 28 вер 2024

КОМЕНТАРІ • 2,9 тис.

  • @TomScottGo
    @TomScottGo  4 роки тому +6426

    It's good to be back in the actual Centre for Computing History! They're still closed to the public right now for obvious reasons, but have a look in the description for a link to them and their fundraiser to help them get through the closure!

    • @silvertube11
      @silvertube11 4 роки тому +89

      Time traveler

    • @aiikozie
      @aiikozie 4 роки тому +6

      Big chonk

    • @cr4zeelee145
      @cr4zeelee145 4 роки тому +38

      "4 days ago"

    • @HR-in1dm
      @HR-in1dm 4 роки тому +19

      Why does this say 4 days ago if it just came out 🤔

    • @hj9076
      @hj9076 4 роки тому +39

      If u unlist the video , then u can leave a comment for later

  • @zincer2
    @zincer2 4 роки тому +2673

    "Some kind of nerd who wanted to learn something for fun" is probably the same kind of person as 90% of Tom's subscribers

  • @tomato3456
    @tomato3456 4 роки тому +4823

    "What I learned was 'keep your mouth shut'" - Tom Scott, telling a secret to his 2.9 million subscribers

    • @theophrastusbombastus8019
      @theophrastusbombastus8019 4 роки тому +304

      And the lesson I learned was not 'don't do it', it was 'snitches get stitches' - Tom Scott, on the run from the Police, circa 2021

    • @floydhebert3684
      @floydhebert3684 4 роки тому +12

      And it’ll probably be seen by more than 2.9 Million people

    • @saccaed
      @saccaed 4 роки тому +19

      That is the actual secret. Know when to keep your mouth shut.

    • @hotaru8309
      @hotaru8309 4 роки тому +12

      @@theophrastusbombastus8019 If it's "snitches get stitches" that is learned, it's probably not the police that he's running from.
      Also, I'm picturing him running clutching his stomach running out that scenario.

    • @woodfur00
      @woodfur00 4 роки тому +2

      @@hotaru8309 Have you been paying attention to the news lately?

  • @theCodyReeder
    @theCodyReeder 4 роки тому +4601

    Haha! I remember that pineapple video!

  • @floridag8rfan
    @floridag8rfan 4 роки тому +2456

    "No way to check that the President wasn't ... being coerced."
    I always assumed that there was not only a "correct" code on the Biscuit, but that there was also a coercion code, basically telling the recipient that "this source is compromised, disregard further signals from this source."

    • @YoutubeAdministrator
      @YoutubeAdministrator 4 роки тому +806

      We had this at a safe in a store I worked. If you typed in a pin containing double zero it would open the safe but also send an alarm to the security company + the Police.

    • @ahreuwu
      @ahreuwu 4 роки тому +483

      @@UA-camAdministrator we told you not to tell anyone!

    • @inanjarif1388
      @inanjarif1388 4 роки тому +206

      @@ahreuwu *laughs in robbery*

    • @pirobot668beta
      @pirobot668beta 4 роки тому +130

      ANGRC series crypto-radios (1970's tech) had a similar thing; lots of operator sequences could lead to auto-destruct!
      Any one of a dozen combinations of control settings will release the magic smoke from all the transistors.
      Hell, using the damn thing while driving on a bumpy road could start auto-destruct!
      The paranoia around these things being compromised was intense!
      OK, memory being what it is, it likely wasn't AN/GRC that I was thinking about...

    • @YoutubeAdministrator
      @YoutubeAdministrator 4 роки тому +24

      @@pirobot668beta sounds very cool. Wonder how much equipment we have of these killswitches in today.

  • @gschaftla
    @gschaftla 4 роки тому +292

    "Computers can only do what you say, they can't do what you mean" is probably my favorite quote now.

    • @zwenkwiel816
      @zwenkwiel816 3 роки тому +16

      Damn computers just need to learn to listen better. I threaten mine with violence whenever it doesn't do what I want. Doesn't seem to accomplish much but it does make me feel better...

    • @sadthomas5067
      @sadthomas5067 3 роки тому +5

      @@zwenkwiel816 Yes Mr.President, we found him do we launch the missile?

    • @Dranok1
      @Dranok1 3 роки тому +3

      Many years ago my department manager had a poster behind her desk:
      I hate this damned computer,
      I wish that they would sell it;
      It never does quite what I want,
      but only what I tell it.

    • @SquareoftheLightOnes
      @SquareoftheLightOnes 3 роки тому

      It should be "computers will only do what you or the manufacturers say." The ones who built the operating system also get a say in what your computer can and can't do, and the manufacturers have precedence over the end user... unless you have an open source operating system like linux, but why would you torture yourself like that?

    • @bikeny
      @bikeny 2 роки тому +1

      @@zwenkwiel816 I'm hoping your computer isn't named HAL, otherwise you're going to be having some real problems.

  • @koxukoshu
    @koxukoshu 4 роки тому +1995

    "You can't exactly change it, I tried once"
    *Glasses-wearing, Pineapple-consuming, Long-haired war flashbacks*

  • @retroace6717
    @retroace6717 4 роки тому +837

    Tom: * Talking about Nuclear Weapons *
    *The Basics*

  • @cocknballtorturer6839
    @cocknballtorturer6839 3 роки тому +281

    You know he's still mad about getting in trouble in high school...
    We all have that one thing we did super long time ago that doesn't matter anymore but you still wish you didn't do it

    • @vonkaiser6817
      @vonkaiser6817 3 роки тому +14

      One thing! my bloody list is in the hundreds, and I haven’t even finished school

    • @Rx7man
      @Rx7man 3 роки тому +10

      trust me, as you get older, you'll regret more things that you didn't do than those you did!

    • @emeraldday4755
      @emeraldday4755 3 роки тому

      I don't have any such thing

    • @maknyc1539
      @maknyc1539 3 роки тому

      cough

  • @emozley7667
    @emozley7667 4 роки тому +11

    3:28 Look at the PC in the background! The subtle Easter eggs like this are amazing

  • @gvjpersonal
    @gvjpersonal 3 роки тому +3

    This video is a masterclass in story-telling and public speaking. Tom started off with Reagan and a tense situation with a nuclear crisis, hooking the listener/viewer. Told them all about how multi factor authentication works and concluded by giving closure to the original story, while also articulating the big takeaways and caveats.

  • @Ginjitzu
    @Ginjitzu 4 роки тому +218

    "Computers can't stop you from asking for terrible things."
    Quit looking at my search history Tom.

    • @smartroadbiker
      @smartroadbiker 4 роки тому +10

      Too late it's been leaked on the 'net, I'm reading it now! ooooo did you really buy those?! Cheeky! Hehe 😇🤣

    • @thetabs57
      @thetabs57 4 роки тому +3

      @@smartroadbiker women humor

    • @bashthefash420
      @bashthefash420 4 роки тому +15

      @@thetabs57 incel humour

  • @neelgokhale644
    @neelgokhale644 4 роки тому +174

    Tom the picture of the phone at 4:30 was really smart
    The video went live at 4PM, so if you watched it when it came out you were at that point at 16:04, the exact time on the phone
    This is why I love your vids

    • @magentamovie6520
      @magentamovie6520 4 роки тому +6

      For me it's 11am ;-;

    • @deefdragon
      @deefdragon 4 роки тому +12

      I totally didn't catch that. While timezones make it not a thing for a lot of places, for the UK timezone, its freaking brilliant.

    • @Ironhide1125
      @Ironhide1125 4 роки тому +12

      These easter eggs will forever be loved

    • @Multibe150
      @Multibe150 4 роки тому +6

      It says 16:05 at 5:00 :0

    • @Bion479
      @Bion479 4 роки тому +4

      It also is 16:05 at the 5 minuite mark and has today's date correct

  • @dabeamer42
    @dabeamer42 4 роки тому +144

    "they can't do what you mean" (7:42). When I was a young programmer, I was complaining about a stupid bug (of my own creation) that I was chasing, and my boss said "Oh, you forgot to put in the DOWHATIMEAN instruction", with a silly smile.
    Someday, maybe...

  • @violetmcneill4705
    @violetmcneill4705 4 роки тому +342

    1:54 'password: CORblimey1926' a true British gentleman

  • @boahneelassmal
    @boahneelassmal 3 роки тому +4

    5:25 ah, yes the RSA key chain SecurID. Those were the times when you got the little token generator out of the pocket, saw it has 3 bars left, hastily put it in, only for it to expire the moment you hit enter.

  • @ChrisBeard
    @ChrisBeard Місяць тому

    Ive watched this video a bunch of times and I've just noticed the edit in the PET screen with the pineapple video. Great work. Kudos

  • @m.streicher8286
    @m.streicher8286 4 роки тому +186

    Gets done telling us exiting story about cold war era*
    "Don't worry, I'll talk about your stupid mundane phone now."

  • @FifaGian21
    @FifaGian21 4 роки тому

    This guy’s delivery is so good.

  • @levelup1279
    @levelup1279 2 роки тому +2

    Thank you, I just enabled 3 factor authentication for my nuclear weapons apparatus!

  • @m1n3craftPCtut0r1al
    @m1n3craftPCtut0r1al 4 роки тому

    I actually watched the video of you attempting to remove your fingerprints. When you did the joke at the end with the stove you genuinely got me, so good on you Tom

  • @MinistryOfMagic_DoM
    @MinistryOfMagic_DoM 4 роки тому +1

    You actually can check if the president is under duress. There are keywords for duress that could be passed along in the conversation. It requires that both people know the keywords and act on them though.

  • @gamerex9378
    @gamerex9378 2 роки тому

    In the mid 90s, my uncle told me "A computer is only as smart as you are." and the last part of this video reminded me of that. So thank you for that.

  • @PurplProto
    @PurplProto 4 роки тому +16

    Yes yes yes! Thank you for encouraging people to take security more serious!
    And doing what you do best, giving some history and explaining it well.
    Love your videos Tom 🙂

  • @Vujnovic634
    @Vujnovic634 4 роки тому +114

    3:27
    "I've tried"
    That video is 10 years old🤣

  • @thriceandonce
    @thriceandonce 4 роки тому

    Briefly having the monitor in the background "play" the pineapple video when you talked about falling to remove your fingerprints was a nice touch!

  • @hoangtran4736
    @hoangtran4736 4 роки тому +79

    "I tried once"
    *flashbacks to tom trying to get rid of his fingerprints using pineapple and sandpaper*

  • @Mar_Ten
    @Mar_Ten 4 роки тому

    Sitting here without phone and locked out of my accounts.
    10/10 would recommend, it's fool proof

  • @supremechaosbeing2696
    @supremechaosbeing2696 2 роки тому +1

    3:20 nice a callback to the pineapple fingerprint video

  • @animewow311
    @animewow311 4 роки тому +28

    3:50 is something that is kind of already being done, Tom. Some companies are starting to use ML algorithms to track your keyboard and mouse behavioral patterns to identify that it is you that is inputting them. They usually use proceed to use phone identification when you fail that test.

    • @walale12
      @walale12 2 роки тому

      Yes, I've had 3D secure authentication ask for an SMS code, and then ask me to type my email address with the way I typed it apparently being a form of identification

    • @zakattack5863
      @zakattack5863 Рік тому +1

      That’s just recaptcha

  • @tehlaser
    @tehlaser 4 роки тому

    One way to improve the scenario where a computer doesn't know if you are being forced to authenticate is to have a duress code.
    In the biscuit example, one of the codes means "launch," but a different position actually means "I am under duress, do not follow my orders, send help." The President knows the position of both codes. Whoever's doing the forcing can't know ahead of time if the President is using the launch code or the duress code.
    That still doesn't stop a President who is not sane, and the attackers may be able to threaten to do horrible things if they discover that the duress code has been used, so it's not perfect, but detecting the use of the duress code will take time, making the attack harder.

  • @patrickbours7140
    @patrickbours7140 3 роки тому +1

    Always interesting to see a non-biometric expert (or is it biometric non-expert) comment on biometrics. There are systems developed that can detect if it is a real finger or face that is presented to a sensor or if it is a copy (like the lifted fingerprint or a printed face image or even a video played). And I am not a science fiction writer, but I can also tell you that behavioural biometrics as an authentication factor work extremely well. For example keystroke dynamics gives you a "free" second factor when somebody types their password. Performance might not be as good as for biological biometrics (like fingerprint and face), but you can capture this behaviour continuously. You can then use behavioural biometrics actually to remove access if you have left your computer unguarded and it is taken over after you have used your 2-factor authentication to log on.

  • @Lunar_Watches
    @Lunar_Watches 4 роки тому +15

    This 8 minute video taught me more info than a whole day in school

    • @kajmak64bit76
      @kajmak64bit76 4 роки тому

      American schools... pfff... try Scandinavian schools bro xD you learn everything and no homework

    • @chloegaribaldi
      @chloegaribaldi 4 роки тому

      This series could have been enough for the students of the computer science high school where I taught math this year to ace their finals. But, alas, almost no one had any interest in studying.
      (I write from Italy btw)

  • @johnbeauvais3159
    @johnbeauvais3159 4 роки тому +4

    2:50 You learned the correct lesson here Tom
    “Be good, if not be good at it, if you get caught give them a name just not yours or mine”

  • @ishner
    @ishner 3 роки тому

    The old way is know your signature and have your signet ring.
    You use your signet with sealing wax to impress the seal of your house onto the page.
    Also served as a anti-tampering device because it is hard to get the wax to readhere to paper once it had been broken off.

  • @aaronbaconvods
    @aaronbaconvods 4 роки тому +7

    "The Lesson I learned was to keep your mouth shut" - Gleefully telling millions of people about it

  • @rolphd8917
    @rolphd8917 4 роки тому +85

    Never seen that red shirt before

    • @neggaknight
      @neggaknight 4 роки тому +5

      Oscar Sanderson don’t think you can see your reflection in a comment

    • @enbymina
      @enbymina 4 роки тому

      shit's maroon

    • @velqrow
      @velqrow 4 роки тому +3

      dude you're supposed to write a comment, not just your full name

    • @hissingfaunaa
      @hissingfaunaa 4 роки тому

      @Oscar Sanderson bad

  • @Rx7man
    @Rx7man 3 роки тому

    I got you beat on the teacher password thing.. when I was in school I had the password to the main grades database, and yes, I did go snooping around in it and had the ability to change or delete any or all grades, or could assign different students to different classes...
    The password was "Jupiter"

  • @Greggy955
    @Greggy955 4 роки тому +4

    I think what puts a lot of people off from using two factor authentication is the annoyance and inconvenience, and some people are willing to sacrifice cyber security for said convenience.

  • @spywalkz1
    @spywalkz1 4 роки тому +58

    3:27
    Tom: "I tried once"
    Me: *pineapple flashback intensifies*

  • @islarf5095
    @islarf5095 3 роки тому

    "computers can only do what you say. They can't do what you mean"
    As a tech advisor for a broadband company. I wish this was more know .

  • @lithobraking
    @lithobraking 4 роки тому +12

    Tom: "Science fiction writers have also imagined complicated AI systems that can learn someone's behavior patterns over time and recognize them..."
    This is kinda happening right now. Fraud departments in banks and credit-card companies analyze transactions data to find suspicious purchases. They also probably use machine learning to deal with vast amount of data being collected.

    • @DaedalusYoung
      @DaedalusYoung 4 роки тому

      And isn't this how ReCAPTCHA works? They can detect if your input is human enough.

    • @symbioticcoherence8435
      @symbioticcoherence8435 4 роки тому

      Can confirm. They do use mashine learing to find malicious transactions, often it gets then forwardet to a human for additional verification.
      Also, I can tell my phone to learn the specific way I walk and to always be unlocked, when it has recently been in my pocket. (it looks for patterns in the accelerometer data that I generate when I walk) I dont do that for various reasons, but I could have an annoyingly strong password that I get asked sometimes (to force me to memorize it) and to mostly unlock without a password if it thinks it has been in my pocket recently, but to always ask, when its not in my pocket.

    • @Havanacuba1985
      @Havanacuba1985 4 роки тому

      Gait detection to analyse and match your way of moving/walking

  • @lilymercy
    @lilymercy 2 роки тому +1

    and this is why i type my credit information every time i make an online purchase rather than save it to my browser. maybe i’m lazy elsewhere (coughpaswordcough) but not my bank info

  • @andersbuchjeppesen5493
    @andersbuchjeppesen5493 4 роки тому +99

    You can’t change your fingerprints “I tried once”
    Oh boy do I remember that video

  • @Seegalgalguntijak
    @Seegalgalguntijak 4 роки тому +17

    The problem with these hardware factors is: They potentially undermine anonymity. When I use the same token (i.e. FIDO2 or YubiKey etc) with different services, having different "nicknames" there, and *not* wanting the server operators to know that it's the same person behind both accounts, using the same hardware token is a potential security risk. Yes, with Amazon or eBay or any shopping website, they need to know my identity, because they need to obtain payments from me and they need to know an address where to send the goods I bought, *but* companies like Google, Facebook or Twitter do not. I don't use anything from them that requires payment - or if I would, then I'd have to have a completely separate account, or even device in the case of a phone, in order to use that, because letting them know who I actually am while I use their services is completely out of option.

    • @thriceandonce
      @thriceandonce 4 роки тому +2

      And they always want to know your phone number. My actual bank doesn't because, as Tom explained, it's not the most secure way of using a phone for 2FA. So those sites constantly bugging you to turn on 2FA continues to feel like they're just trying to collect as much of your data as possible.

    • @clonkex
      @clonkex 4 роки тому +2

      @@thriceandonce They don't know it's the same device generating the token, though. They only know that the token is valid based on the secret key they sent to token generator.

    • @enrymion9681
      @enrymion9681 4 роки тому

      ​@@clonkex Don't most 2FA's require giving a phone number? I haven't come across one where you could just use any random phone as long as you have some sort of authentication app installed on it and somehow confirmed that that's the device you want to use for authentication.

    • @Havanacuba1985
      @Havanacuba1985 4 роки тому

      Seegal Galguntijak exactly ,I have no sim in my phone , I don’t wish to be contactable anywhere I go , now PayPal are saying I have to have a mobile when I have a perfectly good landline

    • @Seegalgalguntijak
      @Seegalgalguntijak 4 роки тому

      @@clonkex In case of OTP, that's true. But with FIDO2, I wouldn't bet on it.

  • @allomain1311
    @allomain1311 3 роки тому +1

    Fun fact, if you are using steam , you should ALWAYS have a 2 factor authentication, it is really easy to find a password, but the phone message, well thats another story... Thankfully steam has some limitations for those not using 2 factor which can indeed protect your account....

  • @CynUnion-ji9uj
    @CynUnion-ji9uj 8 місяців тому

    When I worked at a popular, now-mostly-defunt toy retailer, I shoulder surfed a bunch of managers' usernames and passwords so that I could get bad customers to leave quicker.

  • @mjdorads
    @mjdorads 2 роки тому +1

    Two reasons why I don't use it:
    1) When I loss my phone with my old prepaid SIM in it, my accounts no longer allow me to login using my new phone because I can't do two factor authentication via SMS. It needs my old number. I was locked out for more than 6 months of trying to convince the tech support that it is really me, the owner of the account.
    2) I am renting a room and it is on underground basement. The cellular data can't reach my room. So if I'm gonna need to login into my account, I have to go out to receive the SMS OTP.

  • @xperialinks
    @xperialinks 2 роки тому

    You can’t change your fingerprint, I tried once. Referring to the can you change your fingerprints with pineapple video. It’s good to see Tom Scott acknowledging his past.

  • @genericname8727
    @genericname8727 4 роки тому

    Dissected a flower in a biology class once and the skin on my finger tips peeled away for weeks and were somewhat scarred even after they’d fully healed. Idk if it was necessarily the flower but the doctor told me it was a chemical burn. I’d not touched anything chemical really, and the doctor said it’s possible to get chemical burns from plants, so it’s possible that the alkaline fluid from the flower burned off my fingerprints. That said, my fingerprints eventually returned as my fingertips continued to heal and scars fade.

  • @JeremyYoungyoutubechannel
    @JeremyYoungyoutubechannel 4 роки тому +6

    "Hey Tom how do you solve 2+2?"
    - *Explains quantam mechanics*

  • @DerpyTheCow47
    @DerpyTheCow47 4 роки тому +4

    "I tried once" - a reference to the pineapple juice video a while ago. That was a REALLY good reference

  • @NuSpirit_
    @NuSpirit_ 4 роки тому +2

    3:27 now that's a throwback Tuesday :D

  • @lucas.demello
    @lucas.demello 4 роки тому +2

    "It was close"
    *close his fists*
    This part gave me goosebumps

  • @brayx6697
    @brayx6697 4 роки тому

    That callback to the pineapple video made me chuckle

  • @WolvericCatkin
    @WolvericCatkin 3 роки тому

    Tom: "You can't change that... I, tried once..."
    People only watching new videos: "You tried once?? I don't understand-"
    Me: "I do. _I understood that reference..._ "

  • @S3Bayaya
    @S3Bayaya 3 роки тому

    I was expecting some password only manager app advert at the end. I was surprised there is none of it.

  • @pogman3982
    @pogman3982 4 роки тому +1

    Your a legend my dude

  • @camygarcia4864
    @camygarcia4864 2 роки тому

    Tom: computer can only do what you say
    Hal 9000: am I a joke to you

  • @ewa3D
    @ewa3D 4 роки тому +13

    ubisoft has sent me emails saying "new login activity from iran and mongolia" but when i login in the states i get an email saying suspicious activity

    • @epekka
      @epekka 4 роки тому

      that's probably not good

    • @Squaretable22
      @Squaretable22 4 роки тому +1

      It probably thinks you're Iranian or Mongolian now lmao

    • @j.s.3414
      @j.s.3414 4 роки тому +1

      You're likely receiving phishing emails...don't log in using links in emails, always type the main website into your browser and then navigate to your account.

  • @davidgillies620
    @davidgillies620 3 роки тому +1

    One of my mates at school got the fileserver password by putting the Econet transceiver in one of the computer lab's BBC micros into promiscuous mode and sniffing it off the wire while the teacher typed it on from across the room, which is _kind_ of like looking over someone's shoulder, except better.

  • @3RR0R415
    @3RR0R415 4 роки тому +1

    password at
    1:53 is CORblimey1926
    2:03 is MakesSense!

  • @JuneNafziger
    @JuneNafziger 3 роки тому

    "And when the only input device to your computer is a keyboard, a password absolutely makes sense"
    Password being typed on screen "MakesSense!"

  • @kelvin31272
    @kelvin31272 4 роки тому +2

    'You can't change your fingerprints....uh....I tried...once...'
    *memories rush back*

  • @InterCity134
    @InterCity134 4 роки тому

    Problem is many commercial sites don’t do proper 2 factor authenticating and insist on weak 1.5 factor authentication which leads to a false sense of security from the user and the company. Sending a code to a person by email or sms is NOT two factor as there is a high chance the email or SMS can be intercepted or redirected.

  • @D.E.L.T.A
    @D.E.L.T.A 3 роки тому +1

    2:05: The password in the corner of the screen is "MakesSense!"

  • @Kkmiojexx
    @Kkmiojexx Рік тому

    "Well, if it gets leaked, you can't change your fingerprints... I TRIED ONCE" DAAAYYUUMMNN that pineapple video lmao

  • @Fighting_Falc0n
    @Fighting_Falc0n 3 роки тому

    90% of the comments are about the fingerprint. Love to see that originality.

  • @Wingtrois
    @Wingtrois Рік тому

    5:54 „You - that’s not ideal” ~Tom Scott 2k20

  • @WTP_DAVE
    @WTP_DAVE 4 роки тому

    i found that concision very succinct

  • @Derpyderpderper
    @Derpyderpderper 4 роки тому

    Tom: If your finger print gets leaked, you can't really change it, i've tried, once.
    Me: oh wow that brings back memories

  • @ShOrt_RoUnD
    @ShOrt_RoUnD 4 роки тому

    2:48 that’s the real take away from this video. No truer words have ever been spoken

  • @keco185
    @keco185 4 роки тому +4

    I like Apple’s system of sending a message to your phone where you type in a pin given on the website you’re logging into along with a physical position on a map

    • @DancingRain
      @DancingRain 4 роки тому

      Until your battery dies. Or you lose signal. Or your phone gets shut off for any number of reasons.

    • @keco185
      @keco185 4 роки тому +1

      Dancing Rain if you don’t have internet on your phone than you probably don’t on your computer either. And if your battery is dead you can just plug your phone in to charge

    • @DancingRain
      @DancingRain 4 роки тому

      @@keco185 Interesting assumption. Wrong, but interesting. I have family in the rural united states, where internet access generally works, but cell phone reception is terribly unreliable. And the more mountainous or remote a rural area you're in the worse cell phone reception gets.
      In addition, I'm guessing you've never had a cell phone suddenly decide it doesn't want to take a charge any more. They can and do malfunction from time to time.

    • @keco185
      @keco185 4 роки тому +1

      Dancing Rain so you have a house with internet but an iPhone doesn’t use that internet?

    • @DancingRain
      @DancingRain 4 роки тому

      @@keco185 bold of you to assume I have an apple iPhone.
      But more importantly, text messages don't go through the internet, they go through the cell network.

  • @fafardh
    @fafardh 2 роки тому +1

    3:20 Objection! Ain't no high tech needed to lift fingerprints well enough to fool fingerprint readers. Unless you consider adhesive tape "high tech"...

  • @scarde1748
    @scarde1748 4 роки тому +1

    Funny story, One day I was trying to change my bio on roblox, but I had settings pin enabled, but I had forgot it, so I moved on and I was suddenly logged out, when I tried to log back in, it said my password was wrong, in points of crisis, I'm a logical thinker, so I quickly changed my password via email, I then checked to see if anything had changed, and funny enough the only thing that had happened was my settings pin was removed. I'm still confused, as the hacker went through a password, my email and my Settings PIN.

  • @sarkybugger5009
    @sarkybugger5009 4 роки тому

    Rubber hose decryption rarely fails!

  • @EvilParagon4
    @EvilParagon4 4 роки тому

    The What You Have authentication is the worst. So many things require you to not have money, but to have things that need money, and when you're poor, getting locked out of something is the last thing you need to happen.
    I got locked out of my PayPal for 7 months because someone tried to break into it and I couldn't afford to pay my phone bill the whole time until I finally borrowed my brother's phone to let me call up and prove it was me. All because I don't have a licence (no car so what's the point?) or a birth certificate (not exactly a convenient item to hang onto) or a passport (an expensive document when I don't travel because poor?).
    Then hey, I was finally able to get in and pay for my phone bill.

  • @warrenkeystone5195
    @warrenkeystone5195 4 роки тому +2

    "you can't exactly change it... i've tried once"
    *[intense pineapple flashbacks]*

  • @Ken-tc3nq
    @Ken-tc3nq 4 роки тому

    I'm a systems engineer, don't use Yubikey or smart cards. They're very vulnerable and Google hands out Yubikey so that should tell you something. RSA or vendor-specific authenticator apps are the way to go

  • @user-dx8nj7qj2g
    @user-dx8nj7qj2g 3 роки тому

    3:49 "science fiction writers have alos imagined complicated artificial intelligence systems that can learn someone's behaviour patterns over time and recognise them" I mean actually banks already do something similar, but only for larger purchases, if you make a large purchase that it deems unusual it'll pause the transaction and they'll contact you, to verify you did it. not always though.

  • @Deep_field
    @Deep_field 4 роки тому

    i find your story about the teachers password funny. Same exact thing happened to me in highschool. Told someone and that was my downfall

  • @comparatorclock
    @comparatorclock Рік тому +1

    on the teacher's password thing, it is worth noting that there is a saying for that: it aint illegal until you're caught

  • @shadowwolf12398
    @shadowwolf12398 2 роки тому +1

    My signature can’t be forged because I’m constantly changing it because I can never decide

  • @Bluey
    @Bluey 3 роки тому +1

    3:26 with pineapple

  • @werefrogofassyria6609
    @werefrogofassyria6609 4 роки тому +8

    The lesson wasn't "Don't do it, but keep your mouth shut."
    That's like the true lesson of the story of the boy who cried wolf: never tell the same lie twice.

  • @angry_volbonan7805
    @angry_volbonan7805 4 роки тому +1

    At 1:54 the password that showed up was corblimey1926

  • @crooker2
    @crooker2 Рік тому

    I commonly use three factor authentication. Username/password and authentication code, which I must obtain by inputting my fingerprint. Quite secure.

  • @Swordopolis
    @Swordopolis 4 роки тому

    7:00 massive subtweet of the current possessor of the nuclear codes

  • @miniman123451
    @miniman123451 4 роки тому

    @tom scott we would love a video about benfords law

  • @minimalgrammar1276
    @minimalgrammar1276 4 роки тому +6

    "There was no way to check that the President was sane"
    PepeLaugh ohnonononononono

  • @matthewbenedict5923
    @matthewbenedict5923 3 роки тому

    2:25 nice touch

  • @OrigiName
    @OrigiName 4 роки тому

    The password for Dr Corbató was corblimey 1962

  • @Roberto-qh2hr
    @Roberto-qh2hr 4 роки тому

    I legitimately thought the title said why you should not turn on two factor authentication

  • @LambdaCreates
    @LambdaCreates Рік тому

    For those wondering, the password at 1:55 is either these 2:
    CORbIbimey1926 (with the capital i)
    or
    CORblbimey1926 (with the lowercase l)

  • @dliessmgg
    @dliessmgg 4 роки тому +3860

    "computers can only do what you say, they can't do what you mean"
    i wish my parents would finally learn this

    • @soldier3079
      @soldier3079 3 роки тому +23

      When i was watching the video (the last minutes) i scrolled to the comments and when i was reading it was synced with the video itself

    • @stargate525
      @stargate525 3 роки тому +35

      @Squant Because parents (instead of grandparents) are now of the generation who learned that computers can't do what you mean. And now they're frustrated because the computers are BAD at guessing what they mean because we're used to being much more explicit than the average.

    • @bartonseagrave9605
      @bartonseagrave9605 3 роки тому +5

      Didn't grandparents invent computers?

    • @stargate525
      @stargate525 3 роки тому +59

      @@bartonseagrave9605 Their generation did. But that's like saying Werner Von Braun's generation built rockets, ergo everyone of that generation is a rocket scientist.

    • @Abcdefghijklmnopqrstuvwxyz1024
      @Abcdefghijklmnopqrstuvwxyz1024 2 роки тому

      Parents can't do either

  • @svleda9145
    @svleda9145 4 роки тому +5183

    I swear Tom Scott is just that dude who can make you smile with a random fact any time

  • @Pr3st0ne
    @Pr3st0ne 3 роки тому +1579

    "Signatures can be forged" is an understatement. 99% of people who require a signature for anything have actually no idea what your signature looks like, and it's practically a formality.

    • @Dazlidorne
      @Dazlidorne 2 роки тому +277

      Another bad thing about signatures is that yours changes over time. If they actually used them to verify identity, you could be denied even if it were you. I worried about this when I voted by mail in the last election. The signature on file with the election officials is from high school. My signature has changed drastically since then.

    • @sprazz8668
      @sprazz8668 2 роки тому +208

      I can't even forge my own signature

    • @YingwuUsagiri
      @YingwuUsagiri 2 роки тому +17

      Signatures and initials have moreso become a thing for those that are relevant, like when accepting a package from a delivery guy. If any of my neighbours go onto their app in case the delivery guy was too lazy to put in a card saying hey, it's dumped at this address they can see my NS with a squiggly line and know it's at my house.

    • @Pr3st0ne
      @Pr3st0ne 2 роки тому +36

      @@YingwuUsagiri that's a ridiculously specific edge case and I wouldn't be able to tell you the signature/initials of half my neighbors

    • @roofogato
      @roofogato 2 роки тому +5

      JOKES ON YOU MY SIGNATURE IS A LIL DOOFLE I MADE

  • @ELVIStheDotA
    @ELVIStheDotA 4 роки тому +1647

    "So the moral of the story is to not do the bad thing?"
    "No. The moral is to not tell people you did the bad thing."

    • @arvaneret_329
      @arvaneret_329 4 роки тому +35

      But what's actually moral is to avoid doing the bad thing altogether.

    • @thekingoffailure9967
      @thekingoffailure9967 3 роки тому +74

      I thought of a bad thing i'd done that I had kept a secret and almost used it as an example here like a dumbass

    • @Rx7man
      @Rx7man 3 роки тому +20

      @@arvaneret_329 but is just knowing a teacher's password a "bad thing"?

    • @مجتبىيحيى-ر6ه
      @مجتبىيحيى-ر6ه 3 роки тому +5

      Dont do the bad thing and if you be bad and did it do not be worst and dont tell anybody

    • @animationspace8550
      @animationspace8550 3 роки тому +17

      @@arvaneret_329 "It isn't illegal if you don't get caught" - A friend of mine from middle school

  • @JonathanKayne
    @JonathanKayne 4 роки тому +2736

    The great thing about computers: they do exactly what you say.
    The terrible thing about computers: they do EXACTLY what you say.

    • @billionai4871
      @billionai4871 4 роки тому +269

      Computers are the second dumbest thing that computer scientist have to deal with on a daily basis

    • @asianxhispanic
      @asianxhispanic 4 роки тому +1

      😳

    • @imveryangryitsnotbutter
      @imveryangryitsnotbutter 4 роки тому +36

      @Bounze You had to explain the joke.

    • @deliriousjason8133
      @deliriousjason8133 4 роки тому +58

      It's like a douchebag genie who takes your words too literally.

    • @mirjanbouma
      @mirjanbouma 4 роки тому +18

      @Bounze the number one being the users was implied. You kind of killed the joke by explaining the punchline.

  • @TheFarCobra
    @TheFarCobra 4 роки тому +5954

    That truly is all we ever learn as children: Not “don’t do it” just “don’t get caught”

    • @magentamovie6520
      @magentamovie6520 4 роки тому +43

      Exactly!

    • @skylark.kraken
      @skylark.kraken 4 роки тому +295

      Or at least have a very good excuse for innocently doing wrong ready

    • @cauchyschwarz3295
      @cauchyschwarz3295 4 роки тому +198

      I think that is the lesson that punishment entails. If you make someone suffer for doing something deemed wrong they just learn not to be caught.

    • @ayhamshaheed7740
      @ayhamshaheed7740 4 роки тому +9

      I don’t quite get what you mean. We’re taught not to do ‘bad’ things are we not?

    • @pony_OwO
      @pony_OwO 4 роки тому +104

      @@ayhamshaheed7740 It's what we are told but not what we learn.