THIS 2-Factor-Authentication method is NOT secure!!

Поділитися
Вставка
  • Опубліковано 20 гру 2024

КОМЕНТАРІ • 294

  • @NaomiBrockwellTV
    @NaomiBrockwellTV  2 роки тому +55

    As per all my other videos, no I didn't delete your comment. UA-cam auto deletes comments all the time. If yours disappears, try posting again in various forms until it sticks, and good luck! 🙏 Also, since posting this video I've found out that google authenticator now allows you to back up all codes on another device! Have added that note to my video description.

    • @brandonfarley5297
      @brandonfarley5297 2 роки тому +1

      Do you have a podcast by any chance?

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +3

      @@brandonfarley5297 yep! everything linked on my website www.nbtv.media/episodes/this-2-factor-authentication-method-is-not-secure

    • @cryptowealthonyt
      @cryptowealthonyt 2 роки тому

      Naomi my apologies? Where is the link to google auth. back up codes info?

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      @@cryptowealthonyt there is no link. the info is in the video description.

    • @TwstedTV
      @TwstedTV 2 роки тому +2

      2FAS Auth app is another really good one. I use both 2FAS Auth and Authy.
      The ONLY problem I have with Authy, is their android app consist of a 4 digit pin to log in. which is pretty insecure IMHO.
      I even tried to get them to implement a better password login with Alphanumeric, this was 4 years ago. still nothing was done and I have asked several times.

  • @iristhepuppygirl
    @iristhepuppygirl 2 роки тому +5

    i have been using a yubikey for about a year now and have been loving it. Great video

  • @xperyskop2475
    @xperyskop2475 2 роки тому +8

    Yubikey is the key to proper 2fa security

  • @ukkendoka
    @ukkendoka 2 роки тому +3

    I've been Yubikey for 2 years now. Very happy. I would recommend the NFC Yubikey to anyone.

    • @brodriguez11000
      @brodriguez11000 2 роки тому

      Unfortunately a lot of phones don't have NFC.

    • @ukkendoka
      @ukkendoka 2 роки тому

      @@brodriguez11000 I’d also recommend phones with NFC. :) . You can buy one that plugs into your phone otherwise.

  • @terry2can914
    @terry2can914 2 роки тому +3

    That crocheted top girl you’re rocking it💃🏽💃🏽

  • @mjmeans7983
    @mjmeans7983 2 роки тому +5

    A good way to protect those accounts that ask common questions, like mother's maiden name, or name of your first pet, is to lie. If you type in an answer that has nothing to do with the questions, then someone who investigates you and your family will never guess it. Yes, it might be hard for you to remember that the answer you gave to the question of your first pet's name is "the Peloponnesian war", but it will be bloody impossible for someone else to guess, no matter how well they have studies you. Well, unless that actually was your pet's name. Yelling down the hall ... "Here, Pello"?

  • @Darkk6969
    @Darkk6969 2 роки тому +1

    I use KeePassXC with NextCloud to keep the database sync'd on my devices. I also use Aegis on my Android phone. Cool thing about KeePassXC is that it displays QR code of the TOTP token so you can scan it with Aegis. Works pretty well.

  • @reefhound
    @reefhound 6 місяців тому +1

    Nearly every large financial institution uses SMS for 2FA, many of them exclusively. They move billions of dollars in transactions every day in an industry where security is critical. Maybe, just maybe, they know what they are doing? 2FA is supposed to be "something you know" and "something you have". An auth app is "something you know" (the seed) not "something you have". Hardware keys are good except there is almost always a backup way in. I'll bet it's more likely your hardware key gets stolen than your SIM swapped.

  • @lossless4129
    @lossless4129 2 роки тому

    Been using a yubi for 4 years, love it

  • @mr.amsterdam2063
    @mr.amsterdam2063 2 роки тому +4

    There are not many out there spending time to learn, AND spending time sharing that with others. It is very noble if you give your quality time and energy to do. For sure the definition of a good person without the intention to get something in return. You are one of them, thank you!
    As you can see English isn't my langue so I misunderstand or need some other way to explain please,
    07:20 A lot of your friends use AndOTP and some Keypassxc, password manager with TOTP...
    07:42 Some TOTP apps can also be integrated with your password manager but you would be very warry....
    07:20 & 07:42 =Password manager with TOTP /or TOTP integrated with your password manager...is not the same?
    If the same, both very warry, right? If not the same, 07:20 is the way to go?

  • @timbinder1966
    @timbinder1966 Рік тому +2

    Hi Naomi, I love your videos, they are so useful. I have a way of improving the security on iphones. In settings, scroll down to screen time. Open screen time and scroll down to "Content and Privacy Restrictions. Here you can toggle on or off Allow password changes and account changes to "don't allow. I have both of these set to "don't allow. Very useful.

  • @harrisonhicks9697
    @harrisonhicks9697 2 роки тому +2

    Superb, Naomi. Really well done.

  • @natemarx4999
    @natemarx4999 2 роки тому +4

    The Queen is blessing us with more uploads, we must continue to behave well for more!

  • @Portugal478
    @Portugal478 2 роки тому +2

    Ta Naomi, great update on digital security!

  • @fiftyshadesofurban
    @fiftyshadesofurban 10 місяців тому +1

    8:40 Some would say someone typing in private login info on anything with that man's face on it, is a dead giveaway that you're going to lose everything. lmao

  • @IamAcerbus
    @IamAcerbus 2 роки тому +6

    I love that you cite helpful articles for further reading. 😊

  • @timothystockman7533
    @timothystockman7533 2 роки тому +1

    I have a pair of Yubikeys, and tried to start using them, but support is just not quite there, yet, so I have disabled them for now.

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      yeah platforms are increasingly using yubikeys, keep an eye out as they add support, and you can switch in yubikeys as they do

  • @angelad1008
    @angelad1008 2 роки тому +2

    I think that this is your best wardrobe yet. You're always very fashionable, but today is my favorite of your styles. Oh, and thanks for the great info. I really was listening while admiring the embroidery.

  • @thisisntmeitssomeperson
    @thisisntmeitssomeperson 2 роки тому +1

    While general consensus is that SMS 2FA is better than no 2FA, it may be the opposite in some ways. If I use SMS 2FA (even with a VOIP number), on multiple sites/apps/platforms, inevitable leaks can be cross-referenced with each other and a profile can be formed. This is particularly pernicious if any such leak includes your name, address, work, etc. Did your research for this video lead you to such claims, and either way, what are your thoughts on this? As you can tell from my username, I’ve been called paranoid once or twice :) But with all the automated data scraping and analysis going on, it doesn’t seem so far-fetched.

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      Well 2fa is security measure not a privacy measure, if you want both then an anonymous sim might be your best bet!

    • @thisisntmeitssomeperson
      @thisisntmeitssomeperson 2 роки тому

      @@NaomiBrockwellTV True, but as you well know, security and privacy are somewhat intertwined. Anonymous SIM certainly helps. I use something similar. Phone numbers individualized to each service help even more, but somewhat expensive if you need dozens of them. Ultimately, phone number reuse (for an authentication factor) is similar to password reuse (also an authentication factor), just not AS dangerous.

  • @xandstapleford1682
    @xandstapleford1682 2 роки тому +2

    One good open source OTP app for iOS that allows encrypted backup is Raivo OTP if anyone’s looking. It’s the only one I could find that met those requirements

  • @sagichdirdochnicht4653
    @sagichdirdochnicht4653 2 роки тому

    For TOTP Codes... ALLWAYS have some Form of Backup / register to multiple Devices. But you've been told to do Backups for everything for the last 20 Years, if you didn't learn it allready - tough Luck.
    I have them stored on Yubikeys, which can't be recovered as well. Which I see as a Security Feautre. Realize the Plural - Key*s*. If I loose one, I'm still able to access everything and create new TOTPs.

  • @medicalwei
    @medicalwei 2 роки тому

    5:50 actually the old code is still valid for slightly a bit of time for user experience sake

  • @tootalldan5702
    @tootalldan5702 2 роки тому +8

    TFA is great as long as you have an offline option without the Internet or phone service. It happens where I live but I still need to work on my laptop. I have that option with an online code and an offline code in rural travel locations. Thanks Naomi for the discussion and links.

  • @antonygoedhals6272
    @antonygoedhals6272 2 роки тому +4

    Great video. Thank you! One thing you need to point out with security keys: you need more than one, in case you lose that one you’ve used. AND many websites allow only 1 security key so these should be supplemented with a secondary form of 2FA not dependent on that single key.

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +1

      I haven't come across any websites that only allow one key, that's a super annoying practice! Thanks for the heads up!

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  Рік тому

      can confirm, paypal only allows one key 🤦‍♀

  • @dhavanbhayani4907
    @dhavanbhayani4907 Рік тому

    @2FAS is open source, private, cloud backups, no account required, community driven 2FA app.

    • @thomasedison9047
      @thomasedison9047 Рік тому

      D m vinethics he'll help you He fixed mine he has 90k followers account. UA-cam is not letting me to write to you in full make sure is the right account you Dm

    • @thomasedison9047
      @thomasedison9047 Рік тому

      ON Instagram

  • @Avarua59
    @Avarua59 2 роки тому +1

    Thank you. Very good information. BTW - nice sweater!

  • @chloefletcher9612
    @chloefletcher9612 2 роки тому +7

    Pretty happy with Microsoft Authenticator. Has a password lock on the app and backs up to your onedrive (imperfect but not terrible - it's encrypted at rest and in transit, at least on MS side).

  • @italimarco
    @italimarco 2 роки тому +10

    Always helping us with great content. Thanks Naomi!

  • @FunnyHacks
    @FunnyHacks 2 роки тому

    [edit: I'm wrong. While there are many standards for time based one time passwords that have existed long before TOTP came around, TOTP itself refers to a specific standard.]
    6:08 *Any Google-Authenticator-based TOTP app will work. There are many different TOTP formats, and only ones that are based on Google Authenticator's implementation are interchangeable with Google Authenticator.

  • @TheCurlPapi
    @TheCurlPapi Рік тому +1

    My email got hacked over a month ago and still dealing with other accounts being attempted to be logged into. Just received a yubikey and never going through that kind of stress again

  • @iamagi
    @iamagi 2 роки тому +5

    The fact that Google can’t recover you 2fa codes is a feature not a bug.
    I add them to two devices when ever I sign up for a new service.

  • @NWforager
    @NWforager 2 роки тому +2

    strong security Alpha . thank you . Nice Shiba shorts too . Love to know more about strengthening sim 2fa .
    Wondering if changing a sim card will cause totp rejection on same device 👀

    • @NWforager
      @NWforager 2 роки тому

      @@mirrorneurongirl Neat . many banks for some reason don't have totp and your findings are a good extra layer via an isolated google voice number .

  • @bluewinterwolf
    @bluewinterwolf Рік тому

    You can lock the autentication app and any other with an App Lock app, these lock the apps themselves so when you want to open one you have to put in a seperate password in before the app loads as the App Lock app loads first.

    • @ultraret
      @ultraret Рік тому +1

      I wonder how secure that is if it just hides or really encrypts -- stupid that google doesn't lock the app themselves

  • @anuzis
    @anuzis 2 роки тому +4

    Great episode! Already have a few security keys, but they are pretty old school. looking forward to the next episode you mentioned that will look into key differences in security keys!

  • @kevOzilla
    @kevOzilla 2 роки тому +1

    The best way to NEVER GET HACKED is to have a physical yubikey without it not even you can sign into your account so if you lose it you screwed unless you have a backup code written down somewhere

    • @MarvelousMarvinB
      @MarvelousMarvinB 2 роки тому

      I have two yubikeys. I just register both. One yubikey is on my keychain and the other is hidden somewhere.

  • @kcgunesq
    @kcgunesq Рік тому

    Like many i am sure, my company requires us to have Microsoft Authenticator. However, I find it works very well. It is secured behind a password or biometrics and backups the data.
    Also, i think the tip to not use the same service as your password manager is sound.

  • @hanelyp1
    @hanelyp1 2 роки тому

    Screwgle has burned me on 2FA. Forcing activation of 2FA on my chromebook, defaulting to using the paired phone as a security key, they broke login. Due to some kind of bug in the pairing software I have to reset pairing anytime either device restarts, which I can't do until I'm logged in on both devices. So I'm down to a choice of, at login time:
    - SMS as a second factor
    - generating one time keys
    - disabling 2FA using a device I can log into.

  • @gossedejong9248
    @gossedejong9248 2 роки тому +2

    thank you! Looking forward to your advice on the keys.....

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +1

      Coming soon!

    • @gossedejong9248
      @gossedejong9248 2 роки тому

      @@NaomiBrockwellTV and just so that you know: you are brilliant, fantastic, and great!!!!

  • @benf101
    @benf101 2 роки тому

    3:46 there's poop on my screen... oh wait, it's just Klaus Schwab

  • @mnmlst1
    @mnmlst1 Рік тому

    I absolutely love every single blouse you use. They are so pretty!
    Totally off topic, I know, but oh my, they are beautiful.

  • @troy_productiveai
    @troy_productiveai 2 роки тому +2

    This was brilliant. VERY well done. Shared!

  • @tomausman8645
    @tomausman8645 2 роки тому +2

    Great show 🇨🇦🖖🇨🇦

  • @xXxJakobxXx3
    @xXxJakobxXx3 2 роки тому +1

    Very informative video. Maybe consider adding chapters so the more informed audience can quickly jump to the important points, especially if you use a clickbait title!

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      please define clickbait for me

    • @xXxJakobxXx3
      @xXxJakobxXx3 2 роки тому

      @@NaomiBrockwellTV The title suggests that there is one specific insecure 2FA method. So I clicked on it, thinking someone had discovered a new security flaw in a 2FA method. Instead, I got a video explaining various 2FA options and listing their pros and cons.

    • @xXxJakobxXx3
      @xXxJakobxXx3 2 роки тому

      I am sorry, I should have read the description!

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +1

      @@xXxJakobxXx3 The video is about how sms 2fa is not secure, and how OTP apps are not as secure as many people think, and I explain why. I don't think that's clickbait.

  • @jasonkaiser1179
    @jasonkaiser1179 2 роки тому

    The problem with security keys is if someone physically steals your key then (and biometrics) their security is useless. I can see a cascading future of needing 3fa then 4fa, 5fa ect. Example, a key needs to be inserted into a device matching multiple specific hardware id's (tpm as an example among others) running on a specific internal network over a specific VPN. These right now would be people needing an extremely high degree opsec and are completely user unfriendly.

    • @ironfist7789
      @ironfist7789 2 роки тому

      Generally, you still have to input a password. If one key is stolen you can remove it from the account with the backup key. If both are stolen you... for example with coinbase, I think you can have the account frozen and then provide extensive documentation such as id/passports to verify identity. Course, if you have 2fa to login to a computer you only manage or something you might be out of luck. People will have to start thinking of them as like house keys or a passport or driver's license that you need to audit for periodically and then take action if they are gone. When people used to steal check books (probably they still do) it was always a bit problematic.

  • @HOLLYWOODlosANGELES
    @HOLLYWOODlosANGELES Рік тому +1

    *Merci pour cette montagne d'informations !!*

  • @stepot3715
    @stepot3715 2 роки тому +1

    So if my phone is stolen along with my sim card with my personal number' can I still open my google account on another device?

  • @richardmendoza4389
    @richardmendoza4389 2 роки тому +1

    I have the Yubico 5 NFC series, & I never use it for my Galaxy S20, as it doesn't really serve its purpose. The hold-it-to-your-phone feature doesn't work, & even when I plugged it into my phone & tried to log into my Google account, Google wouldn't recognize it. Just not seeing the whiz-bang effectiveness nor usefulness of it. & the number of companies that accept it are still quite limited. Meh.

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      Great point!

    • @richardmendoza4389
      @richardmendoza4389 2 роки тому

      Good luck with the police trying to get it to work first! LOL All joking aside, for me, the jury's still out using the fingerprint system, as I'm sure my Phillip K. Dick paranoid side believes they're all being collected into some shadow database for nefarious reasons. Strangely, it works near flawlessly on my pc, while using it in conjunction with Bitwarden. Also--thanks to Naomi's recommendation--I switched over to the DuckDuckGo browser, where I'm trying out their new app tracker blocker (in beta) & email tracker blocker. Anything to help keep from having my bank card being hacked (again).

    • @brodriguez11000
      @brodriguez11000 2 роки тому

      The hardware key should support more than one standard.

    • @aaronboggs5799
      @aaronboggs5799 2 роки тому

      No issues with my Yubikey 5 NFC and a OnePlus Nord N10 5G using the Yubico Authenticator app. 🤷‍♂️

  • @2point..0
    @2point..0 2 роки тому +1

    Excellent @Naomi Brockwell, cant wait for that Security Keys video!!! Thank you!!!

  • @_awizzo_
    @_awizzo_ 2 роки тому +2

    Thanks Naomi.....That was enlightening :)

  • @michellebrunken1340
    @michellebrunken1340 2 роки тому +3

    Love your content, and the fact it is always unique and useful. Thank you

  • @losttownstreet3409
    @losttownstreet3409 Рік тому +1

    all here mention is insecure in comparison to a method used some long time ago: certified cryptographic devices with verification process in place with connects to secure access module (special sim card) and then in return connects to verified cryptographic software. It was rolled out with ID cards in some countries but never got really activated (you had to pay to get access to the feature which was already on your ID-card) and some people didn't like it that all email is going to be securely encrypted even for the law enforcement.

  • @johnbeckmeyer1696
    @johnbeckmeyer1696 Рік тому

    How is Google different with regards to privacy vs security? I don't see the difference?

  • @jamesmarchetti3286
    @jamesmarchetti3286 2 роки тому

    Oh my God! You are so right on time! On the last President's Day someone tried to Hack my phone and Amazon account ! I called them the next day Tuesday and told them. My phone Security programs protected me ! So Amazon locked my account and I called my Bank to lock my Account! The caller ID said Amazon Sanfrancisco! It wasn't them but my phone didn't save the phone number! To give to them. Amazon Tech Support was Awesome!!!

  • @nathanmead4080
    @nathanmead4080 2 роки тому +1

    Hey Naomi! So I’ve been careful to record all of 2FA setup keys for my google authenticator. That means that if I do lose my phone or access to the authenticator app I could set it all backup on a new phone or redownloaded google auth app using the setup keys, right?

    • @GuillaumeRossolini
      @GuillaumeRossolini 2 роки тому

      Yes.
      Also the feature wasn't in the app at first, but now you can retroactively get the seeds, right from the app (which Naomi edited the description to mention)

    • @severianocuellar1327
      @severianocuellar1327 4 місяці тому

      Do not use Google Authenticator , use Apps with end-to-end encryption . GA sends the “seed key” over the network unencrypted. Seed key is the one contained in the QR code.

  • @herreraedgar694
    @herreraedgar694 Рік тому +2

    The only security measure against hacking is to not use technology.

    • @vmobile890
      @vmobile890 3 місяці тому

      I was thinking going back to original way paper and phone calls . Takes too long and phone calls navigating through automated systems and don’t like giving some info to a human .

  • @terry2can914
    @terry2can914 2 роки тому +2

    Thx for this info as I need it ✊🏽✊🏽💃🏽💥

  • @wumwum42
    @wumwum42 2 роки тому +2

    i use bitwarden with bitwarden totp and on my phone i use authenticator pro for protecting my bitwarden account

  • @sylversyrfer6894
    @sylversyrfer6894 2 роки тому +2

    Ironically, banks are often the worst safety offenders by offering 2FA by SMS ONLY.

    • @aaronboggs5799
      @aaronboggs5799 2 роки тому +1

      This is so true. Banks are generally pretty horrendous in this regard.
      I'm not sure if it's still the case, but at least as recently as a couple years ago, passwords for Wells Fargo online accounts were case *insensitive*. Totally inexcusable.

    • @reefhound
      @reefhound 6 місяців тому

      They move billions of dollars in transactions every day in an industry where security is critical. Maybe, just maybe, they know what they are doing?

  • @eight-double-three
    @eight-double-three 2 роки тому +1

    On the TOTP replay topic: I believe the relevant OWASP cheatsheet does highlight this, and strongly suggests the server stores the last OTP and does NOT let people re-use it. Whether implementers of said systems are following that practice, that's another interesting question...

    • @FireRat
      @FireRat 2 роки тому +2

      The example they used of a phishing site isn't even a replay attack because they can use the code you entered to gain access with it being the first time it was used, not a replay

  • @AbuMubarak
    @AbuMubarak 2 роки тому +1

    You didn't mention AEGIS for TOTP

  • @ritagriffin7120
    @ritagriffin7120 Рік тому

    Is microsoft authenticator or authy better for security and preventing haching? (Although authy needs the mobile number)

  • @cryptowealthonyt
    @cryptowealthonyt 2 роки тому +1

    This was a timely video for me regarding security keys. Thanks Naomi!

  • @warmonkey96
    @warmonkey96 2 роки тому

    Microsoft Authenticator works really well as you can set it up to require authentication from the user before it even opens.

  • @Referee006
    @Referee006 Рік тому

    When will the UA-cam video be out comparing and contrasting security keys. This was a very informative video, and I want to purchase a security key but I don't know what are the best security keys for me.

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  Рік тому

      Last month! ua-cam.com/video/UhANsAtvLN0/v-deo.html

    • @Referee006
      @Referee006 Рік тому

      Thanks for your reply. I followed the link that you sent, but it led me to the video that I watched this morning in which you indicated that another video will follow in which you will compare and contrast the various kinds of security keys. Thanks again.

  • @tossedsalad4669
    @tossedsalad4669 2 роки тому

    I like how she has to apologize for privacy concerns every time she mentions a google product. As she mentioned, they're pretty darned good at security. Sure I would go with another option than google authenticator but I don't object to things simply on the basis that they come from google. I wonder if the privacy nuts have pushed the discussion in an illogical direction for most people. As for me, I think I will create a small circle of trust in google and take a chance with possibly receiving targeted ads and having my anonymized data shared to 3rd parties, rather then trusting a wider variety of 3rd parties to be involved in all my services and taking a chance having my critical accounts (like email and cloud storage) hacked.

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      We should absolutely not use google if concerned about privacy because they're atrocious. But for things that don't compromise your privacy so much, the security they offer can definitely be worth using certain services.

  • @darkwolf41nite53
    @darkwolf41nite53 Рік тому +1

    Actually I would like to use One of the 2FA keys you shown goes into usb can use it on Bluetooth it’s handy !

  • @steveos6472
    @steveos6472 2 роки тому

    Anyone remember RSA's little mess from a few years ago with their 2FA tokens. Like anything - it is only as secure as much as you trust the companies products.

  • @alphatech__
    @alphatech__ 2 роки тому

    What about session hijack does key protect from them

  • @kbs7340
    @kbs7340 2 роки тому +1

    Really appreciate the info Naomi thx 💖

  • @prettysmile6869
    @prettysmile6869 2 роки тому

    Securitykey does it have to be a separate device? I mean is it possible to have a securitkey on a different phone? Like when you have 2 phones for separate phonenumbers? 🇳🇱❤️🇺🇦

    • @prettysmile6869
      @prettysmile6869 2 роки тому

      @Sissel yes it is the flag from The Netherlands with love and solidarity to Ukraine. Peace 2 the world

  • @duckshot
    @duckshot 2 роки тому

    People fail to realize there is a difference between 2 Step Authentication and 2 Factor Authentication. SMS is 2 Step and can be man in the middle attacked. A phone clone etc. Google Auth works well but you point out some the exact issues that caused me to leave Google for another app.

  • @user-qm7bp4ul5t
    @user-qm7bp4ul5t Рік тому

    I cant imagine people who's not interested in security watching this video... hahahaha too much info!!!!

  • @UnBubba
    @UnBubba 10 місяців тому

    I have not yet come across a security key with a signature counter. Just searching for options now. If anyone can recommend one, I'd appreciate you sharing. Thanks in advance.

  • @Chuck8541
    @Chuck8541 2 роки тому +1

    So much damn info…I feel more lost after watching the video, than before.

    • @Chuck8541
      @Chuck8541 2 роки тому

      It’s like…the safest thing to do, is to just use the internet as little as possible.
      ¯\_(ツ)_/¯

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +1

      Take a deep breath and ask me any question :)

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      Indeed as JJ said, you can now export you google authenticator seed to another device, I didn't realize it when making the video!

  • @Cryptonomics7
    @Cryptonomics7 2 роки тому +2

    Def looking forward to the upcoming video on security keys! thanks

  • @PP-ob8zr
    @PP-ob8zr 2 роки тому +1

    HI Naomi, Same great channel...same pretty lady! Thank you great job! 😊👍👍

  • @markb9347
    @markb9347 2 роки тому +1

    Definitely looking forward to your next video. Thanks Naomi!

  • @samsunga6927
    @samsunga6927 2 роки тому

    Keys that authenticate the URL... do they also check that the website SSL cert fingerprint has not changed or query other witnesses to said fingerprint? I hate those MItM (man -in-the-middle) attacks from my company or my church or my ISP or my devious friend, lol!

  • @jonny777bike
    @jonny777bike Рік тому

    I hate that the new iPhones have gotten rid of the touch and replaced it with the face recognition. I wear glasses and when Im in bed I don't wear glasses. In the past I could use my finger but they got rid of that. We need to get rid of SMS for 2FA. Also websites should go by the latest standards of NIST. All websites should allow you to past the passwords.

    • @thomasedison9047
      @thomasedison9047 Рік тому

      D m vinethics he'll help you He fixed mine he has 90k followers account. UA-cam is not letting me to write to you in full make sure is the right account you Dm

    • @thomasedison9047
      @thomasedison9047 Рік тому

      ON Instagram

  • @LuisCaneSec
    @LuisCaneSec 2 роки тому

    Yubikeys are pretty fantastic. I use them to authenticate SSH and Sudo for my linux desktops and servers. Be ready to do some chroot to recover a locked computer, if you mess up, though.

  • @cityhunter2501
    @cityhunter2501 2 роки тому

    no backup is the reason why I ditched Google Authenticator and went with MS Authenticator. Now I can easily restore all my codes to any devices with my account.

  • @hoopoe_
    @hoopoe_ 2 роки тому

    Can you recommend any alternative to Boxcryptor, now that they've been taken over by Dropbox?

  • @harveygresham3636
    @harveygresham3636 2 роки тому +1

    your channel is so ... useful. thank you.

  • @RaveSongRecords
    @RaveSongRecords 2 роки тому +2

    Excellent review ! Thanks so much! I’ve been wondering about a security key! 🔐

  • @HinaraT
    @HinaraT 2 роки тому

    I just would like that what you described as a replay attack is a man in the middle attack. (I would like to call that proxy attack but I'm not sure if this terminology is correct but it is essentially to just reroute the traffic like a proxy so you can usurp the real website but still have the green lock as the traffic is genuinely secured between you and the proxy)
    Replay attack is when you can reuse what the user send to someone else even if it is encrypted to bypass the authentication.
    One common use for example on old car keys is recording the signal send from the car key to the car. Then to open the car, you just "play" your record back.
    In case of TOTP it would mean for example if an evil extension copy the TOTP code sent to the good website, then send it to someone else to make it connect immediately with the same code.
    Normally websites should block a TOTP code from being using twice to connect. It is a best security practice, unfortunately that doesn't mean every website prevent it.

  • @elduderino7767
    @elduderino7767 2 роки тому +2

    google authenticator has a "transfer accounts" option now, so i just use that to sync all my auth codes to a retired air gapped phone - safer than keeping a copy of backup codes in your documents folder
    yeah keepassxc is nice with browser integration and cross platform support - but don't use it as your 2 factor method!

  • @iaincampbell4422
    @iaincampbell4422 2 роки тому

    Phone 2FA used to be trivially overcome vía SS7 exploits.

  • @yesnathan22
    @yesnathan22 Рік тому

    How about using MSFT/google authentication for your email and use google voice number for mobile.

  • @sunchips5
    @sunchips5 2 роки тому +1

    This is a really good video. Thank you.

  • @shrikeofterven6006
    @shrikeofterven6006 Рік тому +1

    Does anybody use true answers for those security questions? I personally have had about as many high school mascots as I have had security questions. My father was born in at least 30 countries that he was never born in.

  • @wombatdk
    @wombatdk 2 роки тому +1

    Great advice.
    Btw, for "security questions" you absolutely do not need to answer the actual questions. "What's your favorite pet?" "Chocolate Cookies" is a lot harder to guess. Just make something up that you can remember down the line :)

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +1

      I’d recommend using randomly generated strings for those and storing in a password manager!

    • @wombatdk
      @wombatdk 2 роки тому

      @@NaomiBrockwellTV I'm wary of password managers myself, though I use one - sorta.
      It's on a repurposed old phone without Internet or WiFi (it's also in airplane mode). Offline storage is the only safe storage, IMO.

  • @gitshell
    @gitshell 2 роки тому +4

    Thank you for the awesome content.

  • @ashleymorris6636
    @ashleymorris6636 9 місяців тому

    How do you copy and paste passwords safely and typing in master password for your password vault. Can anyone help please

  • @zgdafzgdaf4264
    @zgdafzgdaf4264 2 роки тому +1

    Nice review. For Fido, need to disable other recovery options such as phone,. Also most phones, mobile devices have Fido chips built in and could use this method for a factor. The ultimate goal is to get rid of passwords.

  • @dystopianjustice247
    @dystopianjustice247 2 роки тому

    Would you please do a video for security for journalists and dissidents?How does a security key protect accounts, if providers share info with corrupt law enforcement who falsify records to get warrants?

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому

      Freedom of the press foundation is a great resource for that

  • @johnspitta6725
    @johnspitta6725 Рік тому +1

    Holy S…t. I’m throwing my phone in the trash and going back to a Day Runner.

  • @ogcrypto6022
    @ogcrypto6022 2 роки тому +3

    Well it seems like there's no hope even with two-factor Authentication so what's the point of being in cryptocurrency if you get hacked and all your money gets stolen all the time?

    • @NaomiBrockwellTV
      @NaomiBrockwellTV  2 роки тому +1

      hmmmm I don't think the takeaway was that all 2fa is insecure! auth apps and security keys are great, highly recommend

  • @ckpriv6167
    @ckpriv6167 Рік тому

    Hi. great content. I activate the backup of my totp, I have forget this.
    About SMS, I don’t have one on my phone. I have a virtual one. Is it more secure ? or the same as having a real one ?
    external device are interesting. is it more secure than biometric auth ?

  • @greatwolf.
    @greatwolf. 2 роки тому +6

    Make sure you cover crypto hardware wallets like KeepKey that have FIDO webauth implemented so it can be used as a security key.

    • @dzidmail
      @dzidmail 2 роки тому

      Yeah. Trezor and ledger have it too

  • @abek3684
    @abek3684 5 місяців тому

    How is you I key authentication works I don’t get it got keys