Backing Up Google Authenticator 2FA Codes? Use This Instead!

Поділитися
Вставка
  • Опубліковано 21 жов 2024

КОМЕНТАРІ • 118

  • @CyphDragon
    @CyphDragon Рік тому +29

    I switched over to Aegis instead of Google Authenticator or Authy a couple years ago, and like it. It works pretty well, and it's open source which I *love* for security applications

    • @esaedvik
      @esaedvik Рік тому +3

      And their exports are encrypted JSON's, if you so choose.

    • @Sammyli99
      @Sammyli99 Рік тому

      mate how can you switch when the "companies use one system". maybe I have not seen, that you can "select" the type of authenticator...

    • @CyphDragon
      @CyphDragon Рік тому +4

      @@Sammyli99 it's a bit of a process, but fairly straightforward. You disable 2FA from the account first, and then you enable it again. When the site gives you the QR code to scan, you just use Aegis to scan it instead of whichever app you were using before. Job done.

    • @jjann54321
      @jjann54321 Рік тому +1

      I'll be happy when more companies and organizations allow/support the Yubico Authenticator App. It's a great app and very secure, however, not many [mainstream] companies support the Yubico Authenticator App but I hope in time it catches on.

  • @NIAtoolkit
    @NIAtoolkit Рік тому +11

    I’m contemplating moving from authenticator apps to a hardware solution. The keys I have don’t support TOTP codes. After a little research, the YubiKey 5C is the way to go

  • @jmr
    @jmr Рік тому +15

    Super pissed at Google! They didn't give me an option to skip. Mine got backed up. I had to go into settings to disable it. Damage done though! I don't think it's that difficult to copy keys manually. It can be done via QR pretty fast so I don't want cloud backup. That 2FA directory Shannon mentioned is awesome though. I might switch banks now that I have a nice directory. I found one with Yubikey support and they keep trying to pay me to switch.

  • @godmodewu
    @godmodewu Рік тому +6

    I use Bitwarden as my pswd manager and authenticator, i pay the yearly premium cost($10USD) because i cant be bothered hosting my own database, it is also opensource, Shannon has done a video on this before. I think its so worth it. I also have a few yubikeys which i still need to setup.

  • @RobSnow-ui4sz
    @RobSnow-ui4sz 11 місяців тому +2

    Great video - You can also not use the cloud by turning this off in the new Google authenticator app. This will make it more like the previous version before the new version. Also if you have a second device you can export your codes to another device as well. It will ask if you want the other device to be disabled but you can decide on that.

  • @ulrikeg8552
    @ulrikeg8552 Рік тому +1

    Great info as always (and I love your hair)!

  • @robertseptim3579
    @robertseptim3579 Рік тому +1

    I lost access to all my accounts because of google authenticator's latest update. I'm done with Google. Subbed!

  • @sawoftime8262
    @sawoftime8262 Рік тому

    I don't know how true this is, but the wiki says that data from SIM cards can be read, especially if you use a smartphone at the checkout, and someone stands behind you and pretends to dig into his device, while in fact scans the devices of others for vulnerability...
    But the truth is that in the past it was better when people did not use mobile devices - this is evil! o.O!
    *Shannon Morse, Thank You =)!*

  • @jugamath
    @jugamath Рік тому +7

    Authy with a strong Backup Password seems like a better option. Authy can be used wherever Google Auth can, and it's more flexible. I'm curious what others think of Authy's security in comparison.

    • @JoriDiculous
      @JoriDiculous Рік тому +2

      Authy is much better than google Auth. Its real easy to get you codes back when you change phone, not so at all with the Google pos.

    • @neuideas
      @neuideas Місяць тому +1

      Twilio has been hacked before, and some TOTP codes were compromised. I would stay away from them. I currently use 2FAS, which has a password-encrypted backup synched to Google. It's your option to use this feature. It will also allow you to create a password-encrypted local backup file, if you prefer.
      Aegis is also a solid choice.

  • @jdchaves2869
    @jdchaves2869 Рік тому +5

    Great advice as usual. I have 2 yubi keys which I am slowly trying to get on all my accounts and off of authenticator. I am REALLY considering bit defender for passwords, and I think they are still working on an auth code app, which they mention will be end to end encrypted from the start. Thanks for all the great information.

  • @SirDigbyChickenCaesar
    @SirDigbyChickenCaesar Рік тому +1

    Your hair looks like candy. Thanks for the news :D

  • @stevemorman8249
    @stevemorman8249 Рік тому +3

    What about the 2FAS open source app? You don't need to supply your phone number or email like you do with Authy. Have you looked at it?

  • @speedracer9132
    @speedracer9132 Рік тому +2

    2 things, 1 that 2fa directory would greatly benefit from filters so I could see only services allowing software/hardware 2fa, and 2 yubico shouldn’t have raised the prices

  • @brat1475
    @brat1475 Рік тому +1

    Thank you for the great video. What are your thoughts on Microsoft Authenticator? Is there cloud backups encrypted?

  • @LaczPro
    @LaczPro Рік тому +3

    What about Microsoft Authenticator? It's also a big company that also offers an authenticator and cloud backup like Google. Are they receiving those codes without encryption?

  • @BDBD16
    @BDBD16 Рік тому +3

    I am looking forward to when Google says the "Beta" is over for their Authenticator app and start charging per code.

    • @pjohnson21211
      @pjohnson21211 Рік тому +2

      equally likely is they will discontinue it.

    • @BDBD16
      @BDBD16 Рік тому

      @@pjohnson21211 Google Graveyard anyone?

  • @_BangDroid_
    @_BangDroid_ Рік тому +3

    Banks don't use hw keys because of heavy regulation and rigid policies that usually always inhibit innovation. That and the gerontocracy.

    • @JoriDiculous
      @JoriDiculous Рік тому +1

      All banks here (Norway)use hardware keys. Combined with Mobile keys if you dont have you key with you. And its the same key (hardware and mobile) you use for all online shopping.

    • @LionRoars918
      @LionRoars918 Рік тому +2

      @@JoriDiculous .. consider yourself lucky. My bank .. is numeric password only with no 2FA. I personally want everything to be a hardware key only.

    • @BDBD16
      @BDBD16 Рік тому +1

      I have a hardware key from my bank.

    • @_BangDroid_
      @_BangDroid_ Рік тому +1

      The gerontocracy must be a bigger factor. Some countries have it worse than others. I don't know why any bank would want their accounts less secure.

    • @Arachnoid_of_the_underverse
      @Arachnoid_of_the_underverse Рік тому

      U.S. banks cant seem to get PIN codes for their debit cards either rather than relying on easily faked signatures.

  • @ecash00
    @ecash00 Рік тому

    Best place for security is YOU...a memory key is great. And like sec. camera's I want them at HOME and DIRECT them to where I want..

  • @Jaabaa_Prime
    @Jaabaa_Prime Рік тому +1

    Hi Shannon. you mentioned the future and PassKeys again. I have several Yubikey 5 keys and have used FIDO2 (WebAuthn) to lock down my online accounts with these keys. Are PassKeys weaker than my USB devices?

  • @mattblack5352
    @mattblack5352 Рік тому +3

    2FAS auth seems pretty good since it has auto cloud sync and can be password protected

  • @MissFoxification
    @MissFoxification Рік тому

    Not your cloud, not your data.
    Why not set up your own cloud? Nextcloud, running on bare metal, Proxmox, Docker or your system of choice?

  • @apricotdog
    @apricotdog Рік тому +3

    How weird. I was literally looking at exporting my authenticator keys (not the cloud) an hour ago so that I can use them with a yubikey. (Spoiler. It doesn't work).

  • @Vilblue
    @Vilblue 3 місяці тому

    I can't seem to find an actual explanation of why the lack of E2E encryption is risky.

  • @thumbtak123
    @thumbtak123 Рік тому

    My backup to my phone is my smartwatch. Not Google Authenticator, but there are others that work on your smartphone.

  • @greatveemon2
    @greatveemon2 11 місяців тому

    so if the website suddenly changed domain name like twitter suddelny changed to x. Isn't that will stop the yubikey from authenticating?

  • @dwaynelarose278
    @dwaynelarose278 Рік тому +1

    Keepass is your best option if you want otp backed up

  • @Physics072
    @Physics072 2 місяці тому

    No good excuse for why they are not sending the data over encrypted channels. Was it done on purpose?

  • @impermanenthuman8427
    @impermanenthuman8427 3 місяці тому

    Authy says (at least currently) that the keys are encrypted on the device first then sent to their cloud backup so even if someone tries to intercept the encrypted keys between each end their still encrypted so how does ‘end to end encryption’ help?
    They used to do backups to windows desktop which was handy as you could backup to drive that was secured offline most of the time, but now it’s only to another mobile device or cloud it seems which is either more expensive to get a second device or less secure ‘just in case’ a hacker gets into authys cloud and manages to crack the encryption on the keys…if that’s realistically possible?
    Thanks for a good vid 👍🏻

  • @jonathonhazelhurst
    @jonathonhazelhurst Рік тому

    Do you still have the Nest Secure system and what are you planning to do with the upcoming shutdown of support in April 2023?

  • @hurgoz2426
    @hurgoz2426 Рік тому

    Hi! Thanks for this video :) I've show it's possible to backup the Yubikey keys to a Keepass. Have you already test it? 🧐

  • @LionRoars918
    @LionRoars918 Рік тому +1

    Can you do a video about passkeys at Google ? I just really want to use my Yubikey everywhere as that is the only thing I trust whether that be USB on my PC or NFC on my Pixel phone.

  • @anubisystems
    @anubisystems 3 місяці тому

    Thanks for sharing!!

  • @Wigglythegreat2
    @Wigglythegreat2 Рік тому +1

    Does this mean that if sync was on in google authenticator, we should delete all the authentication methods within each service and add it back in after sync has been disabled?

  • @mk4355
    @mk4355 Рік тому +1

    Microsoft Authenticator is locked by biometric or pin, too

    • @Jopn83
      @Jopn83 7 місяців тому

      The question is if the backup is encrypted? I also use it, but if I lose my phone I need to back up my tokens

  • @adventureswithtime
    @adventureswithtime Рік тому

    Do you have a video on authenticator apps: either Google or Authy? I need to use one and want guidance on which to use.

    • @ShannonMorse
      @ShannonMorse  Рік тому

      Not yet, but I can make a comparison video!

    • @adventureswithtime
      @adventureswithtime Рік тому

      @@ShannonMorsewell I need to select one now because EverNote is requiring the use of an authenticator app.

  • @zyberjunker
    @zyberjunker 8 місяців тому

    I don't understand, those codes change every 30 seconds, how and what you are going to back up? Sorry, I am new to this and have been halfway hacked recently.

  • @MrRedStream
    @MrRedStream 7 місяців тому

    what if somebody stole unlocked phone / saw code, and added his own fingerprint in phone settings? Are thieft's fingerprint going to work with Authy or Google Authenticator?

  • @Darryl26
    @Darryl26 Рік тому

    Can you do a video of a top 5 or 10 secure email for 2023? and which one you prefer the most? Would be much appreciated, thank you!🙏🏻

    • @ShannonMorse
      @ShannonMorse  Рік тому +1

      Great suggestion!

    • @jjann54321
      @jjann54321 Рік тому

      @@ShannonMorse That will be an interesting video and I'm here for it. I'm curious what will define "secure." Will it include using PGP or hiding behind TOR or be hosted in countries outside the reach of countries that like to "reach?" Free vs. paid? Down the rabbit hole we go!

  • @Lukebarca
    @Lukebarca 11 місяців тому +1

    oh wow Hak5 have not heard of that name in a while

  • @christopherrasmussen8718
    @christopherrasmussen8718 Рік тому

    Negative. Every Chromebook I power wash shows the privacy notice. The log

  • @cjc363636
    @cjc363636 Рік тому

    Hi, I use a wifi iPad as an authenticator app backup. Works the few times I used it. Is that secure? (The iPad is a streaming "TV" iPad in my house.)

  • @erakus
    @erakus Рік тому

    tried your code on a yubikey 5c fips and didnt get 5 bucks off. only available on non fips models?

  • @bberg4745
    @bberg4745 10 місяців тому

    I moved out of my country and changed the time zone and not getting correct codes. Any tips?

  • @LordMarcus
    @LordMarcus Рік тому +1

    Ok, apropos of nothing and with no shred of sanity, I have never wanted to eat hair before, but yours looks delicious.
    I'm sorry. 😭

    • @LordMarcus
      @LordMarcus Рік тому +1

      Seriously, it looks like cake frosting.

  • @tomharkness
    @tomharkness Рік тому +1

    Can you have multiple Yubi keys? One for the wife, me, backup in safe??

  • @natgenesis5038
    @natgenesis5038 5 місяців тому +1

    Passkeys recovery it’s the main problem

  • @simonsayshomeassistant
    @simonsayshomeassistant Рік тому

    Another great video Shannon! I hope I can learn from your experience to improve my own You Tube channel

  • @JIKANDAULA
    @JIKANDAULA Рік тому

    How can I recover my 2fa key when i lose my software key

    • @ShannonMorse
      @ShannonMorse  Рік тому

      I'm posting a video about recovering account access due to loss! Keep an eye on my page for that video to post this month

  • @DevilsReject765
    @DevilsReject765 Рік тому +1

    How secure is Mac os 😊😊

  • @KeithBarnett
    @KeithBarnett Рік тому

    Google now has Passkey that works like a security key. I have both set up and deleted my other log in options.

    • @ShannonMorse
      @ShannonMorse  Рік тому

      I made a note about passkeys in the video. 😀

  • @koushikraj9815
    @koushikraj9815 Рік тому

    youbikey is good if builtin pwd manager is implemented with cloud sync to personal drive option will be greater. yubico was super high priced litteraly stolen key fetch 1st hand basic android phone. who said mobile will be stolen rather than key. problem was auth/online pwd manager which most get hacked now a days. they can still stole key file which stored in pwd manager anyway. yubico save auth also that means is yubikey stolen and they use windows yubico auth and connects the will get access also.

  • @sarahupton975
    @sarahupton975 Рік тому +2

    I miss TekThing!😢

  • @discerningacumen
    @discerningacumen 11 місяців тому

    How can I transfer all from Google authenticator to another 2FA app?

  • @jessieo5757
    @jessieo5757 Рік тому +2

    Huh, people still use Google Authenticator? Probably still use LastPass too. 🤣

  • @shotbyarian
    @shotbyarian 9 місяців тому

    is E2EE now available fot google auth.?

  • @gsgidney
    @gsgidney 6 місяців тому

    But you can lose a peripheral device.
    Maybe not the best option...lol

  • @joeltyler3427
    @joeltyler3427 Рік тому

    10:46 And eBay

  • @mk4355
    @mk4355 Рік тому

    SMS is still the ultimate backup option. It never gets old, specially in countries where cell service providers tie SIM numbers with social security numbers or national IDs

    • @BDBD16
      @BDBD16 Рік тому +2

      🤣🤣🤣🤣

  • @stangtennis
    @stangtennis Рік тому

    Would love a Yubikey, but they are just way too expensive. Sorry but I just can't get myself to pay that amount of money for what it is. Don't get me wrong it is a great product, and when I get rich I'll get one (guess I will have more money to protect then too)

    • @ShannonMorse
      @ShannonMorse  Рік тому

      The cheaper ones are around $20-30 (cheaper with a coupon) and can reliably protect your online accounts. It's a one time investment with no subscription, so I do think it's worth it compared to the cost of having your identity stolen but I hope you can afford one in the future ❤️

  • @mk4355
    @mk4355 Рік тому +1

    With SMS and social security numbers, you just call cell service provider to block the sim, then when you can visit their office and prove your ID and get a new working sim. Problemo solved.

  • @JoriDiculous
    @JoriDiculous Рік тому +2

    I ditched Google Auth. years ago, when i found it was impossible to transfer my codes from one phone to a new one. Authy allows that.
    Also got a yubi but so few supports it. Steam used to until they messed up something.

    • @crand20033
      @crand20033 4 місяці тому

      You can do transfers with the new version.

  • @_gamezip79
    @_gamezip79 Рік тому

    Please help me i have lost my access google 2fa apo

  • @LazyJones
    @LazyJones Рік тому

    Comment for engagement

  • @-AnyWho-
    @-AnyWho- 7 місяців тому

    authy for desktop is ending ...

    • @ShannonMorse
      @ShannonMorse  7 місяців тому

      This video is pretty old now but yes, I heard the recent news!

    • @ShannonMorse
      @ShannonMorse  7 місяців тому

      This video is pretty old now but yes, I heard the recent news!

  • @nelsonjunior918
    @nelsonjunior918 Рік тому

    3rd world countries are no good for yubi key purchase yet :'(

  • @black_heart_gaming583
    @black_heart_gaming583 Рік тому

    Authy is da best

  • @Trevor-z7b
    @Trevor-z7b Рік тому

    Where's the backup codes on Google authenticator?

    • @ShannonMorse
      @ShannonMorse  Рік тому +1

      I'm working on a video all about backup codes!

    • @Trevor-z7b
      @Trevor-z7b Рік тому

      @@ShannonMorse thank you!

  • @TMWNH
    @TMWNH Рік тому

    Thanks

  • @lukaswerner4390
    @lukaswerner4390 Рік тому

    Crapola

  • @Mrajtheartist
    @Mrajtheartist Рік тому

    ✨⭐✨💞💖💞💖💖💞💖💞💖💞✨⭐✨

  • @Nathan-z7s3d
    @Nathan-z7s3d Рік тому +1

    I'm in need of a girlfriend, who's as pretty as you Shannon. In body and character! Thank you

  • @Anondady
    @Anondady Рік тому

    Dam I want to be your friend to.

  • @JGI43
    @JGI43 Рік тому +1

    Hi Shannon , how secure is apple mail , 😊