How Hackers Get 2FA Codes
13:02
2 ай бұрын
Passkeys are better than passwords
12:42
Dynamic Templating with Kadence
32:36
Пікірлер
@jaeminkim7406
@jaeminkim7406 26 күн бұрын
❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤
@kristylopez1418
@kristylopez1418 Ай бұрын
Thanks for the great information and advice, Kathy, on SIM Swapping and I have just subscribed to your channel. Just have a question. I'm an old timer and have been using PC online banking since the inception way back when. Since the beginning of Social media and mobile banking I have refused to use both, therefore I have very little on line personal info out there. I don't store any passwords on my phone and only use my phone mainly for texting and browsing. I know boring. I emailed my bank and they don't use a security key method as 2 factor authentication method but I think I will buy a security key for the other sites that allow it. I have setup a second email account for my financial stuff as a precaution as my main gmail account has been breached. So my question is, will I still be some what vulnerable to SIM swapping? Also if I sign into my bank, on my PC, and my code gets sent to SMS text can the jerks get into my account? Thanks and have a great day.
@databae1
@databae1 Ай бұрын
do you recommend cloaked wireless for cell service?
@KathyZant
@KathyZant Ай бұрын
I am liking what I am seeing. They definitely understand the problem. Doing some research now, but they're saying all of the right things.
@derekshort
@derekshort Ай бұрын
Good advice! I use Bricks and love it. I always update.
@denzray
@denzray Ай бұрын
happened to me once, I got it resolved but it was a pain in the arse calling tech support that also has no idea of what to do.
@knotox
@knotox Ай бұрын
Cloaked Wireless is the only real protection against SIM swap attacks. They prevent staff from modifying accounts. Only the customer can do that.
@hagbard72
@hagbard72 2 ай бұрын
No banks in Canada use authenticator apps or devices like YubiKey. People have been losing money from scams, and while the banks make a big deal on their sites about backing your online accounts 100%, tons of news stories showing they don't.
@julietittler9171
@julietittler9171 2 ай бұрын
As a middle aged engineer with a child on the spectrum, what do you see as the benefits of getting oneself tested at this point in life?
@Jd-uv9jj
@Jd-uv9jj 2 ай бұрын
Isn’t that why we encrypt iMessage has been using Ecc to encrypt for years now 🤷‍♂️
@djksfhakhaks
@djksfhakhaks 2 ай бұрын
What? Very few people use there phones for text and pots calls. You seriously think that the general public doesn't know about chat and voice apps??😂😂😂😂😂😂
@KathyZant
@KathyZant 2 ай бұрын
SS7 is the network underneath all phone systems. It has been used to hack WhatsApp, Telegram, steal SMS 2FA codes. Are you paying attention?
@KathyZant
@KathyZant 2 ай бұрын
Use the best VPN for securing your communications, Private Internet Access: zant.fyi/piavpn (Affiliate Link)
@walter_lesaulnier
@walter_lesaulnier 2 ай бұрын
I repair computers for a living and you would be amazed about how naive 90% of people are regarding internet security. I'm almost 60, but I've been a computer geek for 50 years. Most people in my approximate age bracket are particularly trusting (gullible), especially since these new fangled abominations called smart phones and devices came out (LOL). On PCs, the biggest problem with my customers is that I can't get them to stop clicking on links in phishing emails.
@shire-lee
@shire-lee 2 ай бұрын
Some people are so damn simple….
@KathyZant
@KathyZant 2 ай бұрын
I bet they're super interested in that attachment they get from some random email address, too. 😬 I had a family member tell me that it was a "special award" and yeah. Gullible indeed. Thanks for watching, Walter. If there's ever any content I can create to help your clients become more aware, please let me know.
@walter_lesaulnier
@walter_lesaulnier 2 ай бұрын
@@KathyZant The worst are the ones that are near perfect copies of emails from whatever bank the person uses. They click on the link and it takes them to a fake replica of their bank's website. Soon as they put in their user name and password, they're toast. 2FA can help, but too many money or transaction websites don't have this on by default.
@zhad6045
@zhad6045 2 ай бұрын
Thought i was gonna see a channel with 10k + subscribers and hella views. This is some profesional video production.
@KathyZant
@KathyZant 2 ай бұрын
Thanks so much for the kind comment! I've had some experience building content for others; this has been more of a side hobby.
@adissonbuchanan1731
@adissonbuchanan1731 2 ай бұрын
Unfortunately xfinity does verify your identity with an sms code read over the phone. Very poor practice I noticed while dealing with them recently. Certain messages say not to share the code, and the ones they ask for don’t say that.
@KathyZant
@KathyZant 2 ай бұрын
Wow, that's bad form. Thanks for sharing that, good for people to be aware.
@David-zp8rx
@David-zp8rx 2 ай бұрын
Thanks to Microsoft for their ridiculous URLs people are so used to constantly typing microsoft credentials in these random (legitimate) hard to read URLs, it makes it hard for average users to discern. Thanks MS..
@KathyZant
@KathyZant 2 ай бұрын
MS security concerns are the gifts that keep on giving. 😩
@octonoozle
@octonoozle 2 ай бұрын
I don't use the internet.
@KathyZant
@KathyZant 2 ай бұрын
Perfect. The solution to everything.
@bwgosselin
@bwgosselin 2 ай бұрын
Use temp email to give out. Use virtual machines
@D.von.N
@D.von.N 2 ай бұрын
Sandboxing (so far) is a safe way to open risky attachments or other files. Virustotal is good at eliminating potential threats. One antivirus can fail spotting malware, but over 70 different vendors have better chance against malware.
@D.von.N
@D.von.N 2 ай бұрын
Hmmm if they click on anyhing sent to them out of blue, even if a follow up, they aren't that savvy then. Always don't trust any links in mobile media where you cannot hover over them or inspect the link in detail independently. This is why I hate smartphones as supposed computers. You have your hands tied in some aspects as an average user. All that advice for the use on PC doesn't quite work in mobile devices. Always search the website of the company and log into it by yourself. Just beware of sponsored links. Those might be phishing sites, too.
@KathyZant
@KathyZant 2 ай бұрын
This phishing campaign definitely targets the limited mobile experience. And yes, ads can be malicious, too. Good advice.
@D.von.N
@D.von.N 2 ай бұрын
@@KathyZant There was a warning somewhere, when people look for a contact number to call usual companies, they just search it and use anything that appears in the first searches, the company name and their number, not knowing they can be fraudulent pages pushed to the top by skilled scammers. Always look for a proper website and use their proper number under 'about us' section.
@RCohle452
@RCohle452 2 ай бұрын
The change some of the letters to cyrillic characters that look similar to the alphabet characters.
@D.von.N
@D.von.N 2 ай бұрын
And that is a growing problem. People cannot trust their eyes these days.
@KathyZant
@KathyZant 2 ай бұрын
Yep, that and homoglyph swapping are used frequently.
@datajake1999
@datajake1999 2 ай бұрын
@@D.von.N When a screen reader encounters these strange characters, the URL is read out in an unusual way. For example, a character that visually looks like a slash is read as divided by, and this will most likely tip off the user letting them know that something phishy is going on (pun intended).
@BrianWoodruff-Jr
@BrianWoodruff-Jr 2 ай бұрын
So what are sites like Amazon supposed to do, not send "update on your package" emails? If everyone is sus, then what's the point? I chose to trust >0 emails, which videos like this make me feel ashamed of.
@KathyZant
@KathyZant 2 ай бұрын
Don’t feel ashamed, at all. Just be aware of what attackers are up to. Hopefully you feel more empowerment through knowledge than anything else. They’re getting more sophisticated, which means we have to be more aware.
@tossedsalad4669
@tossedsalad4669 2 ай бұрын
okay... but extensions have permissions. there is a permission to access site data. is there anything that leads us to believe the permissions are bypassed? if not, this seems like a no never mind to me. of course a malicious extension can always try to abuse the permissions it is given that is not a surprise to anyone
@KathyZant
@KathyZant 2 ай бұрын
Researchers found the coarse-grained permission model underpinning Chrome extensions violates the principles of least privilege and complete mediation. Numerous websites including some Google and Cloudflare portals, store passwords in plaintext within the HTML source code of their web pages, allowing extensions to retrieve them. The systemic practice of giving browser extensions unrestricted access to the DOM tree of sites they load on means it's not really a nevermind and that it's up to users to be judicious about the browser extensions they install.
@tossedsalad4669
@tossedsalad4669 2 ай бұрын
@@KathyZant thanks. I appreciate the well considered reply. I'm not completely convinced, but I'll take another look. you just earned a subscriber. keep up the good work.
@KathyZant
@KathyZant 2 ай бұрын
Happy to have you on board! I'll definitely continue to create content to help you stay safe out there.
@MacS7n
@MacS7n 2 ай бұрын
Which password manager do you use? I need to start using a password manager. Great video btw
@KathyZant
@KathyZant 2 ай бұрын
There are quite a few password managers that are quite good. Bitwarden free is the easiest to get started with; the paid version is only $10/yr. NordPass is good, as is 1Password. I have friends who love Keeper. Given the problems LastPass has had, I'd avoid that one.
@MicroOrbit
@MicroOrbit 2 ай бұрын
Hi Kathy, great video! I use a unique email, yubi key, never click on links or give info over the phone (even if it is the "IRS"). If one wanted a career in cyber without college, how would you go about it? Video idea?
@KathyZant
@KathyZant 2 ай бұрын
Great idea for a video. I didn't study cybersecurity in college as it wasn't a thing back then. I'll put together some thoughts and post a video. Thanks for watching and for the suggestion!
@kolovrat_scarves
@kolovrat_scarves 3 ай бұрын
Yes, Kathy, we first need to dig deeper into ourselves, find out who we really are (knowing our strengths and weaknesses, our in DNA encoded talents and our abilities to achieve our dreams, etc.), learn to value our own individuality (even if we are still working on some improvements) while remaining open to seeing the light and exclusiveness in others. Life is a long journey, and self-discovery can take a significant part (or maybe even a whole part of it), but we better keep moving while maintaining integrity and an analytical-realistic approach to ourselves and to the people we meet on this life path. I don't believe in such a thing as "reinvention", simply because it is beyond our natural abilities - all we can do is adapt our "programmed" personality to the world we have to live in: in next point after our “reset” we may find ourselves on a whole new level where we have gained a much better/honest/advanced understanding of ourselves in our immediate and distant relationships and interactions free of some misconceptions and illusions - all of which will inevitably improve the quality of our lives and ultimately create a feeling perception of oneself as a “renewed” person. I love the theme of your new video - it feels like many of us need to stop at least for a moment in this ongoing rush of life and allow ourselves to see things free from the unclear, nebulous and often harmful concepts imposed on society: this one moment (or two, lol ) can trigger a life-altering chain of events-all we need is to simply see their polarity clearly and navigate accordingly. 😂👍
@KathyZant
@KathyZant 3 ай бұрын
Thank you so much for your comment, @kolovrat_scarves! I debated whether or not I should put this video up, but if it can't be "my" channel, what's the point. I've got more security videos coming, but also want to have the freedom to make more personal videos too. Great thoughts on our programming. I feel like life is a continuous process of undoing that. :) Thanks again for the comment. Means a lot to me.
@faisalrabbani
@faisalrabbani 3 ай бұрын
It's a really nice tutorial. Thank you!
@KathyZant
@KathyZant 3 ай бұрын
Thanks, Faisal! I appreciate the feedback.
@kevinpritchard3592
@kevinpritchard3592 3 ай бұрын
WOW, thanks for bringing this more out into the public forum.
@KathyZant
@KathyZant 3 ай бұрын
Thanks for watching. Yeah, seemed pretty important.
@StarkSpartan
@StarkSpartan 3 ай бұрын
i'm surprised at social media scandals are suppressed in the media. There's not more people that are shocked by these scandals? People should be really concerned.
@KathyZant
@KathyZant 3 ай бұрын
I don't think anyone is very concerned about our privacy. The Equifax breach should have mortified consumers and politicians alike. I'd actually call this corporate hacking. Onavo contained malware, siphoning user activity for competitive intelligence. And yet, no one except for a few security professionals see anything wrong with it.
@StarkSpartan
@StarkSpartan 3 ай бұрын
@@KathyZant I am an industry professional, and I consider this to be a very bad information security scandal. People should be careful about their privacy, sceptical as their first reaction.
@KathyZant
@KathyZant 3 ай бұрын
I agree. I don't think most people understand what happened or the implications. I'd like to uplevel basic security understanding. Here's hoping I don't have to resort to clickbaity titles to get people to click and learn for their own good. 🤞
@StarkSpartan
@StarkSpartan 3 ай бұрын
@@KathyZant I appreciate your efforts and I am very happy I found your channel. It's very good food for thought. Thank you and please continue what you're doing. 🤓
@KathyZant
@KathyZant 3 ай бұрын
I appreciate the vote of confidence! I plan on continuing. Thank you.
@turanamo
@turanamo 3 ай бұрын
FB has been the most unethical company I ever worked for.
@khmf1
@khmf1 3 ай бұрын
meme: People worried about man in the middle attacks. /. Then KZbin sends you even more commercials in between videos.
@KathyZant
@KathyZant 3 ай бұрын
Get Private Internet Access VPN (my recommendation) with 4 months free: zant.fyi/piavpn
@Fatepathfinder
@Fatepathfinder 3 ай бұрын
Kathy, I just enrolled into your Zoom class scheduled on this May but the situation I am in right now cannot wait this long... I installed the Solid Security Pro plugin on my WP site (bought it through the link provided by the nice guy @WPressDoctor - my 'thank you' little tribute for his great tutorials on YT). At the beginning I had troubles with uploading the Plugin from my PC/downloaded software - for that I reached out to the SSP plugin team in the Members area. The person who contacted me back requested access to my site as the admin. Since I was just starting with my new site, I granted the access. I had my passwords changed right after the ended session. On a next following day after the installation of the plugin on my WP site with its 2FA, I revisited my site and found that some plugin's settings were changed and the Firewall configuration became blocked (the Error message popping up right after I hit the Settings>Features>Firewall>Error. After another few days I discovered: my Password was changed behind my back (the one I used for hosting log); I have one file added (php_errorlog) and several files changed; The hosting provider outlines those changes in Red as unrecognised. I found several changes inside on SolidSecurity Pluging Setting done without my knowing; Today I found that my Pass for my SolidSecurity account was also changed (had to reset it using 'forgot password' option). I created another ticket regarding my SSP password breach however it leaves an impression that my concern is not being given serious attention to... With my first one I received next proposition for granting next site access at the admin role. Honestly speaking I do not feel this as anyhow beneficial for me any more- I did not have such problems before I got this plugin installed on my site. I feel that something is really wrong about the whole thing. Kathy, could you, please, take a moment and share with me some of the possible ideas about this situation and its realistic resolution with me? I would be forever grateful to you if you spare some of your valuable time for me. Please.
@Annie0-ys8oj
@Annie0-ys8oj 3 ай бұрын
Oops. This isn’t going to be fun😢
@user-of5fd2ks8d
@user-of5fd2ks8d 3 ай бұрын
KATHY .... you talk like you are drunk or just had a stroke. Get it together mumbler.