How To Protect Yourself From A Two Factor Hack

  Рет қаралды 7,507

Ask Leo!

Ask Leo!

Күн бұрын

Пікірлер: 52
@askleonotenboom
@askleonotenboom 8 ай бұрын
✅ Watch next ▶ Why ANY Two-Factor Is Better than No Two-Factor ▶ kzbin.info/www/bejne/aHWxe6SgfLF7iJo
@glasslinger
@glasslinger 8 ай бұрын
Yes, I have graduated from no factor up to 15 factor authorization! :)
@er...
@er... 8 ай бұрын
Oh, I got some catching up to do!!😁
@Malouri
@Malouri 24 күн бұрын
Regarding 2:40 : didn't AT&T have a huge breach several months ago?
@Anotherperson-m5b
@Anotherperson-m5b 8 ай бұрын
If they don't have your password, they will just say 'forgot password' and use the 2 factor/OTP if they have the sim
@askleonotenboom
@askleonotenboom 8 ай бұрын
That turns the second factor into a single factor, so that's not what happens. Usually "I forgot my password" still requires something in addition to your 2FA code -- usually an email sent to your alternate email address.
@Nik-8it5p
@Nik-8it5p 6 ай бұрын
​@@askleonotenboom, This is what saved my bacon when some bastard stole my number, needless to say I ain't with that phone company any longer. 👍👍
@StijnHommes
@StijnHommes 8 ай бұрын
I'm not so much worried about a thief gaining access to my account, I'm more worried about losing access to my account myself when I lose that second factor. Misplacing a hardware key or having your phone stolen is bad enough, but if you can't log into your account to change your password because you no longer have access to the second factor, it's many times worse. And I don't even have to lose it. Sweaty hands or having wrinkled skin from swimming for a couple of hours is all it takes to not be able to log in with a fingerprint scanner. Face recognition fails in bad lighting. If 2FA is so important, they need to come up with better implementations.
@askleonotenboom
@askleonotenboom 8 ай бұрын
askleo.com/two-factor-loss-risk/
@flyingjeff1984
@flyingjeff1984 6 ай бұрын
My Iphone (and the one before it) regularly "forgets" my fingerprint. Very frustrating.
@JM.TheComposer
@JM.TheComposer 8 ай бұрын
A phone company manager in NJ was charging about $1000 in crypto to do SIM swaps. Bleeping Computer covered it in March 2024. Never link anything important with your phone number. You're just giving the keys to people who don't care about you.
@David.M.
@David.M. 8 ай бұрын
Thanks Leo
@D.von.N
@D.von.N 8 ай бұрын
Another point: if your passkey goes on several places at once, like in your mobile and email, they only need access to one of them to steal your account. A double edged sword.
@Patrick_Gray
@Patrick_Gray 8 ай бұрын
Thanks Leo. I use two factor authentication and also don't bank or pay bills online.
@KeithBarnett
@KeithBarnett 8 ай бұрын
The next best after security keys is passkeys. I’m assuming it wasn’t brought up in this video because it’s really replacing passwords and still not available everywhere. Yet it also is a 2FA method using your device like phone and face ID. I enjoy watching your episodes even though I know a lot of what is talked about but still learn something new once in a while and is a nice refresher on things.
@StijnHommes
@StijnHommes 8 ай бұрын
No Passkeys is same factor authentication.
@KeithBarnett
@KeithBarnett 8 ай бұрын
@@StijnHommes Its a password replacement
@RCohle452
@RCohle452 8 ай бұрын
My university has mandatory 2fa that oddly does not work on university controlled machines ( library pcs and lectern pcs)
@PeteStakk
@PeteStakk 8 ай бұрын
If you mean it signs you in without needing a 2fa code, it's likely they have a conditional access policy in place that provides the 2nd factor automatically. This could be a location based policy or a way of setting approved devices etc.
@D.von.N
@D.von.N 8 ай бұрын
That phishing at 2:40... how does a fake website know to send you the real company's code? Or how does your real website account know you are logging into a fake website that it sends you the code? I haven't met this one yet.
@askleonotenboom
@askleonotenboom 8 ай бұрын
It's a man-in-the-middle attack. I've got an article/video coming on that.
@PeteStakk
@PeteStakk 8 ай бұрын
Great video, provides a lot of relevant information in a very digestible fashion :)
@Melker63
@Melker63 7 ай бұрын
Question: Let's assume that "man in the middle" on that fake site. Can it be helpful to limit the 30 second window to much less by simply waiting to copy the 6 digit code? Giving the crook less reaction time to use that code on the real site?
@askleonotenboom
@askleonotenboom 7 ай бұрын
I suppose, kinda, but you'd have to do that EVERY TIME you use a 2FA code, just in case you didn't notice it was a man in the middle.
@osamakamel9526
@osamakamel9526 8 ай бұрын
Really thanks we always learn a lot from you sir
@Lili-xq9sn
@Lili-xq9sn 8 ай бұрын
I'm thinking if all the films where they kill you then use your face, finger, iris to open your phone.
@bv226
@bv226 8 ай бұрын
Hah. But if you’re dead, why do you care? 😀
@Lili-xq9sn
@Lili-xq9sn 8 ай бұрын
@@bv226 lol. They'll get all your money, instead of it going to your family.
@roncaruso931
@roncaruso931 8 ай бұрын
Great video. Thanks.
@er...
@er... 8 ай бұрын
Computer=machine
@er...
@er... 8 ай бұрын
You said you muted that time I caught you plagiarizing...
@JimE6243
@JimE6243 8 ай бұрын
👍👍 JimE
@curtw8827
@curtw8827 8 ай бұрын
Wonder how safe all these things are if you have Tic Tok on your phone that you use to login and get your SMS text code
@askleonotenboom
@askleonotenboom 8 ай бұрын
So far there's no evidence there's a problem at all. Just a lot of FUD and posturing. I'd love to see some proof.
@curtw8827
@curtw8827 8 ай бұрын
@@askleonotenboom Another KZbin IT guy demonstrated that after installing Tic Tok on his sample device, Tic Tok directed content to him based on other apps installed on the device. He had installed a vacation planning app and a dating app, upon accessing Tic Tok similar content was directed to him based on particular searches on those apps.
@realwitness5341
@realwitness5341 8 ай бұрын
No different than if you have Facebook, X, Linkedln, etc. on your phone. They all take your info, use it and sell it. Get used to it. Oh, and so does your brand new TV set.
@robertsandy3794
@robertsandy3794 8 ай бұрын
If the online service is breached, can't they find a secret key in the database somewhere?
@askleonotenboom
@askleonotenboom 8 ай бұрын
Nope. Or maybe yes, but that's only half of what's required. Without your matching 2factor key it's not usable.
@lerssilarsson6414
@lerssilarsson6414 8 ай бұрын
A dedicated prepaid SIM card for 2FA - no more SIM swap scams?
@lerssilarsson6414
@lerssilarsson6414 8 ай бұрын
@@Adam497 Something non-invasive?
@Chiara-lh2pg
@Chiara-lh2pg 4 ай бұрын
the question I have is: how to hack my facebook account that was hacked with 2fa?
The Problem With OneDrive Backup
22:50
Ask Leo!
Рет қаралды 219 М.
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 45 МЛН
How to Fight a Gross Man 😡
00:19
Alan Chikin Chow
Рет қаралды 20 МЛН
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 34 МЛН
How Can Passkeys Possibly Be Safe?
21:47
Ask Leo!
Рет қаралды 35 М.
Passkeys And Disaster Planning
14:03
Ask Leo!
Рет қаралды 12 М.
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1,1 МЛН
No, Don't Write Down Passwords
8:56
Ask Leo!
Рет қаралды 15 М.
Behind the Scam: Decoding the Secrets of Fraudulent Emails
13:07
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 892 М.
MFA/2FA Showdown: Which Authentication Factor is Best?
16:27
Pro Tech Show
Рет қаралды 15 М.
13 DOS commands you NEVER knew you NEEDED!
21:57
Ask Your Computer Guy
Рет қаралды 72 М.
Another Way to Protect Yourself from 2FA Loss
7:58
Ask Leo!
Рет қаралды 6 М.
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 45 МЛН