Most PRIVATE 2FA apps

  Рет қаралды 118,887

Naomi Brockwell TV

Naomi Brockwell TV

Күн бұрын

Пікірлер: 333
@antoniocolombo9414
@antoniocolombo9414 Жыл бұрын
Just switched from authy to aegis. Thanks!
@OH2023-cj9if
@OH2023-cj9if Жыл бұрын
I did and it took 2 days on and off to change every account over.
@antoniocolombo9414
@antoniocolombo9414 Жыл бұрын
@@OH2023-cj9if how many account do you have? For me took 5 minutes
@OcteractSG
@OcteractSG Жыл бұрын
Such a necessary video for people to watch in this digital age. Thank you!
@BriefNerdOriginal
@BriefNerdOriginal Жыл бұрын
Aegis had been my go-to choice. Glad it's among the best.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Glad you're liking the app!
@leehayes4019
@leehayes4019 Жыл бұрын
As always, thanks for keeping me more informed!
@booradlly
@booradlly 2 ай бұрын
Really starting to love your channel I am an avid Authy user Most videos that trash authy are just plain wrong Your video is the first that not only was not wrong, but actually made me rethink some things. That means he not only were very accurate in your research but you also presented it very well. Props Most videos are so bad they suggest sms is better than authy
@coisasnatv
@coisasnatv Жыл бұрын
The best thing to do is to stop using your phone for this, if your phone get compromised it really doesn't matter how secure is the app you use.
@mukkaar
@mukkaar Жыл бұрын
Well, if you are paranoid or a business, yes. But using TOTP app is much more secure than not having 2fa at all. Hardware key is good if you are worried about tageted attacks.
@coisasnatv
@coisasnatv Жыл бұрын
@@mukkaar Hardware keys are useless when compromised. I use software TOTP with KeepassXC.
@davemosher480
@davemosher480 Жыл бұрын
Thank you for your constant focus on privacy. From a security perspective, I was disappointed that you even brought up a non-supported code base as an option for users. This video is not geared towards developers - but end-users who may or may not be slightly more than technically literate. Even serious developers often overlook security blemishes - and by advocating for a non-maintained code base you are opening them up to bad things down the road. Yes, I know you had a comment at the end about use at your own risk - but without the appropriate security background someone might not correctly understand what you are implying. Again though - thank you for your constant videos, and I watch regularly.
@adegbenroagoro5180
@adegbenroagoro5180 Жыл бұрын
Thank you very much Naomi.
@rodr5243
@rodr5243 8 ай бұрын
😊
@icedwater
@icedwater Жыл бұрын
Re: Authy, I don't think it's enough but they've at least updated their Privacy Notice with effect Aug 10: "We clarified that we do not sell your personal information to, or share your information with, third parties for cross-context behavior advertising." Also I had trouble figuring out FreeOTP, or getting it to generate a token I could do 2FA with
@revealed101
@revealed101 11 ай бұрын
Very few people give thoughts on privacy, if you are one, this video will make more sense
@jesse7631
@jesse7631 Жыл бұрын
Another fantastic and informative video, Naomi. Thank you!
@aa-dz6cr
@aa-dz6cr Жыл бұрын
The sad thing is we're using Google's (Alphabet) to learn about privacy. I remember when most things could be forgotten. Not anymore. Thank you Naomi!!
@eldrago19
@eldrago19 Жыл бұрын
In terms of Google Authenticator, it probably isn't surprising. Security is a tide that floats all boats and Google benefits from more secure Google accounts giving them an incentive not to mess it up. Microsoft is different because most people use MS Auth because they are forced to by work.
@metinhesenov
@metinhesenov Жыл бұрын
Not really. I use MS authenticator over Google because it feels more secure. Google Authenticator doesn't even have a native option for biometric to lock the app
@Elemblue2
@Elemblue2 Жыл бұрын
On graphine OS, on a google pixel, you can just put the stupid MS Auth in a sandbox phone, use it for 20 seconds, then turn off the sandbox. A sandbox turning off is like a phone being destroyed. So that is NOT running in the background.
@dudicoco
@dudicoco Жыл бұрын
On a normal android you could also restrict the app's data usage permissions so that it doesn't have network access. However in both this case and in grapheneos, as soon as you give it the "20 seconds access" it will send data about yourself. The problem with ms authenticator is that in addition to totp codes it also has a 2fa feature that requires network access, which makes it terrible.
@thegorn
@thegorn Жыл бұрын
Naomi is the woman of my dreams. Good vid.
@peter_s
@peter_s Жыл бұрын
Thank you very much for helping me out to find a good and private solution for all my 2FA Codes. I started following your videos 2 weeks ago and you really inspired me to care more about my personal privacy rights. e.g. to change my 2FA App and to change my Cloud Space and to check what is really going on, on my Phone, Desktop and other Devices.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
This is great to hear!
@SuperMark16-24
@SuperMark16-24 Жыл бұрын
An immense thank you for all the work you're doing❤Keep going!!
@mohamad20zx34
@mohamad20zx34 Жыл бұрын
great job with your video miss Naomi hope you stay amazing
@richardharker2775
@richardharker2775 Жыл бұрын
Oh! my goodness. So much info to absorb for an older gentleman but wait.. that little finishing skit made ma laugh out loud. Thanks Naomi Brockwell.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Thanks for staying til the end
@sageowl5032
@sageowl5032 Жыл бұрын
In the case of Authy 3:15 the generic info collected is necessary for the app to function. This info enables Authy to be used on multiple devices, this being one of the great back up features of Authy. If you drop your phone in the toilet you can still Authy on your tablet or desktop.
@Entertainment-is6ex
@Entertainment-is6ex 9 ай бұрын
Yep that's a great benefit of Authy. Until then, Apple iphone+watch was the easiest way to have a 'backup' OTG generator if you drop your phone in the toilet.
@haydnhorne2505
@haydnhorne2505 Жыл бұрын
love the vibrant colour suits you well
@timfd.w.4163
@timfd.w.4163 Жыл бұрын
Gave up on those famous... Adopted 2FAS open source with local backup and optional DRIVE cloud synch
@stryfespoint304
@stryfespoint304 Жыл бұрын
Thank you kindly for this awesome 411 😊
@sergey_a
@sergey_a 10 күн бұрын
For Google, there is no need to use trackers in the android application, the entire android system is one big tracker for them.
@jamescarroll6954
@jamescarroll6954 9 ай бұрын
I just spent an entire morning trying to access one of TWO licensed copies of Microsoft Word. In the painful and Byzantine path that Microsoft and Google set me on. It included a license fee for Microsoft Authenticator, and concluded with Microsoft's admonition to "try again tomorrow." I would wager that the average teenaged "hacker" could have donned its obligatory hoodie and broken the process in a couple of minutes. I, in contrast, probably stand a greater chance of breaking into one of Bill's Bunkers than of using Word anytime this month.
@Annibals
@Annibals 4 ай бұрын
You're doing great work! I've longed for a channel like this
@mhaustria
@mhaustria Жыл бұрын
That’s a great overview! I would have loved to see the iOS build in 2fa password keychain in your list.
@natemarx4999
@natemarx4999 Жыл бұрын
The Queen needs to give us a live.
@aussiegruber86
@aussiegruber86 Жыл бұрын
I love your content, but I am loosing faith in the digital realm, the amount of hacks and privacy leaks recently is making me concerned. In Australia alone 4 major companies I have information with have have all been hacked and my personal data stolen...
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Don' t lose faith. Presume that every company you give information to will eventually get hacked, and decide what information you want to give companies accordingly
@nilpo
@nilpo Жыл бұрын
First, LTT made mistakes. Second, LTT isn’t exactly a beacon of technological intelligence.
@user-ec6ej4dp6t
@user-ec6ej4dp6t 9 ай бұрын
@@NaomiBrockwellTV lol... You don't have a choice 99% of the time.
@alternatuber6698
@alternatuber6698 6 ай бұрын
2FAS is sensible with open source + offline and google drive encrypted with hidden folder backup. Nowadays I use alongside it that ente auth as well.
@TheJj1yang
@TheJj1yang Жыл бұрын
How about new Proton Pass in app 2FA stacks up with other open source 2FA?
@zshadows
@zshadows 9 ай бұрын
I was considering using ProtonPass (and Bitwarden) for 2FA, but it becomes an "eggs in one basket" situation. If someone compromises your Proton account, they get access to everything: Your passwords and even your 2FA protections. Proton themselves even note: You should never use Proton Pass to secure your Proton Account using TOTP. Use a third-party authenticator app instead. For this reason, I'm looking into some third-party so one breech doesn't spill everything.
@ligerllama
@ligerllama Жыл бұрын
Happy St. Patrick's Day, Naomi! ☘️
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Happy St Pat's Day!
@JPEaglesandKatz
@JPEaglesandKatz Жыл бұрын
Thanks.. Very enlightening video... I was suprised about some of the apps like authy..... Time to ditch that one..
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
Thanks for watching
@brucey39
@brucey39 Жыл бұрын
Thanks for your good work Naomi .
@nully.emptier
@nully.emptier Жыл бұрын
excellent content... appreciate the efforts
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
🙏
@mrbit10
@mrbit10 Жыл бұрын
Its amazing how tech just keeps recycling old tech and calling it new, its like lessons never learned, I have lived long enough to be in the days of dongles, (security keys), pain in the butt but they did the job
@estiennetaylor1260
@estiennetaylor1260 Жыл бұрын
Microsoft authenticator works like a charm.
@John7No
@John7No Жыл бұрын
did they had any comment regarding Apple's 2FA that is embedded in their keychain?
@MichaelThwaite
@MichaelThwaite Жыл бұрын
I'd like to know too, I don't think it's well known that Apple macOS and iOS takes care of this in the OS.
@izzyg8316
@izzyg8316 18 күн бұрын
How do Ente Auth and Duo Mobile compare to Aegis and 2FAS?
@tigreonice2339
@tigreonice2339 Жыл бұрын
I was waiting for this video 🎉❤
@MarceldeJong
@MarceldeJong Жыл бұрын
I can understand why Authy stores that data with a useraccount. If you switch to another device (Like you bought a new phone) you don’t have to set up all the 2FA settings again. Just use the same phone number or email address, enter the password you set up and voila, your 2FAs are back. But it’s not like Authy can do anything with that data, right?
@nilpo
@nilpo Жыл бұрын
First, that feature should be opt-in. Second, anyone with the token becomes you. So, yes. If they aren’t using end-to-end encryption to hide your data from themselves, they absolutely can do anything they want with your data.
@fjb9234
@fjb9234 8 ай бұрын
So then when their systems get hacked you’re screwed. Man this is why we have no privacy, cause folks blindly accept what these companies ask of them and pretend it’s in their best interest. Perhaps the education system needs to pivot away from critical race theory and focus on helping y’all learn some critical thinking skills.
@MorningNapalm
@MorningNapalm Жыл бұрын
I have stopped using 2FA on my accounts after nearly losing a couple of important old accounts which had reset on me at the same time I changed to a new phone. The whole back- and forwards compatibility, security process and recovery is poorly thought out.
@timbell4961
@timbell4961 5 ай бұрын
Thank you for your Insight the authenticator issue has been a nightmare for me😢
@SnowyRVulpix
@SnowyRVulpix Жыл бұрын
How do you synchronise across multiple devices without providing your servers with information?
@ronm6585
@ronm6585 Жыл бұрын
Thanks Naomi.
@Mr.Marcus-zn1wh
@Mr.Marcus-zn1wh 5 ай бұрын
Thank your for your hard work. Please tell me your thoughts about CA AUTHENTICATOR and the possible ability for a company using this app to track employees.
@TomTheAustrian
@TomTheAustrian Жыл бұрын
What about YubiCos Authenticator?
@HousewerkRecords
@HousewerkRecords 11 ай бұрын
Hey there, Free OTP doesn’t work with a well known VPN provider. So it may work with other apps but not all.
@Dimonina
@Dimonina Жыл бұрын
What about bitwarden?
@epiksar
@epiksar Жыл бұрын
@VampyToast I agree. Otherwise, that kind of defeats the purpose of two-factor authentication. The idea is that both factors need to fail before someone can access your accounts. If both factors are tied to each other, then realistically, only one needs to fail.
@GrandslamTim1
@GrandslamTim1 Жыл бұрын
Thanks Naomi - so thorough as always
@rjk1404
@rjk1404 4 ай бұрын
Downsides of FreeOTP are, that you can't export the secure codes and that it's not locked by code or biometrics. 2FAS is my way to go...
@richardhendricks8563
@richardhendricks8563 Жыл бұрын
microsoft 2fa is for me. dont mind the analytics. iam using the app for free anyway. they also have a good backup
@QueenCallisto
@QueenCallisto Жыл бұрын
We can't have nice things. Oh, Authy, I had high hope for you.
@michaelprzewrocki4195
@michaelprzewrocki4195 Жыл бұрын
so when smartphone A is dead or stolen i must resetting up the login synch and can use the key which had been displayed beside the qr-code right? will just test. no need to restart synching from scratch?
@pyrusslayer8643
@pyrusslayer8643 Жыл бұрын
Cant wait for Proton Pass to come out it has 2FA too since i cant trust the other apps that much but still i have to be careful of proton too u never know
@DAVIDGREGORYKERR
@DAVIDGREGORYKERR 10 ай бұрын
What about an authenticator based on DES128 which is an extended version of DES64
@JohnSmith-zl8rz
@JohnSmith-zl8rz Жыл бұрын
Raivo on Mac/iOS is open source.
@illwittd
@illwittd 24 күн бұрын
What are some secure authenticator apps ppl can use in 2024? I’m trying to switch off of Authy, and articles about this topic always recommend Google or Microsoft authenticator 🙄
@stevefrey2990
@stevefrey2990 3 ай бұрын
How does Symantec VIP fit in? Is it collecting data?
@cipher893
@cipher893 4 ай бұрын
I’d go with Proton Pass over of the above.
@nobara3526
@nobara3526 8 ай бұрын
Had been using authy for its sync feature across mobile and desktop... but they are stopping the development on desktop so I guess I will switch to Aegis now
@markdove5930
@markdove5930 9 ай бұрын
After doing the 2fa amazon is still asking me for my id card and an recent bill. I gave them my id but i dont have any bills to my name. What shoud i do?
@keithdavis262
@keithdavis262 Жыл бұрын
Not exactly on point, but I've heard that once you save something on Google Drive it is there forever. Even though you may delete the files from your Google Drive, Google stores all of that information. If that is correct, is there anyway to remove all of those old files you have since deleted and moved to a more secure location?
@OH2023-cj9if
@OH2023-cj9if Жыл бұрын
Everything stored in a cloud service is scanned by using law enforcement hash tables to see if it is a known file like a picture or video. Emails are scanned too. Many people are caught each year. Nothing is ever deleted.
@zshadows
@zshadows 9 ай бұрын
Can't answer the root question, but if your cloud backup is encrypted before uploading, it's just random noise to Google.
@obiwankenobe3962
@obiwankenobe3962 4 ай бұрын
I have a question: how are these security analysts able to find out what data is being sent? I would assume it's all done over an encrypted connection, so sniffing traffic is not the answer. They're running some sort of strace-equivalent on Android/OSX, and look at what write()/send() syscalls write to the socket?
@creytax9802
@creytax9802 Жыл бұрын
I like this Channel.
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
This channel likes you too 💛
@KenDillman0612
@KenDillman0612 2 ай бұрын
I guess it's just me, but I find QR codes pretty useless on a mobile device. You have to have 2 devices to use them: one to display the QR code and another to scan it. I just copy the manual code, then open the 2FA app and paste it. Plus I can keep a separate encrypted file of the keys for recovery if the app gets deleted or corrupted or I get a new phone.
@PsychwardCaptive
@PsychwardCaptive 10 ай бұрын
So what should I use for ios then?
@alike5375
@alike5375 10 ай бұрын
great info thanks
@T0X1C89
@T0X1C89 Жыл бұрын
What are your thoughts on using the 2fa functions built into 1password coupled with a security key?
@BeatBoxBrian
@BeatBoxBrian Жыл бұрын
Not open-source, but 1password is probably the best closed-source option out there as far as I’ve heard. Techlore and The New Oil talk about them. Bitwarden is probably better if doing a direct comparison.
@mwolfod
@mwolfod Жыл бұрын
Kosher Cat Authenticator, if it existed, would DEFINITELY be at the bottom of the list of choices. For obvious reasons....
@Iuffycs
@Iuffycs Жыл бұрын
aegis is the best authenticator
@zine_eddinex24
@zine_eddinex24 9 ай бұрын
Good keep up ❤
@0xAl
@0xAl Жыл бұрын
What about Apple’s 2FA?
@ALLINGaming0
@ALLINGaming0 Жыл бұрын
It's not true 2FA if you're running an authenticator app on the device you're using to log in. It is better to use a separate device for the authenticator app and keep it offline.
@rainerrain9689
@rainerrain9689 10 ай бұрын
Like what ,yubi?
@ALLINGaming0
@ALLINGaming0 10 ай бұрын
​@@rainerrain9689 My point is that if you use an Authenticator app you should not install it on a device like your personal smartphone because it is always connected to the internet therefore more likely to get compromised. It is much more secure to install the app on a separate device and keep that device offline since no further connection is required to use the authenticator app. You can use an old smartphone for the authenticator app.
@gitshell
@gitshell Жыл бұрын
I like KeepassDX, aside from passwordmanager, it also supports TOTP
@IndependentNewsMedia
@IndependentNewsMedia 3 ай бұрын
Good overview video, God bless.
@zeeman9145
@zeeman9145 4 ай бұрын
how can we import items from Microsoft authenticator to aegis?
@coast-guard-1cargo-spectio552
@coast-guard-1cargo-spectio552 Жыл бұрын
Thanks Asuka :D
@lynetteford6063
@lynetteford6063 Жыл бұрын
Does this have anything to do with mail merge.
@Saint.questions
@Saint.questions Жыл бұрын
This is great! Thanks!
@ateriana5116
@ateriana5116 Жыл бұрын
Are there also privacy-respecting 2FA apps for PC?
@sevenelven
@sevenelven Жыл бұрын
Yubikey as an authenticator app for PC
@tonys6464
@tonys6464 Жыл бұрын
I use Yubikey over OTP apps everywhere I can but not nearly enough sites are configured for that to include most banks.
@waytospergtherebro
@waytospergtherebro Жыл бұрын
You can write your own in about seven lines of Ruby/Python.
@arifulislamleeton
@arifulislamleeton Жыл бұрын
Hi I'm Ariful Islam leeton I'm software engineer and software development and website development
@casaraku1
@casaraku1 Жыл бұрын
Just because Google does not currently do stuff does not mean they will change their mind... unless they have already all that they need...
@JohnSmith-zl8rz
@JohnSmith-zl8rz Жыл бұрын
Why you don't mention OTPs on Yubikeys? is the most secure due are not tied to internet?
@NaomiBrockwellTV
@NaomiBrockwellTV Жыл бұрын
because you have to send the code over the internet to confirm the website's server has the matching code, which can be intercepted. OTP isn't the most secure, a security key with public key cryptography is the most secure. we have a couple of videos on that: kzbin.info/www/bejne/i5mkf6Z3qdt_hJI kzbin.info/www/bejne/nn20oaypZpmqjZI
@JohnSmith-zl8rz
@JohnSmith-zl8rz Жыл бұрын
@@NaomiBrockwellTV thank you
@reefhound9902
@reefhound9902 2 ай бұрын
We need a way to easily quarantine an app and block all network traffic to it. Especially for apps that are able to run offline and have no functional need to have connectivity.
@MichaelThwaite
@MichaelThwaite Жыл бұрын
Don't download an app at all, just use the embedded solution in macOS/iOS no?
@barryshafer
@barryshafer Жыл бұрын
Any information on Duo Mobile?
@cgbb353
@cgbb353 Жыл бұрын
What about the one built in Dashlane?
@airchina0012
@airchina0012 Жыл бұрын
What about self-hosted passbolt?
@DrZhenya
@DrZhenya Жыл бұрын
What about Yubico's auth. ?
@IdkG7
@IdkG7 Жыл бұрын
Fax
@IdkG7
@IdkG7 Жыл бұрын
Yubico Auth is superior since it’s stored of the key itself, keep using that
@DrZhenya
@DrZhenya Жыл бұрын
@@IdkG7 I’m also interested in the data collecting(they claim they don’t, but you know..)
@Yoshua-Robinson
@Yoshua-Robinson Жыл бұрын
Well Authy actually earns their money from the companies using it.
@BT-gu5yn
@BT-gu5yn 8 ай бұрын
God I LOVE ❤ this woman!
@50_Pence
@50_Pence Жыл бұрын
Really nice vid.
@alexpetrov9911
@alexpetrov9911 Жыл бұрын
keepkey is essential... 2fa using sms, or google is risky & less secure in times.
@mangalegends
@mangalegends Жыл бұрын
I guess the only way to make sure that the open source code is what's on your phone is to build it from source yourself
@nilpo
@nilpo Жыл бұрын
That’s the idea behind open source.
@mossychops
@mossychops Жыл бұрын
Are you on Linkin?
@smokyviking2103
@smokyviking2103 23 күн бұрын
2FAS is the app in the world 🌎
@SimonePGGG
@SimonePGGG Жыл бұрын
Bitwarden?
@labret8937
@labret8937 Жыл бұрын
Maybe new services need to apply for IANA ports so people can block them without hesitation. Need to be FDA approved :)
@username65585
@username65585 Жыл бұрын
The analytics should be removed but Authy does need to have phone number as a second factor to support the backup and multi device functionality. I think the risk of losing access to all my accounts because the device with my 2FA app breaks is greater than the risk from Authy knowing my phone number.
@goodmew1763
@goodmew1763 Жыл бұрын
No they don't need your phone number to support backup. They can allow you to back up yourself by exporting your keys. This can also enable multi-device by exporting/importing your keys, or creating a link between two devices by scanning a unique code stored locally on your devices.
@OH2023-cj9if
@OH2023-cj9if Жыл бұрын
When you set up 2FA on accounts, they give you recovery codes. Store them in your password manager. If you lose access to 2FA, you can still get in.
@MikeHunt-fr7co
@MikeHunt-fr7co Жыл бұрын
@@goodmew1763 I actually asked Authy support to tell me the location of the local backup so I could back them up myself off device, they pretended to not understand the question and gave me the run around. Its amazing how lame these 'solutions' are.
@goodmew1763
@goodmew1763 Жыл бұрын
@@MikeHunt-fr7co Yeah >: I think Authy does 'require' that you use your phone number to create a cloud backup with them (im not sure), but no company 'needs' any info from you to allow you to make backups. So Authy may prevent users from creating private local backups to encourage you to share your phone number.
@alaunaenpunto3690
@alaunaenpunto3690 Жыл бұрын
What about gnome authenticator?
All About Google Reviews: Get More Reviews + Free Template
4:13
Maria - Payfud
Рет қаралды 101
Most PRIVATE Password Manager
22:23
Naomi Brockwell TV
Рет қаралды 286 М.
FOREVER BUNNY
00:14
Natan por Aí
Рет қаралды 14 МЛН
Forget Google Authenticator. THIS Secure Method is Even BETTER
5:19
All Things Secured
Рет қаралды 86 М.
October 2024 - Software Supply Chain Security Review
3:04
Checkmarx Zero
Рет қаралды 10
AI Can’t Replace SDETs - Here’s Why!
6:59
DevHacks 360
Рет қаралды 27
Best Authenticator Apps of 2024
17:43
SaaS Inspection
Рет қаралды 565
Most PRIVATE Cloud Storage
30:50
Naomi Brockwell TV
Рет қаралды 238 М.
I Switched Password Managers (finally)
10:13
All Things Secured
Рет қаралды 63 М.
5 AI Trends in Digital Marketing That Will BLOW Your Mind
7:33
Insights from V
Рет қаралды 278