Why most 2FA implementations are nasty and how to setup OTP Auth on iOS

  Рет қаралды 22,204

Sun Knudsen

Sun Knudsen

Күн бұрын

Пікірлер: 83
@timothybracken1728
@timothybracken1728 4 жыл бұрын
just found your channel and i love your videos, as someone interested in privacy related issues - I find your videos easy to understand!! Keep it coming
@smgt412
@smgt412 4 жыл бұрын
If it's best to keep the password manager and authenticator on different devices, how would you then log in to things on your phone if you're out and about and not around your laptop/other device?
@sunknudsen
@sunknudsen 4 жыл бұрын
Great question Eddie. For most use cases, using OTP Auth on iOS is totally fine. The key takeaway of this episode is to not have the 2FA hashes (or private keys) on the computer. Having them on iOS is safer because apps are compartmentalized from the OS (which is not the case on macOS). For people with more sensitive use cases, I recommend using hardware solutions such as YubiKey which stores the hashes on a little piece of hardware which computes the 6-digit tokens and then communicated them to iOS or macOS using USB or NFC. More on YubiKey in a future episode!
@smgt412
@smgt412 4 жыл бұрын
Sun Knudsen Ok good to know, thanks. Looking forward to future episodes!
@polgz2017
@polgz2017 4 жыл бұрын
I thought I was doing all this alright, but... How are you supposed to log-in on websites if you are on your phone?! If you put hard random passwords generated by your password manager (so you can't remember them), but you can't have the password manager on your phone, because that is your "other" device for 2FA... Must I buy a new phone just for 2FA?? or what would be the correct way?
@_marcobaez
@_marcobaez 6 ай бұрын
This is so amazing, just downloaded OTP Auth! :D
@ilustrado7291
@ilustrado7291 4 жыл бұрын
Sun, could you help us setup our new Yubikeys please? Thanks in advance!
@sunknudsen
@sunknudsen 4 жыл бұрын
For sure! Will get there soon. Which protocols are you curious about?
@Erik-qo5pc
@Erik-qo5pc 4 жыл бұрын
@@sunknudsenHi Sun, Awesome series! It seems like you can use these keys as "app"-integrated 2FA or to generate a password like you are showing in this video. Can you give us an overview of the protocols and what is really useful for a private person. What safety aspects are to consider using these? Is it a good thing to use their 2FA password generator? And is this a standard of security that we will see more of in the future? And what about the "unlocking your Mac with the key thing" :) ?
@vincentchen1714
@vincentchen1714 4 жыл бұрын
Do you recommend storing the secret password to OTP Auth on your 1password?
@sunknudsen
@sunknudsen 4 жыл бұрын
Hey Vincent, great question... Short answer: no. Both the password manager and 2FA app should be as compartmentalized as possible.
@janellewoods834
@janellewoods834 3 жыл бұрын
Hi Sun, thanks for this awesome video! I'm a beginner and really appreciate your help. What do you mean by "leave a copy" at home or parent's place? Can you print that backup file? Do you share that file with trusted people? Thanks so much.
@KeineAhnung1996
@KeineAhnung1996 2 жыл бұрын
Hi Sun I really enjoyed your videos about hardware wallets. Those made me understand a lot more about Cryptoc. in general! I want to ask if you could maybe once talk about the technical aspects and your opinion about the Jabber protocol and maybe the off the record messaging option/plug in. IDK you have heard about this :)
@raskolnikov6347
@raskolnikov6347 4 жыл бұрын
How do you feel about Duo Mobile for 2FA?
@sunknudsen
@sunknudsen 4 жыл бұрын
I used to like Authy (similar to Duo I believe) but given the spec of TOTP is open source, may great open source (and more sovereign) alternatives exist.
@korrasmuscles
@korrasmuscles 3 жыл бұрын
9:50 Could you post a tutorial on using this github project just in case we need to recover our accounts?
@trends-spotter
@trends-spotter 4 жыл бұрын
Sun, where were you before lol!! Just recently discovered your channel. Thank you for wealth of useful info and no BS! Could you do an episode about OS system on the phone that would be good for privacy, if there is such thing lol. I appreciate your reply!
@sunknudsen
@sunknudsen 4 жыл бұрын
Have you watched kzbin.info/www/bejne/inKziqFse6hoqpo I might try GrapheneOS in the future... and will likely share an episode on the subject. Stay tuned!
@sunknudsen
@sunknudsen 4 жыл бұрын
Thanks for the push btw!
@vincentchen1714
@vincentchen1714 4 жыл бұрын
So if you got a new phone and wanted to set up OTP Auth on it, you can just use the same QR code or hash that you saved during the initial set up? Or do you just use the secret key to set it up on a new device with all of the OTP codes migrated over?
@sunknudsen
@sunknudsen 4 жыл бұрын
If both phones run iOS, I would backup the phone on my Mac and use that backup to initialize the other phone. Another option is to create a backup using OTP Auth, save it to iPhone, move it to Mac, plug other phone and move backup to other iPhone and restore backup in OTP Auth.
@vincentchen1714
@vincentchen1714 4 жыл бұрын
@@sunknudsen is your process the same as usual the secret key or QR code though? Does the secret key serve as a backup to initialize a new device?
@salvatoretorcivia8840
@salvatoretorcivia8840 3 жыл бұрын
What is the open source project you mentioned for decrypting your backup if need be?
@JonnyD000
@JonnyD000 4 жыл бұрын
Is there any reason you do not choose the open source apps FreeOTP+ or andOTP?
@sunknudsen
@sunknudsen 4 жыл бұрын
I really like OTP Auth on iOS... but haven't tried these alternatives. The feature that got me hooked is the backup feature which can be used to backup the hashes without relying on the cloud.
@salvatoretorcivia8840
@salvatoretorcivia8840 3 жыл бұрын
You say to not use your TOTP app on the same device that you have your password manager, but I recall in your 1Password video you downloaded it to a mobile device, does this mean that you have a separate iPhone for TOTP?
@juanignaciocirera
@juanignaciocirera 2 жыл бұрын
Hi Sun, can you write a link to OTP Auth, it is Roland the developer? You repeat three times in French but still don’t get that name Goulan is Roland Moers right ?
@sunknudsen
@sunknudsen 2 жыл бұрын
Hey Juan, sure. apps.apple.com/us/app/otp-auth/id659877384
@daisytt
@daisytt 4 жыл бұрын
I have dl this on my iphone. But I dont have mac, I have a PC. Does the backup still works on PC? When I dl the backup, I dont see any code but an empty file
@mf4039
@mf4039 4 жыл бұрын
Hi Sun regarding the backups mentioned in the video - I am an amateur with these things! I am not sure I understand exactly what these backups contain? Could you explain what the backups contain?
@sunknudsen
@sunknudsen 4 жыл бұрын
Great question! The time-based one-time password algorithm (which is what most token-based 2FA implementations use, see en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm) uses a hash (a random string) and the current time to derive tokens. The hash is one of the things devices store when scanning 2FA QR codes. Most apps such as Google Authenticator (at least last time I checked) don’t allow users to backup these hashes in a sovereign way (without relying on iCloud, etc...). That’s where OTP Auth shines (it allows backing up an encrypted version of these hashes which can then be stored on a Mac or any other computer).
@mf4039
@mf4039 4 жыл бұрын
@@sunknudsen Hi Sun thank you so much for your answer!
@derrick3532
@derrick3532 3 жыл бұрын
Where do you recommend storing your authenticators pwd? Or is it something you believe must be remembered in your head? Storing your authenticators pwd in your pwd manager that uses your authenticator for login defeats the purpose.
@theoneD1
@theoneD1 4 жыл бұрын
Hey Sun, how do you feel about "contactless payments"? like tapping your smartphone for transport fares, supermarket checkouts etc... will you be making a video on something like that? do you use it yourself and is it safe to use?
@HelvecioGomes
@HelvecioGomes 4 жыл бұрын
Hey, one question. If I use signal as sms/message app, does it make 2FA more secure? Or it doesn't matter?
@glennbailey9746
@glennbailey9746 4 жыл бұрын
Sun, your videos are brilliant! Bit of background for you, i used to love technology but in recent years i have been fighting back by avoiding as much of it as possibly ( im currently on an old LG flip phone) because im paranoid my smart phone(Mainly) along with other devices are listening ot me and i dont feel i can surf the net without everything being recorded what i do. Your vidoes are actually making me feel very relaxed and i feel i can take control of my tech, so thank you very much. I notice your a Apple man. I am a Windows and Android fan. Most of your videos i havebeen able to follow pretty easy. Some i have had more advantages but others you have profited because of using Apple. In regards to using a 2FA on an android phone i cant use otp auth is there anything else that you would reccomend ? ideally something that i can use for my phone and laptop. Keep doing these videos, they are brilliant, professional and extremely clear to understand. This is coming from a complete noob who doesnt even know how to copy and paste via keyboard till last week =p
@sunknudsen
@sunknudsen 4 жыл бұрын
Hey Glenn, thanks for sharing. I totally feel you on being paranoid (I also have a love-hate relationship with my iPhone). Happy to read this content is helpful. About 2FA, unfortunately I know very little about Android. Actually, you could probably use a YubiKey (although backups are an issue). I should publish an episode shortly on the subject. Stay tuned!
@jman6717
@jman6717 4 жыл бұрын
What would you suggest for android Sun? Great content keep it up!
@shell11
@shell11 4 жыл бұрын
I use my keepass database on android and on my computer (synchronized with syncthing), I'd like to use Aegis as 2FA app on android but I'm not sure if it's safer than the current 2FA SMS setup. If I get an android malware, it could steal 2FA when Aegis is unlocked, and passwords when keepass is unlocked. Or it could get both databases to perform offline bruteforce attack. I suppose that SIM swap attack is less probable (for a normal user) than getting an android malware. What do you suggest? If I keep my password manager database on my pc only, should I backup crypted Aegis tokens in a different location than my pc, in order to keep the two databases isolated? Sorry for the long question.
@eternalrain9233
@eternalrain9233 3 жыл бұрын
Is there an android equivalent for otp?
@azizkurtariciniz
@azizkurtariciniz 3 жыл бұрын
Thank you for your great video! Really impressed by the quality, so I subscribed. Quick question. I’m using Windows PC and it is where I mainly use password manager. I also have iPhone and I have to use same accounts on my phone too. So should I manually login those accounts on my iPhone or is it OK to have 2FA app and password manager in the same iPhone?
@jish2008
@jish2008 4 жыл бұрын
Do you know an easy way to migrate from Authy to OTP?
@magmasunburst9331
@magmasunburst9331 2 жыл бұрын
I must have missed it. It's this app only for ios? Also, if it's not what's the name of it?
@sunknudsen
@sunknudsen 2 жыл бұрын
Yes, iOS-only.
@cyril6696
@cyril6696 Жыл бұрын
Hey Sun ! Thanks for your work. I know you video it's from a while ago but could you recomend to me a 2AF app for Android. Thanks a lot.
@ryaniglesias6381
@ryaniglesias6381 3 жыл бұрын
Hey Sun, I just discovered your channel ......... all your videos and all topics are of interest to me. I will start watching all and "liking". Good job on this video. I use Authy now and have it on my desktop and iPhone but after watching this I am not too sure anymore. I am hesitant about using OTP auth as I am afraid it will go off of the apple store ( I am not techie to figure it out if it goes off). Which other authenticator would you recommend? You talked about Google auth but not Microsoft auth ( or maybe you did in another video). Microsoft auth has an iCloud backup available in settings.
@Bayranav
@Bayranav 2 жыл бұрын
Otp Auth vs Raivo otp ??
@timothybracken1728
@timothybracken1728 4 жыл бұрын
You were the only one that made a tutorial on how to use OTP Auth , thank you ! what is the secret part when you try to setup an account? When you try to set it up via credentials instead of QR code, it asks Secret then on the bottom it says plaintext vs base32..what does that mean?
@user-mm2xh3hq1z
@user-mm2xh3hq1z 2 жыл бұрын
I strongly think nowadays there are way too many security steps that having your bag stolen (with your phone and your laptop as mentioned at 20:59) is an INCREDIBLY HIGHER RISK than needing 2FA everywhere. If your 2FA is put on the source of your accounts, AKA your email, then that's already PRETTY GOOD. I always had problems with too much security that stopped me from doing things rather than being hacked. Jee how important are you that you need 2FA everywhere? whatever 2FA auth you choose, make sure it's DEVICE INDIPENDNET. Again as stated at 20:59, if you lose your bag you are DOOMED. that's waaaaaay more likely than having a keylogger installed on your computer that gets alls the passwords you type.
@meposz
@meposz 3 жыл бұрын
Is it possible to have 2 different 2FA apps (one on iOS and one on Android) for the same accounts (e.g. Reddit, Google, etc.)?
@DubMassTV
@DubMassTV 4 жыл бұрын
Wanted to add my +1 to the requests for a Yubikey video I see in other comments. Interested in your opinion of it in regards to opsec.
@mf4039
@mf4039 4 жыл бұрын
Hi Sun thank you for making these wonderful videoes! You are mentioning that you might talk about Yubikey in on of the future episodes - I know it must take a ton of work to produce these videoes - but would you know 1) if you are going to do it? 2) If so would it be in the near future? All the best and again thank you for making these videoes)
@sunknudsen
@sunknudsen 4 жыл бұрын
Thanks for asking! The 2FA episodes are very important yet not popular at all. #1 For sure! #2 Currently working on a Linux/VPN/SOCKS v5 proxy over SSH sub-series. Perhaps after that. So many interesting topics to cover! 🤓
@mf4039
@mf4039 4 жыл бұрын
@@sunknudsen Thank you for the answer I am looking forward to that!
@mf4039
@mf4039 4 жыл бұрын
Can Yubikey be thought of as an alternative to OTP Auth - do I understand that correct?
@sunknudsen
@sunknudsen 4 жыл бұрын
Yes! The YubiKey stores the hashes and computes the tokens so it adds some level of compartmentalization.
@mf4039
@mf4039 4 жыл бұрын
@@sunknudsen Thank you for the answer truly appreciated!
@gavinblackford4219
@gavinblackford4219 4 жыл бұрын
Hi just found your channel, love your videos, with 2FA what are your thoughts on U2F like Yubikey
@rs07scapeNews
@rs07scapeNews 4 жыл бұрын
I only use offline 2FA with an encrypted USB with my .json file that I can import into my authenticator app on my linux machine and I always remove the 2FA info from my computer after logged into any accounts
@sunknudsen
@sunknudsen 4 жыл бұрын
Hey Chris, looks like your setup is pretty secure. My personal setup is similar. I use Tails to scan the QR codes (using compartmentalization to mitigate backdoor vulnerabilities). Tokens are then stored on a YubiKey making sure the hashes are never accessed directly by macOS. I am considering putting together an episode on that setup in the future. The key takeaway here is that using two separate devices is the way to go!
@jjiacobucci
@jjiacobucci 3 жыл бұрын
Thank you, Sun !
@froekenur
@froekenur 4 жыл бұрын
Hey Sun do you use a demo password :) I can see what your typing on the iphone keyboard :) Anyway, great video, i like your style you are clear and educational. Keep up the good work, your work makes a big difference!
@sunknudsen
@sunknudsen 4 жыл бұрын
Thanks for the heads-up and the push. Yes, demo hardware and software. Can’t bee too safe!
@theoneD1
@theoneD1 4 жыл бұрын
@@sunknudsen what if you turned on the lights and make the room brighter, would that avoid reflections off shiny surfaces? without compromising your home computer setup environment
@THETRUTHOR
@THETRUTHOR 4 жыл бұрын
Hey Sun, Thor here on my actual channel I started for all things Sui Juris, Sovereign. Lookng forward to sharing your channel with my audience.
@sunknudsen
@sunknudsen 4 жыл бұрын
Thanks for sharing the privacy guides!
@adamdittrichone
@adamdittrichone 3 жыл бұрын
This channel is gold! Thank you so much and keep going. Just watched 70% of the videos and implemented most of it. What do you think about Enpass with one-time-code as an 2FA App? I use this app as an password manager and 2FA Auth
@sunknudsen
@sunknudsen 3 жыл бұрын
Thanks for the push and that's a lot of privacy guides in a row! I recommend not using the same app (and device) for both password manager and 2FA. The best shot we have at privacy / security is compartmentalization.
@adamdittrichone
@adamdittrichone 3 жыл бұрын
@@sunknudsen Feeling super secure right now, thanks to you :D Have a wonderful day
@DNH17
@DNH17 Жыл бұрын
OTP locked me out of Amazon services due to a unbinding of the third party OTP generating app, and now Amazon requires me personal ID or documents, this is unacceptable. Security leaving you out of the system is so badly designed in this case that works against clients. Biometrics and so on is no way acceptable. Personal data should not be shared nor can be required but from the Public Authority. THey can't substitute or play as the State. This is negative design. OTP is useless if one has very difficult passwords and also a secured e-mail account... It's incredible Amazon doesn't have an internal OTP generation app! Doesn't allow recovery method, doesn't allow e-mail OTP sending (alternative), doesn't allow Double PASS as an option too... or even an option with an additional PIN, so PW + Pin. This is such a negative status. No way I am gonna send my ID!
@macster1457
@macster1457 3 жыл бұрын
Microsoft Auth is great as well. It also provides the option for backups unlike Google Auth.
@Bayranav
@Bayranav 3 жыл бұрын
OTP Auth is the best app ?
@sunknudsen
@sunknudsen 3 жыл бұрын
It is still my pick in the realm of standalone TOTP apps.
@Bayranav
@Bayranav 3 жыл бұрын
@@sunknudsen great, thanks for your research
@tairikuokami
@tairikuokami 4 жыл бұрын
Lets not forget, if your phone gets locked, destroyed or lost, you will also loose access to all of your 2FA accounts as well. Enjoy your nervous breakdown afterwards.
@thomasipad7719
@thomasipad7719 3 жыл бұрын
Apple has the worst 2FA, it seems. As far as I know, you need to add either an email adress or and telephone number. And not only those are bad ideas, but with that method they also allow to reset the password!!!! This is something that never ever should be able, IMHO.
You Should Be Using Yubikeys!
34:34
Crosstalk Solutions
Рет қаралды 823 М.
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН
Do this and you should be safe online
17:25
Sun Knudsen
Рет қаралды 46 М.
Why 1Password is the best proprietary password manager
27:20
Sun Knudsen
Рет қаралды 85 М.
How to configure iOS for privacy
23:39
Sun Knudsen
Рет қаралды 87 М.
How to use Two-Factor Authentication (2FA) with Authy
17:12
AdamOnTech
Рет қаралды 35 М.
Why VPNs are a WASTE of Your Money (usually…)
14:40
Cyberspatial
Рет қаралды 1,5 МЛН
Apple's NEW Passwords app (+ why I’m NOT using it)
6:30
All Things Secured
Рет қаралды 233 М.
Why Signal is more private and secure than iMessage and SMS
15:56
What is a Passkey?
18:05
Ask Leo!
Рет қаралды 142 М.
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1,1 МЛН
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН