Thanks for tuning in to Go Incognito! 🕵️♂️ 1) Go Incognito Premium has no ads, includes quizzes & guides, hundreds of improvements, a certificate, and much more! Support our mission & join the premium experience: techlore.teachable.com/p/go-incognito 2) To access the sources, changelog, GitHub repo, and more, visit Go Incognito's Homepage: techlore.tech/goincognito.html 3) To order Go Incognito merchandise, visit our Privacy Shop: teespring.com/stores/techlore-merch 4) Go Incognito is offered for free thanks to all of our supporters. Support Techlore and our mission today: techlore.tech/support.html
@techlore5 жыл бұрын
Ideally nothing? Brave is meant to be out of the box ready to go. If you want something that’s hardened, go to Firefox.
@qnyzrev65395 жыл бұрын
I have two questions. The Prism-break site says that you should not use Authy with a two-step app, why is that? prism-break.org/en/categories/android/Firefox add-on says that Ghostery should not be put, why is it? prism-break.org/en/subcategories/android-web-browser-addons/
@misterwinner84594 жыл бұрын
Want Your Views on Aegis Authenticator If Possible compare Aegis Vs AndOTP
@Shayden525 жыл бұрын
Hands down one the most informative security video series on the internet, that is also easy to understand. Love the changing backgrounds to indicate how hardcore the methods are! Keep it up, your content is unique!! ;D
@redeyesdrogon7865 жыл бұрын
2FA is very important. I learned a lot from this! Awesome video man! Love the videos
@techlore5 жыл бұрын
Thanks man!!
@Mic-Mak5 жыл бұрын
My biggest issue with 2FA apps is that a lot of online services require that you give them your phone nombre to enable 2FA with an authenticator app. I’m not comfortable with that.
@techlore5 жыл бұрын
What sites do this? I haven’t really experienced this issue.
@jamesedwards39233 жыл бұрын
@@techlore Yahoo.com
@fayojixe99252 жыл бұрын
Twitch
@darwinsexplosions5 жыл бұрын
Great video! I’ve been subscribed for a couple weeks now and I am really happy with the content!
@BLUU-qh2jf5 жыл бұрын
5:07 - Is Authy really FOSS?
@techlore5 жыл бұрын
Not fully no. Check the changelog later tonight.
@goosty175 жыл бұрын
I literally love your channel. Such amazing content. Keep it up!
@piratebuddy46492 жыл бұрын
Can't find your telegram community link anywhere.
@techlore2 жыл бұрын
We don't recommend Telegram. We have a forum (recommended) and Discord. Let me know if you'd like those links!
@piratebuddy46492 жыл бұрын
@@techlore Got forum in your site, thank you for the community man.
@BunPentruTine3 жыл бұрын
Hello. What is your opinion about app based 2FA like Google Authenticator vs Prompt style 2FA. Wondering if any of them is different enough in security level or they're pretty much the same. Thank you.
@logwind4 жыл бұрын
how does the website know the code displayed in the auth app is correct? how is that synchronized?
@cesaraugustoseijasnino16244 жыл бұрын
You need also to talk about, what happen if your loss your phisical 2FA, Recovery codes?, where you store that codes?, in a password manager, encrypted in a cloud drive?, paper?.
@hamzehqatash62562 жыл бұрын
Thanks a lot 🌹
@techlore2 жыл бұрын
You're welcome 😊 Thanks for all your nice comments!
@Psil03 жыл бұрын
Any tip on how to store backup codes for Authenthicator Apps? I'm worried about paper backup codes in case of a fire or something like that.
@esquilax55632 жыл бұрын
Store them in an encrypted file, and backup the file. 2 good options are your password manager's database, or a Veracrypt file container
@INdoFreakNesian3 жыл бұрын
Any recommendations for a MacOS 2FA app? Like Ravio for mac?
@trexcal39694 жыл бұрын
Your information is appreciated and valuable but I need to (see you using & setting up the app) - andOTP . I have no clue and completely no understanding of how this is supposed to work. I learn and understand better visually as opposed to reading or hearing. AND how will I be affected if lose cell ph after andOTP is set up ? PLEASE make video.
@jamesedwards39232 жыл бұрын
I agree sir. Plus you can encrypt the file. Via open-pgp or AES.
@RCdiy4 жыл бұрын
What happens if we lose our phone or the software gets deleted? Or we don’t have our phone with us? Say I went to another country I forgot to take my phone with me?
@stiventson44644 жыл бұрын
True, that's why I haven't use it yet, I would like another alternative
@mulletman17052 жыл бұрын
It matters which 2fa app you choose. Authy is not a good choice, it's closed source, it requires a phone number, there is no way to export 2fa codes for backup to usb memory stick, etc so if authy stops working over day you loose access to all your accounts.
@WanderingAroundAZ3 жыл бұрын
The only problem with code generator apps is that if you have to reset your phone or you get a new phone, you have to jump through a bunch of hoops to get the 2FA setup on the new/reset phone.
@techlore3 жыл бұрын
Not really. Apps like Aegis & AndOTP have export/import functions which transfer all 2FA codes in a few minutes tops. You should actually export/backup your keys so you don’t lose them with your phone.
@fartsloudly40342 жыл бұрын
Authy took like two minutes for me when I was changing my phones.
@tryptex5 жыл бұрын
I knew this was coming because I saw the thumbnail at the end of your last video :)
@2FAS4 жыл бұрын
Thanks for the video!
@joepjoep9531 Жыл бұрын
Regularly changing passwords isn’t even advised by NIST. It can easily make it even less secure than to set a very good one for multiple reasons
@RobertoGuillermoMartin4 жыл бұрын
Which 2FA is better? Code via email or an app (Google authenticator, etc)
@techlore4 жыл бұрын
App
@bluesailormercury5 жыл бұрын
Handsomest KZbinr ever!
@joewger5 жыл бұрын
Excellent video! I had SMS and thought it was the same as an app like authy etc. . I just got messages to my phone and typed in the two code numbers and got access to my account. No QR code since I was on my laptop typing the numbers in to the sms box.
@thomasipad77193 жыл бұрын
OTP Auth, not FreeOTP
@unclealig3 жыл бұрын
nice vid. but still dont get, how these FOSS 2FA work in principle. when for example using google 2FA and i want to login into google, then google sends me a sms code, which they can confirm once i login with this data. how can a "3rd party" app like the FOSS ones give me a 2FA code, which google recognizes, if the code does not come from their app/side? thx
@vansolo97945 жыл бұрын
Nice work H
@robindabank67112 ай бұрын
Thanks
@jam68755 жыл бұрын
Best place to store backup codes?
@techlore5 жыл бұрын
No “right” answer. But I personally store them in a text document on a Veracrypt encrypted container.
@tonycornetta5 жыл бұрын
Techlore Can you show us step by step on how you do this?
@techlore5 жыл бұрын
Here's my guide on creating a container: kzbin.info/www/bejne/eWOYh4p3fNFqitk Just move a text document into a container and you're good.
@ISOLATEDViRuS5 жыл бұрын
yubikey also offers a 2FA app: Yubico Authenticator. This requires the yubikey to have the 2FA accounts loaded onto the usb key, and a password to unlock the key to access the keys.
@dubesor5 жыл бұрын
always make sure you have at least 2 devices/2 ways as second factor.. so many dumb people eg have 1 single iphone and then lose it and lock themselves out of their account for a month.
@IgnoreMyChan5 жыл бұрын
'Dumb people' of less technically skilled people? How could they know? At least now they know.
@techlore5 жыл бұрын
Yes, although that’s why you save backup codes, I’ll add this to the changelog. You could argue having two devices with the code is less safe though...as jeopardizing one of two devices leads to direct access to your 2FA code. The purpose of 2FA is ONE point only you have control over. Having cloud backups of 2FA codes and several devices lowkey lessens the purpose of 2FA. I’d argue less is more, just make sure to save backups!
@jamesedwards39235 жыл бұрын
You have to remember security is about layering. FIDO Keys, Software Authentication, and Backup Codes. Like he said, SMS should only be used as a last resort. FIDO Keys are great because all the online accounts I tried it on. Accept more than one key. So that means backups. Buy as many as you can afford and scatter them.
@jamesedwards39235 жыл бұрын
Man you are correct. Most of these people have money and time to set up all their recovery factors. Yet make no effort to do it.
@jamesedwards39235 жыл бұрын
@@IgnoreMyChan I am inclined to agree with him. Apple gives you to avenues of authentication. Two-Factor and Two-Step Verification, in my experience there are two types of Apple Users. IT Professionals and lazy users who think they are secure because they spent $2000 on a phone! When a $200 to $400 could do the same stuff. support.apple.com/en-us/HT204152?fbclid=IwAR2-vw6Hcd3kCnKG4syYPMReF_uvVphn5ZOeAyR8ss8vxRUKchRKlLNWsNk The problem free p, paid, or open source. It does not matter most users are lazy. I knew one Apple user who used SMS. Had no recovery email address. Had security questions. Nothing. He came to me for help. Again, most users do not care at all. Apple makes it easy to implement basic security.
@oooo0O0oooo2 жыл бұрын
What about aegis?
@techlore2 жыл бұрын
Aegis wasn't available when we made this video, but we do recommended it!
@martinusmoretti7292 жыл бұрын
I'm Dutch and my government still uses SMS-2FA if you want to log in to platforms for civil affairs… I wonder which stupid ass is responsible for that. In any case, it just shows that not everyone is aware of where the risks are. Unbelievable that this is still happening at this level.