How TOTP (Time-based One-time Password Algorithm) Works for 2 Factor Authentication

  Рет қаралды 70,085

Lawrence Systems

Lawrence Systems

Күн бұрын

Amazon Affiliate Store
➡️ www.amazon.com...
Gear we used on Kit (affiliate Links)
➡️ kit.co/lawrenc...
Try ITProTV free of charge and get 30% off!
➡️ go.itpro.tv/lts
Use OfferCode LTSERVICES to get 5% off your order at
➡️ lawrence.video...
Tesla Referral Program Offer
🚘 www.tesla.com/...
Lawrence Systems Shirts and Swag
👕 teespring.com/...
Digital Ocean Offer Code
➡️ m.do.co/c/85de...
HostiFi UniFi Cloud Hosting Service
➡️ hostifi.net/?v...
Protect you privacy with a VPN from Private Internet Access
➡️ www.privateint...
Google Fi Service Referral Code
📱g.co/fi/r/TA02XR
More Of Our Affiliates that help us out and can get you discounts!
➡️ www.lawrencesy...
Twitter
🐦 / tomlawrencetech
Patreon
🔗 / lawrencesystems
Our Forums
🔗 forums.lawrenc...
GitHub
🔗 github.com/law...
Discord
🔗 / discord
Our Web Site
🔗 www.lawrencesy...
PIA Internet Access Affiliates Link
www.privateint...
How TOTP (Time-based One-time Password Algorithm) Works for 2 Factor Authentication
Here is the TOTP Bash Script I used in the video
github.com/jak...

Пікірлер: 37
@EnglishRain
@EnglishRain Жыл бұрын
What an excellent video, Tysm! I take things haven't changed much under the hood right?
@bmpatel20
@bmpatel20 4 жыл бұрын
Great video, thank you for making it easy to understand.
@TJoseph2
@TJoseph2 7 жыл бұрын
I recently had a scare when I ended up dropping my phone into water. The first thing that popped into my head was I can't get into any of my accounts anymore. Luckily I had trusted my laptop for most of my accounts so i was able to log in and disable 2 factor. I love 2 factor authentication but this made me rethink my backup solutions just in case I broke my phone again.
@crusader8403
@crusader8403 Жыл бұрын
Backup codes
@georget10i
@georget10i 4 жыл бұрын
Awesome explanation. Thank you!
@An.Individual
@An.Individual 4 жыл бұрын
0:18 surely such a hacker would then also have the secret key for TOTP So TOTP will defend against a user hack but not against a server hack.
@therealb888
@therealb888 4 жыл бұрын
It's never meant to, that's completely different game.
@AnkitKamli
@AnkitKamli 4 жыл бұрын
How can I understand the otp code generating algorithm of an *http* website? I have my username & PW. But otp gets delayed due to my weak network or might be different reasons, is there any way I can generate or understand otp without waiting for the otp code in my sms.
@adeltabsh8578
@adeltabsh8578 4 жыл бұрын
Where can I find the bash code? Thanks
@andresz1606
@andresz1606 6 жыл бұрын
Did you say that "someone could hijack your phone number without getting your phone"? Mind to explain exactly how could this be achieved? I doubt such thing is possible unless you work for the mobile operator or the CIA. I think the authenticator was implemented mainly because companies don't want to pay for the SMS.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 6 жыл бұрын
Impersonating someone and having the phone company switch it. Does not require a job at the CIA...lol kzbin.info/www/bejne/gp3Gcnuhn8d0iNUm52s
@Chem-iu5jx
@Chem-iu5jx 3 жыл бұрын
But the secret key is encypted somehow or isn't it?
@smccrode
@smccrode 7 жыл бұрын
I wish Authy and related apps could somehow transfer devices when I get a new iPhone and restore from and encrypted backup. Maybe it’ll be solved someday. Normal users won’t know about this. Heck I barely caught it when I got a new phone.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 7 жыл бұрын
I have been looking at Authenticaor+ as it has an encrypted backup option. I will be doing a review of it soon.
@johnibbs5848
@johnibbs5848 7 жыл бұрын
Authy does allow you to transfer devices from a cloud synced backup. It even allows you to have the accounts available on multiple simultaneous devices. Just go into settings and enable backups and multi-devices if you want.
@LightningSnake
@LightningSnake 7 жыл бұрын
stuart you can use an App called Latch, that syncs everything from Cloud without relying on a phone number
@Jamesaepp
@Jamesaepp 6 жыл бұрын
Syncing to the cloud in any way for 2FA completely defeats the purpose.
@notstarboard
@notstarboard 4 жыл бұрын
One question I've always had on this is whether it would be easy to brute force into an account even without the authenticator if you had someone's username and password. Like, you only have 30 seconds before the code resets but there are also only 1,000,000 unique combinations for the typical six-digit 2FA code. Do most sites just cap the number of attempted logins in a short period of time to reduce the risk of someone guessing the code? Let's say a site limits you to five login attempts per hour and it takes me six months for me to hear about the breach and reset my password. In that situation an attacker would have about a 2.2% chance of accessing my account before I could change my password, assuming they're always trying the maximum amount of codes and no one stops them. Comparing that to the 100% chance they'd have without 2FA, this seems like a clear win for 2FA. With that said, I don't have much feel for how possible brute force attacks are in the real world. Is it reasonable to expect attackers could only do a handful of attempts an hour? Or could they theoretically just brute force right through with no limits? Obviously 2FA is better than nothing, but given that there are downsides too (e.g. slower login times, higher risk of losing access to your account) I'm trying to gauge the practical utility of 2FA.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 жыл бұрын
Most any modern site supports rate limiting.
@notstarboard
@notstarboard 4 жыл бұрын
@@LAWRENCESYSTEMS Makes sense! Thanks.
@stuartwhittaker1105
@stuartwhittaker1105 7 жыл бұрын
that weird sound issue is there again, its got to be that silver mic you use for this vlog, the other mic you use doesn't make the weird noise, is the diaphragm on its way out, or possibly some distortion creeping in somewhere. you got a different mic to use, I hear ebay is good for (hint) ?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 7 жыл бұрын
+Stuart Whittaker I listen to the last one and just can't find the noise, can you give me the time index for hearing it?
@stuartwhittaker1105
@stuartwhittaker1105 7 жыл бұрын
first example is faint at 0:3 seconds when you say open standard. they are all pretty faint to be honest(and numerous examples(maybe its clipping a bit)) but I really find it makes it hard to listen to when its happening, I'm using sennheiser game zero's, just tried my sony headphones and it happens with those as well. can anyone else hear it, tell me I'm not going mad :(. I know hearing declines with age, is there any young people at your gaff who can have a listen, I'm not having a dig, its true :)
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 7 жыл бұрын
I think it is just a lack of a pop filter and me being too close to the Microphone
@monkeyking2750
@monkeyking2750 7 жыл бұрын
I accidently deleted one of my exchange website 2 factor authentication , I try to login using the backup code but it said expire, now i can not log in to my account, my account has bitcoin's in it, I try to message the site support but not sure if they response..
@FURIArts
@FURIArts 5 жыл бұрын
So did they respond?
@therealb888
@therealb888 4 жыл бұрын
@@FURIArts did they?
@keongg6877
@keongg6877 3 жыл бұрын
did they?
@rootvalley2
@rootvalley2 Жыл бұрын
paypal now supports GAuth
@masterbjohnson2
@masterbjohnson2 7 жыл бұрын
Typo in title - TOTP
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 7 жыл бұрын
Thanks, Fixed it :)
@Gluluman
@Gluluman 4 жыл бұрын
Paypal is unsafe and awful. Even C- eBay dropped Paypal /Braintree
@botowner8623
@botowner8623 4 жыл бұрын
andOTP
Não sabe esconder Comida
00:20
DUDU e CAROL
Рет қаралды 22 МЛН
😜 #aminkavitaminka #aminokka #аминкавитаминка
00:14
Аминка Витаминка
Рет қаралды 1,6 МЛН
Кәсіпқой бокс | Жәнібек Әлімханұлы - Андрей Михайлович
48:57
VAMPIRE DESTROYED GIRL???? 😱
00:56
INO
Рет қаралды 8 МЛН
How HOTP and TOTP work
4:20
iter
Рет қаралды 21 М.
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1,1 МЛН
Automate One Time Password (OTP) using JavaScript
26:12
SDET Unicorns by Dilpreet Johal
Рет қаралды 28 М.
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 573 М.
MFA the Right Way   One Time Passwords with PyOTP
25:01
PyGotham 2018
Рет қаралды 9 М.
What’s the Best Two-Factor Authentication Option?
11:30
Ask Leo!
Рет қаралды 42 М.
Goodbye Passwords! Hello Passkeys
10:29
Andy Malone MVP
Рет қаралды 77 М.
How does Two-Factor Authentication - 2FA work?
14:04
KacperSzurekEN
Рет қаралды 17 М.
What’s the Best Two-Factor App?
9:23
Ask Leo!
Рет қаралды 13 М.
Não sabe esconder Comida
00:20
DUDU e CAROL
Рет қаралды 22 МЛН