You're probably doing it wrong | Multi-Factor Authentication Explained

  Рет қаралды 5,161

Side Of Burritos

Side Of Burritos

Күн бұрын

Пікірлер
@jayjoneslive
@jayjoneslive Жыл бұрын
I wouldn’t mind a physical key, but they need to be way more affordable and maybe have more security methods that other sites can use sending Bluetooth signal or something like that.
@jgn2112
@jgn2112 2 жыл бұрын
Dude, this channel is becoming the Project Farm of security channels. Can't wait for the upcoming FIDO vids! I have no WiFi or cellphone signal at my office so a FIDO method of authentication might be a much better option all the way around! It just makes me nervous.
@centauri936
@centauri936 2 жыл бұрын
You can actually use TOTP offline. Even when you set up the shared secret initially, this is transfered via qr code and the authenticator device does not need internet to receive it. That said, I recommend hardware security keys regardless :) Don't be nervous, just get a backup and keep it safe somewhere. This is the way!
@sideofburritos
@sideofburritos 2 жыл бұрын
Haha, thank you! Ah, I didn't even think of that added benefit of it. Google has an "Advanced Protection Program" that I want to make a video about. I want to sign my YT account up for it, and it requires two hardware keys so that all other methods can be disabled. I've been hesitant for the "what if" scenarios and I lose access to my account. So I get it, haha.
@hayonglee1600
@hayonglee1600 2 жыл бұрын
Just stumbled across your channel looking to learn about Gos. In Korea, you can create your own ubikey with any usb. And it is generally required for all banking activity. You can also transfer the code to a phone. And for most people they use the banking app to do thus. Buy for those who know how, can do this manually. Buy on top of that key, you need the password for that key. And in most cases, in order to change it, you need to go into the bank with your ID.
@sideofburritos
@sideofburritos 2 жыл бұрын
Hmm, that's interesting. Do you go to the bank and create it there, or do you have software you download and create it yourself? When you say it's required for all banking activity, does that include purchases and transactions? Or only activity where you're transferring, deposition, or withdrawing money?
@hayonglee1600
@hayonglee1600 2 жыл бұрын
@@sideofburritos So the last time I had to open a bank account. I needed to make a username and make a temporary password (number based, usually 4 digets). Then when I get to my personal computer, I will download the banks app, input the username and temporary password. It will ask for a USB. Which it will place a certificate on the USB. So when ever you need to use the bank you need to use that certificate(online banking). That certificate is needed in basically all interactions on the banks site. Including password changes. That certificate is only valid for 1 year and needs to be re-created once a year. With a new password(an old password can be used, until the bank changes its minimum requirements for the password. The last time that happened was when they required special keys(. ! *). They sometimes also updated the password length requirement (in the last 9 years once or twice). And in recent years. They have added otp and calls. When they call you, you need to input the bank code from the pc. Same system as otp if not mistaken. Now for internet shopping. Everytime you buy something from a western site or a Korean site(there are exceptions, but 99%). When you get to the payments section, it will send you to the banks verification page. Where you need to input a different password word.(if it is your first time doing this you need set it up. And from then after(and when creating it) you need or phone call and or the usb(in some cases). To sum up you need 2 passwords and a USB that has a digital certificate that is only valid for one year. Sorry typing on my phone. Email me if you need to be more in depth. Or need clarification. Hope that helps. :)
@dread1089
@dread1089 2 жыл бұрын
Amazing video, hope the security playlist gets expanded often.
@sideofburritos
@sideofburritos 2 жыл бұрын
Thanks! I'm planning on it!
@TheBoomshine
@TheBoomshine 2 жыл бұрын
Great original content! I'll have to give this one a few watch-overs as some stuff goes over my head. :)
@sideofburritos
@sideofburritos 2 жыл бұрын
Haha, thank you!
@salpertia
@salpertia 2 жыл бұрын
I lost my yubikey a week ago and was pretty bummed out as it was the only thing that gets me into my web services without waiting for a reset.. Found it yesterday, sat on the toilet and left it in the tp rack
@sideofburritos
@sideofburritos 2 жыл бұрын
This was a great story 🤣, glad you found it, and thanks for sharing.
@philrose7716
@philrose7716 2 жыл бұрын
Josh I believe ProtonMail is going to roll out a way you can use MFA. Do you think you could do a review and explain the benefits?
@sideofburritos
@sideofburritos 2 жыл бұрын
They announced this a few months ago -proton.me/blog/security-keys unfortunately, you still can't disable the less secure MFA methods. From what I understand, they need to have all their apps support hardware keys before they can let you disable the other methods. That being said, I think it would be good to have a video on “securing X account” or some other common services people use.
@idobenhamo953
@idobenhamo953 2 жыл бұрын
hey, Im really enjoying your channel and learned a lot from you! i actually ditched my iphone last week and bought pixel 6 and immediately installed graphene on that. so thanks! i wanted to ask about the permission "sensors" on the apps... you can pour some light on that?
@sideofburritos
@sideofburritos 2 жыл бұрын
Glad to hear! Congrats on ditching the iPhone! Good question on the sensor toggle. GrapheneOS has both the sensor and network toggle that stock Android OS doesn't have. This week's video will be on the topic, so hopefully that'll answer the question.
@idobenhamo953
@idobenhamo953 2 жыл бұрын
@@sideofburritos thanks a lot!!! best regards!
@ArtOfHealth
@ArtOfHealth 2 жыл бұрын
The rabbithole just shortens when facts are more clearly explained. Thanks. Some reviewers have said the camera is degraded with GrapheneOS. Do you mostly use your computer and very little on your mobile devices?
@sideofburritos
@sideofburritos 2 жыл бұрын
GCAM definitely has more features, but I use the GrapheneOS camera app primarily. I would say I use my mobile device 20% of the time and my computer 80%. I hate typing on the small screen. My hope is that GrapheneOS will support the Pixel tablet when it's released someday, and I would like to then use that primarily with a keyboard.
@ArtOfHealth
@ArtOfHealth 2 жыл бұрын
@@sideofburritos Have you tried a Chrome OS computer? $1200 to $2600 depending on perks. The problem is Graphene is not built for PC. Yet. My business associate bought a Chromebook for $1300 and he loves it after years with Apple limitations and hardware issues. Plurilock is in Canada. They offer two MFA solutions. Adapt and Defend. That is all I know for now. Thanks
@centauri936
@centauri936 2 жыл бұрын
@@ArtOfHealth I've been using a chromebook lately. (Your price points seem very high for those btw.) I think they might be the most secure desktop computers you can possibly use right now. Chrome os inherits the strong application sanboxing of the chrome browser. It is fundamentally based on linux (even lets you run virtualized linux very easily), but actually employs verified boot and disk encryption properly, neither of which can be said of any major linux distro. By design, it's really easy to power down chromebooks and come back right where you left off, which allows you to easily take full advantage of its strong encryption at rest and verified boot to combat malware persistence. It also applies updates seamlessly in the background, mitigating users who don't want to be interrupted to update. Boggles the mind that no one else has figured this out yet, even though smartphones have worked this way for years. I would love to see a proper non google build of chromium os at some point, mainly so that it can be used without a google account, but unfortunately we don't have that yet. I still have come to the conclusion that it is the best option for me.
@sideofburritos
@sideofburritos 2 жыл бұрын
@centauri I agree it's the most secure desktop option available. The major deterrent for me right now is the privacy aspect of it, but the security it offers is attractive.
@ArtOfHealth
@ArtOfHealth 2 жыл бұрын
@@centauri936 Thank you very much!
@noomondai
@noomondai 2 жыл бұрын
Thanks Josh, great info!
@branislavavramovic2601
@branislavavramovic2601 2 жыл бұрын
Thank you very much for such a detailed explanation. Is there a chance to make some videos in the future and test out /e/ OS and Divest OS? Both should be solid when it comes to privacy and if I understood correctly, they could be used on a wide range of devices.
@sideofburritos
@sideofburritos 2 жыл бұрын
You're welcome! Hmm, perhaps. Some others have requested videos on those OS's. You are correct, they do support a wider range of devices which is good for those who can't obtain the Pixel.
@benf101
@benf101 2 жыл бұрын
I use TOTP whenever possible, but honestly it's no better than a long password. Why would I say that? Because every time you set up a TOTP they give you a list of "backup codes", which are NOT time based and can be used in place of my time based one time passwords. It's like wearing a bullet proof vest with a bullseye on my forehead. Again, I do use them because they add some protection, but a second place to enter another password would be just as good.
@sideofburritos
@sideofburritos 2 жыл бұрын
I can see your point, but TOTP provide *some* phishing protection vs the backup codes. You'll regularly be using the TOTP code, and if that gets phished it's only valid for 30-60 seconds. If you had a second password, that could be phish much easier, and it would be valid indefinitely.
@devadeep1842
@devadeep1842 2 жыл бұрын
Nice video on MFA 😍😍 still waiting for more videos to learn from you eagerly
@sideofburritos
@sideofburritos 2 жыл бұрын
More to come!
@homie4235
@homie4235 2 жыл бұрын
I think Fido 2 will start to be supported more with Apples new OS adding support for it (passkeys).
@sideofburritos
@sideofburritos 2 жыл бұрын
I saw an article that Apple is going to "kill the password" a few weeks ago. Just looked more into it after you mentioned it, and I agree. Looks like "Passkeys" will be built on WebAuthn, so that's great they didn't try to roll their own. The good thing about big tech is they're able to push other companies into adopting methods much quicker than they would on their own. It's not always for the best, but I think this will be.
@c-LAW
@c-LAW 2 жыл бұрын
6:00 aegis Authenticator can encrypt secrets, Google authy Does not allow you to see or export your secrets. Authy (sucks) locks you into Google's ecosystem. BTW, Love your channel and your presentations!
@sideofburritos
@sideofburritos 2 жыл бұрын
Hmm, I know it has the "Encryption" option where it encrypts the vault. But I haven't been able to find anything to make the secrets irretrievable. Is that a different setting? Thank you! I agree about Authy, not a huge fan of that. Especially the whole cloud storage (I believe that's what it uses) for MFA codes.
@MiroBG359
@MiroBG359 2 жыл бұрын
my T-mobile number got sim swapped in May. They had control of my account for over 2 hours. T-mobile is still refusing to tell me how it happened or any numbers that were in contact while the scammers had my number
@sideofburritos
@sideofburritos 2 жыл бұрын
Wow. I'm glad you were able to get control back at least. I won't why they won't give you any more info? Perhaps someone got social engineered, and they don't want to share?
@MiroBG359
@MiroBG359 2 жыл бұрын
@@sideofburritos probably someone on the inside did it and they're trying to avoid admitting fault. Fortunately, my SIM is the add-a-line and I try not to use SMS 2FA but I still do in some places. T-mobile corporate completely blew me off, not even a denial., ignored me completely. Regular CSR would only say the fraud team will investigate.
@MikeTrieu
@MikeTrieu 2 жыл бұрын
Hmm, you failed to mention that the built-in Secure Elements in many phones (like Google's Titan M and iPhones) can actually act as FIDO2 authenticators without having to rely on extra hardware.
@sideofburritos
@sideofburritos 2 жыл бұрын
I thought about it, but I'm not really a fan of that option. For how much I wipe my phone and reinstall it, it wouldn't be practical. I think for some it can be a great to use, but that day you erase your phone because of some strange behavior you just lost your MFA device. With a separate piece of hardware it's always “there”. At least that's my theory on it.
@kimhbryan
@kimhbryan 2 жыл бұрын
Nice video. It’s sad that support for more secure MFA methods is lacking. Once hardware keys are mainstream, I’ll invest in a set.
@sideofburritos
@sideofburritos 2 жыл бұрын
Hopefully more companies are pushed into supporting it, it really is the way to go.
@juliotechmx
@juliotechmx 2 жыл бұрын
Does Yubikey work with Grapheneos?
@sideofburritos
@sideofburritos 2 жыл бұрын
It does works via. the browser. You need to have Sandboxed Google Play services installed for it to function at this time.
@oldaccount7463
@oldaccount7463 2 жыл бұрын
Guessing a password manger TOTP would rank c tier?
@sideofburritos
@sideofburritos 2 жыл бұрын
Hmm, I think my answer on that would be the famous "it depends". If you have a cloud password manager like I do, probably more towards C (maybe B-), especially since I can view the secrets in it. I still think even that setup it better than the push notifications. If you have something offline/local, I would say it would be more so B tier.
@MikeTrieu
@MikeTrieu 2 жыл бұрын
Yeah, "MFA fatigue" is real. Just ask Uber recently. If you suddenly start getting a bunch of MFA notification prompts, for the love of your sysadmin, *DO NOT JUST CLICK THROUGH THE PROMPTS!*
GrapheneOS Sensors and Network permission toggle
3:36
Side Of Burritos
Рет қаралды 7 М.
You should uninstall F-Droid - Part 2
5:15
Side Of Burritos
Рет қаралды 24 М.
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
DRM explained - How Netflix prevents you from downloading videos?
18:17
Mehul - Codedamn
Рет қаралды 239 М.
eSIM Explained | How to activate eSIM Android | GrapheneOS
7:23
Side Of Burritos
Рет қаралды 16 М.
FULL reveal of what apps I use on my personal phone | GrapheneOS
10:39
Side Of Burritos
Рет қаралды 37 М.
How To Become A Blockchain Developer In 2023?
18:05
EatTheBlocks
Рет қаралды 169 М.
TLS Handshake Explained - Computerphile
16:59
Computerphile
Рет қаралды 570 М.
Best Open Source Android Apps | 3 Top Android Apps
4:51
Side Of Burritos
Рет қаралды 8 М.
Think Fast, Talk Smart: Communication Techniques
58:20
Stanford Graduate School of Business
Рет қаралды 43 МЛН
What is a Passkey?
18:05
Ask Leo!
Рет қаралды 58 М.