Do this and you should be safe online

  Рет қаралды 45,550

Sun Knudsen

Sun Knudsen

Күн бұрын

In this episode, we explore how following 7 steps greatly improves one’s online security.
==============================
TL;DR
==============================
00:00 Intro
02:42 Using truly random passwords
03:36 Using full disk encryption
03:56 Using multi-factor authentication
06:56 Using password manager
08:19 Compartmentalize sensitive data and computing
10:19 Locking screen when one is away and shutting down computer at customs
11:09 Dropping password rotations unless password is compromised
==============================
LINKS
==============================
Password policy series 👉 • Password policy series
TrustToken 👉 www.trusttoken.com/
Exploring the password policy rabbit hole 👉 sunknudsen.com/stories/explor...
EFF passphrase word list 👉 www.eff.org/dice
passphraseme 👉 github.com/micahflee/passphra...
==============================
SUPPORT
==============================
Support this channel 👉 sunknudsen.com/donate

Пікірлер: 100
@davdelven
@davdelven 5 ай бұрын
For laymen like me, watching such videos for the first time really puts off online activity. The only exception I perceive is if you are a real security freak or your activism is simply worth rewarding.
@sophiegadoury
@sophiegadoury 2 жыл бұрын
Yes I appreciate the fact that you are answering questions from the community at the end of the video!
@andreribeiro6808
@andreribeiro6808 2 жыл бұрын
Hey Sun, I completely understand u. You think that using these clickbaits thumbnails, people who click on the video may get disappointed that the content is not what they are looking for. But when someone sees a thumbnail like this, they are just expecting that the content will be useful and up-to-date. And this is exactly what you are providing in the videos. To be perfect, I think that you just need to add some tech info into the titles 🚀
@JonnyD000
@JonnyD000 2 жыл бұрын
Great video, looking forward to the clipboard episode. I've been curious about that topic for a while.
@JulianAlien12
@JulianAlien12 2 жыл бұрын
You are one of the bst KZfaqr I watch you since 376 Followers Make so on!
@b_bullish6700
@b_bullish6700 2 жыл бұрын
Sun I really like the click bait titles. It just makes the content seem more exciting. Also I love your content and am so grateful for it. I litterally had the worst security possible b4 i started watching you and thanks to you it has been vastly improved
@mc-ty4br
@mc-ty4br 2 жыл бұрын
Waiting on that YubiKey miniseries 🙏
@mc-ty4br
@mc-ty4br 2 жыл бұрын
I agree with you, click-baity titles might don't feel like a good a good fit for your content. HOWEVER, if the stats show more reach/interactivity then it's worth it.
@MrVagyok
@MrVagyok 2 жыл бұрын
Totally, I was about to say this too. 🤟👍
@johnholme783
@johnholme783 8 ай бұрын
Thanks for the info! I had to learn about computer security the hard way! Wish I had seen videos like this several years ago!
@dj_hannah
@dj_hannah 2 жыл бұрын
I really enjoy your content. I am looking forward to any Yubikey episodes!!!!
@FulanodeTal-wh8ub
@FulanodeTal-wh8ub Жыл бұрын
love your content!! short videos with plenty information!!
@mohanroy1434
@mohanroy1434 2 жыл бұрын
Awesome!!
@RoryVanucchi
@RoryVanucchi 2 жыл бұрын
great info. thanks
@bschetanswaroopreddy7237
@bschetanswaroopreddy7237 2 жыл бұрын
I, personally, am loving these thumbnails back but no worries Sun, You can and probably should use the thumbnails you want to be featured. Anyway, Exceptional Video!
@sunknudsen
@sunknudsen 2 жыл бұрын
Thanks for the support. Using less clickbaity thumbnails does feel right… it’s hard to find the right balance between “gaming the algorithm” vs staying authentic to one’s self knowing it results in less discoverability.
@tothemoon8465
@tothemoon8465 2 жыл бұрын
@@sunknudsen Go for it man, no shame. See the clickbait thingy as you helping *more people* get a more healthy approach to their digital life. It's either that or them just clicking another cat video. (:
@ibendiben
@ibendiben 2 жыл бұрын
@@sunknudsen don't. Honesty makes you stand out. We need to learn people how to look for it.
@bobchen6314
@bobchen6314 2 жыл бұрын
很有意義的一支影片,希望你能繼續做下去!
@pititomoras5835
@pititomoras5835 Жыл бұрын
Thank you, very instructive!
@sunknudsen
@sunknudsen Жыл бұрын
Pleasure!
@samathastevens5831
@samathastevens5831 2 жыл бұрын
Also, all those security phrases don't use something anyone could relate to you. Or general public information. I accidentally hacked into someone else's email once, and I know nothing! I was trying to set up a school account. I really should have had a coffee or energy drink first! But they were using Yahoo mail. I went out and tried setting this up according to their insutructions. Somehow, I got to an e-mail by a person with a very similiar name to mine. My password wasn't working, so I thought I must have changed it right before I was distracted for a sec. So I click "forgot password" The security question "who won the us open last year". I googled it. Then I reset their password!! I realized as soon as I was in that there were all these emails about golf and it was somebody's account! So...make those security questions really far out there. And the password something no one would ever link to you. Just my advice.
@avikdsaha
@avikdsaha 7 ай бұрын
excellent
@martinlutherkingjr.5582
@martinlutherkingjr.5582 Жыл бұрын
What’s a good alternative to a rasberry pi for doing air gapped sensitive operations like cryptocurrency private key stuff? (I realize a hardware wallet is ideal) How secure is orange pi?
@tothemoon8465
@tothemoon8465 2 жыл бұрын
Best!!
@lawyere6260
@lawyere6260 2 жыл бұрын
Thx bro will keep u on updated on what i am creating $
@raduneo
@raduneo Жыл бұрын
Thank you so much for your content sun, I am addicted to learning more from your channel and admire your effort and enthusiasm. Do you know if there is a safe version of EverNote or OneNote with good note taking / organizing capability that you can share with friends over the internet where your information is encrypted and safe?
@ronm6585
@ronm6585 2 жыл бұрын
Thanks.
@lykp
@lykp Жыл бұрын
Hey Sun! Thank you for your content, I recently stumbled upon your channel and started watching most of your videos! Quick question: why you suggest it is ok to use same password on laptop and password manager? Doesn’t this just open a few extra attack vector? Ty and keep up the good work!
@first9428
@first9428 2 жыл бұрын
thankyou so much sir ❤️❤️❤️....
@sunknudsen
@sunknudsen 2 жыл бұрын
Pleasure!
@seanlowe5547
@seanlowe5547 2 жыл бұрын
What do you think about Brave browser. Thanks for the vids
@MyDogSteppedOnaBeee
@MyDogSteppedOnaBeee 2 жыл бұрын
Hi Sun what happened to the Big Sur setup video?
@vikas911
@vikas911 2 жыл бұрын
Yes please create video showing installing through pip passphraseme. Thank you :)
@usaintwinnin7312
@usaintwinnin7312 2 жыл бұрын
Wondering if you did a video on the safari - Advanced - experimental features settings? Should they be turned on or off?
@veterantruthtube3298
@veterantruthtube3298 Жыл бұрын
yes more q&a's please
@chrisc.1005
@chrisc.1005 2 жыл бұрын
What are your thoughts on people search sites? With just a phone number for example, you can look up someone’s address, full name etc. Opting out of these sites seems useless as the information is public
@NoWay2SeeTheirHoax
@NoWay2SeeTheirHoax 2 жыл бұрын
Hi, Sun. What are your thoughts on Apple Pay/Wallet? Do you consider it safe?
@CookeAaronJ
@CookeAaronJ 2 жыл бұрын
As a rule, is it generally better to access your most secure info (eg bank account) via secured browser or the app of the company (eg app from bank with account)?
@kriskotaro3680
@kriskotaro3680 2 жыл бұрын
I'm very interested in knowing more about the passphraseme.
@jrgardner777
@jrgardner777 2 жыл бұрын
Do you have an opinion on Steve Gibson's SQRL technology?
@uwo7130
@uwo7130 2 жыл бұрын
Thoughts on M1 Macbooks never fully powering off?
@user-zr7kz4vs7c
@user-zr7kz4vs7c 2 жыл бұрын
How to separate school and personal data on iPhone?
@jorge_c
@jorge_c 2 жыл бұрын
You mention Trezor but you missed the fact it can also be used as a FIDO2 device which can be recovered with the seed phrase. For that reason I prefer a Trezor or Ledger over a Yubikey
@aaron6841
@aaron6841 2 жыл бұрын
Where did your video go about encrypted flash drives? The basic version?
@ericbrown4960
@ericbrown4960 2 жыл бұрын
Hello Sun, just coming to your content now and I can tell you that ironically I almost didn't start watching because of the click-bait headlines. My opinion... Skip that crap. I find your stuff very valuable. I hope that helps.
@angus928
@angus928 2 жыл бұрын
Can we get an update on if you have upgrade to Big Sur? or still sticking with Catalina? Would really appreciate it, thanks!
@sunknudsen
@sunknudsen 2 жыл бұрын
Yes! Will publish episode on this topic shortly.
@sparrowcide
@sparrowcide 2 жыл бұрын
I am currently using firefox lockwise to save my passwords and sync them to different devices. Is it safe? Or should I always save passwords locally?
@sunknudsen
@sunknudsen 2 жыл бұрын
It is always safer to save passwords locally… that said, I have not researched Firefox Lockwise so I cannot comment. That said, interesting topic!
@md.ishraquebinshafique1968
@md.ishraquebinshafique1968 2 жыл бұрын
Which Yubikey would you recommend using?
@sunknudsen
@sunknudsen 2 жыл бұрын
For most use cases, I would recommend the YubiKey 5 NFC or YubiKey 5C NFC.
@theoneD1
@theoneD1 2 жыл бұрын
IM JUST CURIOUS SUN, HAS YOUR COMPUTER EVER BEEN COMPROMISED? HOW DID YOU FEEL? AND WHAT IMMEDIATE ACTION DID YOU TAKE TO PREVENT IT FROM SPREADING?
@sunknudsen
@sunknudsen 2 жыл бұрын
Interesting question… Step 1: disconnect internet by unplugging modem. Other steps depend on exploit.
@gumott
@gumott 2 жыл бұрын
I have this huge problem with windows, to enable disk encription i have to use a microsoft account and link it to my device, How do you Proceed? cuz i've heard windows is a privacy nightmare
@pipeliner8969
@pipeliner8969 2 жыл бұрын
Can you provide chapters?
@sunknudsen
@sunknudsen 2 жыл бұрын
Good idea… on it!
@sunknudsen
@sunknudsen 2 жыл бұрын
Done
@pipeliner8969
@pipeliner8969 2 жыл бұрын
@@sunknudsen great love this video!
@misterl9850
@misterl9850 2 жыл бұрын
I have a question: does the bitwarden generate secure passphrases?
@ezra1369
@ezra1369 Жыл бұрын
Yes if you use their password generator
@CJ-wc5lb
@CJ-wc5lb 2 жыл бұрын
Is it safe to share your MAC address to someone?
@maxvinella941
@maxvinella941 2 жыл бұрын
Please create content for passphraseme. thanks
@meister-t
@meister-t Жыл бұрын
2 bad experiences: I used to use 2FA, but then I came across a post by someone who's phone stopped working and changed phones, and they lost access to everything. LastPass blocked me from my account after we had a power outage, so I used my phone's internet to make an access point for my laptop, went to log in as usual, and they blocked my account. I lost access to everything!
@fearless6947
@fearless6947 Жыл бұрын
where you able to recover it all?
@theoneD1
@theoneD1 2 жыл бұрын
WHAT IF YOU FIND YOURSELF IN A DEAD SPOT/DEAD ZONE WHERE A SIGNAL IS FROM WEAK TO NO SIGNAL AND YOU DONT RECEIVE THE 2 STEP VERIFICATION CODE AND YOU TRY LIKE 3-4 TIMES AND STILL NOTHING. IS IT POSSIBLE THAT SOMEONE COULD INTERCEPT YOUR PHONE TO GRAB THE CODE? AND COULD THAT BE THE REASON FOR A WEAK SIGNAL?, LETS SAY YOU USE AN OLD BRICK PHONE (NOT SMARTPHONE), WOULD THAT BE POSSIBLE?
@sunknudsen
@sunknudsen 2 жыл бұрын
I would recommending avoiding SMS 2FA altogether because of SIM port attacks… using app such as OTP Auth on iOS is more convenient and secure. One level up from there is using a security key such as YubiKey (more on this shortly).
@richardpowless8894
@richardpowless8894 Жыл бұрын
How and where do I save the randomly generated password?
@theoneD1
@theoneD1 2 жыл бұрын
IF YOUR WIFI WAS COMPROMISED, WOULD USING YOUR "1PASSWORD" BE UNSAFE? WOULD IT MATTER IF YOU USE A VPN? OR CAN HACKERS STILL BREACH THE "1PASSWORD"?
@sunknudsen
@sunknudsen 2 жыл бұрын
I will try to answer this question (among others) at the end of next episode.
@theoneD1
@theoneD1 2 жыл бұрын
@@sunknudsen OK, NO PROBS ;)
@rydmerlin
@rydmerlin 2 жыл бұрын
FYI re: credit cards. You don’t need a PIN to use a credit card. I like the new idea but you didn’t read my second question ;-) Thanks for reading the first.
@theoneD1
@theoneD1 2 жыл бұрын
WHEN USING "LOCK SCREEN" IS THE WIFI STILL ACTIVE BEHIND THE SCENES? WOULD THE VPN STILL BE ACTIVE BEHIND THE SCENES?
@sunknudsen
@sunknudsen 2 жыл бұрын
Yes, both would still be active.
@theoneD1
@theoneD1 2 жыл бұрын
@@sunknudsen OK, GOOD TO KNOW, ITS OFTEN THE UNKNOWN FACTOR THAT HOLDS ME BACK FROM APPLYING THESE SECURITY STEPS. BUT THANKS FOR CLARIFYING THAT UP ;)
@hvaandres
@hvaandres 2 жыл бұрын
Do you recommend using password managers on Mobile devices?
@sunknudsen
@sunknudsen 2 жыл бұрын
It is safer to use both password manager and multi-factor authentication app on contemporary mobile operating systems vs on desktop. That said, when possible, I recommend air gapping both.
@theoneD1
@theoneD1 2 жыл бұрын
IF YOU USE A WIFI THAT HAS BEEN COMPROMISED, AND YOU PLUG IN THE "UBIKEY" WOULD THAT COMPROMISED THE UBIKEY'S SECURITY?
@sunknudsen
@sunknudsen 2 жыл бұрын
It depends on the exploit… theoretically, key material is safe given compartmentalization. That said, someone could exfiltrate password and TOTP token and quickly change credentials to takeover account.
@theoneD1
@theoneD1 2 жыл бұрын
@@sunknudsen EEK!!... THINGS LIKE THIS FREAKS ME OUT, SENDS ME INTO PANIC MODE. =D
@MrVagyok
@MrVagyok 2 жыл бұрын
YubiKey never allows to export outside of the secure element any private key material, unless you set it up for using the YubiKey for GPG in which case you provide private & public keys and add it to the YubiKey. Isn’t that?
@lovebaja
@lovebaja 2 жыл бұрын
Sun, I wish you'd start publishing on Odysee like Rob Braxman.
@michalroesler
@michalroesler Жыл бұрын
F**K yeah.
@im_hd3050
@im_hd3050 2 жыл бұрын
Domen uk Nov
@byokey
@byokey 2 жыл бұрын
i like your videos, but you should change you googles!
@MikeHunt-rw4gf
@MikeHunt-rw4gf 2 жыл бұрын
Algorithm.
@ibendiben
@ibendiben 2 жыл бұрын
A good descriptive/standing out thumbnail, with a catchphrase is awesome. But CLICKBAIT is killing KZfaq for me. Turns everything into manufactured commercial content. The only reason I like watching your channel is because there is an honesty to the way you present yourself and the content. And isn't this channel all about trustworthiness and honest government vs populism and false advertisement?
@theoneD1
@theoneD1 2 жыл бұрын
OK, WHATS GOING ON, YOU'VE DISAPPEARED OFF THE RADAR AGAIN, YOU DIDNT GET COVID DID YOU?
@ishan7946
@ishan7946 2 жыл бұрын
Crap! None of the steps mentioned hide your IP address, which is most prominent in being safe online. So, work on encrypting your IP address first, rest everything later.
@ftc-nl1041
@ftc-nl1041 Жыл бұрын
😅😂🤣
@Yates__
@Yates__ Жыл бұрын
If you're worried about a $5 wrench attack, get a gun.
@infotruther
@infotruther Жыл бұрын
water boarding
@JensUhlmannOfficial
@JensUhlmannOfficial 2 жыл бұрын
Could you upload your videos in 4K again? The bitrate of your uploads sadly seems pretty low and it is kind of offputting to be honest, since pretty much every channel uploads in 4K now. I am aware that your videos have their value in your knowledge and not in the visuals, and I am very grateful for your knowledge. But editing wise, your videos are not very complex so it shouldn't make that much of a difference to you I suppose :) Anyway, keep up the good work and I am looking forward to your M1 Mac videos!
@joshkinder8871
@joshkinder8871 2 жыл бұрын
Clickbait is only a problem when the content is shit. Yours sir, is not. Bait away!
@infotruther
@infotruther Жыл бұрын
passkeys
@georgwilhelm319
@georgwilhelm319 2 жыл бұрын
What's your view on Package managers, like homebrew. from a privacy perspective?
@fell_eagle5093
@fell_eagle5093 Жыл бұрын
is KeePassXC secure enough?
@dean2521
@dean2521 2 жыл бұрын
On the second part. A super long super secure password that you can easily memorize, use your mothers maiden name+your bestfriend phone number+your first phone number, your second phone number For example, mitsubishi567263820009163574888876351738555 Good luck
The “Bank of Spain” buried deep into our computers
7:08
Sun Knudsen
Рет қаралды 5 М.
Why I no longer use a VPN (most of the time) and nor should you
11:25
Sun Knudsen
Рет қаралды 1,2 МЛН
Schoolboy - Часть 2
00:12
⚡️КАН АНДРЕЙ⚡️
Рет қаралды 9 МЛН
小蚂蚁被感动了!火影忍者 #佐助 #家庭
00:54
火影忍者一家
Рет қаралды 42 МЛН
Can A Seed Grow In Your Nose? 🤔
00:33
Zack D. Films
Рет қаралды 30 МЛН
Hacker Breaks Down 26 Hacking Scenes From Movies & TV | WIRED
21:14
BYE DUCK DUCK GO, here's my new search engine! Private Alternatives to Google
17:41
What is MKV and why MakeMKV Is the Best to Save Your DVDs
8:35
RapidSeedbox.com
Рет қаралды 8 М.
6 Must-Have Security Gadgets That Fit in Your Pocket
9:03
All Things Secured
Рет қаралды 1,8 МЛН
Tutanota review and why it’s one of a kind (compared to Proton)
15:51
How to configure iOS for privacy
23:39
Sun Knudsen
Рет қаралды 86 М.
Hacker Teaches How to Manage Passwords
4:51
Valuetainment Short Clips
Рет қаралды 132 М.
How To Become Invisible Online
24:06
Hallden
Рет қаралды 2,8 МЛН