Why well-implemented 2FA mitigates both infosec and opsec attack vectors

  Рет қаралды 11,766

Sun Knudsen

Sun Knudsen

Күн бұрын

In this episode, we explore why well-implemented 2FA mitigates both infosec and opsec attack vectors.
==============================
SUPPORT
==============================
Support this channel 👉 sunknudsen.com/donate

Пікірлер: 31
@bendrix
@bendrix 4 жыл бұрын
Seriously, You don't know it yet but you are a super hero with a brainiac wonderfulness bro. Keep doing what you are doing. I'm your loyalist fan ever!!!! So proud of all that you are doing. I've watched every video at least 2x!
@sunknudsen
@sunknudsen 4 жыл бұрын
Thanks Ben, that really means a lot to me. Starting a VLOG is a shit ton of work and comments like yours are jet fuel.
@capedcrusader5282
@capedcrusader5282 4 жыл бұрын
@@sunknudsen 😊😊😊😁 Exactly!
@mzmzmzm
@mzmzmzm 3 жыл бұрын
Your channel is a rabbit hole 🕳 (in a good way!)
@sunknudsen
@sunknudsen 3 жыл бұрын
Happy to see others are joining me in the rabbit hole. 🤓
@Ncxgroup
@Ncxgroup 3 жыл бұрын
I enjoy what you're doing. Great information and point of view.
@godhanikevin
@godhanikevin 4 жыл бұрын
Why you have a less subscriber ? i never comment any you tube video but i do for you kepp doing your great work i like your every video and i blindelly trust your every advise on privacy topic
@sunknudsen
@sunknudsen 4 жыл бұрын
Thanks for the push... I guess privacy is a niche thing... that being said, our community is growing. 🤓
@ChopTheViking
@ChopTheViking 3 жыл бұрын
Another OpSec consideration for phone biometrics: if for some reason you are arrested in the US, biometrics can be compelled by the courts. So if you have a thumb print or face unlock, the court can compel you to unlock the phone via biometrics. They cannot legally compel you to enter in a password though.
@nomoore
@nomoore 3 жыл бұрын
Hi Sun, I recently found your channel and I’m loving it. What are your thoughts on using a password manager such as 1password and then a separate authenticator app on the same computer tied to a hardware token (such as a yubikey, with yubikey authenticator)? That should satisfy infosec as well as opsec, since the hardware is needed to open the authenticator. Am I right? In the case of the yubikey I believe the TOTP hashes are actually stored on the hardware key, not the in the software auth app.
@FulanodeTal-wh8ub
@FulanodeTal-wh8ub Жыл бұрын
your videos are short and good
@daishokey7440
@daishokey7440 3 жыл бұрын
Hey Sun, last video you recommended 1Password, because it enables you to locally sync your vault between your laptop and your phone. In this video on the other hand, you say that you should never ever put your password manager on the same device as your 2FA app. I am confused :D Do you use your password manager on your phone or not? By the way, congrats to 10k subscribers!
@FlyingNacho
@FlyingNacho 3 жыл бұрын
I'm pretty confused about this too. I wish @Sun Knudsen could clarify a bit further, I'm sure it'd help many people!
@MK-sy3ru
@MK-sy3ru 2 жыл бұрын
Hi Sun thank you for doing this amazing work. Looking at yubikey, which ones are the better choice out of security key c nfc (FIDO only) vs yubikey 5c nfc (OATH-TOTP, PIV/Smart card, as well as FIDO). Is FIDO the golden standard? IAgain thank you for your work!
@raduneo
@raduneo Жыл бұрын
Great video Sun. But when you have a passeord manager synched through local vault with your phone, doesn't that mean you have both the password manager AND 2FA on the same device? Obviously you would need the password manager on the phone too.... Ideas on this?
@shell11
@shell11 3 жыл бұрын
I hope you will do a recap episode about where to keep a password manager app (with its database) and where to keep the OPT authenticator app. And how to safely backup both in similar scenario. I suppose we should not keep both app/files in the same device (laptop/smartphone), for example is it suggested to use smartphone to receive OPT codes only and laptop to get access to password manager database only (in order to limit the compromised data in case of a device gets hacked). If making a similar split makes sense, do you think also backups should be performed with different drives, in order to ensure both files are never in the same online device?
@saumya942
@saumya942 3 жыл бұрын
Hey Sun, while I understand the risk with biometric authentication... Wouldn’t you agree that for most people it is less likely for a cyber criminal to physically attack them as compared to seeing/record them entering their password in public? In such a scenario, isn’t it better to unlock password manager and payment apps using biometric instead? Also, correct me if I’m wrong, but faceid on iOS require you to be attentive, right?
@Kurt013
@Kurt013 3 жыл бұрын
But having a password manager on one device and the 2FA on another device, will limit you. If you're not at home and you have, let's say, password manager only on your pc/mac, how would you do if you need that?
@sunknudsen
@sunknudsen 3 жыл бұрын
Great question... I would recommend against having both password manager and 2FA apps on desktop but having both on iOS is safer because of how iOS sandboxes apps.
@cmdrefstathiusplacidus9003
@cmdrefstathiusplacidus9003 Жыл бұрын
so I was interested in using Authy and then I heard they were hacked, my understanding is that the multiple device functionality that was vulnerable, and it wasn't the code itself but employees that became victims of social engineering at the root of the issue, would you still be confident in Authy as a solution?
@user-zr7kz4vs7c
@user-zr7kz4vs7c 3 жыл бұрын
Do you think that Hardware Security Keys is better than TOTP auth (app)?
@sunknudsen
@sunknudsen 3 жыл бұрын
Hey, depends on use case and which hardware security key is used (among other rabbit holes), but binary answer is yes. That said, one needs a solid backup strategy. Episode to come!
@user-zr7kz4vs7c
@user-zr7kz4vs7c 3 жыл бұрын
@@sunknudsen Don’t get me wrong, I love your channel a lot! Please keep your efforts. I am not sure which security key I should buy. Do you have any recommendations?
@ayadalmallak4738
@ayadalmallak4738 3 жыл бұрын
Dear please can you suport and help me, my 2FA its not work the mail it's OK and password ok when they ask about Google authenticator I but it they said it's not much I have the pickups code,
@yashptel
@yashptel 3 жыл бұрын
If he can wack me, he can probably threaten or try to kill me to get the password anyways. So I don't get the point about biometrics. I know it'll be more secure to disable it. But really?
@sunknudsen
@sunknudsen 3 жыл бұрын
I like the idea of having to be conscious to access my passwords... Aside from threats or physical attacks, drugs can be used as well.
@yashptel
@yashptel 3 жыл бұрын
@@sunknudsen Yeah in that case. It will be safe. I still would prefer a short 6 digit pin or something instead of my long ass password. Because I prefer both convince and security.
@sunknudsen
@sunknudsen 3 жыл бұрын
I agree... the trade-offs are hard from a user experience perspective. For me, it was hard at first... and eventually I forgot how convenient things were before become privacy conscious and unless I go back, a new "normal" has settled in.
@MikeHunt-rw4gf
@MikeHunt-rw4gf 3 жыл бұрын
Algorithm.
@yashptel
@yashptel 3 жыл бұрын
Btw Android also uses aes for storage encryption. It's probably 128bit. So there's that
Why Signal is more private and secure than iMessage and SMS
15:56
Why we can’t trust our home or any other wireless network
9:40
路飞太过分了,自己游泳。#海贼王#路飞
00:28
路飞与唐舞桐
Рет қаралды 40 МЛН
Fast and Furious: New Zealand 🚗
00:29
How Ridiculous
Рет қаралды 46 МЛН
Ouch.. 🤕
00:30
Celine & Michiel
Рет қаралды 29 МЛН
FIDO Promises a Life Without Passwords
9:58
IBM Technology
Рет қаралды 400 М.
Why I use macOS vs Linux as my daily driver
12:20
Sun Knudsen
Рет қаралды 47 М.
Do this and you should be safe online
17:25
Sun Knudsen
Рет қаралды 45 М.
Why VPNs are a WASTE of Your Money (usually…)
14:40
Cyberspatial
Рет қаралды 1,4 МЛН
How to configure iOS for privacy
23:39
Sun Knudsen
Рет қаралды 86 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 475 М.
Password Cracking - Computerphile
20:20
Computerphile
Рет қаралды 3,4 МЛН
路飞太过分了,自己游泳。#海贼王#路飞
00:28
路飞与唐舞桐
Рет қаралды 40 МЛН