Here's Why I Moved to Security Keys for 2FA

Here's Why I Moved to Security Keys for 2FA

Techlore

1 год назад

90,293 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@fromrealworld_
@fromrealworld_ - 09.12.2023 10:34

Bro.. I flashed my phone... I used my fingerprint as security key.. Now my fingerprint is required to open discord.. What should I do please help

Ответить
@TheMegaOddly
@TheMegaOddly - 03.12.2023 06:05

I would love if my bank would give me a way to use 2FA to use hardware key over app or sms

Ответить
@Maldroid
@Maldroid - 02.11.2023 08:20

In my perspective, hardware keys pose a potential risk as they are susceptible to theft, which in my opinion, is a more likely scenario than someone hacking into a full-disk encrypted phone or computer. Unless these keys are fortified with additional security measures such as password protection, I don't perceive them to be superior to using my phone as a method of two-factor authentication. Phishing doesn't pose a substantial threat to me, given that I utilize 1Password, which has anti-phishing features. However, I do recognize that hardware keys may offer enhanced security for certain individuals.

There is absolutely no way you can steal my phone, unlock it or decrypt it, decrypt Aegis, and login to any account faster than I change my 2fa(s). This may be possible with a stolen hardware key.

Ответить
@michaelunderwood6298
@michaelunderwood6298 - 14.10.2023 20:55

I recently updated my phone since it forced me to do so, but when it finished updating it, all of my photos, videos and apps I have downloaded were all gone including the authenticator. I used the authenticator for roblox for my account log in, but now that it has been deleted, i can't log in nor find the exact authenticator i used. I tried setting back up the log in code on other authenticator apps, but it didn't work. So now i can't log in to my account anymore. Can someone help me?

Ответить
@bronkolie
@bronkolie - 11.10.2023 19:34

Why would you keep one key in your wallet and another in your laptop? Surely if the one in your laptop breaks you wouldn't need the backup that urgently? Also wouldn't that be a problem if you fall into water? You'd think you should just keep one at home. idk tho

Ответить
@katrinasetera6899
@katrinasetera6899 - 02.10.2023 23:06

Is it safe to leave it in your PC all the time?

Ответить
@handicappuccino8491
@handicappuccino8491 - 23.09.2023 22:59

They should make these with security cameras on them so you wouldn’t have to buy multiple ones maybe they can team up with us security camera company

Ответить
@josephturberg3014
@josephturberg3014 - 02.09.2023 16:11

these things are impossible to set up properly, there are many workarounds for these things as banks and google and every other platform that "Supports" them don't work at all. don't waste your money

Ответить
@Saadlatif92
@Saadlatif92 - 30.08.2023 09:52

Why does Instagram not have the option for Yubikey or for any physical hardware token form of 2FA?

It’s very weird considering that Facebook has this option and both companies are part of Meta.

Ответить
@rydmerlin
@rydmerlin - 20.08.2023 00:25

If you keep it with your laptop you lose it and your laptop together.

Ответить
@user-rt8zp3kn2s
@user-rt8zp3kn2s - 31.07.2023 05:11

can your employer track your location with this key?

Ответить
@immortalcyanogen779
@immortalcyanogen779 - 27.06.2023 20:06

What about onlykey?

Ответить
@wilmerceballospina7588
@wilmerceballospina7588 - 28.05.2023 19:33

I don’t know if I fully trust these keys … see they could Install a keylogger and still be hacked.

Ответить
@5lothamLovesPedos
@5lothamLovesPedos - 27.05.2023 22:31

I always thought 2fa was stupid.

Ответить
@RitzyBusiness
@RitzyBusiness - 26.05.2023 17:04

I've been using yubikeys for over a decade now. While I am not particularly a security enthusiast, I find them to be extremely convenient. Especially when traveling to countries where you might not have your phone number. Getting locked out of your email because you don't have your phone # is not a good time.

But also have a key that only I have access to makes things quite nice. I wish banking institutions would allow me to use it. As of now, my banks are my weakest links when it comes to 2fa

Ответить
@San_Dee
@San_Dee - 14.05.2023 11:24

Do you have a video on having multiple 2FA and using the others as backup? Say hardware keys are your active 2FA, meaning the only one you use, and you lost your hardware keys, but fortunately you’ve got your TOTP Authenticator code backed up in a location that doesn’t require the use of that hardware key. My thought being that you have multiple 2FA, which seems less secure, but if you aren’t using the other ones it lessens the possibility they are compromised. Instead just have them stored on an encrypted USB or in a veracrypt folder on the cloud (your thoughts on the security of this too?) for the day all your hardware keys are lost. Realistically I don’t see why having more than one backup 2FA is necessary if you would be storing that 3rd 2FA backup in the same secure place. Or any other thoughts on this, best alternative backup 2FA (might depend on the 2FA offered by each service).

Basically any video you can point to where you talk about using multiple 2FA and your security thoughts on this. Thanks!

Ответить
@BenIngham
@BenIngham - 13.05.2023 19:33

What’s weird here to me is why you would use an external security key over something like Passkeys. I have multiple security keys which I use weekly, but I use biometrically protected Passkeys wherever supported

Ответить
@AUDIO2AUTO
@AUDIO2AUTO - 09.05.2023 23:36

Let me see you sim swap my email. Just send the code to the email instead of a phone company not smart enough to not swap you with someone thats not you.

Ответить
@AUDIO2AUTO
@AUDIO2AUTO - 09.05.2023 23:35

Until you lose or the key gets stolen.. lol

Ответить
@Spiralnebel_GB
@Spiralnebel_GB - 06.05.2023 12:07

@Techlore: The Nano can be used in a Pixel 6a, right? Plugin in with the sensor up or down, right?

Can someone tell me if it fits into the cutout at the USB-C Port of the Otterbox Commute?
Otterbox can not tell me even i provided the exact dimensions 🙄

Ответить
@charleshines2142
@charleshines2142 - 02.05.2023 05:26

It is true that SMS is better than nothing. Not everyone is going to SIM swap attack everyone. Not only that but a SIM swap attack would disconnect your service. If you catch that quickly enough and get down to your phone carrier you may just have a small chance to fix the problem. I doubt you would catch that S.O.B. who did it but at least then hopefully if you catch it soon enough he will realize that you know something is happening and move on. Don't abandon SMS unless you have something better. Those ones that tell you that SMS is useless are probably the hackers hoping that you would just give up on 2FA and make it easier. Some people do play tricks on you that way!!

Ответить
@wolixoriginal
@wolixoriginal - 01.05.2023 09:22

Do you know now security keys now integrit on phones to say your fingerprint be your utf

Ответить
@alicethegrinsecatz6011
@alicethegrinsecatz6011 - 01.05.2023 01:02

You don't need to plug them in. You can use NFC on some models

Ответить
@pperrinuk
@pperrinuk - 30.04.2023 20:38

I have three fido devices I got years ago get them out now and then for another shot... always too much of a pita. Now if there were a password manager that used U2F to effectively U2F enable all the sites I use, I guess it may be ok.

A couple of mine do bluetooth, NFC and USB, but never really worked with android - and I only recently got a phone that does NFC....

Maybe time to dig the out again!

Ответить
@Techkomsan
@Techkomsan - 30.04.2023 06:47

I prefer to security key better than 2FA

Ответить
@ISCARI0T
@ISCARI0T - 30.04.2023 05:49

people who care about security as randoms are insanely delusional. narcissism + low knowledge in computer science, happens i guess..

Ответить
@TonyPadgett
@TonyPadgett - 29.04.2023 05:07

Woudn't leaving that key in your laptop be a risk? For example, what if someone stole your laptop with it in it?

Ответить
@someoneoncesaid6978
@someoneoncesaid6978 - 29.04.2023 04:26

If you keep it plugged into your laptop, and someone steals your laptop, you've provided them (literally) the key to hacking all of your accounts.

Ответить
@hugoedelarosa
@hugoedelarosa - 29.04.2023 02:52

I wish their keys were made of durable materials or that they were honest with clients and tell them: “don’t store these with your keys in your pocket”

Ответить
@Andre-qo5ek
@Andre-qo5ek - 28.04.2023 21:19

wow.. so many banks simply do not have any 2fa or mostly phone/sms/email. they really have to catch up.

Ответить
@asishreddy7729
@asishreddy7729 - 28.04.2023 19:41

If I lose my hardware key is there an option to switch over your old credentials from the lost key to a new hardware key over the internet? Otherwise, revoking the old key and adding a new one in all my websites will be a tremendous headache. I know we will have a backup key as well, but we still have to revoke the lost key on all the websites.

Ответить
@manny7886
@manny7886 - 28.04.2023 18:09

Great video. I use mine with my password manager Bitwarden. I wish financial institutions (i.e. banks, credit card companies) support hardware 2FA.

Ответить
@electricz3045
@electricz3045 - 28.04.2023 14:23

Yubikey is actually 3fa so the title you've chose make little sense...

Ответить
@DigitalDissident
@DigitalDissident - 28.04.2023 12:50

how much you get paid for this sponsorship

Ответить
@capn
@capn - 28.04.2023 10:31

People with security keys: "Wow look at me, my security is impenetrable!"
People with fingers: "yoink that real quick thanks"

Ответить
@LionRoars918
@LionRoars918 - 28.04.2023 08:24

Or your bank has no 2FA. Yes truly these days thats sad.

Ответить
@asificam1
@asificam1 - 28.04.2023 07:12

I'd like to see more developer guides for integrating u2f with your own websites... most focus on the htop mode of the yubikey specifically rather than the universal and far superior U2F.

Ответить
@Kaleb-lf8kf
@Kaleb-lf8kf - 28.04.2023 07:00

surprised you didn't redo the video with how many mistakes there are, other then that great advice

Ответить
@tATuCentral
@tATuCentral - 28.04.2023 06:51

Absolutely love security keys and the peace of mind they provide. However it baffles me that every bank I have only allows SMS verification 😒

Ответить
@pointvector1951
@pointvector1951 - 28.04.2023 03:28

2fa is perfect in every way. Everyone should have it, despite it being a pain in the ass. It's impossible to get around and if you do it, it will be impossible for anyone, no matter the circumstances to get your information. THAT is what I've been hearing for years. Why all the backpeddleing now? Oh, it's because cybersecurity wants to sell us a new pos that will be even more problematic if there are ever any issues. I hope every one is in for a lifetime of fun if anything ever happens to these things.

Ответить
@lexshizumdot2115
@lexshizumdot2115 - 27.04.2023 22:27

I bought 2 Security Yubikeys , because they fit my threat model. I still struggle with the "management" part but I'll get there, it's just a matter of finding the more intuitive arrangement, but overall I like this solution a lot. The irony is the few services I use that accept hardweare keys are the (only) ones that accept TOTP. It's all or nothing, so I've decided, whenever it's possible, to delete accounts or services that don't offer at least SMS 2FA.
Thanks a lot for your video, and all your work :)

Ответить
@zigi1337
@zigi1337 - 27.04.2023 21:20

good luck with carrying that around

Ответить
@gmmxn
@gmmxn - 27.04.2023 20:19

I have been using yubikeys for years, I even give them as a birthday present sometimes to friends and family....

Ответить
@mukkaar
@mukkaar - 27.04.2023 20:04

U2f is nice, but personally I would only recommend it for business, including working for yourself. TOTP is frankly more than enough.

Ответить
@An.Individual
@An.Individual - 27.04.2023 19:27

Leaving the yubikey plugged into the laptop sounds like a terrible idea.

Ответить