Another Way to Protect Yourself from 2FA Loss

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • НаукаНаука

Комментарии • 55

  • @dav1dw
    @dav1dw 6 месяцев назад +2

    Just use something like 2FAS app which allows you to backup and encrypted file and even save to google drive. 2FAS also has biometric and PIN locking which google authenticator does not.

  • @purgalimited
    @purgalimited 6 месяцев назад +6

    I think it is clever to save 2fa keys to separate keepass vault. It’s nice to know that I am not alone 😊

    • @MaxPower-11
      @MaxPower-11 6 месяцев назад +1

      That’s exactly what Authy lets you do as a built-in backup feature.

  • @khari83637
    @khari83637 6 месяцев назад +1

    If you must print codes - clear print memory if on shared printer

  • @gtcstorm40
    @gtcstorm40 4 месяца назад +1

    I believe google now does a cloud backup of the codes.

  • @mikemoats2519
    @mikemoats2519 6 месяцев назад +1

    I put Google Authenticator on an old phone. Even though the old phone (Samsung Galaxy S6) does not have service anymore, the authenticator still works. I keep this phone in my safe at home.

    • @regwatson2017
      @regwatson2017 3 месяца назад

      Until you go to turn it on when you need it and the screen has died...

    • @fibercouggocougs8656
      @fibercouggocougs8656 3 месяца назад

      @@regwatson2017 I have more than one phone in the safe that has Google Authenticator on it.

  • @SpiritintheSky.
    @SpiritintheSky. 6 месяцев назад

    I am not too proud to admit that "smart" phones are one area that has always been quite beyond me, in great part because manufacturers attach precious little importance to providing proper, comprehensive instructions. Surely I'm not the only one? Perhaps you would consider "branching out" into that mysterious form of communication?

  • @gwine9087
    @gwine9087 6 месяцев назад +2

    I hate the fact that, in order to use it, I have to have my phone with me. When I am working at my deskstation, at home, I do not tend to have my phone nearby. I prefer to receive a text, which I can access, from my PC.

    • @Knards
      @Knards 6 месяцев назад

      I never use my phone for this, as it is extremely rare I would browse on the phone

    • @purgalimited
      @purgalimited 6 месяцев назад

      Sms is boring 😂 not all sms are available on PC, some services are blocking an access to SMS on PC if there is a passcode sent in sms

    • @bassmaiasa1312
      @bassmaiasa1312 6 месяцев назад

      @@purgalimited What does boring have to do with it? I don't think security is a game.

    • @dfs-comedy
      @dfs-comedy 6 месяцев назад

      I wrote some Perl code to spit out my TOTP auth codes, and I keep the secrets in an encrypted file on my PC. That way, I don't need access to my phone to successfully auth with TOTP.
      Receiving texts is unsafe. If someone hijacks your SIM card, they can get access to your verification codes.

  • @DwarMeji
    @DwarMeji 6 месяцев назад +1

    Thanks!

  • @johnkenney7217
    @johnkenney7217 5 месяцев назад +1

    If you put all these in your "Screenshots", or whatever, folder, how do you tell the difference between them? Isn't there a different QR code for each site, e.g., Fidelity, Citibank? Wouldn't you want to name your snip by the site name? Of course, this gives bad guys a road map, but we're assuming your using encryption or other protection.

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад +1

      I happen to use different folders, but one way or another, yes, you need to identify which service the code belongs to.

  • @lilmsgs
    @lilmsgs 6 месяцев назад +3

    How do you know Google will continue to allow a user to set up 2FA a second time on the same QR code? It seems insecure that they even allow using a QR code twice.

    • @raylopez99
      @raylopez99 6 месяцев назад +1

      Google even has a nasty habit of dropping support for existing products... so I'm holding out on 2FA until it becomes more mainstream.

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +4

      They don't know you set up a second (or third or whatever) device. That's all happening on the device only.

    • @lilmsgs
      @lilmsgs 6 месяцев назад +1

      @@askleonotenboom
      Hummm, I see

    • @dfs-comedy
      @dfs-comedy 6 месяцев назад +4

      There's no way Google can tell which 2FA device you're using.

    • @dfs-comedy
      @dfs-comedy 6 месяцев назад

      @@raylopez99 2FA in the form this video describes is standardized and used by many, many web sites. You really should be using it.

  • @toondesmarets3033
    @toondesmarets3033 5 дней назад

    I put my QR screen shots and codes on a thumb drive. So they are save

  • @Lili-xq9sn
    @Lili-xq9sn 6 месяцев назад

    Not so secret when many apps have access to your photos.

  • @himanshuchhabra1942
    @himanshuchhabra1942 6 месяцев назад +1

    I have 23 accounts set up in Authy app. Do you expect me to turn off 23 accounts 2FA , then create new QR for each account and then save 23 QR codes . ??

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +1

      That's almost exactly what I'm doing, albeit very very slowly. (I'm also moving away from Authy since they're discontinuing the desktop app.) But the video is more a reminder of what to do the next time you set up 2FA.

    • @himanshuchhabra1942
      @himanshuchhabra1942 6 месяцев назад

      @@askleonotenboom Which Authenticator app do u recommend now ???

  • @larrylambert2058
    @larrylambert2058 6 месяцев назад +2

    Why not just use Authy?

    • @libbyd1001
      @libbyd1001 6 месяцев назад +2

      You can. The point here is, what if you lose the device on which you have Authy (or whatever 2fa app you use)? By saving the QR code or text string as outlined in this video, you can get a new/different device, install a new 2fa app and re-create your credentials more easily.

    • @larrylambert2058
      @larrylambert2058 6 месяцев назад +1

      @libbyd1001 as Leo pointed out some time ago, Authy can be retrieved on another device without the original device. Refer to his last overseas trip when he lost his phone. At that time he recommended Authy because Google failed.

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +2

      I also have another article in the pipeline: authy's desktop version is going away.

    • @pipe2devnull
      @pipe2devnull 6 месяцев назад

      Are you sure the QR code and text code are guaranteed to be valid indefinitely?

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +1

      @@pipe2devnull Nothing is EVER guaranteed in this world, especially tech. But it'll work as long as the (lost) 2FA device would have kept working.

  • @thegr8rambino
    @thegr8rambino 6 месяцев назад

    what about microsoft authenticator? is there a similar thing?

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +1

      this technique works with all Google Authenticator compatible apps, of which the MS authenticator is one.

  • @RameshExplorer
    @RameshExplorer 6 месяцев назад

    Please make a video on How to clone a Window 11 Operating system to a USB

    • @andrewmurray1550
      @andrewmurray1550 6 месяцев назад

      Use Acronis to clone the drive. (or similar software).
      You'd need a source drive and target drive; the target would need to be equal to or larger in capacity than the source

  • @Wol747
    @Wol747 6 месяцев назад

    But do I find the QR or text code if I already have my authenticator app set on my phone to do what you suggest, ie keep a copy as a-backup?

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +1

      You can't. That's why you have to turn 2FA off, and then turn it back on again to get a new code.

    • @dfs-comedy
      @dfs-comedy 6 месяцев назад +1

      Most good authenticator apps let you export the secrets. For example, Google's app will let you export it as a QR code; you can take a picture of that and it becomes your backup.

    • @Wol747
      @Wol747 6 месяцев назад

      I@@dfs-comedy I've got the Google authenticator and if it"s got a way of doing that it's well hidden!

    • @Wol747
      @Wol747 6 месяцев назад

      @@askleonotenboom I don't get it: isn't the suggestion that one has a copy of the actual app settings? I see no way of copying these in the Google app so if I lose my phone (actually unlikely since I rarely carry it, but however!) I'v got no way of retrieving the use of it on another phone.

    • @askleonotenboom
      @askleonotenboom  6 месяцев назад +1

      @@Wol747 This is something you do when you first setup 2FA. If your app doesn't allow export (as many do not), then you need to turn off 2FA, and turn it on again to capture the new code.