What is “Credential Stuffing”

Поделиться
HTML-код
  • Опубликовано: 10 сен 2024

Комментарии • 31

  • @askleonotenboom
    @askleonotenboom  5 месяцев назад

    ✅ Watch next ▶ Why Password Managers Are [Still] Safer than the Alternatives
    ▶ ruclips.net/video/h_37XLfoHco/видео.html

  • @tedbell4416
    @tedbell4416 5 месяцев назад +4

    Simple video to the point not 5 ads in the middle , you're the best Leo I've ever seen 😁

  • @dicksonkariuki9495
    @dicksonkariuki9495 3 месяца назад

    You have explained it very well

  • @glasslinger
    @glasslinger 5 месяцев назад

    Is same password OK with 2 factor authorization? How could they intercept my phone in time to use the code which is only valid for a minute.

    • @unmapped89361
      @unmapped89361 5 месяцев назад +1

      No, it's not recommended.

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад +1

      Not OK. While 2FA helps, it's still a dangerous practice.

    • @glasslinger
      @glasslinger 5 месяцев назад

      @@askleonotenboom I watch all your help and sometimes don't see the logic in it. How would phone oriented 2 factor authenticating fail? Seems that someone would have to hack your phone, which would be quite difficult. You say it is a dangerous practice. Exactly what is the danger in it?

    • @unmapped89361
      @unmapped89361 5 месяцев назад +1

      @@glasslinger
      1. Would you only use this same password with accounts with 2FA activated, or also with accounts where 2FA is not possible? - Then those latter accounts wouldn't be secure at all...
      2. What form of 2FA are we even talking about? SMS, E-Mail, push-app, TOTP, Security Key, ...? They are not evenly secure... and mostly not 100% secure. And if your password is leaked and everywhere the same, your "2FA" would be reduced to "1FA" then, so to speak...

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад

      @@glasslinger Two factor can be bypassed in real time with a man-in-the-middle attack. askleo.com/two-factor-hack/

  • @garrymcgaw4745
    @garrymcgaw4745 5 месяцев назад +1

    What say they hack your Password Mangers password?.

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад +2

      Then you have much bigger problems beyond just credential stuffing. However most password managers make this EXTREMELY difficult, and difficult to use if ever captured. For example, if your password manager itself supports 2FA, enabling that makes this close to a non-issue.

    • @garrymcgaw4745
      @garrymcgaw4745 5 месяцев назад

      @@askleonotenboom Thanks Leo

  • @pbrigham
    @pbrigham 5 месяцев назад +1

    And the good news is that son, you will not need passwords at all, but until then, do what the guy says.

    • @davinp
      @davinp 5 месяцев назад

      some services like Microsoft offer passwordless accounts. Some are starting to offer passkeys

  • @dee23gaming
    @dee23gaming Месяц назад

    Nothing beats pen and paper. Just now they hack password managers 😅

  • @Serai3
    @Serai3 5 месяцев назад +1

    The safest way to remember your passwords is to WRITE THEM DOWN. Stop trusting the cloud or some program . ANY of those can be hacked. WRITE THEM DOWN with your own hands.

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад

      I respectfully and strongly disagree. askleo.com/are_password_managers_safe/

    • @Serai3
      @Serai3 5 месяцев назад +1

      @@askleonotenboom Yes, they're safe - until they aren't. Nope, sorry. I've seen too many dustups where people lost a bunch of info which had been assured safe. I keep a notepad with my passwords and I write them down. Unless someone is specifically going to come to my house and root around trying to find it, that's where they stay. No internet setup is safer than simply not being there at all.

  • @JimE6243
    @JimE6243 5 месяцев назад

    Guilty!
    How do I get over the fear of using a password manager and that I am not in control? I have a fear of one day I'll wake up and be locked out of everything because I do not have the password on my secret cheat sheet.
    I keep telling myself that I should but fear always sets in and takes over. JimE

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад

      Two articles for you:
      askleo.com/are_password_managers_safe/
      askleo.com/lose-access-to-my-password-vault/

    • @JimE6243
      @JimE6243 5 месяцев назад

      @@askleonotenboom Thanks again Leo. I'll read them both and try to gain some confidence. JimE

  • @franciscohorna5542
    @franciscohorna5542 5 месяцев назад

    you ever been a victime of this b4 the problem is ppl are using week passwords

    • @unmapped89361
      @unmapped89361 5 месяцев назад +1

      If you use the same password on every site, it is not important whether the password is strong or weak - if your password get's leaked, it's leaked... and can be used on your every site

    • @franciscohorna5542
      @franciscohorna5542 5 месяцев назад

      @@unmapped89361 yes i know but strong passwords is a must to to may ppl use weak ones hope that helps

  • @er...
    @er... 5 месяцев назад +1

    Two videos in one day...and you're wearing a suit (or is that a jacket)? What's going on here?

    • @grahampalmer
      @grahampalmer 5 месяцев назад

      Must be cold, it looks like a thermal jacket.

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад +1

      Two videos: an accident. No video Friday to make up for it. :-)
      That's a light zippered sweatshirt. Sometimes it can be a little chilly.

    • @er...
      @er... 5 месяцев назад

      @@askleonotenboom No video Friday? But today is Friday...and there's a new vid!

    • @GnomeChomsky1928
      @GnomeChomsky1928 5 месяцев назад

      @@askleonotenboom Pace yourself Leo, you might run out of topics/issues to discuss. lol.