Forget Google Authenticator. THIS Secure Method is Even BETTER

preview_player
Показать описание

Get $5 off any Yubikey (2 max) using code ALLTHINGSSECURED at checkout.

If you care about your personal security and privacy online, download my free security checklist here:

🔹🔹🔹What You Should Watch Next🔹🔹🔹

We've got a lot of great privacy- and security-related content here on the All Things Secured YouTube channel (although we admit we're a bit biased). If you're wanting to increase your online cybersecurity, here's what's next:

🔹Support All Things Secured (Recommended Services)🔹
If you enjoy this kind of practical security and privacy content, one of the best ways you can help support this channel is by using these affiliate links to our favorite products and services. When purchasing through these links, you not only get the best available deal, the companies will also pay us a small commission. Thank you for your support!

*********************
Video Timestamps
*********************
0:00 - Authenticator Apps have a Problem
0:29 - Basics of 2 Factor Authentication
1:09 - How Yubico Authenticator is Different
2:13 - Yubico Authenticator Setup Tutorial
3:40 - FAQ for Hardware Authenticator apps
4:58 - 2FA is NOT too Difficult
*********************

The problem with using Google Authenticator, Microsoft Authenticator, Authy, Duo or one of the many other 2FA authenticator apps is this: what happens if you lose your phone, it gets stolen, or you want to have access from multiple devices? That's where hardware based solutions like this one from @Yubico are useful. They're also more secure. Here's how to use it.

#cybersecurity #onlinesecurity #yubikey
Рекомендации по теме
Комментарии
Автор

I've been using Authy and have it on my phone, computer, and laptop. If I lose my phone or it gets destroyed I just install it on the new one or access it on another device. Seems like you would be in a real bind if you lost the key while traveling and your other key was at home. On the other hand, I suppose it is more secure to use a physical key. I like the idea, but the thought of losing it while away from home is an issue for me.

billyrogers
Автор

My IT guy recommended getting 2 keys and keeping one in a safety deposit box in case the first is lost or destroyed. Good idea?

billwall
Автор

This is brilliant! I didn't know about the password to protect access to the Key itself! Thanks a million Josh

steveshuffle
Автор

"it doesn't matter that my son drops a hammer over my phone" hahaha nice one my friend

carnavalesenpanama
Автор

I've been playing around with a Yubikey for a couple of months and, while it's a really good product from a security standpoint, real-world usability is a problem for me. In particular, my most sensitive accounts (banking, developer account, company production environment, etc.) are ones I may need to access at a moment's notice, if there's an issue. If I lose my tiny Yubikey, I'm locked out of those accounts until I can retrieve the backup. Often, if I'm traveling on business, that can be a matter of days later, making the Yubikey a potential risk to my business. This means I need to have another means of managing 2FA, which ends up being an app on my phone. But then, why bother with the Yubikey at all?

tsundokujim
Автор

Thanks a ton, Josh. I've been learning a lot because of your videos. Best regards from Germany.

AlexanderPochertPiano
Автор

I like microsoft authenticator because your MS account has the option of being passwordless and even if your phone breaks you can get back into it with a backup email...though obviously a yubikey is technically more secure, it's overkill for most people, though it makes sense to use it on your most important accounts.

surinder
Автор

Authy can be backed up and also used on multiple devices.

kouroshaalai
Автор

I really appreciate your videos, I subbed and I'm binge watching them because you are doing a great job.

williamwilliams
Автор

I was under the impression that an account requesting google authenticator had to use google authenticator changes everything :D
Thanks Josh :)

Guitargasm
Автор

Around 4:18 you say you can use 2FA on an unlimited number of accounts.... I think you should clarify that's only for FIDO U2F, but not for FIDO2 (limit is 24 unless I understood something wrong, I'm just a noob yet) .. OK OK .. FIDO2 is probably not considered "2nd factor", because it's passwordless.. There is no "second", it's "all in one."

sermarr
Автор

Hi, 1:56 is this available only for theier ~50$ Yubikey or also for their 25$ Security Key?

kaori-
Автор

Too expensive in Brazil, it isn’t sold here officially

HowardRoarkBR
Автор

What do you think of combining yubikey with 1password OTP. You could use the yubikey to safeguard the 1password and use the internal OTP from 1password. Which should be easier to share and store (backup). Probably this would be a better idea for the less important accounts (also to circumvent the 32 limit).

lucsegers
Автор

Always loved your format. Also didn't know I can do that with the Keys.
I use Aegis as well to beckup my important 2FA codes.
Will definitely put the most important once in my keys

fredzibulski
Автор

That looks cool. But one thing, is that key degradable like hard disk which degrade with time and corrupt the content.

nightking
Автор

Your videos are very informative and to the point. On another note, Authy has a cloud backup feature that lets you backup the MFA accounts library to a cloud backup (like Google) that you can then restore to a new device in case it gets lost/stolen/damaged. It requires a strong password to accomplish the above. This avoids one having to set up each MFA all over again on the new device. I agree though that nothing beats a hardware key.

MrSoulMonk
Автор

Rather than having a second key, I am thinking to save the seeds in some encrypted file (like a keepass db) and store that file in a secure offline location. The rationale is: suppose I lose my primary key, and only then find out my backup key is broken. If you have ever found yourself on the side of the road with a flat tire, only to find out your spare was never inflated, you know what I mean. It takes some discipline to test backups regularly. But I am new to physical devices so I am willing to change my mind once I get some experience.

robertturtle
Автор

Where do you store the stick? If someone stole your phone and stick, then he has everything he need? So where is save place for the stick eg I am at the beach? Waterproof neckbrace?

DieTabbi
Автор

Excellent!! video Josh. I am learning a lot from you.

Daniel-bbpy