2FA: Two Factor Authentication - Computerphile

2FA: Two Factor Authentication - Computerphile

Computerphile

6 лет назад

500,680 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

Roast Beefy Weefy
Roast Beefy Weefy - 30.04.2023 03:29

edna. mode.

Ответить
Codeface
Codeface - 16.04.2023 18:02

how did we get from "more factors help" to "oh and the additional factor cannot just be random, let's look at this HMAC" ?

Ответить
Shoshin Zen
Shoshin Zen - 04.04.2023 08:39

Is there any research papers regarding this, or something explaining the technical side a bit more?

Ответить
LittleRockSix
LittleRockSix - 25.03.2023 21:04

wait wait wait wait....

I figured command override passwords in star trek was always to be used in an emergency from anywhere on the ship/base therefore necessitating a voice activation through the computer voice terminal. Of course it will be a one-time or few time use within the actual emergency and to be updated immediately after use.

For extremely delicate and serious uses you need both the captains and the commanders and/or chief engineers concurring inputs.
i.e self-destruct activation.

Ответить
Shan Batej
Shan Batej - 30.11.2022 04:10

Do keys make you secure? like hardward, like the yubikey 5c nfc?

Ответить
Анатолий Анатолий
Анатолий Анатолий - 13.09.2022 10:41

You could have stored all your TOTP keys in a separate database of a password manager and, once you phone has broken down, you'd ask a friend for a substitute phone for a few weeks if they have a spare obsolete model, and you'd install the password manager there and the TOTP base.

Your story about the two weeks without TOTP is actually what happens when you know enough to set up a password manager and use a password database regularly but forget to set up proper backup system BEFOREHAND. If you TOTP base exists only on your phone and doesn't get backed up regularly and often enough, then when you phone breaks you'll lose it, so find out how to better sync and backup stuff from your many clients. And better use cloud + encryption for one of the backup copies, but also have a few local ones. And maybe store the backups in such a way so that you'd have 3 (2 local and 1 in the cloud) up-to-date ones and 3 (2 local and 1 in the cloud) 1 day or so late, and also have version control for all your backups, that way, even if you do something wrong and the new backup isn't right, the version control will have the previous version and the 1 day late scheme will save you from re-writing a backup repo with a repo that has a corrupted index.

Check out BorgBackup.

Ответить
Kisan Nepal
Kisan Nepal - 07.09.2022 12:36

02700400143663000001

Ответить
DM 👉@Mistressballe
DM 👉@Mistressballe - 21.06.2022 13:02

☝️☝️☝️The name above me fix 2fa problem. contact him now if you need help

Ответить
DM 👉@Mistressballe
DM 👉@Mistressballe - 21.06.2022 13:02

☝️☝️☝️The name above me fix 2fa problem. contact him now if you need help

Ответить
ScoopsPatartes
ScoopsPatartes - 23.05.2022 08:37

I noticed some apps like discord have backup codes displayed on the actual app just in case you do not have access to your authenticator apps. Is this a security flaw? It seems like it could be. Feels like it defeats the purpose.

Ответить
Omar Qunsul
Omar Qunsul - 15.05.2022 12:56

Which previous video was he referring to?

Ответить
Angelito Torrejos
Angelito Torrejos - 10.05.2022 09:02

My brain cells just died listening to his explanations lols

Ответить
Robert R.
Robert R. - 27.04.2022 22:49

And I thought I was a nerd!

Ответить
John G.
John G. - 20.03.2022 15:41

it's not so much identify you are who you say you are, it is more knowing some information that is harder to know. for instance if you have access to a mobile phone, you have access to ALL the apps on that phone, be that an authenticator app, a stored password database, that doesn't mean the person is you. but it is harder for some other person on the other side of the world having access.

Ответить
DM 👉@Mistressballe
DM 👉@Mistressballe - 10.03.2022 12:07

👆👆👆The name I'm pointing help me fix mine. Contact he now if you also need help...

Ответить
DM 👉@Mistressballe
DM 👉@Mistressballe - 10.03.2022 12:07

👆👆👆The name I'm pointing help me fix mine. Contact he now if you also need help...

Ответить
ぽてとです
ぽてとです - 12.12.2021 16:29

素晴らしい👏
って言いたいけど内容わかんないし英語もわかんないや!

Ответить
Benjofrencho🇭🇹
Benjofrencho🇭🇹 - 12.12.2021 03:20

When a Fortnite player looks at this...

Ответить
grayuh
grayuh - 11.12.2021 14:26

i lost my account 2fa

Ответить
Blz_W
Blz_W - 07.12.2021 12:18

Fortnite

Ответить
Hulfstop
Hulfstop - 06.12.2021 13:01

Your talking about fortnite

Ответить
Synth Wave
Synth Wave - 05.12.2021 17:43

Several times now, they have done a SIM swap and the hackers got hold of the text message with the code and then logged in. After this, our company will never use SMS text for MFA again.

Ответить
Ken
Ken - 02.12.2021 11:08

I log in with the factor of the way I am. This is the hardest to get since it can only be found on every single social media app I use and changes every tenth of a nanosecond.
For example right now I self identify as a non-binary loathing banana that's sexually attracted to fleas.

Ответить
Polkarfield
Polkarfield - 02.12.2021 02:35

Either I use it and be paranoid I’ll loose access to the email/number I use, or don’t and be paranoid someone will really easily breech my things.

Ответить
K S
K S - 09.11.2021 15:20

Perhaps in Star Trek their communicator provides an exact location, and it verifies both the voice and the location of the voice match.

Ответить
K S
K S - 09.11.2021 15:18

Unix time is UTC

Ответить
Tommaso Scervino
Tommaso Scervino - 01.11.2021 19:58

Ti adoroooo

Ответить
Pinefenario
Pinefenario - 29.10.2021 00:30

Idea : scan the qr code for 2fa with multiple devices. Yes the security is a little less, but if your phone gets broken you still have the totp on your other phone…. I don’t know if you guys are reading this in 2021. But could you do a video about the mathematics behind webauthn?

Ответить
stxllr
stxllr - 24.10.2021 06:58

Thanks dude, this was very helpful, you're carrying my CS exam right now. :)

Ответить
Slaymoose1239
Slaymoose1239 - 21.10.2021 02:46

Hi

Ответить
eduardo arturo
eduardo arturo - 18.10.2021 04:39

Bro 2fa fortnite

Ответить
Everime
Everime - 25.09.2021 07:33

meh boy mike has the most loveable facial expressions and way of speaking.. like idk its just soo nice to just watch

Ответить
Xeridea
Xeridea - 08.08.2021 21:18

Computer security, verify you are who you say you are. US voting.... anyone can vote for anyone else.

Ответить
Muntaha Zaqzouq
Muntaha Zaqzouq - 22.06.2021 14:57

Hi
Can anyone help me retrieving my permenantly disabled facebook account?

Ответить
Sobanya
Sobanya - 26.05.2021 14:36

We get crazy internet speeds, but can't get SMS in time or ever. That's my main problem with two factor

Ответить
Shiva Shiva
Shiva Shiva - 22.05.2021 21:15

Спасибо

Ответить
beerprayer
beerprayer - 11.05.2021 16:10

why wouldnt 2fa be read first then the password. So that people couldnt social engineer your password?

Ответить
Krysta
Krysta - 05.05.2021 21:08

Omg all thanks to those who recommended me to Shield_cr4ack on Instagram he’s a pro, he unlocked my PC all thanks to him

Ответить
Lord Darth Deth
Lord Darth Deth - 26.04.2021 08:43

@Comupterphile. I am wrong for presuming that 2FA to work, I must have a KEY that corresponds to my Facebook profile to gain access? My situation is that my account was hacked and then the activated the 2FA feature that I hadn't previously used. Facebook confirmed that I was hacked, but since I was logged out on my other devices, I can't access the key. I've contacted FB, but they've been giving me a hard time... They won't deactivate/bypass the feature and won't send me text authentication instead... What can I do?

Ответить
G
G - 25.04.2021 05:24

Who is this guy?? He should be an educator. Fantastic speaking and explanatory skills!

And btw, to whom is he speaking? Is he being interviewed/ Why else does he looks past the camera?

Ответить
erf
erf - 22.04.2021 18:11

NO do not enable this feature you will lose access to your accounts if
you lose access to your original phone numbners do not use

Ответить
mocire
mocire - 20.04.2021 17:58

so my master password is 11 characters long with symbols, upper and lower case letters and digits. would this be considered strong or weak?

Ответить
g lazare
g lazare - 10.04.2021 20:40

I learned so many things that my university didn't really teach me in this channel Thank you guys

Ответить
Luigi Cotocea
Luigi Cotocea - 17.03.2021 14:57

Clicks video: lets talk how i lost a discord account due to 2FA

Ответить
Jayden the Math Guy
Jayden the Math Guy - 17.03.2021 04:49

Nobody:
Computerphile: Ah let’s start talking about passwords-

Ответить
YOYO
YOYO - 12.02.2021 05:47

Save your keys for you 2fa in your password manager folks

Ответить