Upgrade your Discord Account Security!

Sdílet
Vložit
  • čas přidán 16. 07. 2024
  • Discord released a brand new update available to everyone that allows you to make your Discord account more secure. But it does have some drawbacks and it's not going to allow you to dive head first into discord without your brain enabled.
    Discord scams have been extremely prevalent, and general good practice says that we should always secure our important accounts with two factor authentication. But there are drawbacks, your 2FA code could be phished through a devious Discord login page. Only if there was a system that could make it nearly impossible for a normal person to fall for a phishing page...
    SOCIALS
    -----------------------------------------------------------------------------
    Discord Server
    / discord
    Twitter
    / notexttospeech
    TIMESTAMPS
    -----------------------------------------------------------------------------
    00:00 - Security Keys!
    00:45 - 3 Reasons why security keys are better
    01:51 - 2. Backed up in the cloud
    02:44 - 3. Easy to use
    03:27 - How it works
    04:29 - Set up and Use
    06:48 - Drawbacks
  • Věda a technologie

Komentáře • 617

  • @rhettorical
    @rhettorical Před 8 měsíci +413

    As always, security comes down to users being stupid far more than anything a hacker could come up with.

    • @clipbitlocker
      @clipbitlocker Před 8 měsíci +2

      .... or old. Wait till you 5 years older. Then you learn how hard it is to keep up.

    • @BigJemu
      @BigJemu Před 8 měsíci +33

      @@clipbitlocker skill issue

    • @bloosixjr7505
      @bloosixjr7505 Před 8 měsíci +2

      No lol. Data leaks on other websites are very common, and if you reuse a single password, that could get your account compromised.

    • @clipbitlocker
      @clipbitlocker Před 8 měsíci

      @@bloosixjr7505 Correct and data leaks and data breaches happen for 2 main reasons. There's an insider (social engineering) or people are so old that they are not aware of safe cybersecurity practices. How many people out there have a grandma/grandpa that has been tricked by scam?

    • @davemiller638
      @davemiller638 Před 8 měsíci +8

      @@bloosixjr7505 What if I reuse a married password?

  • @breadmachine_official
    @breadmachine_official Před 8 měsíci +396

    *HEADS UP!*
    Passkeys with QR codes are safer than the Discord login QR codes because the device connects to the PC via Bluetooth. This means if you don't have Bluetooth built-in to your PC or you don't have a USB Bluetooth adapter, the QR code will not appear to log-in.

    • @Paul_11232
      @Paul_11232 Před 8 měsíci +20

      ​@@nanopiyou not existing helps too

    • @suryasrivastava8174
      @suryasrivastava8174 Před 8 měsíci

      Yes

    • @suryasrivastava8174
      @suryasrivastava8174 Před 8 měsíci

      Jk 1:52

    • @BobOrKlaus
      @BobOrKlaus Před 8 měsíci +8

      Thank you, if noone told me it doesnt work without bluetooth I would have sat here wondering why it doesnt work for me

    • @candianatan
      @candianatan Před 8 měsíci

      xd. Its fun but it happend to me too a time ago@@BobOrKlaus

  • @Pengal25
    @Pengal25 Před 8 měsíci +58

    That gaming computer just to watch CZcams was the biggest callout

    • @nostalgicumbry3279
      @nostalgicumbry3279 Před 8 měsíci +2

      I feel so seen. Bought a new computer a few years ago just to play runescape and watch youtube.

    • @SonOfSparda03
      @SonOfSparda03 Před 8 měsíci

      I bought a top of the line PC and I only play league so pretty much yea

    • @OriginBullet
      @OriginBullet Před 8 měsíci

      I feel personally attacked 😅

  • @Kodufan
    @Kodufan Před 8 měsíci +95

    A little thing about the analogy. The two numbers will be prime numbers, meaning that the result has one and only one set of two numbers to make it. It is really, REALLY hard to crack. You basically need to just guess and check

    • @maxomega3
      @maxomega3 Před 8 měsíci

      very well put. His explanation was spot on except for this

    • @supramaxis
      @supramaxis Před 8 měsíci +1

      once i saw this comment i thought of the modular multiplicative inverse operation

    • @alizardguy
      @alizardguy Před 8 měsíci +1

      omg kodu haiiii

  • @Maxime-fo8iv
    @Maxime-fo8iv Před 8 měsíci +26

    Fun fact: You don't have to "wait until the code refreshes because you can't type the numbers fast enough because you only had 2 seconds left to put them in" (2:49): just enter the code that you see and it will just work, even after the code disappeared!

    • @MasicoreLord
      @MasicoreLord Před 8 měsíci +8

      from my experience not long after it disappears that code would have expired, assuming the device you were using's clock is synced closely

    • @chlorobyte_projects
      @chlorobyte_projects Před 8 měsíci +9

      Indeed. That authentication system actually checks 3 separate codes - the one for the current time, and the one before and after, so assuming your system time is synced up, that code will work for a whole 30 more seconds.
      ...and now you know that it's technically a 3 in 1000000 chance to guess the code rather than 1 in 1000000.

    • @MasicoreLord
      @MasicoreLord Před 8 měsíci

      @@chlorobyte_projects didn't realize Discord did that, guess it makes sense, since it increases the reliability

    • @FlipPlayzYT
      @FlipPlayzYT Před 8 měsíci

      so a 1/333333 chance@@chlorobyte_projects

  • @Schwanz250
    @Schwanz250 Před 8 měsíci +39

    I never thought Discord would think about our security

    • @aeswere
      @aeswere Před 8 měsíci

      @@VaultCord I think checking the device hardware/whatever would also help, or whenever a page is reloaded it checks if the device is still the device prior to loading, having you reauthenticate if whatever marker they use is changed. I'm sure there's probably a simpler way but this sounds secure, no?

  • @crowruin2
    @crowruin2 Před 8 měsíci +206

    For anyone wondering you can use just Security Keys as 2FA
    You do not need to have TOTP as a backup
    Also remember to save those backup codes in-case you lose your Yubikeys

    • @D0Samp
      @D0Samp Před 8 měsíci +3

      The same way you should have saved your recovery codes for 2FA before, by the way. Otherwise, passkeys only swap out your password (which has relatively little entropy compared to the usual public-key system) for a challenge-response authentification.

  • @Shakkael
    @Shakkael Před 8 měsíci

    I understood that great analogy very well! Good job!

  • @elliejohnson2786
    @elliejohnson2786 Před 8 měsíci +2

    I literally just completed a course on cyber security and it talks about these in great detail :D

  • @MoonLightOfficialOwO
    @MoonLightOfficialOwO Před 8 měsíci +6

    I love your vids! Keep it up, please, and I hope you're taking care of yourself :D
    nice analogy 💗

  • @atake176
    @atake176 Před 8 měsíci

    It's such a discord moment. Implementing a log in method that prevents phishing, and leave a thing that is abused by scammers and bypasses your new secure method. God I love discord

  • @n3er0o
    @n3er0o Před 8 měsíci +6

    4:44 there is a little annoyance here with Windows 10 (if you're still using that). Sometimes a window will pop up asking you for your Windows PIN when instead you want to register a physical security key. You need to click cancel on that popup and *only then* the window you show in the video here pops up asking you to confirm your security key. Make sure the setup makes you touch your security key's button or otherwise you just set up Windows Hello with your (probably) very weak Windows password.

  • @KARMA.XD.
    @KARMA.XD. Před 8 měsíci +2

    "On that gaming pc you use to watch youtube" Never felt so called out before lmao

  • @faddybasilisk09
    @faddybasilisk09 Před 8 měsíci +2

    Nice analogy mg 💪💪

  • @kmcat
    @kmcat Před 8 měsíci +45

    4:18 that's not quite right, It generate a semi prime number, the program is looking for two prime number multiplied together that equal the semi prime number from before .
    I'm sure this using U2F which is using Challenge response authentication
    6:31 SIM swapping is a bit pointless as under laying protocol SS7 has a simple SMS redirection vulnerability; that's never getting fixed due to governments using the flaw

  • @Blakegamer7000
    @Blakegamer7000 Před 8 měsíci +3

    To be honest I stopped using Discord a few months ago because I just didn't feel safe on there I use better apps instead.
    But it is nice to see that they're finally adding precautions for this kind of stuff because my old old account got hacked years ago

    • @TechnoMasterBoy
      @TechnoMasterBoy Před 8 měsíci

      Didn't feel safe? What are you sharing, military secrets or some shit?
      Get a good password, it's not hard to make one that's easy to remember AND secure.
      And don't be a brainlet clicking on every link and downloading every file someone sends you.
      If you get hacked, it's your own stupidity that's at fault.

    • @hi-kt3qr
      @hi-kt3qr Před 8 měsíci +6

      Most of the time being hacked is your fault, you used a password that can easily be guessed

  • @mihai.ro09
    @mihai.ro09 Před 8 měsíci

    Hey man I discovered you and I really like your content I’m going to subscribe to you man I really enjoy your content

  • @thenextworstone9050
    @thenextworstone9050 Před 8 měsíci +1

    3:54 Nice analogy!

  • @chazthecheeseguy
    @chazthecheeseguy Před 8 měsíci +315

    Cool! I love securing my account! Good job Discord.

  • @BasicsCodingg
    @BasicsCodingg Před 8 měsíci

    "on that gaming computer you use to watch youtube" i dont like how accurate this is

  • @nico1337
    @nico1337 Před 8 měsíci +32

    I'm using a NitroKey 3A NFC (plus a NitroKey FIDO2 as a backup) because they are fully open source (hardware and software) instead of YubiKey. They do have some drawbacks tho

    • @darwinpolio
      @darwinpolio Před 8 měsíci +1

      whats the drawbacks? might get one

    • @nico1337
      @nico1337 Před 8 měsíci +3

      ​@@darwinpolio YubiKeys are just more well-known and might be better supported. But I can only tell one instance where only YubiKeys were allowed, and that was on Kraken (kinda niche, trading platform). As far as I understand, FIDO2 is a standard, so it's not really a restriction because they can't support others - just because they want to.
      Then NitroKeys are a bit more expensive and the setup for YubiKeys might be a bit easier as they have a bit better fledged out software.
      Just do your own research, but these are no actual drawbacks for my personal taste.

    • @freshcutbackup380
      @freshcutbackup380 Před 8 měsíci +3

      security shouldnt be open-source

    • @nico1337
      @nico1337 Před 8 měsíci

      @@freshcutbackup380 Security by obscurity is not actual security.

    • @electricz3045
      @electricz3045 Před 8 měsíci

      ​@@freshcutbackup380it should. You never ever want to use something poopiotary.

  • @Dragon359
    @Dragon359 Před 8 měsíci +10

    While it was (in relative terms) a more mild hacking I suffered with a discord keylogger, morning grogginess and luck on the end of a hacker who sold me the 'my friend is making a game' while speaking through a friends account he hacked...that was making a game, got my account hacked.

    • @GurkenbauerTim
      @GurkenbauerTim Před 8 měsíci

      Had a similar situation. Bought something overseas (smth from kickstarters) and I was waiting until it finally shipped to me. Then I get an email "Delivery failed, verify address". Luckily I thought about messaging the sender and he told me they didn’t start the delivery and that they still had to prepare my package.

  • @frogybot
    @frogybot Před 8 měsíci

    MAN I *LOVE* sticking till the end!
    I get my hugs and kissies :3

  • @lowwastehighmelanin
    @lowwastehighmelanin Před 8 měsíci

    EFFING FINALLY. I admin several servers I needed this ages ago.

  • @Aurro727
    @Aurro727 Před 8 měsíci

    thank you, very cool mr discord man
    also nice analogy

  • @nikowolfbilger
    @nikowolfbilger Před 8 měsíci

    nice analogy mate!

  • @erinalasacarina
    @erinalasacarina Před 8 měsíci

    what a wonderful analogy

  • @ThatOneNo-Name
    @ThatOneNo-Name Před 8 měsíci +2

    Made security key. Thanks NTTS.
    Nice analogy btw.

  • @anouaro.a7905
    @anouaro.a7905 Před 8 měsíci

    Nice Analogy❤

  • @DerpBurgerPlayz
    @DerpBurgerPlayz Před 8 měsíci +1

    nice analogy

  • @MarioDarkboom
    @MarioDarkboom Před 8 měsíci

    Nice Analogy :)

  • @user-ed4ql5ky8m
    @user-ed4ql5ky8m Před 8 měsíci

    For the people that don't have devices with biometric lock features, you can use your Windows PIN as well if your logged into your Microsoft account

  • @sawrams
    @sawrams Před 8 měsíci +1

    with windows hello you also can use pin code to make security key, did that myself on my youtube- i mean gaming laptop

  • @1HKNG
    @1HKNG Před 8 měsíci

    Nice analogy!

  • @irisbaggins
    @irisbaggins Před 8 měsíci

    Oh, this made me realise I had sms on, which I THOUGHT I'd turned off. Thanks for reminding me :)

  • @Khipher
    @Khipher Před 8 měsíci +9

    As someone who uses the flipper zero’s U2F feature as a security key for literally everything that I can possibly use it for, I see this as an absolute win (I just like using my silly little cybersecurity pentesting device)

  • @depressedraccoon
    @depressedraccoon Před 8 měsíci

    nice analogy mate

  • @bk_bro11
    @bk_bro11 Před 8 měsíci

    Actually not that bad of an analogy. I assume you were explaining hashing and if if you were you explained it almost perfectly.

  • @lepershing1902
    @lepershing1902 Před 8 měsíci

    Nice analogy!

  • @Vlame
    @Vlame Před 8 měsíci +4

    I reported like 6 websites and a Discord server who has this phishing method. the discord server got deleted but 2 hours later a new one was created with the same name and invite link.
    This method was also done using a fake captcha bot. Unfortunately Discord doesn't do anything about it

  • @Lucaplayz200
    @Lucaplayz200 Před 8 měsíci +1

    Nice analogy now hopefully your self esteem is better

  • @k3nt571
    @k3nt571 Před 8 měsíci

    Nice analogy 👍 , your welcome

  • @kubaolszewski890
    @kubaolszewski890 Před 8 měsíci +2

    It just dropped so have fun watching everyone

  • @petertrex
    @petertrex Před 8 měsíci +3

    Actually you can just use your PC's pin, which is pretty convivnient too.

  • @Original_Pedi_Boy
    @Original_Pedi_Boy Před 8 měsíci +1

    in South Africa, i have my Sim Swap set up with my provider that i have to go to my provider store and pysically be present to perform a sim swap, cant be done on the phone and you have to have my physical ID

  • @Kaedahara
    @Kaedahara Před 8 měsíci

    Nice analogy 😊

  • @georgidimitrov2557
    @georgidimitrov2557 Před 2 měsíci

    Thank you buddy 😉😉

  • @Elementening
    @Elementening Před 8 měsíci +1

    nice analogy

  • @wojtekpolska1013
    @wojtekpolska1013 Před 8 měsíci +4

    5:38 uh oh you just showed your backup keys publicly on youtube, this makes it so that anyone can login into your account now by using the backup keys to reset the passkey

  • @Stoned_Penguin
    @Stoned_Penguin Před 8 měsíci

    your outro is hella weird but the content is too good to have a sweet kiss scare me away... 😘

  • @TheAnimeLurk
    @TheAnimeLurk Před 8 měsíci

    At first I was mad at being called out with the gamer pc to watch youtube, but then I was able to put him in his place as I logged in using my webcam with Windows Hello. Thanks for the tip!

  • @ccgm_harpy
    @ccgm_harpy Před 8 měsíci

    I've had a yubico key for a while, happy Discord finally added support. Now my bank needs to get on board!

  • @NorthWARail
    @NorthWARail Před 8 měsíci +3

    I just had my account hacked two days ago i got it back yesterday because discord surprisingly responded in a matter of 1 hour and ik trying to reactivate 2FA but it wont let me. Should i just do the security key thing?

  • @david-zv6yz
    @david-zv6yz Před 8 měsíci

    Nice analogy

  • @EnBunk
    @EnBunk Před 8 měsíci

    A naked man fears no pickpocket.

  • @markzuckerbread1865
    @markzuckerbread1865 Před 8 měsíci +2

    I feel like public-private key cryptography needs to be taught in every school these days, its something you use everyday and can benefit from understanding.

    • @hi-kt3qr
      @hi-kt3qr Před 8 měsíci

      useless, not everybody is a geek

    • @walkacrossit
      @walkacrossit Před 8 měsíci

      ​@@hi-kt3qrinstead they're dumbasses that fall for scams like these

  • @cam4991
    @cam4991 Před 8 měsíci +1

    They should’ve added this years ago. People have been asking for security key support for a really long time

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 8 měsíci

    At 7:30 but that is with every business and phone app devs. Look at what phone apps ask permission for without telling you what permissions are needed.

  • @CZghost
    @CZghost Před 8 měsíci

    I find it funny you plugged in the "pi" in the number slot :D That's not gonna produce an integer, nope. :D

    • @sams_enfp
      @sams_enfp Před 8 měsíci

      The floor function: Am I a joke to you?

  • @影-銀
    @影-銀 Před 8 měsíci

    already using it

  • @abbatrombonelol
    @abbatrombonelol Před 8 měsíci +2

    The best security system is and always will be yourself

  • @Strudlll
    @Strudlll Před 8 měsíci +1

    Bros catchphrase is we'll talk about that later

  • @beanbeanjuice
    @beanbeanjuice Před 8 měsíci

    I'm gonna need to do this for my rotisserie chicken later...

  • @GeneTv
    @GeneTv Před 8 měsíci

    nice anology. Another way of explaining this is that a public key is like a picture of your signature (you know how it looks like but not how to create it). Your private key is the path which the pen will go when writing your signature.
    Now, when you log in to a website that you created the key-pair for, the website will send you a unique challenge (basically a text) every time you log in. When using your biometrics, you allow the browser to use your private key to create a signature. The browser sends back the challenge text with the signature and the website verifies that it's the correct challenge with your correct signature. Even if someone would be able to capture the signed challenge text, they would not be able to use it a second time, since the challenge is different each time.
    Also, scanning that passkey qr code (not the Discord one) with your phone, doesn't sent the actual private key to the computer. Your phone connects via bluetooth, get's the challenge from your computer, uses the private key which is stored on your phone, signs the challenge and sends back the signed challenge to the computer so that the computer can send it back to Discord.

  • @Heufneutje
    @Heufneutje Před 8 měsíci +3

    This is kinda cool but also kinda useless unless Discord starts requiring 2FA more. I found out the hard way that if your login token gets hijacked from your PC Discord will just let someone use that token to change the email address on your account without requiring you to reauthenticate.

    • @Heufneutje
      @Heufneutje Před 8 měsíci

      @@VaultCord To be fair, I'd argue that changing your email address on your account should be inconvenient seeing how commonly it's abused by scammers to lock someone out of their account.

  • @SolarizedPhoenix
    @SolarizedPhoenix Před 8 měsíci +10

    For those who just want ELI5 in security keys;
    The public key is used to encode a message to send to the private key owner. Discord sends your computer a specific question (Challenge) and your PC, with the private key, can read and answer this challenge.

    • @killingtimeitself
      @killingtimeitself Před 8 měsíci

      presumably through reverse pub key it would encrypt it and send it back, unless of course the challenge is non critical. not familiar with the specifics there.

    • @erikkonstas
      @erikkonstas Před 8 měsíci

      @@killingtimeitself Not sure what you're saying, but I'm pretty sure that your "reverse pub key" is, in fact, the private key, which is *EXTREMELY* difficult to get from the public key (this is how all of cryptography works, make it DIFFICULT for the attacker to gain the key).

    • @killingtimeitself
      @killingtimeitself Před 8 měsíci

      i meant reverse pubkey as in reversing the direction of the transaction with another key set@@erikkonstas

    • @schwingedeshaehers
      @schwingedeshaehers Před 8 měsíci

      if you are interessed in it, and know "basic" (probably at least prime, modulo and Fields, and how they are (mathematically) connected) math/Crypto things, it is not that hard

  • @meibear4921
    @meibear4921 Před 8 měsíci

    my brother has a passkey and he usually uses this with discord and that feature was there for him for like 2 months

  • @vodkacsaa
    @vodkacsaa Před 8 měsíci +3

    u did not forget to regenerate ur 8 character security codes right?

  • @CZghost
    @CZghost Před 8 měsíci

    I'm actually thinking of getting myself the Yubi physical USB security key. Honestly it's just a stick I can wear on my keys, and whenever I need to use it, I can just pull the keys out of my pocket, or simply just grab them off a shelf and insert it into the PC. I wear my keys almost all the time on myself. So it makes sense to put it on my keys. I have never lost my keys, there's of course the risk of that, but it's very low. Unless I get really drunk, the chance of losing my keys is next to zero.

    • @kaedenmurphy9937
      @kaedenmurphy9937 Před 8 měsíci +1

      Yeah, that's fair. It's still good to have peace of mind though, because the one day in your life that you *do* lose or damage your keys could be a very bad day if you lost access to all of your accounts.

  • @patrikcath1025
    @patrikcath1025 Před 8 měsíci +5

    Aw yeah, now instead of 2FA (bad) I can use 2FA (good)!

  • @semihguner1
    @semihguner1 Před 8 měsíci +9

    5:38 you SHOULD hide those codes, people can log in using those

    • @george1717
      @george1717 Před 8 měsíci

      Was just going to comment the same thing

    • @GurkenbauerTim
      @GurkenbauerTim Před 8 měsíci +1

      He probably changed them after recording the video.
      It even says that generating new backup codes makes the old ones invalid

  • @kunalsmh
    @kunalsmh Před 8 měsíci

    Let's GO I paused before the kiss !!!

  • @JefferyPlayz42
    @JefferyPlayz42 Před 8 měsíci +1

    thanks for the bye bye kiss it made my day

  • @adorluigi
    @adorluigi Před 8 měsíci

    nice analogy kid

  • @lucas13w
    @lucas13w Před 8 měsíci +2

    me when security key

  • @watch_dog_genesis
    @watch_dog_genesis Před 8 měsíci +3

    Although getting a security key would seem like a good idea, but let's look at it with different eyes:
    -it's another new way of putting smth private under a same lock and key with a master key held up by a creator of said lock and key;
    -you can add your phone/any gadget to that key, but if you lose it/ it gets stolen, you out of luck;
    -all it does is giving a minor setback to hackers, and once it gets passed, we have to think of new ways to secure data;
    All in all, all those security keys and such are for people who uses their account for business(or popular people, eg youtubers), there's no need for such things for normal people, all it does is gives you more paranoia with each new update for security measures.
    At the end of the day, a lock is there to keep an honest folk away, if you have a goal to bypass that lock, you will get it eventually.

    • @schwingedeshaehers
      @schwingedeshaehers Před 8 měsíci

      > At the end of the day, a lock is there to keep an honest folk away, if you have a goal to bypass that lock, you will get it eventually.
      thats corrent in the "real" world, but not to that degree in the "virtual" world.
      there is crypto, that is mathematically secure at least for now, (takes trillion of years to crack)

  • @Libur_kun
    @Libur_kun Před 8 měsíci

    4:30 makes me feel like im storing all the nuclear codes on my discord account

  • @aceofaces
    @aceofaces Před 8 měsíci +5

    Quick tip: Windows 11 has the option for a device as a passkey on Windows Hello. You can pick that option and enroll the phone's passkey. It will even remember your phone to quickly pick it as an option.

  • @ttaylor-st
    @ttaylor-st Před 8 měsíci

    Damn. Literally just migrated away from Discord and they rolled out this cool update... hopefully the Matrix team is working on this, haven't seen any issues/prs though.

  • @OneAndOnlyZekePolaris
    @OneAndOnlyZekePolaris Před 8 měsíci

    Yeah,,,, that SIM card thingy is old news. That is why my first phone has a slot for them but it does not have a SIM card in it. They are not even required the phone companies are just dumbing down security and installing malware anyways via remote.

  • @nastroukapro
    @nastroukapro Před 8 měsíci

    NTTS you don't need to blur QR codes because your phone connects to your PC/laptop with Bluetooth

  • @ggorg0
    @ggorg0 Před 8 měsíci +1

    Just wanna say, that if you use the discord desktop app it will not pop up the QR code for your phone

  • @lzxty6024
    @lzxty6024 Před 8 měsíci +2

    dad when are you coming home with the milk

  • @orangeferdi
    @orangeferdi Před 8 měsíci

    Finally!

  • @DrSoftPawbs
    @DrSoftPawbs Před 8 měsíci

    Gonna use my old Amazon staff yubi key for this

  • @t00k1
    @t00k1 Před 8 měsíci

    tysm bro

  • @lajawi.
    @lajawi. Před 8 měsíci

    I can't activate Touch ID on my iPhone as a Security Key, it asks to scan the displayed QR-code or use an external device (like a YubiKey).

  • @techwhipped
    @techwhipped Před 8 měsíci

    One thing left to ask is this useful even if someone has grabbed a person discord token.

  • @Kyoya26
    @Kyoya26 Před 8 měsíci +1

    Yubikeys are so expensive in my country so, i'll have to pass this 😔

  • @robindenkik
    @robindenkik Před 8 měsíci +15

    5:38 maybe blur these codes lol (unless you generated new ones)

  • @Ruxian
    @Ruxian Před 8 měsíci

    jokes on you i have an industrial grade fingerprint reader configured to my pc

  • @ecdragonlady8006
    @ecdragonlady8006 Před 8 měsíci

    0:30 BRO JUST CALLED ME OUT LMAO 😭😭😭💀💀💀

  • @byrd203
    @byrd203 Před 8 měsíci

    thats not the only way if you enable use pin on the account you can add a windows passkey I did this it works

  • @LoveMeKnot
    @LoveMeKnot Před 8 měsíci +1

    when you found out you still not safe 😅

  • @BenieTheDragon
    @BenieTheDragon Před 8 měsíci +1

    4:57.. What if you use Firefox? I get no popup.

  • @vincentnthomas1
    @vincentnthomas1 Před 8 měsíci

    this is a bit missleading about storing passkeys in the cloud and yubikeys not doing that

  • @HeadshotOtaku
    @HeadshotOtaku Před 8 měsíci

    2:49 I seen been long using the authenticator app browser extension, and based on my experience, is very convenient, since, I don't really use a mobile phone, and I can back up the authenticator keys from the browser extension, and copy paste directly from the browser. But this isn't ideal for anyone with different situations.

  • @cancatervate
    @cancatervate Před 8 měsíci

    nice analogy! 🥵

  • @Lampe2020
    @Lampe2020 Před 8 měsíci +1

    5:38 I hope you changed those after the video, because I think you shouldn't share your backup keys with the internet…

  • @BaxAndrei
    @BaxAndrei Před 8 měsíci

    2:53 2fa codes are still usable 30 seconds after they expire in app