Storing 2FA in Your Password Manager: Is it Safe?

00:05:41
https://www.youtube.com/watch?v=xHEX6wWYgS0

Résumé

TLDRDie video bespreek die vraag of dit verstandig is om jou twee-faktor-authentifikasiekodes saam met jou wagwoorde in 'n wagwoordbestuurder te stoor. Die spreker noem die voordele van gemak en verhoogde sekuriteit teen hackpogings, maar waarsku ook teen die risiko's van om alles op een plek te hê, soos 'n inbraak op jou toestel of wagwoordbestuurder. Hy raai aan om MFA apart van wagwoorde te hou, hoewel dit 'n vraag van persoonlike veiligheid en gemak is. Inderdaad, dit bly belangrik om MFA in plek te hê, selfs al is dit in jou wagwoordbestuurder, en die spreker moedig kykers aan om 'n gesonde benadering tot sekuriteit te handhaaf.

A retenir

  • 🔑 MFA in 'n wagwoordbestuurder is gemaklik, maar het risiko's 🍵
  • 🛡️ Meer sekuriteit as jy jou MFA aparte hou 📱
  • 👨‍💻 'n Hoof rede van hackings is databreach, nie die bestuurders nie 🔐
  • 🧩 Gebruik sterk, unieke wagwoorde om jou rekeninge te beskerm 💪
  • 💡 Maak seker jy het ten minste een vorm van MFA, al is dit in 'n wagwoordbestuurder 🔑
  • 📊 Voorkoms van wagwoordbestuurder breuke is laag, maar steeds 'n moontlikheid ⚠️
  • 🚀 'n Aparte toestel vir MFA kan jou sekuriteit verbeter 📱
  • 🔄 Moderne dienste maak dit makliker om MFA apart te hou 🛡️
  • 🤖 Probeer verskillende dienste soos Proton Pass vir beter veiligheid 🌐
  • 📩 Nie opwagting om MFA te gebruik weens sekuriteit nie, implementeer dit dadelik! ⏰

Chronologie

  • 00:00:00 - 00:05:41

    Die vraag oor die gebruik van 'n wagwoordbestuurder soos Keypass om wagwoorde en twee-faktor-ouerontslagkodes te stoor is belangrik en het oor die jare ontwikkeling ondergaan. Daar is verskeie voordele, insluitend gerief en veiligheid, aangesien die meeste aanvalle deur datalekke kom. Dit beklemtoon die belangrikheid van sterk, unieke wagwoorde en die beskerming wat twee-faktor-ouerontslag bied. Daar is egter 'n nadeel, naamlik die sentralisering van al jou sensitiewe inligting. Dit kan 'n probleem wees as jou toestel nie goed beveilig is nie, soos in openbare ruimtes. Die risiko van 'n data-oortreding van die wagwoordbestuurder self is ook 'n bekommernis, maar dit is 'n geringe waarskynlikheid. Dit is belangrik om jou bedreigingsmodel in ag te neem en te oorweeg om jou MFA-kodes op 'n ander toestel te hou. Die moderne vermoë om ander dienste soos Proton Pass en Entheo te gebruik, maak dit maklik om dit apart te hou, wat 'n veiliger benadering kan wees. Alhoewel dit 'n gerieflike opsie is om MFA in jou wagwoordbestuurder te hou, is dit steeds beter om dit afsonderlik te hou indien moontlik.

Carte mentale

Vidéo Q&R

  • Is dit veilig om MFA in 'n wagwoordbestuurder te stoor?

    Ja, dit bied gemak, maar dit verhoog ook die risiko as jou wagwoordbestuurder gekompromitteer word.

  • Wat is die nadele van die stoor van MFA-kodes in 'n wagwoordbestuurder?

    Die groot risiko is dat as iemand toegang tot jou wagwoordbestuurder verkry, hulle ook toegang tot al jou MFA-kodes het.

  • Wat is 'n beter alternatief vir die stoor van MFA-kodes?

    Dit is beter om jou MFA-kodes op 'n aparte toestel of in 'n aparte program te hou.

  • Is daar enige risiko's verbonde aan wagwoordbestuurders?

    Ja, selfs al is daar 'n lae kans op 'n breuk, kan dit steeds gebeur.

  • Waarom is dit belangrik om sterk, unieke wagwoorde te gebruik?

    Dit help om jou rekeninge te beskerm in geval van 'n databreach.

Voir plus de résumés vidéo

Accédez instantanément à des résumés vidéo gratuits sur YouTube grâce à l'IA !
Sous-titres
en
Défilement automatique:
  • 00:00:00
    okay oh my gosh I this is this is like a
  • 00:00:02
    historically good question so I'm I want
  • 00:00:04
    to go ahead and like tackle this do you
  • 00:00:06
    think that using keypass for saving your
  • 00:00:08
    passwords and your two- Factor
  • 00:00:09
    authentication codes is a good idea so
  • 00:00:12
    um this is a question that's come up a
  • 00:00:15
    lot um over the years and I kind of
  • 00:00:18
    evolve my opinions over time but I think
  • 00:00:20
    overall it's overall stayed the same so
  • 00:00:23
    really the question here here is should
  • 00:00:25
    you store your multiactor authentication
  • 00:00:27
    codes inside of your password manager
  • 00:00:30
    where your passwords exist I'm going to
  • 00:00:32
    give you some pros the pros obviously
  • 00:00:35
    convenience um two you're still getting
  • 00:00:38
    a lot of security right because the main
  • 00:00:40
    reason we have multiactor like the the
  • 00:00:43
    main attack that we see out in the wild
  • 00:00:45
    is there's a data breach and they leak
  • 00:00:47
    your
  • 00:00:48
    password and you know people are going
  • 00:00:51
    to go on they're going to get your email
  • 00:00:52
    they're going to get the leaked password
  • 00:00:53
    they're going to put it in and they're
  • 00:00:55
    going to get into your account if you
  • 00:00:56
    have MFA set up they're going to go oh
  • 00:00:58
    crap there's MFA
  • 00:01:00
    can't get in you you can still do that
  • 00:01:03
    you have the same amount of protection
  • 00:01:04
    whether or not your MFA is in your
  • 00:01:06
    password manager the likely attack
  • 00:01:08
    Vector is not someone hacking into your
  • 00:01:10
    password manager the likely attack
  • 00:01:13
    Vector is a specific service or multiple
  • 00:01:15
    Services being caught in a data breach
  • 00:01:17
    that leaks some of your information this
  • 00:01:20
    is why it's very important to use strong
  • 00:01:21
    unique passwords and that's what a
  • 00:01:23
    password manager comes in and it's also
  • 00:01:25
    why it's good to have multiactor
  • 00:01:27
    authentication even if it's in your
  • 00:01:28
    password manager because then if there
  • 00:01:31
    is any of that leakage then they still
  • 00:01:34
    won't get access into the account so
  • 00:01:37
    those are kind of the pros and why I
  • 00:01:38
    think it's good and it overall like if
  • 00:01:41
    if you don't have MFA at all and what's
  • 00:01:43
    stopping you is you don't know whether
  • 00:01:45
    or not to set up MFA in your password
  • 00:01:47
    manager do it right now because having
  • 00:01:49
    MFA in your password manager is hands
  • 00:01:52
    down objectively going to give you
  • 00:01:54
    better security than having no MFA and
  • 00:01:57
    just a password manager so already want
  • 00:01:59
    to start with that in terms of cons I
  • 00:02:02
    think this is very obvious and it's why
  • 00:02:04
    people ask the question you have
  • 00:02:06
    everything in one place so while that is
  • 00:02:09
    an issue here are the situations the
  • 00:02:12
    specific situations where I think it is
  • 00:02:13
    an issue one there's endpoint security
  • 00:02:17
    right so you have let's say key pass you
  • 00:02:19
    ask about keypass let's say have keypass
  • 00:02:21
    a password manager that's installed on
  • 00:02:22
    your computer but let's say your timeout
  • 00:02:25
    is set to 1 hour and let's say you're at
  • 00:02:27
    a coffee shop you leave your computer
  • 00:02:28
    unlocked keypass is still locked there's
  • 00:02:30
    no timeout you go to the bathroom
  • 00:02:32
    someone takes your laptop now they have
  • 00:02:34
    access to all your passwords and all
  • 00:02:36
    your MFA in one place whereas if you had
  • 00:02:39
    a multiactor authentication separate
  • 00:02:40
    from that like maybe on your phone they
  • 00:02:43
    would have had to take both devices and
  • 00:02:44
    they would have had to unlock both
  • 00:02:46
    devices to get into your most sensitive
  • 00:02:48
    accounts so endpoint security is
  • 00:02:51
    improved when you're able to migrate MFA
  • 00:02:53
    onto a different device or like a
  • 00:02:55
    different program even that's locked
  • 00:02:57
    with a different password anything you
  • 00:02:59
    can can use to separate will give you
  • 00:03:01
    better security the other situation
  • 00:03:03
    where it's beneficial this is extremely
  • 00:03:05
    rare and I think it is the more common
  • 00:03:06
    thing people are concerned about is some
  • 00:03:08
    kind of password manager data breach
  • 00:03:10
    where your password manager itself leaks
  • 00:03:13
    all the data to some hacker or a hacker
  • 00:03:15
    breaks into your password manager
  • 00:03:18
    remotely I want to make this clear
  • 00:03:20
    highly unlikely to ever happen even the
  • 00:03:23
    worst password data breaches that we saw
  • 00:03:24
    with the last pass I don't believe like
  • 00:03:27
    ever leaked necessarily like everyone's
  • 00:03:29
    MFA and passwords all in one place so
  • 00:03:32
    even if you use last pass during their
  • 00:03:34
    crazy data breach with MFA in last pass
  • 00:03:37
    you still would have been pretty well
  • 00:03:39
    off at the end of the day but I still
  • 00:03:41
    don't recommend it if that's your main
  • 00:03:43
    concern so this is always going to come
  • 00:03:45
    back to being a threat model question I
  • 00:03:47
    personally do not keep my tofa codes
  • 00:03:49
    with my password manager um mainly
  • 00:03:52
    because it's so convenient nowadays to
  • 00:03:53
    keep it separate so back in the day when
  • 00:03:55
    it was just Aegis and like you know
  • 00:03:58
    something for iOS but they didn't even
  • 00:03:59
    in sync um it was hard to do that and
  • 00:04:02
    back then I was more open to saying like
  • 00:04:05
    yeah just keep it in your password
  • 00:04:06
    manager cuz it's far more convenient but
  • 00:04:08
    I'm going to be real like I'm using
  • 00:04:10
    proton pass and enteo right now and the
  • 00:04:12
    convenience factor isn't that different
  • 00:04:15
    like anoth has Cloud syncing so it can
  • 00:04:17
    be on all of my devices it's a really
  • 00:04:19
    clean interface super clean to use and
  • 00:04:22
    proton pass you know I've already made
  • 00:04:24
    my thoughts clear I think it's a
  • 00:04:25
    wonderful password manager super
  • 00:04:27
    efficient super convenient and yes
  • 00:04:29
    Technic technically like it would save
  • 00:04:30
    me a few seconds maybe like each time
  • 00:04:33
    I'm logging in uh via proton pass cuz it
  • 00:04:35
    would AutoFill in the top code but like
  • 00:04:39
    it's not that inconvenient so um pretty
  • 00:04:42
    much I think that if you're able to do
  • 00:04:44
    it and you're willing to try a different
  • 00:04:45
    service give it a shot I actually think
  • 00:04:48
    that we're getting to a place now where
  • 00:04:49
    it's pretty easy and not that big of a
  • 00:04:52
    deal for me to recommend keeping them
  • 00:04:53
    separate mostly because of enteo and
  • 00:04:56
    2fas and all these services that are
  • 00:04:58
    making to ke both open and easy to use
  • 00:05:02
    and still secure so those are my
  • 00:05:04
    thoughts kind of ranty either way do not
  • 00:05:08
    just not enable MFA because you're
  • 00:05:09
    concerned about the password manager
  • 00:05:11
    thing um at minimum just put in your
  • 00:05:13
    password manager if that's what's
  • 00:05:13
    holding you back otherwise if you want
  • 00:05:15
    to be better um move it to its own
  • 00:05:17
    dedicated
  • 00:05:19
    place this clip came from our main
  • 00:05:21
    Channel techlore where we talk about
  • 00:05:22
    digital rights and how to keep yourself
  • 00:05:24
    and the people around you safe online as
  • 00:05:27
    well as just reclaiming a little bit
  • 00:05:28
    more ownership if you enjoy this content
  • 00:05:31
    want more nuance and want a little bit
  • 00:05:33
    more of a deep dive check out our main
  • 00:05:35
    channel here on the screen or in the
  • 00:05:36
    description and we'll see you there
Tags
  • MFA
  • wagwoordbestuurder
  • sekuriteit
  • databreach
  • twee-faktor-authentifikasie
  • sleutelbestuur
  • hackpogings
  • persoonlike sekuriteit
  • gemak
  • sterk wagwoorde