1
1

00:00:00,340  -->  00:00:02,240
<v ->Multifactor authentication.</v>
2

2

00:00:02,240  -->  00:00:04,360
In this lesson, we're going to talk about the importance
3

3

00:00:04,360  -->  00:00:06,460
of using multifactor authentication.
4

4

00:00:06,460  -->  00:00:09,470
So, what exactly is multifactor authentication?
5

5

00:00:09,470  -->  00:00:11,050
Well, multifactor authentication
6

6

00:00:11,050  -->  00:00:13,570
means that you're authenticating or proving your identity
7

7

00:00:13,570  -->  00:00:15,240
using more than one method.
8

8

00:00:15,240  -->  00:00:16,470
For it to be multifactor,
9

9

00:00:16,470  -->  00:00:18,700
you have to at least two methods or more.
10

10

00:00:18,700  -->  00:00:20,810
You can have two, three, four, or five.
11

11

00:00:20,810  -->  00:00:22,820
Now, when you talk about different methods,
12

12

00:00:22,820  -->  00:00:24,600
we're talking about different categories.
13

13

00:00:24,600  -->  00:00:26,040
We're talking about something you know,
14

14

00:00:26,040  -->  00:00:27,830
something you have, something you are,
15

15

00:00:27,830  -->  00:00:29,890
something you do or somewhere you are.
16

16

00:00:29,890  -->  00:00:32,200
We're going to talk about each of these in this lesson.
17

17

00:00:32,200  -->  00:00:34,200
Now, our first one is something you know
18

18

00:00:34,200  -->  00:00:35,820
and this is the most common factor
19

19

00:00:35,820  -->  00:00:37,880
and it's known as a knowledge factor.
20

20

00:00:37,880  -->  00:00:39,780
This is because you have to know something.
21

21

00:00:39,780  -->  00:00:40,800
If it's something you know,
22

22

00:00:40,800  -->  00:00:43,650
this would be something like a username, a password, a pin,
23

23

00:00:43,650  -->  00:00:45,490
or answers to personal questions.
24

24

00:00:45,490  -->  00:00:47,930
All of these are considered knowledge factors.
25

25

00:00:47,930  -->  00:00:50,180
If you know it and I can try to figure it out,
26

26

00:00:50,180  -->  00:00:52,270
then I would know it and now I have that knowledge too,
27

27

00:00:52,270  -->  00:00:54,320
and I can authenticate as you.
28

28

00:00:54,320  -->  00:00:55,610
Now, one of the common questions
29

29

00:00:55,610  -->  00:00:58,180
I see inside the Network+ exam is asking you
30

30

00:00:58,180  -->  00:01:00,720
what would be considered two-factor authentication?
31

31

00:01:00,720  -->  00:01:02,400
Now, one of the answer choices they'll give you
32

32

00:01:02,400  -->  00:01:04,730
will be something like a username and a password.
33

33

00:01:04,730  -->  00:01:06,057
Now lots of students will see this and they'll think,
34

34

00:01:06,057  -->  00:01:07,827
"Hey, this is a username and a password.
35

35

00:01:07,827  -->  00:01:09,337
"That must be two factors, right?
36

36

00:01:09,337  -->  00:01:10,610
"Cause I have two things."
37

37

00:01:10,610  -->  00:01:11,740
But that's not true.
38

38

00:01:11,740  -->  00:01:14,450
A username and password both come from this factor,
39

39

00:01:14,450  -->  00:01:15,820
which is known as the knowledge factor
40

40

00:01:15,820  -->  00:01:17,110
or something we know.
41

41

00:01:17,110  -->  00:01:19,830
Therefore, it's still considered a single factor.
42

42

00:01:19,830  -->  00:01:22,160
Now, this is not going to give you the best security,
43

43

00:01:22,160  -->  00:01:24,840
so instead, we want to add a second factor
44

44

00:01:24,840  -->  00:01:27,430
to get us 2FA, two-factor authentication,
45

45

00:01:27,430  -->  00:01:29,590
or multifactor authentication.
46

46

00:01:29,590  -->  00:01:32,200
So, what are some weaknesses with passwords?
47

47

00:01:32,200  -->  00:01:33,570
Well, the most common weakness
48

48

00:01:33,570  -->  00:01:35,970
is that people don't change default credentials.
49

49

00:01:35,970  -->  00:01:38,170
You might have a default password on a brand new system
50

50

00:01:38,170  -->  00:01:39,960
like a wireless router or access point
51

51

00:01:39,960  -->  00:01:41,640
and the password is password
52

52

00:01:41,640  -->  00:01:43,490
and nobody ever bothers to change it.
53

53

00:01:43,490  -->  00:01:46,020
I've seen this time and time again in my penetration tests.
54

54

00:01:46,020  -->  00:01:47,220
Don't do that.
55

55

00:01:47,220  -->  00:01:48,480
Whenever you get a new device,
56

56

00:01:48,480  -->  00:01:50,730
you need to go in and change those default credentials
57

57

00:01:50,730  -->  00:01:53,640
because default credentials are really easy to guess.
58

58

00:01:53,640  -->  00:01:55,880
Also, people will use common passwords
59

59

00:01:55,880  -->  00:01:57,680
and that becomes a big issue.
60

60

00:01:57,680  -->  00:01:59,320
Now, when you talk about common passwords,
61

61

00:01:59,320  -->  00:02:02,260
that means using the same password across multiple devices
62

62

00:02:02,260  -->  00:02:05,660
or using a common phrase or word as their password,
63

63

00:02:05,660  -->  00:02:08,060
things like love and password and secret.
64

64

00:02:08,060  -->  00:02:10,290
Those things are just way too common.
65

65

00:02:10,290  -->  00:02:12,270
Now, every year there's a dictionary that comes out
66

66

00:02:12,270  -->  00:02:13,760
called "The Attacker's Dictionary"
67

67

00:02:13,760  -->  00:02:16,300
and it shows all the commonly used passwords.
68

68

00:02:16,300  -->  00:02:18,410
We can use those passwords in that list
69

69

00:02:18,410  -->  00:02:19,910
as part of a dictionary attack
70

70

00:02:19,910  -->  00:02:20,950
to be able to find your password
71

71

00:02:20,950  -->  00:02:22,900
pretty darn quickly in most cases.
72

72

00:02:22,900  -->  00:02:24,100
Now, another issue we have
73

73

00:02:24,100  -->  00:02:26,630
is that people use weak or short passwords.
74

74

00:02:26,630  -->  00:02:28,700
If you're going to use something like dog or puppy
75

75

00:02:28,700  -->  00:02:31,190
or cupcake or dog123,
76

76

00:02:31,190  -->  00:02:33,500
these are all short and weak passwords.
77

77

00:02:33,500  -->  00:02:35,110
Anything that is a standard dictionary word
78

78

00:02:35,110  -->  00:02:37,620
is completely bad and you should not use it.
79

79

00:02:37,620  -->  00:02:40,510
Anything less than eight characters is also pretty bad.
80

80

00:02:40,510  -->  00:02:41,343
You really want to make sure
81

81

00:02:41,343  -->  00:02:43,690
you have a nice long, strong, secure password
82

82

00:02:43,690  -->  00:02:45,570
and to do that, you need uppercase letters,
83

83

00:02:45,570  -->  00:02:48,210
lowercase letters, numbers, and special characters,
84

84

00:02:48,210  -->  00:02:49,480
all mixed together.
85

85

00:02:49,480  -->  00:02:51,710
This will help increase the security of your password
86

86

00:02:51,710  -->  00:02:54,000
and you want to make sure it's a long password.
87

87

00:02:54,000  -->  00:02:56,410
Now, if you're only going to use a single factor authentication
88

88

00:02:56,410  -->  00:02:57,880
like a username and a password,
89

89

00:02:57,880  -->  00:03:00,670
at least make sure you're using a long, strong password.
90

90

00:03:00,670  -->  00:03:02,700
The reason for this is that attackers know
91

91

00:03:02,700  -->  00:03:05,000
that they can break our passwords over time.
92

92

00:03:05,000  -->  00:03:06,800
There's lots of different attacks we can use,
93

93

00:03:06,800  -->  00:03:08,850
like a dictionary attack, a brute force attack
94

94

00:03:08,850  -->  00:03:10,160
or a hybrid attack.
95

95

00:03:10,160  -->  00:03:11,480
Now, a dictionary attack occurs
96

96

00:03:11,480  -->  00:03:13,410
when the attacker tries to guess the password
97

97

00:03:13,410  -->  00:03:15,230
by checking every single word or phrase
98

98

00:03:15,230  -->  00:03:18,230
contained within a word list, which we call a dictionary.
99

99

00:03:18,230  -->  00:03:19,440
Now, an attacker's dictionary
100

100

00:03:19,440  -->  00:03:21,400
isn't like the dictionary you used in high school.
101

101

00:03:21,400  -->  00:03:23,340
It doesn't contain just real words.
102

102

00:03:23,340  -->  00:03:24,680
Many attacker's dictionaries
103

103

00:03:24,680  -->  00:03:26,820
contain things like the word password
104

104

00:03:26,820  -->  00:03:27,990
but they'll also sub it out
105

105

00:03:27,990  -->  00:03:30,100
and have the a becoming an @ symbol
106

106

00:03:30,100  -->  00:03:31,730
or the s becoming a $.
107

107

00:03:31,730  -->  00:03:33,370
And they'll have lots of different combinations of these
108

108

00:03:33,370  -->  00:03:34,830
in the single dictionary.
109

109

00:03:34,830  -->  00:03:37,270
When the attacker tries to crack your password using a list,
110

110

00:03:37,270  -->  00:03:38,940
we consider it a dictionary attack
111

111

00:03:38,940  -->  00:03:40,290
whenever there's a list involved,
112

112

00:03:40,290  -->  00:03:42,030
even if they're not real words.
113

113

00:03:42,030  -->  00:03:44,700
So, the best defense against a dictionary attack
114

114

00:03:44,700  -->  00:03:47,150
is to not use anything that looks like a regular word,
115

115

00:03:47,150  -->  00:03:49,570
even if you start substituting in symbols for letters
116

116

00:03:49,570  -->  00:03:51,230
that still looks like a regular word
117

117

00:03:51,230  -->  00:03:53,380
and it's probably in an attacker's dictionary.
118

118

00:03:53,380  -->  00:03:56,130
On the other hand, if a dictionary attack isn't successful,
119

119

00:03:56,130  -->  00:03:59,000
the attacker may move on and try to do a brute force attack.
120

120

00:03:59,000  -->  00:04:00,300
Now with a brute force attack,
121

121

00:04:00,300  -->  00:04:02,340
they're going to try every possible combination
122

122

00:04:02,340  -->  00:04:04,010
until they figure out your password.
123

123

00:04:04,010  -->  00:04:06,520
For example, let's say your password was a pin
124

124

00:04:06,520  -->  00:04:08,180
and it's four digits long.
125

125

00:04:08,180  -->  00:04:11,340
Well, the attacker could start out with 0000,
126

126

00:04:11,340  -->  00:04:16,210
then try 0001, then 0002, and they keep going up
127

127

00:04:16,210  -->  00:04:18,240
until they finally get your four digit code,
128

128

00:04:18,240  -->  00:04:21,820
which may be something like 5246 or whatever it was.
129

129

00:04:21,820  -->  00:04:23,560
The thing is that with a brute force attack,
130

130

00:04:23,560  -->  00:04:26,170
they will always be successful eventually.
131

131

00:04:26,170  -->  00:04:27,640
It's just a matter of time.
132

132

00:04:27,640  -->  00:04:29,530
And so the key here is to prevent them
133

133

00:04:29,530  -->  00:04:32,010
by creating longer and more complicated passwords
134

134

00:04:32,010  -->  00:04:34,210
because the longer and more complicated the password is,
135

135

00:04:34,210  -->  00:04:36,160
the longer it's going to take an attacker to guess it
136

136

00:04:36,160  -->  00:04:37,170
using brute force
137

137

00:04:37,170  -->  00:04:39,640
and going through all the possible combinations.
138

138

00:04:39,640  -->  00:04:42,060
For example, if you have an eight character password,
139

139

00:04:42,060  -->  00:04:43,860
even if it has uppercase, lowercase,
140

140

00:04:43,860  -->  00:04:45,260
numbers, and symbols in it,
141

141

00:04:45,260  -->  00:04:48,200
it will take less than a few days to crack that password
142

142

00:04:48,200  -->  00:04:49,840
using a decent graphics card.
143

143

00:04:49,840  -->  00:04:51,650
Now, if I raise it up to nine characters,
144

144

00:04:51,650  -->  00:04:53,670
it will take me about five days to crack it.
145

145

00:04:53,670  -->  00:04:56,010
With 10 characters, it becomes four months;
146

146

00:04:56,010  -->  00:04:57,850
11 characters, 10 years;
147

147

00:04:57,850  -->  00:05:00,320
and 12 characters, about 200 years.
148

148

00:05:00,320  -->  00:05:02,460
You can see there's this exponential curve here
149

149

00:05:02,460  -->  00:05:05,070
but remember, computers are always getting faster and better
150

150

00:05:05,070  -->  00:05:06,850
at cracking every single day.
151

151

00:05:06,850  -->  00:05:08,210
So all these numbers I just gave you,
152

152

00:05:08,210  -->  00:05:10,250
by next year you can cut them in half
153

153

00:05:10,250  -->  00:05:12,190
and the year after that, cut it in half again,
154

154

00:05:12,190  -->  00:05:13,950
and it'll keep going down and down and down,
155

155

00:05:13,950  -->  00:05:16,330
so we have to get longer and stronger passwords.
156

156

00:05:16,330  -->  00:05:18,510
As a good rule of thumb, you want your password to be
157

157

00:05:18,510  -->  00:05:21,630
at least 12 characters minimum for good security.
158

158

00:05:21,630  -->  00:05:23,410
Now, the final method a hacker can use
159

159

00:05:23,410  -->  00:05:25,320
is what's known as a hybrid technique.
160

160

00:05:25,320  -->  00:05:28,350
This is a mixture of a dictionary and a brute force method.
161

161

00:05:28,350  -->  00:05:30,530
Now basically, the attacker tries to gather keywords
162

162

00:05:30,530  -->  00:05:31,630
that would relate to your life
163

163

00:05:31,630  -->  00:05:33,990
and then make their own custom dictionary lists.
164

164

00:05:33,990  -->  00:05:35,520
For example, I might go on Facebook
165

165

00:05:35,520  -->  00:05:38,080
and try to find out your spouse's name, or your dog's name,
166

166

00:05:38,080  -->  00:05:39,300
or your favorite sports team,
167

167

00:05:39,300  -->  00:05:41,430
and then I put all the words related to those things
168

168

00:05:41,430  -->  00:05:43,220
into a custom dictionary list.
169

169

00:05:43,220  -->  00:05:45,970
Then, my password cracking program would take that list
170

170

00:05:45,970  -->  00:05:48,930
and add different things to it as a form of brute force.
171

171

00:05:48,930  -->  00:05:50,890
For example, let's say your favorite sports team
172

172

00:05:50,890  -->  00:05:52,520
was the Ravens up in Baltimore.
173

173

00:05:52,520  -->  00:05:55,190
I might use two words as part of my dictionary list:
174

174

00:05:55,190  -->  00:05:56,710
Baltimore and Ravens.
175

175

00:05:56,710  -->  00:05:58,780
Then, the program will try things like Baltimore123
176

176

00:05:58,780  -->  00:06:01,590
or Ravens911 or whatever.
177

177

00:06:01,590  -->  00:06:03,490
And they'll substitute in symbols and numbers
178

178

00:06:03,490  -->  00:06:05,870
and add things to it and make different combinations,
179

179

00:06:05,870  -->  00:06:07,840
trying to figure out what your password is.
180

180

00:06:07,840  -->  00:06:10,280
This is essentially a modified version of brute force
181

181

00:06:10,280  -->  00:06:12,860
but it does speed up the time it takes to crack a password
182

182

00:06:12,860  -->  00:06:14,390
if I use the right keywords
183

183

00:06:14,390  -->  00:06:16,160
because I'm giving it some sort of a starting point,
184

184

00:06:16,160  -->  00:06:18,060
instead of picking everything out at random.
185

185

00:06:18,060  -->  00:06:20,270
But again, this isn't 100% effective
186

186

00:06:20,270  -->  00:06:22,240
because if I choose something like Ravens
187

187

00:06:22,240  -->  00:06:24,180
and you didn't use that as part of your password stem,
188

188

00:06:24,180  -->  00:06:25,450
I'm not going to ever get there
189

189

00:06:25,450  -->  00:06:27,300
because it's not a traditional brute force attack
190

190

00:06:27,300  -->  00:06:29,760
where I try every single possible combination.
191

191

00:06:29,760  -->  00:06:31,470
The next factor of authentication we have
192

192

00:06:31,470  -->  00:06:33,020
is known as something you have,
193

193

00:06:33,020  -->  00:06:35,040
also known as a possession factor.
194

194

00:06:35,040  -->  00:06:36,930
Now, this can be something like a smart card,
195

195

00:06:36,930  -->  00:06:38,870
which stores a digital certificate on a card
196

196

00:06:38,870  -->  00:06:40,360
that you have to insert in your computer
197

197

00:06:40,360  -->  00:06:42,280
and then unlock it using a pin.
198

198

00:06:42,280  -->  00:06:44,830
Now, this means you have something you have, the card,
199

199

00:06:44,830  -->  00:06:46,450
and something you know, the pin,
200

200

00:06:46,450  -->  00:06:48,710
so we have two factors of authentication.
201

201

00:06:48,710  -->  00:06:49,960
Now, another thing you might use
202

202

00:06:49,960  -->  00:06:51,940
is something like an RSA key fob.
203

203

00:06:51,940  -->  00:06:54,080
Now, an RSA key fob is going to change a number
204

204

00:06:54,080  -->  00:06:55,840
on a little device that's in your pocket
205

205

00:06:55,840  -->  00:06:57,710
every 30 to 60 seconds.
206

206

00:06:57,710  -->  00:06:59,320
Now, when you go to log into your machine,
207

207

00:06:59,320  -->  00:07:00,887
it's going to ask for your username and password
208

208

00:07:00,887  -->  00:07:02,730
and a rotating pin number
209

209

00:07:02,730  -->  00:07:05,740
because that pin number's provided by that key fob,
210

210

00:07:05,740  -->  00:07:07,110
so this means you have something you know,
211

211

00:07:07,110  -->  00:07:09,440
that knowledge factor because your username and password
212

212

00:07:09,440  -->  00:07:10,810
but you also have something you have,
213

213

00:07:10,810  -->  00:07:13,660
this key fob by typing in that rotating pin number.
214

214

00:07:13,660  -->  00:07:15,320
By combining those two things together,
215

215

00:07:15,320  -->  00:07:17,530
I now have two-factor authentication.
216

216

00:07:17,530  -->  00:07:20,530
Another option we have is using something like an RFID tag.
217

217

00:07:20,530  -->  00:07:22,470
Now, some employers have badges that you wear
218

218

00:07:22,470  -->  00:07:24,420
and there's an RFID tag built into it.
219

219

00:07:24,420  -->  00:07:25,540
To log into your system,
220

220

00:07:25,540  -->  00:07:26,881
you tap your badge onto the computer,
221

221

00:07:26,881  -->  00:07:28,250
that's something you have,
222

222

00:07:28,250  -->  00:07:30,010
and then you enter a pin number or password,
223

223

00:07:30,010  -->  00:07:31,020
something you know.
224

224

00:07:31,020  -->  00:07:32,510
Again, this gives you a good
225

225

00:07:32,510  -->  00:07:34,360
two-factor authentication solution.
226

226

00:07:34,360  -->  00:07:36,570
Something you have and something you know.
227

227

00:07:36,570  -->  00:07:39,580
The next factor authentication we have is something you are.
228

228

00:07:39,580  -->  00:07:41,840
We refer to this as an inheritance factor.
229

229

00:07:41,840  -->  00:07:44,150
Now, inheritance factors are things like fingerprints
230

230

00:07:44,150  -->  00:07:45,900
because only I have my fingerprints.
231

231

00:07:45,900  -->  00:07:48,580
I can also use retina scans because only I have my eyes
232

232

00:07:48,580  -->  00:07:51,270
or a voiceprint because only I talk the way I talk
233

233

00:07:51,270  -->  00:07:53,340
and a computer can actually tell my voice
234

234

00:07:53,340  -->  00:07:55,400
versus somebody who is imitating my voice.
235

235

00:07:55,400  -->  00:07:57,820
My voice print is going to be unique to me.
236

236

00:07:57,820  -->  00:08:00,180
All these things can be used as an inheritance factor
237

237

00:08:00,180  -->  00:08:01,660
or something you are.
238

238

00:08:01,660  -->  00:08:04,050
Now, these types of factors are not as commonly used
239

239

00:08:04,050  -->  00:08:05,210
in most organizations
240

240

00:08:05,210  -->  00:08:07,260
because a lot of people feel it's intrusive.
241

241

00:08:07,260  -->  00:08:09,190
For example, if every time I were to log into my computer,
242

242

00:08:09,190  -->  00:08:11,000
I had to put my eyeball up to a scanner,
243

243

00:08:11,000  -->  00:08:12,640
that's a little creepy, right?
244

244

00:08:12,640  -->  00:08:13,473
And I probably wouldn't want to
245

245

00:08:13,473  -->  00:08:14,840
log into my computer very often.
246

246

00:08:14,840  -->  00:08:16,280
So instead, most of the time
247

247

00:08:16,280  -->  00:08:17,940
we're going to use two-factor authentication
248

248

00:08:17,940  -->  00:08:19,930
with something you know and something you have
249

249

00:08:19,930  -->  00:08:21,310
because it is a lot easier.
250

250

00:08:21,310  -->  00:08:23,300
But if you work in a high security environment,
251

251

00:08:23,300  -->  00:08:25,720
you might find a door lock or something of that nature
252

252

00:08:25,720  -->  00:08:28,860
that it's going to rely on a thumbprint or a retina scan.
253

253

00:08:28,860  -->  00:08:31,180
Now, the next factor we have is something you do,
254

254

00:08:31,180  -->  00:08:33,020
which is known as an action factor.
255

255

00:08:33,020  -->  00:08:34,690
This might be the way you sign your name,
256

256

00:08:34,690  -->  00:08:36,820
the way you draw a particular pattern on a screen,
257

257

00:08:36,820  -->  00:08:39,100
or the way you say a particular passphrase.
258

258

00:08:39,100  -->  00:08:42,010
All these are something you do that's unique to you.
259

259

00:08:42,010  -->  00:08:43,960
That action can be measured by a computer
260

260

00:08:43,960  -->  00:08:45,710
and used for authentication.
261

261

00:08:45,710  -->  00:08:47,080
Usually, you don't want to use this
262

262

00:08:47,080  -->  00:08:49,760
as a single factor, though, because it is prone to error.
263

263

00:08:49,760  -->  00:08:51,950
So instead, you'll add it with something you know
264

264

00:08:51,950  -->  00:08:54,070
and that will give you two-factor authentication
265

265

00:08:54,070  -->  00:08:56,610
because people can forge your name and the way you sign
266

266

00:08:56,610  -->  00:08:58,160
but generally, the way you press
267

267

00:08:58,160  -->  00:08:59,050
and the way you put pressure
268

268

00:08:59,050  -->  00:09:02,190
on certain parts of your signature is more unique to you.
269

269

00:09:02,190  -->  00:09:04,540
Our final factor is somewhere you are.
270

270

00:09:04,540  -->  00:09:06,640
This is known as a location factor.
271

271

00:09:06,640  -->  00:09:08,330
Now, we do this one of two ways.
272

272

00:09:08,330  -->  00:09:10,900
We can either use geotagging or geofencing.
273

273

00:09:10,900  -->  00:09:12,210
When we do a geotagging,
274

274

00:09:12,210  -->  00:09:14,310
that's going to be based off your GPS or your phone
275

275

00:09:14,310  -->  00:09:15,720
or the device you're using.
276

276

00:09:15,720  -->  00:09:17,880
For example, if I'm trying to log into my local server
277

277

00:09:17,880  -->  00:09:20,249
that uses geotagging and it's going to check my coordinates
278

278

00:09:20,249  -->  00:09:23,020
and my GPS, and it sees that I'm sitting in Moscow
279

279

00:09:23,020  -->  00:09:24,660
instead of being in Puerto Rico,
280

280

00:09:24,660  -->  00:09:26,010
that means it's going to reject me
281

281

00:09:26,010  -->  00:09:27,930
because it realizes it's not Jason.
282

282

00:09:27,930  -->  00:09:30,150
Jason's not in Moscow, he's sitting in Puerto Rico,
283

283

00:09:30,150  -->  00:09:32,630
so that person doesn't need to be on our network.
284

284

00:09:32,630  -->  00:09:35,400
Now, the other way we can do this is by using geofencing.
285

285

00:09:35,400  -->  00:09:37,170
Geofencing is used more
286

286

00:09:37,170  -->  00:09:38,630
when we actually want to track a device
287

287

00:09:38,630  -->  00:09:40,460
and see if it's going to leave a certain area.
288

288

00:09:40,460  -->  00:09:41,980
And if it does leave that area,
289

289

00:09:41,980  -->  00:09:43,850
which is set off by GPS coordinates,
290

290

00:09:43,850  -->  00:09:46,300
it will then send an alert and let us know.
291

291

00:09:46,300  -->  00:09:47,770
So maybe we have a bunch of mobile phones
292

292

00:09:47,770  -->  00:09:48,990
for all of our employees
293

293

00:09:48,990  -->  00:09:50,188
but we don't want them to use them
294

294

00:09:50,188  -->  00:09:52,070
anytime they leave our city.
295

295

00:09:52,070  -->  00:09:54,820
Well, we can set up a GPS location coordinates
296

296

00:09:54,820  -->  00:09:56,270
around our city borders
297

297

00:09:56,270  -->  00:09:58,380
and any time they cross those city lines,
298

298

00:09:58,380  -->  00:09:59,730
it would actually send up an alert
299

299

00:09:59,730  -->  00:10:01,560
back to our mobile device management suite
300

300

00:10:01,560  -->  00:10:05,040
to say this person is no longer within our coverage area.
301

301

00:10:05,040  -->  00:10:07,030
This is basically a location factor.
302

302

00:10:07,030  -->  00:10:08,870
It's an additional way to provide protection,
303

303

00:10:08,870  -->  00:10:10,040
additional authentication,
304

304

00:10:10,040  -->  00:10:12,450
in addition to something like a username and password
305

305

00:10:12,450  -->  00:10:14,310
and makes sure your devices are within the range
306

306

00:10:14,310  -->  00:10:16,010
of where you want them to be used.
