1
00:00:06,450 --> 00:00:08,520
- In this lesson 19.3,

2
00:00:08,520 --> 00:00:11,220
we're gonna focus in on authentication.

3
00:00:11,220 --> 00:00:13,890
Let's just start with an access primer.

4
00:00:13,890 --> 00:00:17,310
As a reminder, identification
is how a subject

5
00:00:17,310 --> 00:00:19,020
is uniquely recognized.

6
00:00:19,020 --> 00:00:21,840
And we talked about identity
proofing earlier on,

7
00:00:21,840 --> 00:00:23,910
as well as having a federated identity

8
00:00:23,910 --> 00:00:25,353
or a portable identity.

9
00:00:26,400 --> 00:00:30,930
Authentication is how an
identity is proven to be genuine.

10
00:00:30,930 --> 00:00:32,070
Now, in the physical world,

11
00:00:32,070 --> 00:00:34,620
we might use a driver's
license or a passport.

12
00:00:34,620 --> 00:00:36,180
We're going to have to have other ways

13
00:00:36,180 --> 00:00:38,280
to prove our identity, right,

14
00:00:38,280 --> 00:00:40,950
in the technical or logical world.

15
00:00:40,950 --> 00:00:43,170
And then authorization defines

16
00:00:43,170 --> 00:00:46,620
how access rights and
permissions are granted,

17
00:00:46,620 --> 00:00:50,793
identification, authentication,
and authorization.

18
00:00:52,020 --> 00:00:54,150
Now, authentication, again, is the process

19
00:00:54,150 --> 00:00:57,570
of proving an identity to
an authentication system.

20
00:00:57,570 --> 00:01:00,300
You're proving your
identity to be genuine.

21
00:01:00,300 --> 00:01:02,820
Now, the proof is referred to as a factor

22
00:01:02,820 --> 00:01:07,170
and a combination of a username
or identity, if you will,

23
00:01:07,170 --> 00:01:10,323
and factor is referred
to as your credentials.

24
00:01:12,360 --> 00:01:15,120
Now, there are four primary
authentication factors,

25
00:01:15,120 --> 00:01:20,120
knowledge, possession,
biometric, and location.

26
00:01:20,220 --> 00:01:21,870
Knowledge is something a user knows,

27
00:01:21,870 --> 00:01:23,940
like your password, a passphrase,

28
00:01:23,940 --> 00:01:26,550
a PIN, or an answer to a challenge,

29
00:01:26,550 --> 00:01:28,800
or an out-of-wallet question.

30
00:01:28,800 --> 00:01:31,230
Possession, well, that's
something that you have, right?

31
00:01:31,230 --> 00:01:33,570
Could be a token, a smart card,

32
00:01:33,570 --> 00:01:35,643
could even be your cell or mobile phone.

33
00:01:36,750 --> 00:01:40,980
Now, biometric is either
something a user is

34
00:01:40,980 --> 00:01:42,720
or something a user does.

35
00:01:42,720 --> 00:01:46,200
Now, something a user is,
is referred to physiological

36
00:01:46,200 --> 00:01:47,460
and something a user does

37
00:01:47,460 --> 00:01:50,400
is referred to as a behavioral marker.

38
00:01:50,400 --> 00:01:52,500
And then lastly, we have location,

39
00:01:52,500 --> 00:01:54,090
which is somewhere a user is.

40
00:01:54,090 --> 00:01:56,130
That could be based on GeoIP,

41
00:01:56,130 --> 00:01:59,010
a geofence, latitude or longitude,

42
00:01:59,010 --> 00:02:02,160
or even proximity to a specific device.

43
00:02:02,160 --> 00:02:05,343
So, knowledge, possession,
biometric, and location.

44
00:02:06,960 --> 00:02:08,850
So, let's look a little
deeper into each one of these

45
00:02:08,850 --> 00:02:10,203
starting with knowledge.

46
00:02:11,730 --> 00:02:14,190
The most common type of knowledge factor

47
00:02:14,190 --> 00:02:16,770
really is just a data
string that's created

48
00:02:16,770 --> 00:02:19,350
by a user or a password generator.

49
00:02:19,350 --> 00:02:22,170
Now, we'll refer to that as
a password, or if it's long,

50
00:02:22,170 --> 00:02:25,290
sometimes we refer to it
as a passphrase or a PIN.

51
00:02:25,290 --> 00:02:26,823
PIN is generally numbers.

52
00:02:28,080 --> 00:02:30,990
But knowledge could also be a
cognitive challenge question.

53
00:02:30,990 --> 00:02:32,250
Now, we've all filled these out.

54
00:02:32,250 --> 00:02:34,830
That's when you are
presented a set of questions

55
00:02:34,830 --> 00:02:37,020
and you get to choose the
questions and the answers

56
00:02:37,020 --> 00:02:38,370
during the enrollment period.

57
00:02:38,370 --> 00:02:41,910
And then later on, if your
identity needs to be verified,

58
00:02:41,910 --> 00:02:43,590
you know, the second step there,

59
00:02:43,590 --> 00:02:46,173
you will be presented
that challenge question.

60
00:02:47,160 --> 00:02:49,650
And then we have out-of-wallet
challenge questions.

61
00:02:49,650 --> 00:02:51,270
Now, these are questions and answers

62
00:02:51,270 --> 00:02:54,510
that are derived from public
subscription databases.

63
00:02:54,510 --> 00:02:56,190
Like which of these cars did you own?

64
00:02:56,190 --> 00:02:58,770
Or which of these streets did you live on?

65
00:02:58,770 --> 00:03:01,230
But in all cases, this
is based on knowledge.

66
00:03:01,230 --> 00:03:02,580
It's based on something, you know,

67
00:03:02,580 --> 00:03:04,350
whether it's a password, a PIN,

68
00:03:04,350 --> 00:03:06,900
a passphrase, a cognitive
challenge question,

69
00:03:06,900 --> 00:03:09,600
or an out-of-wallet
challenge question, right?

70
00:03:09,600 --> 00:03:10,860
They're all the same factor.

71
00:03:10,860 --> 00:03:12,573
They're all based on knowledge.

72
00:03:15,210 --> 00:03:16,560
Now, it's interesting in the past year

73
00:03:16,560 --> 00:03:20,670
NIST has put some new
password guidelines out there

74
00:03:20,670 --> 00:03:22,590
that I think are very interesting

75
00:03:22,590 --> 00:03:25,890
about length, and what's
allowed, and what's disallowed,

76
00:03:25,890 --> 00:03:29,940
and how frequently or
infrequently you should reset it.

77
00:03:29,940 --> 00:03:31,470
Should you show your password,

78
00:03:31,470 --> 00:03:33,660
should you permit paste and uniqueness.

79
00:03:33,660 --> 00:03:35,220
And these are all detailed

80
00:03:35,220 --> 00:03:40,170
in NIST Special Publication
800-63 Password Guidelines.

81
00:03:40,170 --> 00:03:41,620
So, let's talk through these.

82
00:03:42,900 --> 00:03:46,110
NIST says that you should
use long passwords,

83
00:03:46,110 --> 00:03:48,570
eight to 64 characters,

84
00:03:48,570 --> 00:03:51,750
but to prioritize length over complexity.

85
00:03:51,750 --> 00:03:52,583
That's really interesting.

86
00:03:52,583 --> 00:03:53,910
And this sort of a change in the way

87
00:03:53,910 --> 00:03:56,160
we've approached passwords in the past.

88
00:03:56,160 --> 00:03:58,320
Prioritize length over complexity.

89
00:03:58,320 --> 00:03:59,910
Why? Because it's all about

90
00:03:59,910 --> 00:04:02,490
users being able to
remember their passwords,

91
00:04:02,490 --> 00:04:05,550
not writing them down, not
putting 'em in a spreadsheet,

92
00:04:05,550 --> 00:04:08,820
not having to constantly
have their passwords reset.

93
00:04:08,820 --> 00:04:11,793
So, prioritizing length over complexity.

94
00:04:13,920 --> 00:04:15,780
The suggestion is that all ASCII

95
00:04:15,780 --> 00:04:18,150
and Unicode characters should be allowed

96
00:04:18,150 --> 00:04:20,703
including emojis and spaces.

97
00:04:21,930 --> 00:04:24,120
We should disallow dictionary words.

98
00:04:24,120 --> 00:04:26,790
So, we shouldn't be able
to have real regular words

99
00:04:26,790 --> 00:04:30,600
and simple number sequences
like 1, 2, 3, 4, 5, 6, 7, 8, 9,

100
00:04:30,600 --> 00:04:33,483
which is an incredibly common password.

101
00:04:34,320 --> 00:04:35,880
And they suggest that we don't

102
00:04:35,880 --> 00:04:37,950
enforce password expiration periods.

103
00:04:37,950 --> 00:04:40,110
Don't make your users
change their passwords

104
00:04:40,110 --> 00:04:42,270
every 30 days or every 60 days.

105
00:04:42,270 --> 00:04:44,940
They can keep their passwords,
their passwords are fine,

106
00:04:44,940 --> 00:04:48,150
unless there's a suspicion of compromise.

107
00:04:48,150 --> 00:04:50,760
Again, we're really trying to
make it easier for our users

108
00:04:50,760 --> 00:04:52,830
so they remember their passwords, right?

109
00:04:52,830 --> 00:04:54,360
They don't have to keep writing them down.

110
00:04:54,360 --> 00:04:56,040
They don't have to keep changing them,

111
00:04:56,040 --> 00:04:57,303
because they forgot them.

112
00:04:58,950 --> 00:05:01,920
Allow show password
option so they can see it,

113
00:05:01,920 --> 00:05:03,720
but disallow hints.

114
00:05:03,720 --> 00:05:04,710
So that's interesting.

115
00:05:04,710 --> 00:05:06,690
Allow it to show it so as you're typing it

116
00:05:06,690 --> 00:05:08,430
to show what you're typing,

117
00:05:08,430 --> 00:05:10,080
but not to allow hints, right?

118
00:05:10,080 --> 00:05:12,660
Because hints could be,
anybody could see the hints

119
00:05:12,660 --> 00:05:13,493
and then be able to say,

120
00:05:13,493 --> 00:05:15,900
"Oh, I can guess that password."

121
00:05:15,900 --> 00:05:19,350
To remit paste functionality
when entering a password.

122
00:05:19,350 --> 00:05:21,300
Now, that's really great,

123
00:05:21,300 --> 00:05:24,000
because if someone's using
let's say a password manager

124
00:05:24,000 --> 00:05:26,520
and they wanna copy and
paste in the password manager

125
00:05:26,520 --> 00:05:29,403
right into the application.

126
00:05:30,300 --> 00:05:32,190
And that's lastly uniqueness.

127
00:05:32,190 --> 00:05:35,040
That we wanna encourage users
to use a unique password.

128
00:05:35,040 --> 00:05:37,410
And absolutely, it is recommended

129
00:05:37,410 --> 00:05:40,323
using a password manager for generation.

130
00:05:41,250 --> 00:05:45,540
So, these are the NIST
800-63 Password Guidelines

131
00:05:45,540 --> 00:05:46,590
and you can read more about them

132
00:05:46,590 --> 00:05:50,073
in the Special Publication 800-63.

133
00:05:51,690 --> 00:05:53,130
Now, there's also a suggestion

134
00:05:53,130 --> 00:05:55,980
that our users should be
using password managers

135
00:05:55,980 --> 00:05:58,230
also known as password vaults.

136
00:05:58,230 --> 00:06:00,000
Now, password vaulting is a technology

137
00:06:00,000 --> 00:06:02,757
used to securely store
and manage passwords

138
00:06:02,757 --> 00:06:05,040
and other sensitive credentials.

139
00:06:05,040 --> 00:06:06,900
I can't imagine functioning

140
00:06:06,900 --> 00:06:09,540
without a password manager, honestly.

141
00:06:09,540 --> 00:06:13,050
Password vaults store
passwords in a secure location.

142
00:06:13,050 --> 00:06:17,370
Accessible only to authorized
individuals and systems.

143
00:06:17,370 --> 00:06:20,070
Now, passwords stored in
the vault are encrypted

144
00:06:20,070 --> 00:06:22,710
using very robust encryption algorithms.

145
00:06:22,710 --> 00:06:26,310
And access to a password
vault or password manager,

146
00:06:26,310 --> 00:06:29,100
is typically protected
by strong authentication

147
00:06:29,100 --> 00:06:32,880
such as biometric verification
or two-factor authentication,

148
00:06:32,880 --> 00:06:35,310
which we'll be talking about shortly.

149
00:06:35,310 --> 00:06:38,370
Password vaults often
provide the capability

150
00:06:38,370 --> 00:06:41,940
to generate strong, complex
passwords automatically.

151
00:06:41,940 --> 00:06:43,830
And then the vault will securely

152
00:06:43,830 --> 00:06:45,780
store those generated passwords,

153
00:06:45,780 --> 00:06:48,720
eliminating the need for
users to remember them,

154
00:06:48,720 --> 00:06:49,953
which is really awesome.

155
00:06:52,590 --> 00:06:54,240
Let's talk about possession.

156
00:06:54,240 --> 00:06:55,710
And first, we're gonna look at possession

157
00:06:55,710 --> 00:06:58,260
in terms of a one-time password.

158
00:06:58,260 --> 00:07:00,900
Now, a one-time password
is either generated

159
00:07:00,900 --> 00:07:04,953
by something you have or
sent to something you have.

160
00:07:06,180 --> 00:07:10,080
A time-based, one-time
password, or a TOPT,

161
00:07:10,080 --> 00:07:12,000
is a hardware or software token

162
00:07:12,000 --> 00:07:15,330
that generates an
one-time password, an OTP,

163
00:07:15,330 --> 00:07:18,330
using a shared secret with
an authentication server

164
00:07:18,330 --> 00:07:20,310
and the current time.

165
00:07:20,310 --> 00:07:24,720
Where a hash-based OPT is a
hardware or software token

166
00:07:24,720 --> 00:07:28,140
that generates the OPT using a secret key

167
00:07:28,140 --> 00:07:30,930
and a cryptographic hash function.

168
00:07:30,930 --> 00:07:34,590
And then we can have an
SMS or a voice-based OPT,

169
00:07:34,590 --> 00:07:37,500
which is a numeric or alpha numeric code

170
00:07:37,500 --> 00:07:41,580
that's sent to a phone number,
either via voice or text.

171
00:07:41,580 --> 00:07:44,250
So, in for a time and hash OTP

172
00:07:44,250 --> 00:07:45,930
you have to have the token, right?

173
00:07:45,930 --> 00:07:47,730
And for the SMS or voice,

174
00:07:47,730 --> 00:07:50,190
you have to have that mobile phone.

175
00:07:50,190 --> 00:07:51,750
So, you have to have
something in your possession

176
00:07:51,750 --> 00:07:54,453
that, that one-time
password is being sent to.

177
00:07:56,100 --> 00:07:57,420
Now, another form of possession

178
00:07:57,420 --> 00:07:59,250
would have be having a smart card.

179
00:07:59,250 --> 00:08:01,740
A smart card is a card or badge

180
00:08:01,740 --> 00:08:03,570
that's in the user's possession

181
00:08:03,570 --> 00:08:05,580
and the smart card will
have an embedded chip

182
00:08:05,580 --> 00:08:07,980
and one or more certificates.

183
00:08:07,980 --> 00:08:11,700
Very often smart cards are
also used as our ID badges

184
00:08:11,700 --> 00:08:15,210
for building access and
for network authentication,

185
00:08:15,210 --> 00:08:16,440
we're using 'em for both.

186
00:08:16,440 --> 00:08:18,000
Now, a contactless smart card

187
00:08:18,000 --> 00:08:20,160
has a one inch to three inch range

188
00:08:20,160 --> 00:08:24,570
and a proximity smart card has
a one inch to 15 inch range.

189
00:08:24,570 --> 00:08:26,220
Implementation of smart cards

190
00:08:26,220 --> 00:08:28,740
require a smart card management system,

191
00:08:28,740 --> 00:08:31,440
which includes customization, issuance,

192
00:08:31,440 --> 00:08:33,933
revocation and replacement.

193
00:08:35,850 --> 00:08:37,260
Then we come to biometrics.

194
00:08:37,260 --> 00:08:38,940
Now, biometrics are physical

195
00:08:38,940 --> 00:08:41,400
or behavioral human characteristics

196
00:08:41,400 --> 00:08:44,673
that can be used to
digitally identify a person.

197
00:08:45,660 --> 00:08:50,660
Biometric options are physiological
markers, what you are,

198
00:08:50,760 --> 00:08:53,973
or behavioral traits,
which is what you do.

199
00:08:55,500 --> 00:08:57,300
Now, we're gonna be talking

200
00:08:57,300 --> 00:08:59,943
all about biometrics in our next lesson.

201
00:09:01,710 --> 00:09:04,320
So, let's talk about factor requirements.

202
00:09:04,320 --> 00:09:05,970
Our options for factor requirements

203
00:09:05,970 --> 00:09:08,430
are single factor,
multi-layer, multi-factor,

204
00:09:08,430 --> 00:09:12,810
also referred to as 2FA
and two-step verification.

205
00:09:12,810 --> 00:09:14,820
Single factor says only one factor

206
00:09:14,820 --> 00:09:16,740
is required for authentication.

207
00:09:16,740 --> 00:09:19,050
And sadly, that's still really

208
00:09:19,050 --> 00:09:21,000
probably the most popular factor.

209
00:09:21,000 --> 00:09:23,550
One factor and it's all generally gonna be

210
00:09:23,550 --> 00:09:24,603
just your password.

211
00:09:25,440 --> 00:09:27,180
Multi-layer is two or more

212
00:09:27,180 --> 00:09:30,630
of the same type of factor
required for authentication.

213
00:09:30,630 --> 00:09:32,430
So, if I have to put
in a password and PIN,

214
00:09:32,430 --> 00:09:34,230
those are both something I know, right?

215
00:09:34,230 --> 00:09:35,850
That would be multi-layer.

216
00:09:35,850 --> 00:09:37,020
If I have to put in a password

217
00:09:37,020 --> 00:09:39,480
and answer a challenge question,

218
00:09:39,480 --> 00:09:41,340
either a cognitive or out of wallet,

219
00:09:41,340 --> 00:09:43,470
they're both something I know, right?

220
00:09:43,470 --> 00:09:45,090
So, that would be multi-layer.

221
00:09:45,090 --> 00:09:47,520
So, two or more of the same type of factor

222
00:09:47,520 --> 00:09:48,993
is called multi-layer.

223
00:09:49,980 --> 00:09:54,600
Multi-factor is when I have
two or more different types

224
00:09:54,600 --> 00:09:57,360
of factors required for authentication.

225
00:09:57,360 --> 00:10:00,060
So, if I have to put in a password

226
00:10:00,060 --> 00:10:02,850
and I have to also maybe use my thumb

227
00:10:02,850 --> 00:10:04,770
to, you know, or a finger to log in

228
00:10:04,770 --> 00:10:07,770
that would be something I know
and something I am, right?

229
00:10:07,770 --> 00:10:11,280
If I have to have, if I know a code

230
00:10:11,280 --> 00:10:13,350
plus I have to put in the a

231
00:10:13,350 --> 00:10:16,470
add that to the code of that
comes from my token, right?

232
00:10:16,470 --> 00:10:18,150
That would be something I have, my token,

233
00:10:18,150 --> 00:10:19,710
plus something I know, right?

234
00:10:19,710 --> 00:10:21,210
My personal code.

235
00:10:21,210 --> 00:10:22,620
So, two or more different types

236
00:10:22,620 --> 00:10:24,810
of factors required for authentication.

237
00:10:24,810 --> 00:10:27,120
And then two-step verification,

238
00:10:27,120 --> 00:10:31,410
just confirms a user's identity
by requiring a response.

239
00:10:31,410 --> 00:10:32,910
So, an example of a second step

240
00:10:32,910 --> 00:10:35,130
would be a user repeating back a code

241
00:10:35,130 --> 00:10:38,580
that got sent to a mobile
number or an email address.

242
00:10:38,580 --> 00:10:40,140
So, single-factor, multi-layer,

243
00:10:40,140 --> 00:10:42,873
multi-factor and two-step verification.

244
00:10:44,100 --> 00:10:47,301
Now, you may start hearing
the term passwordless.

245
00:10:47,301 --> 00:10:50,250
Passwordless refers to a
method of authentication

246
00:10:50,250 --> 00:10:53,310
that eliminates the need
for traditional passwords

247
00:10:53,310 --> 00:10:56,790
as the primary means of
verifying a user identity.

248
00:10:56,790 --> 00:10:58,950
So, instead of relying on passwords,

249
00:10:58,950 --> 00:11:02,490
passwordless authentication
relies on alternate methods

250
00:11:02,490 --> 00:11:05,043
or factors to authenticate users.

251
00:11:07,260 --> 00:11:09,360
So, how do you decide, right,

252
00:11:09,360 --> 00:11:10,830
how many factors you should have?

253
00:11:10,830 --> 00:11:12,570
The type of factors, you know,

254
00:11:12,570 --> 00:11:14,220
how do you make these decisions?

255
00:11:14,220 --> 00:11:17,040
Well, decisions regarding the
type and the number of factors

256
00:11:17,040 --> 00:11:20,280
should always, always, always,
always, always, always,

257
00:11:20,280 --> 00:11:22,410
be commensurate with the business value

258
00:11:22,410 --> 00:11:25,800
of what's being protected,
your regulatory requirements,

259
00:11:25,800 --> 00:11:27,870
and your contractual obligations.

260
00:11:27,870 --> 00:11:30,993
In other words, strategically
aligned with the organization.

261
00:11:32,430 --> 00:11:35,220
That my friends brings us
to a three-second challenge.

262
00:11:35,220 --> 00:11:37,170
Five challenge questions,
three seconds each.

263
00:11:37,170 --> 00:11:38,270
You know how to do it.

264
00:11:39,450 --> 00:11:41,790
Question one, this type
of challenge question

265
00:11:41,790 --> 00:11:45,390
uses a preselected question and answer.

266
00:11:45,390 --> 00:11:47,493
One, two, three.

267
00:11:48,540 --> 00:11:52,290
That is a cognitive challenge question.

268
00:11:52,290 --> 00:11:54,750
Number two, the use of two or more

269
00:11:54,750 --> 00:11:57,360
different factors for authentication.

270
00:11:57,360 --> 00:12:00,480
Two or more different
factors for authentication.

271
00:12:00,480 --> 00:12:02,640
One, two, three.

272
00:12:02,640 --> 00:12:06,183
That's multifactor,
also referred to as 2FA.

273
00:12:07,770 --> 00:12:12,600
Number three, the combination
of username and factors.

274
00:12:12,600 --> 00:12:13,800
What do we refer to that as?

275
00:12:13,800 --> 00:12:16,740
A combination of a
username and their factors.

276
00:12:16,740 --> 00:12:17,913
One, two, three.

277
00:12:18,840 --> 00:12:20,253
That's gonna be credentials.

278
00:12:21,240 --> 00:12:23,640
Number four, a hardware or software token

279
00:12:23,640 --> 00:12:26,460
that generates an OTP,
a one-time password,

280
00:12:26,460 --> 00:12:29,580
using a secret shared
with authentication server

281
00:12:29,580 --> 00:12:31,143
and the current time.

282
00:12:32,130 --> 00:12:33,540
This is an easy one.

283
00:12:33,540 --> 00:12:34,560
One, two, three.

284
00:12:34,560 --> 00:12:35,820
What do you got?

285
00:12:35,820 --> 00:12:37,530
That's a time OTP,

286
00:12:37,530 --> 00:12:40,200
'cause it's using the current time.

287
00:12:40,200 --> 00:12:43,350
Number five, GeoIP is an example

288
00:12:43,350 --> 00:12:45,123
of this authentication factor.

289
00:12:46,020 --> 00:12:47,583
One, two, three.

290
00:12:48,630 --> 00:12:50,163
And that's gonna be location.

291
00:12:51,240 --> 00:12:53,610
So, that brings us to
a security and actions

292
00:12:53,610 --> 00:12:54,750
we can apply our knowledge.

293
00:12:54,750 --> 00:12:57,510
And this one's about Gmail authentication.

294
00:12:57,510 --> 00:12:59,580
You are designing an internal seminar

295
00:12:59,580 --> 00:13:02,130
on personal cybersecurity best practices.

296
00:13:02,130 --> 00:13:03,690
So, what people should do at home,

297
00:13:03,690 --> 00:13:05,730
what they should share
with their families.

298
00:13:05,730 --> 00:13:07,380
One of your topics is the importance

299
00:13:07,380 --> 00:13:09,510
of strong email authentication

300
00:13:09,510 --> 00:13:11,250
and you're planning on demonstrating

301
00:13:11,250 --> 00:13:14,040
Google's Gmail authentication process.

302
00:13:14,040 --> 00:13:16,170
Now, whenever you sign into Gmail,

303
00:13:16,170 --> 00:13:18,390
you'll enter your password as usual,

304
00:13:18,390 --> 00:13:22,050
and a one-time code will be
sent to your phone via text,

305
00:13:22,050 --> 00:13:24,300
a voice call, or a mobile app,

306
00:13:24,300 --> 00:13:27,570
and a reply must be sent with that code.

307
00:13:27,570 --> 00:13:29,400
So, what terminology should you use

308
00:13:29,400 --> 00:13:31,380
to describe this process?

309
00:13:31,380 --> 00:13:33,880
Go ahead and put me on
pause, jot down some notes.

310
00:13:36,630 --> 00:13:37,620
Well, this is an example

311
00:13:37,620 --> 00:13:40,083
of multifactor, two-step verification.

312
00:13:41,910 --> 00:13:44,180
Multiple factors are something you know,

313
00:13:44,180 --> 00:13:46,740
in this case, password,
and something you have,

314
00:13:46,740 --> 00:13:48,540
because you have to
have your phone, right?

315
00:13:48,540 --> 00:13:51,510
You need to know your
password and your phone.

316
00:13:51,510 --> 00:13:55,230
Now, two-step verification
confirms a user's identity

317
00:13:55,230 --> 00:13:58,230
by requiring a response.

318
00:13:58,230 --> 00:14:00,870
Step one, the user signs
in with their password.

319
00:14:00,870 --> 00:14:03,870
Step two, the Google authentication server

320
00:14:03,870 --> 00:14:06,780
responds by sending a one-time
code to the user's phone

321
00:14:06,780 --> 00:14:09,240
and the user responds by sending the code

322
00:14:09,240 --> 00:14:11,850
back to the authentication server.

323
00:14:11,850 --> 00:14:14,940
We should always, always be
training our user community

324
00:14:14,940 --> 00:14:19,020
to really lock down and
secure their email, right?

325
00:14:19,020 --> 00:14:21,750
If our adversaries can get into our email,

326
00:14:21,750 --> 00:14:24,693
well, they can cause all
kinds of crazy havoc.

327
00:14:26,160 --> 00:14:29,040
So, teaching them this and
being able to explain it,

328
00:14:29,040 --> 00:14:30,723
definitely security in action.

329
00:14:31,620 --> 00:14:33,360
Big word cloud, you know what to do.

330
00:14:33,360 --> 00:14:36,030
Make sure that you understand,
right, all of these terms

331
00:14:36,030 --> 00:14:38,190
and all of these concepts
before you move on.

332
00:14:38,190 --> 00:14:40,560
If not, go on back through the lesson

333
00:14:40,560 --> 00:14:42,330
and then when you're ready,
come to the next lesson

334
00:14:42,330 --> 00:14:44,243
and I'll be waiting for you right there.
