ไม่สามารถเล่นวิดีโอนี้
ขออภัยในความไม่สะดวก

How To Setup & Use Passkeys on Yubikey & Your Phone! - Full Walkthrough

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ส.ค. 2024
  • Today we’ll setup a passkey on Ebay, then Google, then Paypal. Again, remember that this is a relatively new feature for consumer account protection online, so right now finding a site that uses passkeys is going to be hit or miss. Some sites do say they support passkeys but the implementation is a little glitchy, so for those sites I would recommend setting up 2FA instead.
    I’ll show you how to set up a hardware bound passkey with my Yubikey, and then I will show you how to set up a passkey that is bound to your phone.
    This episode is sponsored by Yubico!
    Get $5 a Yubikey 5 NFC: www.yubi.co/sh...
    Get a Yubikey and protect your accounts! amzn.to/3S8BSLL *
    Watch my Passkey episodes here! - • All About Passkeys
    LINKS:
    Who is using passkeys? www.passkeys.c... and passkeys.direc...
    Passkeys FAQ: www.yubico.com...
    www.yubico.com...
    Hardware Bound Passkey FAQ: www.techrepubl...
    FIDO2 and Passkeys: www.techrepubl...
    1Password now supports passkeys: www.techrepubl...
    FIDO White Paper: media.fidoalli...
    fidoalliance.o...
    How Long Does It Take To Brute Force A Password in 2023? www.hivesystem...
    Passkeys with Google: www.theverge.c...
    Passkey.org: passkey.org/#T...
    FTC: Links marked with * are affiliate links, which means I make a small commission off any sales.
    Becoming a Morse Code Member by checking out the perks linked here!:
    / @shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    SUBSCRIBE! 🌸 www.youtube.com...
    TWITTER 🌸 / snubs
    Patreon 🌸 / shannonmorse
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    SUPPORT MY WORK
    Patreon 💛 / shannonmorse
    Buy Me a Coffee 💛 www.buymeacoff...
    Shop 💛 snubsie.com/shop
    TeeSpring 💛 teespring.com/...
    Coupon Codes 💛 snubsie.com/su...
    Tech I Use & Recommend 💛 kit.co/Shannon...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    FOLLOW THE SOCIALS THINGS
    Twitter 🌸 / snubs
    Instagram 🌸 / snubs
    TH-cam 🌸 www.youtube.com...
    Website 🌸 www.shannonrmor...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    TECH I USE AND RECOMMEND
    My Kits, Builds, and Must Haves ✨ kit.co/Shannon...
    My Amazon Influencer Page ✨ www.amazon.com...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    MY OTHER SHOWS
    ThreatWire 🌙 www.youtube.com...
    Sailor Snubs 🌙 www.youtube.co...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    GET IN TOUCH
    Mail ✈
    snubsie.com/co...
    Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com
    My Media Kit ✈ snubsie.com/wo...
    Sponsor This Channel ✈ snubsie.com/sh...
    Music from 🎵 Epidemic Sound: www.epidemicso...
    💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜
    😍 FTC DISCLAIMER 😍
    Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Any products provided as gifts are listed above. Thank you for your support!
    Comment section code of conduct policy:
    Constructive feedback is appreciated, but please leave unproductive, divisive and harmful conversation at the door. Hateful comments are not tolerated, and these kinds of messages will be automatically removed. Thank you for making this community a welcoming experience for all viewers :)
    snubsie.com/co...

ความคิดเห็น • 112

  • @vasiovasio
    @vasiovasio 5 หลายเดือนก่อน +5

    Shannon, your enthusiasm is Contagious! Keep Going, Girl! ☺️☺️☺️

  • @PadraigDoran
    @PadraigDoran 10 หลายเดือนก่อน +34

    Hi Shannon and others. PayPal and eBay sites don't allow registration of a backup security key and should be called out on it. It's recommended practice to register at least 2 hardware security keys. There's already a ticket about it on PayPal community support but seems to be ignored.

    • @againstbulshit2895
      @againstbulshit2895 7 หลายเดือนก่อน

      Hardware key got broken, no more access 😂

    • @PadraigDoran
      @PadraigDoran 7 หลายเดือนก่อน

      Well you can have a TOTP Code as a backup authenticator so there's at least that, but would be better just to allow many physical keys @@againstbulshit2895

    • @killer2600
      @killer2600 6 หลายเดือนก่อน +2

      For 2FA, on PayPal a security key IS the backup to using an authenticator app (TOTP) or vice-versa. Personally, I use the authenticator app 2FA on PayPal. Backing up the QR codes and installing them on new devices is easy and never limited by website rules or UI. I use a Yubikey for TOTP so I'm still retaining the "hardware kept secrets" aspect of a (FIDO) security key.

  • @lVlegabyte
    @lVlegabyte 10 หลายเดือนก่อน +3

    I love when you upload security videos.I actually understand them

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +1

      This is the best compliment. Thank you! I'm glad my videos are easy to understand 😁

  • @Cbat1
    @Cbat1 10 หลายเดือนก่อน +4

    Hey Shannon, I really like the content you put out. It is very helpful to this old man. I’d love to see more iOS oriented content, if possible. Thanks for what you do!

  • @keaco73
    @keaco73 9 หลายเดือนก่อน +1

    Clear as mud! Glitchy passkeys is an understatement.

  • @autobot3b5
    @autobot3b5 10 หลายเดือนก่อน +2

    Awesome series! I'd love to see more about Yubikeys. They have so much more options such as using it for PGP keys, and more. I'd love to hear your option and see a walk-through tutorial.

  • @christopherguy1217
    @christopherguy1217 10 หลายเดือนก่อน +3

    I have learned that when setting up TOTP to select the "I can't scan the QR code" option and to get the seed directly. I setup the Yubico for TOTP using the seed I input. I securely record the seed so I can repeat this on my backup Yubico as sites don't allow multiple TOTPs.

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +1

      That's a smart and useful tip!

  • @grizfan93
    @grizfan93 10 หลายเดือนก่อน +4

    How would I handle accessing an account on multiple devices? For example, if I secured my Google account with a passkey, either a Yubikey or my iPhone, how would I then log into that Google account on my smart TV or cable box for Android TV?

    • @JonTheChron
      @JonTheChron 5 หลายเดือนก่อน

      From your phone as it's done now :)

  • @radekcrlik5060
    @radekcrlik5060 10 หลายเดือนก่อน +3

    Great explanation. I've started using HW keys only recently. Embarassing because I work in IT :) And I still find how it all works with all those options a bit confusing. Must be a nightmare for folks with non IT background.

    • @nadya4315
      @nadya4315 หลายเดือนก่อน

      What if I lost my passkey ? It means I wouldn’t restore access to email?

    • @radekcrlik5060
      @radekcrlik5060 หลายเดือนก่อน

      @@nadya4315 A lot of services I've used force you to use a secondary method for authentication. For example, one time codes. So you should be ok while loosing only a passkey. But true, you need to store those somewhere safe.

    • @radekcrlik5060
      @radekcrlik5060 หลายเดือนก่อน +1

      @@nadya4315 Almost every service I've used don't allow you to use only 1 method of authentication when you use this 2FA or key. So they wanted me setup a second HW key or one-time login codes or something. So if you loose your primary passkey you can still login with a second method. I hope it helps :)

  • @piotrlapinski
    @piotrlapinski 3 หลายเดือนก่อน

    I’m an owner of the 5c nfc.
    Still can’t figure out from your videos what the difference between passkeys and hardware keys is, I imagine both require sticking or tapping your Yubikey. Listening to you from Poland 🇵🇱 🎉

  • @ZAKtalksTECH
    @ZAKtalksTECH 10 หลายเดือนก่อน

    Very helpful. Thanks for making the details simple. Shared with family.

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +1

      Glad it was helpful! Miss you! You going to CES?

    • @ZAKtalksTECH
      @ZAKtalksTECH 10 หลายเดือนก่อน

      @@ShannonMorse I'm still weighing costs and sponsorship. Will let you know.

  • @jeffhale1189
    @jeffhale1189 10 หลายเดือนก่อน

    Thanks for sharing. I enjoy your security content. Blessings on your day.

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน

      Thank you! You too!

  • @michaelekpo4011
    @michaelekpo4011 10 หลายเดือนก่อน

    Excelente! Thank you Shannon for this wonderful video! Would you please do a video on Norton Power Eraser, HitmanPro, and Kaspersky? I wish to see what your opinion is using these products. Thank you once again for your informative videos!!!

  • @Knards
    @Knards 10 หลายเดือนก่อน +1

    Shannon, I am about to upgrade one of my computers from Win 10 to 11. Will the yubikey that is registered to the 10 work on the 11? Or is that registration on the websites? Is there a need to make a short video on what to do if you upgrade or do a clean install of windows as it pertains to the current Yubikey?

  • @ScottSugimura
    @ScottSugimura 10 หลายเดือนก่อน +3

    I understand Passkey is relatively new. But, if I use Passkey with a website. Shouldn’t the website let me delete my password? I’m still vulnerable if they’re hacked and my password is stolen? Correct? This assumes I’m not using 2FA. Am I missing something?

    • @Cbat1
      @Cbat1 10 หลายเดือนก่อน

      I was wondering the same thing

    • @Darkk6969
      @Darkk6969 10 หลายเดือนก่อน

      It depends on how they manage the security features on the website. If there is no option to disable the password best you can do is use a password manager to create a really long password and only use it as backup.

    • @portman8909
      @portman8909 6 หลายเดือนก่อน +2

      U2F is still two step. They’d need both the password and key to get into the account. What’s so difficult to understand?

  • @edvinsroze5388
    @edvinsroze5388 6 หลายเดือนก่อน +1

    Hi Shannon - I just followed your instructions to add my Yubikey to eBay - awesome! HOWEVER - they do not seem to have the ability to a a backup key - any suggestions?

  • @sinusoidal100
    @sinusoidal100 4 หลายเดือนก่อน

    Nice videos. I do not get the point of storing a passkey on a device that is protected by a digit PIN. So, 4 digits and you're compromised. So in this case, phone seems more secure (if it does not fallback to a PIN). Or maybe a hardware key with a fingerprint, I'll check for that.

  • @kandjlumber
    @kandjlumber 3 หลายเดือนก่อน

    I have the Yubikey 5 nfc. is this the updated version of the setup? getting kind of confused here..

  • @unmapped89361
    @unmapped89361 10 หลายเดือนก่อน +11

    I like your videos, but I can hardly read what you try to show us. The text/writing is so small.

  • @Darkk6969
    @Darkk6969 10 หลายเดือนก่อน

    Love these videos to show how easy it is to secure those accounts Shannon. If only more websites make use of them.

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +1

      I totally agree!

  • @kg4tri
    @kg4tri 10 หลายเดือนก่อน +1

    I tried to set it up on ebay but it doesn't give me the options for passkey . I set up passkeys in one Google account but it will not let me set it up on the other one on this device . phone only .

  • @storkille1745
    @storkille1745 3 หลายเดือนก่อน

    I have hardware Security key from yubikey but I can’t seem to get iPad Pro 12.9 get to scan it with NFC. Does iPad Pro have NFC ??

  • @user-fb3pp8uo4l
    @user-fb3pp8uo4l 5 หลายเดือนก่อน

    SEEING YOU GET SO EXCITED OVER YUBIKEYS sHannon I'll send you a couple for Christmas

    • @ShannonMorse
      @ShannonMorse  4 หลายเดือนก่อน

      no need! I have too many haha

  • @philorton1940
    @philorton1940 5 หลายเดือนก่อน

    Shannon, thank you for all the good videos! I have bought 2 keys and want to 'map out' my security plan before initiating the keys. One topic I can not find information on is running multiple authenticators on the same device. Thinking about retaining my Lastpass authenticator for sites that are less critical and adding the Yubico authenticator for use with physical passkey sites where higher levels of security are needed. Do you have any information place we can research this setup? Or suggestions? Thank You....

  • @Rydia704
    @Rydia704 2 หลายเดือนก่อน

    Does the PC you hold your phone near have to have bluetooth in order to detect passkey on phone? As mine doesn't pop up with anything.

  • @Dante_Resoru
    @Dante_Resoru 6 หลายเดือนก่อน

    Thats for the video, so passkey would replace the security key feature ? I now have my yubikeys setup with my google account but no passkey, this I did setup in bitwarden. One reason for that was the limit of 25 passkeys storable on yubikey itself, while I still have them set as security keys to my bitwarden account.

  • @baby333
    @baby333 4 หลายเดือนก่อน +1

    4:58 hahaha :P love when you do that
    9:20 SOOOOOOOOOOOOOOOO TRUEEEEEEEE!!!!!!! XD

  • @grahamarcher2729
    @grahamarcher2729 10 หลายเดือนก่อน

    Hi Shannon, another great video! I've just sent off for two Yubikeys (I used your site to get a discount, thanks). Can you have the same PIN on the primary key as the spare? or wouldn't you advise this?

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +1

      You certainly can set them both up with the same PIN but I use different ones for each one. I have a memorization technique to remember each one.

  • @davilajeremy
    @davilajeremy 10 หลายเดือนก่อน

    Nice work. How can you sign in via android? Any videos?

  • @captgrant
    @captgrant 5 หลายเดือนก่อน +1

    No option to setup FIDO key on ebay. Are they still working on it?

    • @optionstraderman
      @optionstraderman 8 วันที่ผ่านมา

      I found the same to be true. I contacted Ebay this morning and was told PASSKEYS are only available for Business Accounts and Ebay Store Accounts, not Personal Accounts. Today is Aug 10, 2024. Instead of Passkeys, I opted to use the YubiKey for 2FA Authentication in combination with the Yubico Authenticator App. Seems to work just fine.

  • @JamesDLegan
    @JamesDLegan 10 หลายเดือนก่อน +1

    What do you do if you have forgotten the pin number? Is there a way to reset it?

    • @tcasex
      @tcasex 10 หลายเดือนก่อน

      The pin number on the yubikey has to be reset, therefore it will wipe the key itself of any certificates, otp, static passwords, etc that have been setup. Gotta start over at that point.

    • @BrainFester
      @BrainFester 10 หลายเดือนก่อน

      @@tcasexJames, have you downloaded the Yubikey Manager app from the web site?

  • @elbundy99
    @elbundy99 9 หลายเดือนก่อน

    Great video, but I have one question, how do I get a phone into the device list like it is shown in video at 6:51. On my iMAC I get only liste my old mobile, for my new pixel8 I have always go via the "use different phone or tablet" option. Even after going multiple times through it an tick the "remember that computer " checkbox it will not shown. When I click on manage devices button I see just my old phone in m devices and not the Pixel8 as well there is no way to add or remove a device.

  • @ricp
    @ricp 21 วันที่ผ่านมา

    is the Biometrics route required for google accounts or could you have done it via the Yubikey instead?

    • @optionstraderman
      @optionstraderman 8 วันที่ผ่านมา

      I'm using the standard YubiKey 5 NFC key on Google using passkeys. It works just fine.

  • @x91w
    @x91w 2 หลายเดือนก่อน

    My Yubikey only stores 5 passkeys, Token2 stores 300. Still a strange low limit

  • @paul-erikhansen5769
    @paul-erikhansen5769 10 หลายเดือนก่อน

    Great video, thanks..... but I just missed the reason to buy/use Yubikey, when you might as well use ie. your mobile phone that you already have?? what are the added benefits of the Yubikey?

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +2

      Hey, check out my passkey playlist! I did a video about the pros and cons of each version

  • @roymazz
    @roymazz 10 หลายเดือนก่อน

    There seems to be a flaw with Adobe. I registered my yubikey as a passkey, put in my PIN from the Windows Security screen, touch the "Y" and it says it was setup successfully, but when I logout and login to try it, the Windows Security screen comes up and says the security key doesn't look familiar. I've setup a passkey on other sites with no problem. Wonder if you could try Adobe and see if you get the same thing.

  • @OliverJonCross
    @OliverJonCross 6 หลายเดือนก่อน

    On desktop Gmail asks for my username and password. I want it to use my phone and fingerprint. I click to create a passkey and I get the windows security message asking me to insert a usb key. I don't get the option to use my phone. I have 2 factor authentication via USB as well. I'm a bit confused at how to set this up and various videos always show the option to choose your phone.

  • @ColoRadio6996
    @ColoRadio6996 10 หลายเดือนก่อน

    GM Shannon, Stay Safe in Denver., J

  • @thethinkingman9338
    @thethinkingman9338 หลายเดือนก่อน

    That was a clear as mud

  • @practicalengineer7442
    @practicalengineer7442 10 หลายเดือนก่อน

    I absolutely love this video. And I love how you showed how to do this with your phone step by step. There is just 2 things though that i wanted to ask. By any chance for passkey to work does your PC have to have Bluetooth capabilities? Secondly i have a Pixel 6A and have a passkey already set up for my phone but yet everytime I try to login i never get the prompt on my phone to verify my identity. I end up having to either use my password or use the QR code everytime just to login. Do you know by any chance is this something on my end or could it be on Google's end?

    • @GrantKegley
      @GrantKegley 10 หลายเดือนก่อน +1

      I'm wondering the same thing regarding the Bluetooth

    • @optionstraderman
      @optionstraderman 8 วันที่ผ่านมา

      Yeah, I'm thinking that Bluetooth IS required. Unfortunately, my PC doesn't have Bluetooth, so it's a no go for using that method for me.

  • @janokartal5690
    @janokartal5690 10 หลายเดือนก่อน

    Nice Shannon 😊

  • @miner3993
    @miner3993 8 หลายเดือนก่อน

    Would I be about to use a Security Key C NFC The YubiKey 5 C NFC to create passkeys for my APPs and Websites? Or do I need to get The YubiKey 5 C NFC. What would be the reason way I would want to get The YubiKey 5 C NFC over the Security Key C NFC

  • @anonymitycoffee917
    @anonymitycoffee917 19 วันที่ผ่านมา

    WITCH ONE DO I BUY TO DESKTOP PC WITH USB THAT DOES HAVE USB -C ON NOT SURE WHAT I LOOKING FOR CAN I JUST HELP WITH THAT NAME OF THE LOOKING FOR TY

    • @optionstraderman
      @optionstraderman 8 วันที่ผ่านมา

      I have not seen a key that does both USB A and USB C. They are two separate keys or you can buy either one and then purchase an adapter to plug it into to switch to the other style port. I have the YubiKey 5 NFC, and I purchased an adapter to go from USB-A to USB-C. Got them on Ebay. Hope this helps.

  • @AlucardFeeds
    @AlucardFeeds 10 หลายเดือนก่อน

    Can someone help me with passkey not saving into the same file? It keeps making new files and not syncing

  • @StephenYoung-iq7qg
    @StephenYoung-iq7qg 10 หลายเดือนก่อน

    Great job thanks for the info you really know you're stuff keep being you"😊 have a blessed and amazing day.🌞 👍 👍 💯

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน

      Thanks, you too!

  • @NotMolly-jf2rh
    @NotMolly-jf2rh 6 หลายเดือนก่อน

    Does yubi work with Brave?

  • @spy8464BB
    @spy8464BB 6 หลายเดือนก่อน

    Hello Shannon. Please respond. I have two 5 series yubikeys and need just a little clarification. While using a 5 series yubikey is there a way to use my key with accounts like B of A..... that don't offer anything but 2FA sms? I keep hearing on other yubikey videos that the 5 series offers multiple uses. Am I missing something?
    Thanks

    • @optionstraderman
      @optionstraderman 8 วันที่ผ่านมา

      It appears it's really up to the individual businesses to decide what security they choose to make available to users. For example, in this video she setup Ebay as a PASSKEY. I went to my Ebay account to do the same and could not find anything referencing PASSKEYS for Personal Accounts. I contacted Ebay and they confirmed that PASSKEYS are only available on Business Accounts and Store Accounts. So I just used my key to login with the 2FA Authentication they have available. I suspect many companies will eventually make Passkey use available, but until they do, a Hardware physical YubiKey + Yubico Authenticator for 2FA is likely the next most secure way to protect your account. Once you have it setup this way, you may want to physically copy the QR Code Page and print it out for every account as you introduce the YubiKey as well as print out a copy of the "Backup Codes" and keep them safe just in case. Once you do that, you can remove or disable all other types of account login 2FA methods so your account becomes relatively bullet proof unless someone has your physical Yubikey in hand.

  • @GrueTurtle
    @GrueTurtle 9 หลายเดือนก่อน

    More security or less privacy?

  • @RobSnow-ui4sz
    @RobSnow-ui4sz 8 หลายเดือนก่อน

    What if I change my phone service from Apple to Android or vice versa. Am I locked into that eco system? How do I port passkeys back and forth systems. I don't think it is possible. If it is do share. Also those that use public libraries computers need not apply so this creates a rift in society for those that have and those that have not. Passwords will be around for a long long time until that can be resolved.

  • @LionRoars918
    @LionRoars918 10 หลายเดือนก่อน

    Love my Yubikey

  • @kg4tri
    @kg4tri 10 หลายเดือนก่อน

    I got a Ybikey a few months ago and set up a second Gmail account to test it out. It never asked for a pin.

    • @ShannonMorse
      @ShannonMorse  10 หลายเดือนก่อน +3

      Some websites won't require the pin on your yubikey.

  • @m.b786
    @m.b786 10 หลายเดือนก่อน

    passkey without GAFAM product ?

  • @God77Particle
    @God77Particle 10 หลายเดือนก่อน

    ❤❤have a great weekend ❤❤

  • @excellancy7739
    @excellancy7739 5 หลายเดือนก่อน

    Most of your videos are on or about PC’s. Why don’t you do one or several on or about Yubico keys for Apple products.

    • @ShannonMorse
      @ShannonMorse  5 หลายเดือนก่อน

      Most of my audience is Windows/Linux/Android and Apple videos don't get a lot of views. I also only have an iPhone, no other Mac products. I may delve into apple products more if there is enough audience base to justify the cost of the products. I would need to purchase them as apple wouldn't send them.

  • @LazyJones
    @LazyJones 10 หลายเดือนก่อน

    Comment for engagement

  • @tenragrats1
    @tenragrats1 7 หลายเดือนก่อน

    I can’t believe how confusing this is,,,,

    • @portman8909
      @portman8909 6 หลายเดือนก่อน

      It’s not? It’s the easiest 2FA option

  • @djo5296
    @djo5296 10 หลายเดือนก่อน

    firefox pls update yourself ; __ ;