How does a security token work? (AKIO TV)

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ก.ย. 2024
  • How can a security token provide a valid access code without communicating with the server? How does such a token work? Let's find out!
    (AKIO TV) MMXVIII

ความคิดเห็น • 78

  • @joshuavelez623
    @joshuavelez623 2 ปีที่แล้ว +10

    The most comprehensive video on this topic on the internet. Simply impressive.

  • @Martin97perussini
    @Martin97perussini 7 หลายเดือนก่อน +2

    Excellent, very clear explanation.

  • @db1234tube
    @db1234tube 2 ปีที่แล้ว +7

    Exceptionally well-done video on the subject matter. Although this video was posted in 2018, it provides very easy to understand information on the subject of Security Tokens. I was recently issued a security token devise and wanted to know how it worked. This video was spot on. Thank you for doing such a great job explaining.

    • @morisn
      @morisn 7 หลายเดือนก่อน

      yeah, I'm watching it in 2024 and still relevant. This kid must be a TH-cam Celebrity now, 🙂

  • @mrmrsabrego9143
    @mrmrsabrego9143 ปีที่แล้ว +1

    This guy really has an amazing way of explaining the concepts, I am jealous. Great Job man.

  • @ChronusXIII
    @ChronusXIII 3 ปีที่แล้ว +4

    I had 3 questions to which I was searching for answers. And you just answered all of them in one video. Thanks mate!

  • @baraamoslimany4768
    @baraamoslimany4768 8 หลายเดือนก่อน +1

    thank you for this explanation, that was an easy and simple

  • @TechKyle
    @TechKyle 5 ปีที่แล้ว +4

    That's actually quite some interesting maths and computing that goes on with these tokens. Great video as always!

    • @AKIOTV
      @AKIOTV  5 ปีที่แล้ว +3

      It is indeed very interesting. Thanks for the comment!

    • @wilsonmarquina
      @wilsonmarquina 2 ปีที่แล้ว

      @@AKIOTV About three years ago my bank gave me an electronic device, an ENTRUST datacard 8-digit random code generator, to carry out online operations in web banking, etc. That device still seems great to me, I even carried it on my keychain, and it had nothing to do with my smartphone and the 6-digit code generator App (less secure) and the possibility of losing the smartphone, being hacked, or be the target of a DDos attack. How can I reuse that ENTRUST datacard device?

  • @istvan368
    @istvan368 4 ปีที่แล้ว +5

    Omg, I have been searching for explanation on this topic for half an hour but didnt find a proper, easily understandable video, but you did it. Thank you very much, your sentences and explanation are just number 1. I have had only a few teachers in my whole life who were able to explain things this way as you did. Thanks again!!!
    I have heard in another video, that if the clock is going in a different speed on the token, then the server tries to generate the hash for 1 minute earlier and 1 minute after as its current counter and it compare those values with the value generated on the token, is that right?
    p.s. i have subscribed to your channel

    • @AKIOTV
      @AKIOTV  4 ปีที่แล้ว +1

      I believe that is indeed a thing, but it depends on the implementation. Someone might opt for a very harsh system for maximum security if that's needed (which wouldn't do what you mentioned) but it's also possible to have a more forgiving approach when convenience is valued. Also you have to consider what happens for 2 minutes, or three? Where do you draw the line? That all depends on how much you value ease of use or security.

    • @istvan368
      @istvan368 4 ปีที่แล้ว

      @@AKIOTV That's true. Thanks for the quick answer. :)

    • @wilsonmarquina
      @wilsonmarquina 2 ปีที่แล้ว

      @@AKIOTV About three years ago my bank gave me an electronic device, an ENTRUST datacard 8-digit random code generator, to carry out online operations in web banking, etc. That device still seems great to me, I even carried it on my keychain, and it had nothing to do with my smartphone and the 6-digit code generator App (less secure) and the possibility of losing the smartphone, being hacked, or be the target of a DDos attack. How can I reuse that ENTRUST datacard device?

  • @manuel56354
    @manuel56354 2 ปีที่แล้ว

    Really really good explanations, thank you very much, I wasn't aware of much of this and have been researching it for 2 days.

  • @sohdd100
    @sohdd100 2 ปีที่แล้ว

    Excellent video, I just pulled apart token which is no longer used as bank has moved to phone based system. This token was operational till couple of months ago, it is clock based token. Manufactured in Oct 30th 2006, so clock did stay in sync for 15 years, used daily and battery lasted that long as well.

  • @bladder1010
    @bladder1010 9 หลายเดือนก่อน

    Thank you for explaining the concepts so clearly.

  • @MrSreenir
    @MrSreenir ปีที่แล้ว

    Well-done video covering the need aspects to understand the token based authentication

  • @FrankyKurniawan
    @FrankyKurniawan 10 หลายเดือนก่อน

    Thanks man, the moment you said 'clock', it Clicks! 👍

  • @AsmodeusTechno
    @AsmodeusTechno 4 ปีที่แล้ว

    Dr. Harinda is undoubtedly the best lecturer!

  • @tatogiorgi1956
    @tatogiorgi1956 2 ปีที่แล้ว

    Excellent explanation...very clear for everyone. Thanks

  • @charalamposvlassopoulos7456
    @charalamposvlassopoulos7456 3 ปีที่แล้ว +1

    Very clear and informative. Great video!

  • @mattloughran8699
    @mattloughran8699 3 ปีที่แล้ว

    Thanks very much! That was an absolutely stellar explanation! Much appreciated!

  • @chinundercover
    @chinundercover ปีที่แล้ว

    I subscribed due to the wooden and duct tape mic stand. This is my people.

  • @morisn
    @morisn 7 หลายเดือนก่อน

    Interesting video, congrats on your knowledge and clear explanation.

  • @whed.8699
    @whed.8699 3 ปีที่แล้ว +1

    That was a really really really helpful video, thank you king.

  • @GamerTayhong
    @GamerTayhong 2 ปีที่แล้ว

    FYI. Clocks can be synchronized via HF radio receiver or GPS receiver. The HF radio takes less power and is used by some wristwatch.

  • @zabluestacks3700
    @zabluestacks3700 2 ปีที่แล้ว

    I would modify the counter based method so that the user can press a "I have accidently pressed button on the token" button on the server after typing in the password. That way, the server counter will be in sync again.

  • @crowderglen
    @crowderglen 10 หลายเดือนก่อน

    Very well presented!

  • @willreidy5851
    @willreidy5851 2 ปีที่แล้ว

    Thanks for your explanation, really helpful and great knowledge

  • @Prof_awesome
    @Prof_awesome 3 ปีที่แล้ว

    Keep it up man your voice is made for youtube!

  • @cyrusserrano2356
    @cyrusserrano2356 2 หลายเดือนก่อน

    very well presented.. cheers.

  • @tinker7722
    @tinker7722 2 ปีที่แล้ว

    Brilliant explanations! Thanks!👍

  • @saadawad7153
    @saadawad7153 3 ปีที่แล้ว

    Your presentation is really outstanding, Keep it going.

  • @dlcfunn8506
    @dlcfunn8506 2 ปีที่แล้ว

    Thank you for the explanation

  • @charleybear0330
    @charleybear0330 2 ปีที่แล้ว

    Great explanation and super helpful Thank you

  • @saratakella2278
    @saratakella2278 4 ปีที่แล้ว +2

    Boy your voice and Accent is nice & so British ....:-)

  • @five-star-media
    @five-star-media 7 หลายเดือนก่อน

    Very well explained

  • @addiboy007
    @addiboy007 2 ปีที่แล้ว

    Great explanation, thank you!!!

  • @AlienShowz
    @AlienShowz 4 ปีที่แล้ว +1

    What’s the difference between a security token and a Yubikey?

  • @franky350
    @franky350 3 ปีที่แล้ว

    thanks, finally found what i was looking for. go on the good work

  • @wilsonmarquina
    @wilsonmarquina 2 ปีที่แล้ว

    Great !!
    Excellent..

  • @robd4391
    @robd4391 4 ปีที่แล้ว +1

    Really interesting, thanks man!

  • @justifyl
    @justifyl 4 หลายเดือนก่อน

    Let's say you are finding this token device, and it takes some good amount of time , AND THEN we press the button for it to give us an 8 digit code. how will that be sync since the click was later on then the servers'

  • @wilsonmarquina
    @wilsonmarquina 2 ปีที่แล้ว

    About three years ago my bank gave me an electronic device, an ENTRUST datacard 8-digit random code generator, to carry out online operations in web banking, etc. That device still seems great to me, I even carried it on my keychain, and it had nothing to do with my smartphone and the 6-digit code generator App (less secure) and the possibility of losing the smartphone, being hacked, or be the target of a DDos attack. How can I reuse that ENTRUST datacard device?

  • @-_-O
    @-_-O 3 ปีที่แล้ว

    I was kind of guessing that's how it works but wouldn't it in theory be possible to extract the data in the memory of the token, then using a number of working examples to figure out how it generates the key?

  • @72dilara
    @72dilara 4 ปีที่แล้ว +1

    great explanation!

  • @frankmontez6853
    @frankmontez6853 2 ปีที่แล้ว

    I've small tiny relatively simple token device which looks pretty much like the one you first explained. Its authentication system for my job taking care of Mom . So , it doesn't seem to have a GPS function. As you've explained , both server and token device both generate a random number ? And it generates a new set of numbers every minute ..

  • @headless5076
    @headless5076 2 ปีที่แล้ว

    What happens if the battery dies in the key fob? The server n the key clock not synchronized if the battery dies. What if the server and the key get synchronize when ever it asks the user to type the key.

  • @mohamedjama8753
    @mohamedjama8753 3 ปีที่แล้ว

    Thank you it is very helpful information

  • @piotr780
    @piotr780 หลายเดือนก่อน

    what type of memory they use ?

  • @frankmontez6853
    @frankmontez6853 2 ปีที่แล้ว

    I've accidentally taken it with me for several hours all over town miles away from home and nothing negative happened .Called Vesta visit clock

  • @matt6405
    @matt6405 4 ปีที่แล้ว

    Very fine video, very informative. Well done. I'm just getting into tokens, what are your thoughts on the Yubico line of tokens?

    • @AKIOTV
      @AKIOTV  4 ปีที่แล้ว

      Not sure, I haven't used one.

  • @aaron6841
    @aaron6841 3 ปีที่แล้ว

    Do you find that many online accounts supports this type of token I can't get it to work with sites like Google or Facebook?

  • @engineerlawalhamzatademola4267
    @engineerlawalhamzatademola4267 2 ปีที่แล้ว

    I want to build this for a company and that's why I'm here

  • @Obelisk57
    @Obelisk57 2 ปีที่แล้ว

    Do all non-counter type tokens issued to be used on the same server, display the same number at any given time block?

    • @AKIOTV
      @AKIOTV  2 ปีที่แล้ว

      No

  • @___echo___
    @___echo___ 2 ปีที่แล้ว

    I like you mic stand lol

    • @___echo___
      @___echo___ 2 ปีที่แล้ว

      great video btw :)
      I'm pretty certain what many people (and I) own is a version of the first system you mentioned, mixed with the last one, I think it has a timer connected to some kind of key/algorithm, you input the 6 digit code the server gives you, get a code back and fill that in. A quick look at its patent page seems to confirm that (it has the patent numbers on the back). Most bank security tokens are like that where I live.
      maybe it allows for larger time blocks?

  • @rdgdxph
    @rdgdxph 4 ปีที่แล้ว

    How does this technology compare to the 2FA of Google Authenticator and Twilio? Would this technology replace security token?

    • @AKIOTV
      @AKIOTV  4 ปีที่แล้ว +1

      same principle except you run it on a phone instead of a dedicated device

    • @rdgdxph
      @rdgdxph 4 ปีที่แล้ว

      @@AKIOTV Thank you!

    • @Kinkstur
      @Kinkstur 3 ปีที่แล้ว

      @@AKIOTV I am using a App called Symantec VIP Access on my phone to generate a code is a dedicated device safer or is the phone just as safe?

  • @minhokim8263
    @minhokim8263 2 ปีที่แล้ว

    Wonderful!

  • @emanuelortiz6945
    @emanuelortiz6945 2 ปีที่แล้ว

    I love your accent OMG

  • @khaledtellopalacios3072
    @khaledtellopalacios3072 4 ปีที่แล้ว

    Good video, thanks

  • @kathrynbeaumont4408
    @kathrynbeaumont4408 2 ปีที่แล้ว

    You've got the same phone as me! Nokia 215

  • @ShahzadPerwaiz
    @ShahzadPerwaiz 2 ปีที่แล้ว

    that was great!!!

    • @AKIOTV
      @AKIOTV  2 ปีที่แล้ว

      Thanks!

  • @lazarorivera3384
    @lazarorivera3384 5 ปีที่แล้ว

    Thank you, buddy

  • @petejones6827
    @petejones6827 ปีที่แล้ว

    so thats why once the battery dies the device is done for.

  • @tanishqredkar2800
    @tanishqredkar2800 2 ปีที่แล้ว

    I have a rsa token fallen on streets of India don't know what to do about it

  • @raytvmy
    @raytvmy 4 ปีที่แล้ว

    is it possible to decrypt the hash with enough of codes generated and time?

  • @fatihkan2601
    @fatihkan2601 2 ปีที่แล้ว

    I just found one of these on the floor and I’m here to know what the hell is it. I will never watch any kind of video like this. :)

  • @gaatutube
    @gaatutube 4 ปีที่แล้ว

    Nice.

  • @cliveholloway1259
    @cliveholloway1259 3 ปีที่แล้ว

    Its all Geek to me.