48
April 27, 2017 Secure Your Account with Two-factor Authentication HKBU IS Awareness Seminars Stephen Chan CGEIT, PMP, CISSP, ISO27001 Lead Auditor

Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

April 27, 2017

Secure Your Account with Two-factor

AuthenticationHKBU IS Awareness Seminars

Stephen Chan CGEIT, PMP, CISSP, ISO27001 Lead Auditor

Page 2: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Note to audience:

The information in this document is strictly for educational purpose

within HKBU, and shall not be further distributed or duplicated

without due permission.

Page 3: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Agenda

• Potential Google Misuse

• Demonstration – How to enable Google 2-Step Authentication

Page 4: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

POTENTIAL GOOGLE ACCOUNT

MISUSE

Page 5: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

GMAIL being used in HKBU

Page 6: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

How much can be done / known

All I have said / received in emails

All contacts

Page 7: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

How much can be done / known

Browsing History, YouTube History, Calendar, Photos, Google+

Huge amount of information in Drive

Plus.. all your online accounts trusting this

google account

Page 8: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Should they be guarded with a

password only?

https://howsecureismypassword.net/

Some of the worst passwords in Human History

!<n%^?^>TV+}FgG93b+C

Some of the worst passwordsfor My Grandma

v2H%$%P{K6!M#P9}W4_M

4C6fK3d2C472qGR9cT6a

Turn out they will be here

Page 9: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Even when you have a super password

1. You may be tricked to tell somebody

2. You may type it to a phishing site

3. The service provider may lose it

4. May be captured by keystroke logging eavesdropping

5. Or Public Wi-Fi eavesdropping

6. Email recovery of your password to hacker’s mailbox

7. Plaintext in your phone / desktop / cloud

8. Being looked over your shoulder (e.g. with a telescope, 30m away)

9. Acoustic sniffing & smartphone motion analysis

Page 10: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

HOW TO ENABLE 2-FACTOR

AUTHENTICATION ON GOOGLE

Theoretical Background

Page 11: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Authentication factors –

Proof that you are you

• Knowledge factors

– Some secret you know, such as a password, PIN, pattern lock, your private information etc.

• Possession factors

– Some physical object you have, such as a USB stick with a secret token, a bank card, a key, a phone

• Inherence factors

– Some physical characteristic of you – biometrics – such as a fingerprint, eye iris, voice

• Any two of the above factors combined –two-factor authenticatione.g. e-Channel for immigration clearance

Page 12: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Best Practice Google Account Security

• Design a strong password for your Google Account suitable for you

• Set up Google Account recovery

• Set up Two Step Authentication on your Google Account

• Make sure you phone is automatically locked by passcode

• Don’t get phished

• Be cautious and sensitive **

Page 13: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

HOW TO ENABLE 2-FACTOR

AUTHENTICATION ON GOOGLE

Step 0 – Preparation

Page 14: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

What you need

• A desktop

• A phone with

– SMS service / Receive verification call from Google

– Google Play access to install APPS

– Data network connectivity (3G / Wi-Fi)

• iPhone can work as well

Page 15: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Enroll Account in 2-Step Verification with

Your Phone

Page 16: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

I got an SMS from my phone

Page 17: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

OK – that phone is mine

Page 18: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

HOW TO ENABLE 2-FACTOR

AUTHENTICATION ON GOOGLE

Step 1 – Enable Google Prompt as the 2nd Factor

Page 19: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Choose Google Prompt and add your phone

Page 20: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

You need to make sure your phone is set

with this Google account

Page 21: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

And then Google will detect your phone

Page 22: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Easily, it works – Google Prompt is set

Page 23: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Basically it is completed!

Page 24: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Now you logon from Another Device

Page 25: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

After typing password, you will be

prompted

At this moment, your phone

will get a Google Prompt

Page 26: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

This will show up on phone – click YES to allow logon

Click YES only if it makes sense

Page 27: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Your phone needs to be online, though

Sometimes you cannot get the Google prompt: your phone may be outside network. Press here if so. (We will tell you how to set up.)

Page 28: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

HOW TO ENABLE 2-FACTOR

AUTHENTICATION ON GOOGLE

Step 2 – Further Enable Google Authenticator

Page 29: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Google Authenticator is an APP

Page 30: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

You need to install from Google Play / App Store

Page 31: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Scan the code from your Phone

Page 32: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Code generated on Phone

for Account Login

072 860

Page 33: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

It works easily

Page 34: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Authenticator App becomes another choice

for your 2nd Factor

Page 35: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Now, try to logon from Another Device

Page 36: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

After typing password, you will be asked

to enter a 2nd-factor

Since your phone may be outside network, you do not receive Google Prompt. Click here if so.

Page 37: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Choose Google Authenticator

Input the code from you phone’s Authenticator,

and you will get in.

Page 38: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

It is quite simple actually.

Page 39: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

HOW TO ENABLE 2-FACTOR

AUTHENTICATION ON GOOGLE

Step 3 – Further Prepare Back-up Codes for yourself

Page 40: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Trusted Devices

• Generally, you do not need to enter the 2nd-Factor all the time if the device is TRUSTED

• You may revoke the TRUST any time

• What can I do, if I want to use a New Device to logon, but my phone is not here?

Page 41: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Backup code can help if the phone is not

present

Page 42: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Backup codes – they are one-time password

Save it, preferably offline.

Page 43: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

HOW TO ENABLE 2-FACTOR

AUTHENTICATION ON GOOGLE

Appendix – Secure Key

Page 44: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Security Key is a bit complicated, but it

helps if you don’t have a phone at all

Page 45: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

SOME MORE OPINIONS

Page 46: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Check your Google Account Security

Page 47: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Welcome to the digital age

1. I / myself vs my account

2. Personas and digital identities

3. Segregate your digital universe

4. Be truthful

5. Unplug and enjoy your worldly life

Page 48: Secure Your Account with Two-factor Authentication · 4/27/2017  · Authentication factors – Proof that you are you • Knowledge factors –Some secret you know, such as a password,

Thank You