0:00 Music 0:06 So mailboxes are obviously something that guys can attack and they can send you phishing, they can send you malicious links. 0:22 And mailboxes also can be compromised because of your previous password reuse. 0:30 So if you use your password five years in a row, be sure that that password is known for sure. 0:42 Yeah, talking about mailboxes, you should understand that if you're using like Outlook or similar stuff or 0:52 Thunderbird from Firefox, they are storing your data in computer, your emails in format dot email. 1:02 That format can be stolen. 1:05 So if somebody will infect your computer, it means that most likely all your emails are gone. 1:14 If that guy will want to copy, he will just copy it. 1:18 So there are some protections. 1:21 Around the clients. 1:22 So think about this. 1:24 How dumb is it? 1:25 So you have the Google Chrome. 1:30 Google Chrome is storing your passwords and Firefox is storing your passwords. 1:34 So let's imagine that when you first run the Firefox or the Google Chrome, they use some algorithm to store your passwords. 1:46 And it is not clear text. 1:50 They are using SQLite and inside the SQLite, they are storing your encrypted credentials. 1:56 So let me show you this solution, Nearsoft Password Viewer. 2:02 If you download it, Web Browser Password View, you will definitely see 2:08 all your saved passwords like this. 2:11 So it will just decrypt them. 2:16 So Firefox and Google Chrome said, oh my God, because of that stuff, everyone can read the passwords. 2:24 So our encryption doesn't work. 2:26 And they said, let's generate 2:28 for everyone profile and that profile will encrypt individually the passwords for everyone. 2:37 But hackers, they clearly understand that now they can just copy profile from your Windows. 2:49 They don't, you know, copy individual files which are encrypted. 2:52 They just copy a profile which has your key. 2:56 So if they will want to basically access... 3:00 your sessions and your passwords, all what they need to do is just copy your profile after just download the portable Google Chrome or Firefox and just drop that profile in that 3:14 portable Google Chrome or Firefox. 3:18 And it will decrypt it for themselves. 3:20 Because all the encryption keys are there, even though if they are there, usually you can just use such software and you will get it. 3:30 So usually there is no way, you know, how to protect your password on your computer. 3:38 I will tell you again. 3:39 So you have the most crazy encryption, which nobody can ever decrypt. 3:49 No way. 3:50 Not possible. 3:50 It's just like the size of this room. 3:55 The key is the size of this room. 3:56 So big. 3:57 But when you run your Google Chrome, right, it doesn't ask you to input anything, right? 4:04 It doesn't ask you to input the password or something, right? 4:07 So it is automatically decrypting it for you, for usability. 4:11 So if I will store your profile and just use the same client as you do, it doesn't matter the salt, anything, because it will decrypt it for me. 4:26 Using your predefined data, which is in that 4:30 profile. 4:31 It generated it for you. 4:32 So if somebody will try to steal that file, right, they will not be able to decrypt it. 4:39 But if the decryption is right in the same folder, it loses the, you know, the sense. 4:47 What I was doing 4:50 previously. 4:51 Now I'm not doing it because I got tired of this. 4:54 So I was using Veracrypt. 4:57 So why I was using Veracrypt? 5:01 I will tell you. 5:02 Because I had like dual system. 5:05 One system, I called it good system, like this. 5:10 Like my windows. 5:11 And I had the bad system. 5:13 And the bad system was the system which had all the tools, all the stuff from the GitHub. 5:21 And I realized that the bad system has access to my hard drive, whereas the good system. 5:28 And the bad system... 5:30 Can easily extract all the information from the good system, right? 5:33 So when I download something from the GitHub, you know, somebody who injected the malicious library in the GitHub, even in the good software, 5:48 So the good software can use the bad library. 5:52 Because that library, like, you know, the guy just gets angry and wanted to put some... 6:00 malware or he was compromised. 6:02 There are like big amount of stories around this, but I'm just saying that my bad system can start to access my good system because I use the same hard drive. 6:17 So I thought, I don't like this. 6:20 So I created the external hard drive where I used the VeraCrypt, USB crypt. 6:31 So what is VeraCrypt? 6:35 So this is Veracrypt. 6:37 So I encrypted my hard drive completely with the Veracrypt. 6:44 And every time when I wanted to access my Firefox, Chrome, documents, whatever, I had to write the password. 6:56 I had to open Veracrypt, input the hard drive, and just input password. 7:08 Why I didn't just cut part of my hard drive? 7:12 Because I thought that I don't have that much space. 7:18 To do those activities, right? 7:20 So let me just have it in external hard drives. 7:24 Was it a pain? 7:26 No, unless I forgot my password. 7:31 So now I have that hard drive. 7:32 I don't remember the password because I know it was crazy. 7:37 And the idea here is that if you want to protect your data, you can do it. 7:44 Even if you lose that hard drive, nobody will be able to do anything, like 99%. 7:50 For me, I have a case when one guy came to me and I was working in cyber police and he said, there is hard drive. 8:00 Which is having 8:02 you know, encrypted data, remove that encryption. 8:07 And I was like, man, like, doesn't look, you know, that it's possible. 8:12 And he said, do it, whatever. 8:14 So like, okay. 8:15 So it was Veracrypt. 8:19 And I understood that it is like, 8:23 Not that easy. 8:23 It's a complex task. 8:25 And we took that hard drive and started to brute force the password for that specific hard drive. 8:33 What was on hard drive? 8:36 I didn't know. 8:37 But the guy was like damn serious. 8:40 He said like, this is like, so he got it from somebody. 8:45 How? 8:46 That is out of my business. 8:47 But I know that he was too much confident that that hard drive should be cracked. 8:54 So using default methods, like very crypt brute force, right? 9:01 No. 9:02 No way. 9:03 Because the password... 9:05 Was not in the word list, right? 9:10 So I was already like, you know, a little bit depressed. 9:13 And I started to talk with my colleagues, like what we're going to do about this hard drive. 9:17 You know, it's like already here, like three days, we just put forcing and we already finished. 9:24 That activity, you know, we are not going to hack it, right? 9:28 So we start to discuss, maybe, 9:32 there is a tiny chance that that hard drive previously was used for some other activities. 9:40 And we start to recover the data in the hard drive. 9:44 Because I've seen that that hard drive was like one terabyte. 9:48 But Veracrypt image was maybe like 800 gigs. 9:54 So I said 200 gigs are the space which may be unallocated. 10:00 Maybe there is something there. 10:04 And you will never believe, it's like the story from the book, but we found that guy downloaded the Linux. 10:17 Think about this, that hard drive was basically there. 10:22 So he downloaded the Linux. 10:24 After he, that guy, he is like smart enough. 10:28 So he downloaded the Linux on that hard drive. 10:31 He booted from that hard drive. 10:36 He downloaded the Veracrypt using the Linux. 10:39 He encrypted the part of that hard drive. 10:42 And after he removed... 10:45 The Linux. 10:46 He like RFRM Linux. 10:49 So he just, so he did what he wanted and he removed the Linux. 10:53 And after he was just using that hard drive when he wanted, like maybe some other Linux or whatever. 11:02 So 11:02 He basically didn't use his own computer to encrypt. 11:09 He used the hard drive itself to encrypt. 11:13 You got the point, right? 11:14 So he booted from the same hard drive where he encrypted because he thought that maybe if he will do on his own computer, maybe it will be possible to recover. 11:25 But Linux has history on the terminal. 11:33 And this guy accidentally, accidentally input his password in that history. 11:41 I think maybe he was like copying it. 11:44 I don't know what he was doing exactly. 11:46 But in the terminal, for some reason, it was like Veracrip, like blah, blah, blah, input this, input that. 11:53 So he was like inputting different commands. 11:56 And in some point, he just input the password. 11:59 Maybe accidentally, I think. 12:00 And that password was like this. 12:03 People were like, how is it possible? 12:05 So I'm just saying that even in the situation which is like not possible, sometimes you can get, you know, the crazy stuff.
0:00 Music 0:06 So mailboxes are obviously something that guys can attack and they can send you phishing, they can send you malicious links. 0:22 And mailboxes also can be compromised because of your previous password reuse. 0:30 So if you use your password five years in a row, be sure that that password is known for sure. 0:42 Yeah, talking about mailboxes, you should understand that if you're using like Outlook or similar stuff or 0:52 Thunderbird from Firefox, they are storing your data in computer, your emails in format dot email. 1:02 That format can be stolen. 1:05 So if somebody will infect your computer, it means that most likely all your emails are gone. 1:14 If that guy will want to copy, he will just copy it. 1:18 So there are some protections. 1:21 Around the clients. 1:22 So think about this. 1:24 How dumb is it? 1:25 So you have the Google Chrome. 1:30 Google Chrome is storing your passwords and Firefox is storing your passwords. 1:34 So let's imagine that when you first run the Firefox or the Google Chrome, they use some algorithm to store your passwords. 1:46 And it is not clear text. 1:50 They are using SQLite and inside the SQLite, they are storing your encrypted credentials. 1:56 So let me show you this solution, Nearsoft Password Viewer. 2:02 If you download it, Web Browser Password View, you will definitely see 2:08 all your saved passwords like this. 2:11 So it will just decrypt them. 2:16 So Firefox and Google Chrome said, oh my God, because of that stuff, everyone can read the passwords. 2:24 So our encryption doesn't work. 2:26 And they said, let's generate 2:28 for everyone profile and that profile will encrypt individually the passwords for everyone. 2:37 But hackers, they clearly understand that now they can just copy profile from your Windows. 2:49 They don't, you know, copy individual files which are encrypted. 2:52 They just copy a profile which has your key. 2:56 So if they will want to basically access... 3:00 your sessions and your passwords, all what they need to do is just copy your profile after just download the portable Google Chrome or Firefox and just drop that profile in that 3:14 portable Google Chrome or Firefox. 3:18 And it will decrypt it for themselves. 3:20 Because all the encryption keys are there, even though if they are there, usually you can just use such software and you will get it. 3:30 So usually there is no way, you know, how to protect your password on your computer. 3:38 I will tell you again. 3:39 So you have the most crazy encryption, which nobody can ever decrypt. 3:49 No way. 3:50 Not possible. 3:50 It's just like the size of this room. 3:55 The key is the size of this room. 3:56 So big. 3:57 But when you run your Google Chrome, right, it doesn't ask you to input anything, right? 4:04 It doesn't ask you to input the password or something, right? 4:07 So it is automatically decrypting it for you, for usability. 4:11 So if I will store your profile and just use the same client as you do, it doesn't matter the salt, anything, because it will decrypt it for me. 4:26 Using your predefined data, which is in that 4:30 profile. 4:31 It generated it for you. 4:32 So if somebody will try to steal that file, right, they will not be able to decrypt it. 4:39 But if the decryption is right in the same folder, it loses the, you know, the sense. 4:47 What I was doing 4:50 previously. 4:51 Now I'm not doing it because I got tired of this. 4:54 So I was using Veracrypt. 4:57 So why I was using Veracrypt? 5:01 I will tell you. 5:02 Because I had like dual system. 5:05 One system, I called it good system, like this. 5:10 Like my windows. 5:11 And I had the bad system. 5:13 And the bad system was the system which had all the tools, all the stuff from the GitHub. 5:21 And I realized that the bad system has access to my hard drive, whereas the good system. 5:28 And the bad system... 5:30 Can easily extract all the information from the good system, right? 5:33 So when I download something from the GitHub, you know, somebody who injected the malicious library in the GitHub, even in the good software, 5:48 So the good software can use the bad library. 5:52 Because that library, like, you know, the guy just gets angry and wanted to put some... 6:00 malware or he was compromised. 6:02 There are like big amount of stories around this, but I'm just saying that my bad system can start to access my good system because I use the same hard drive. 6:17 So I thought, I don't like this. 6:20 So I created the external hard drive where I used the VeraCrypt, USB crypt. 6:31 So what is VeraCrypt? 6:35 So this is Veracrypt. 6:37 So I encrypted my hard drive completely with the Veracrypt. 6:44 And every time when I wanted to access my Firefox, Chrome, documents, whatever, I had to write the password. 6:56 I had to open Veracrypt, input the hard drive, and just input password. 7:08 Why I didn't just cut part of my hard drive? 7:12 Because I thought that I don't have that much space. 7:18 To do those activities, right? 7:20 So let me just have it in external hard drives. 7:24 Was it a pain? 7:26 No, unless I forgot my password. 7:31 So now I have that hard drive. 7:32 I don't remember the password because I know it was crazy. 7:37 And the idea here is that if you want to protect your data, you can do it. 7:44 Even if you lose that hard drive, nobody will be able to do anything, like 99%. 7:50 For me, I have a case when one guy came to me and I was working in cyber police and he said, there is hard drive. 8:00 Which is having 8:02 you know, encrypted data, remove that encryption. 8:07 And I was like, man, like, doesn't look, you know, that it's possible. 8:12 And he said, do it, whatever. 8:14 So like, okay. 8:15 So it was Veracrypt. 8:19 And I understood that it is like, 8:23 Not that easy. 8:23 It's a complex task. 8:25 And we took that hard drive and started to brute force the password for that specific hard drive. 8:33 What was on hard drive? 8:36 I didn't know. 8:37 But the guy was like damn serious. 8:40 He said like, this is like, so he got it from somebody. 8:45 How? 8:46 That is out of my business. 8:47 But I know that he was too much confident that that hard drive should be cracked. 8:54 So using default methods, like very crypt brute force, right? 9:01 No. 9:02 No way. 9:03 Because the password... 9:05 Was not in the word list, right? 9:10 So I was already like, you know, a little bit depressed. 9:13 And I started to talk with my colleagues, like what we're going to do about this hard drive. 9:17 You know, it's like already here, like three days, we just put forcing and we already finished. 9:24 That activity, you know, we are not going to hack it, right? 9:28 So we start to discuss, maybe, 9:32 there is a tiny chance that that hard drive previously was used for some other activities. 9:40 And we start to recover the data in the hard drive. 9:44 Because I've seen that that hard drive was like one terabyte. 9:48 But Veracrypt image was maybe like 800 gigs. 9:54 So I said 200 gigs are the space which may be unallocated. 10:00 Maybe there is something there. 10:04 And you will never believe, it's like the story from the book, but we found that guy downloaded the Linux. 10:17 Think about this, that hard drive was basically there. 10:22 So he downloaded the Linux. 10:24 After he, that guy, he is like smart enough. 10:28 So he downloaded the Linux on that hard drive. 10:31 He booted from that hard drive. 10:36 He downloaded the Veracrypt using the Linux. 10:39 He encrypted the part of that hard drive. 10:42 And after he removed... 10:45 The Linux. 10:46 He like RFRM Linux. 10:49 So he just, so he did what he wanted and he removed the Linux. 10:53 And after he was just using that hard drive when he wanted, like maybe some other Linux or whatever. 11:02 So 11:02 He basically didn't use his own computer to encrypt. 11:09 He used the hard drive itself to encrypt. 11:13 You got the point, right? 11:14 So he booted from the same hard drive where he encrypted because he thought that maybe if he will do on his own computer, maybe it will be possible to recover. 11:25 But Linux has history on the terminal. 11:33 And this guy accidentally, accidentally input his password in that history. 11:41 I think maybe he was like copying it. 11:44 I don't know what he was doing exactly. 11:46 But in the terminal, for some reason, it was like Veracrip, like blah, blah, blah, input this, input that. 11:53 So he was like inputting different commands. 11:56 And in some point, he just input the password. 11:59 Maybe accidentally, I think. 12:00 And that password was like this. 12:03 People were like, how is it possible? 12:05 So I'm just saying that even in the situation which is like not possible, sometimes you can get, you know, the crazy stuff.