00:06:53 Timothy: Chris is on camera twice. 00:09:03 OPCUG Q&A: Zoom keeps crashing on my desktop. Now on my laptop. Desktop rebooting 00:13:54 OPCUG Q&A: Welcome to all members and guests! Guests, if you want to join, see https://opcug.ca/join-or-renew/ Want to present at Q&A? Give us your material and we can create slides, or we have a PowerPoint template you can download and use: https://opcug.ca/downloads/Q&A-Template.potx Send in questions, shares, etc SuggestionBox@opcug.ca 00:16:56 Tom and Rex: What if your file is seventeen exabytes? 00:19:11 Stew Bruce: Diane. You got your camera working! 00:20:19 Diane P: yep i turned off some button :) 00:21:52 Natalie: Whenever I plug my phone to my computer via USB, it charges, regardless of the set option. Luckily, it stops at 80% by default. 00:22:21 Alan German (OPCUG Meeting Coordinator): Luckily may well be a setting! 00:22:44 David Odynski: take your adapter with you on the trip 00:23:14 OPCUG Q&A: Samsung's patch gap https://www.notebookcheck.net/Samsung-Internet-your-monthly-security-patch-never-reaches-it.1372179.0.html 00:23:55 Tom and Rex: Use Brave 00:24:27 Tom and Rex: Reacted to "take your adapter with you on the trip" with 👍🏾 00:25:12 Tom and Rex: Chrome spies too much 00:26:07 Natalie: I use Mozilla for most things, but it's sometimes not accepted by sites. 00:26:20 OPCUG Q&A: Vibe coding competition on Ocotber https://opcug.ca/events/vibe-coding-competition/ Want to compete? Email SuggestionBox@opcug.ca with info on your vibe coding project 00:26:58 David Odynski: don't do any banking on your phone use a cabled pc 00:28:06 Tom and Rex: It could be a tragedy or a comedy.... 00:28:29 Glen: Should the Samsung browser be used at all? Could a malicious website hack your phone through the Samsung browser even when looking at mundane cat videos? 00:28:45 Tom and Rex: Replying to "Should the Samsung browser be used at all? Could a malicious website hack your phone through the Samsung browser even when looking at mundane cat videos?" yes 00:29:03 OPCUG Q&A: Replying to "Should the Samsung browser be used at all? Could a malicious website hack your phone through the Samsung browser even when looking at mundane cat videos?" personally, I wouldn't use it for anything. There are alternatives! 00:30:42 Stew Bruce: Replying to "Should the Samsung b..." Unless you have to use it, I would suggest disabling the App and using something else. 00:32:05 E O'Driscoll: Too bad the chatbot doesn't get the tools needed for the task. 00:32:28 Tom and Rex: that's why it's called vibe coding. You go back and forth, back and forth, back and forth, back and forth, back and forth, back and forth, 00:32:46 OPCUG Q&A: Replying to "Too bad the chatbot doesn't get the tools needed for the task." You can almost certainly ask it how to obtain the tools. But then you probably have to follow the steps 00:33:50 OPCUG Q&A: Replying to "Too bad the chatbot doesn't get the tools needed for the task." If you ask for it to do the program in PowerShell, PowerShell is already installed on Windows. 00:35:25 Tom and Rex: Claude is good for coding 00:42:44 Tom and Rex: Replying to "Should the Samsung browser be used at all? Could a malicious website hack your phone through the Samsung browser even when looking at mundane cat videos?" @Stew Bruce or uninstall if it lets you 00:43:15 E O'Driscoll: I wonder what happens if you tell Claude to stop using patronizing language. 00:44:16 Stew Bruce: Replying to "Should the Samsung b..." I think it is one of those Apps the manufacturer insists on the user having, but it can be disabled. 00:45:40 Tom and Rex: FWIW, if you want a small executable, tell the chatbot to use the C language and the tinyCC compiler 00:48:13 Tom and Rex: For a second factor, if you use an Authenticator app like google Authenticator, you can set it to require you fingerprint or PIN to open. 00:50:02 Natalie: Apparently, CRA is now making their 2nd MFA mandatory.. 00:50:59 France Picard Ottawa: Replying to "Apparently, CRA is n..." They have been warnng us since before tax period but I didn't know they had decided to move ahead. 00:51:15 Alan German (OPCUG Meeting Coordinator): Replying to "Apparently, CRA is now making their 2nd MFA mandatory.." They will allow an authentication app to be used which is a good solution. (e.g. Sophos Intercept X for Mobile AV app has a built-in authenticator)) 00:51:46 Tom and Rex: long password is twenty characters or more, 00:52:19 Alan German (OPCUG Meeting Coordinator): Replying to " long password is twenty characters or more," ...and use a password manager to remember such passwords! 00:55:29 Natalie: RBC allows you to choose from list of phone numbers, and if you want a call or text (e.g. can still get a call to a landline for those who still have one). 00:56:14 Tristan: Replying to " long password is tw..." Some password manager options: https://bitwarden.com/ https://proton.me/pass https://keepass.info/ 00:56:33 Tom and Rex: Criminals with access to the signaling plane (via compromised carriers, rogue interconnects, or leased global titles) can: - Intercept calls and SMS (including one-time passcodes used for 2FA) - Track a subscriber’s real-time location - Redirect traffic or perform “network-level SIM swaps” without touching your SIM or account 00:57:34 Tom and Rex: The public telephone system is highly vulnerable to criminal compromise. The core problem is that much of the global telecom infrastructure still relies on legacy signaling protocols (SS7, Diameter) that were designed for a closed, trusted club of carriers and lack modern security controls like strong authentication, integrity checks, and encryption. 00:58:03 Diane P: usually my user name is my email address. Is that okÉ 01:00:17 Darlene: Where do you look on your email for autofowarding settings? 01:01:58 Tristan: For those familiar with SSH Authentication, Passkey is very similar technology. 01:02:08 Stew Bruce: Replying to "Where do you look on..." Depends on the email you use but, start with “settings” and poke about. 🙂 01:02:55 E O'Driscoll: I use the CRA bingo card. Annoying at first but now I'm used to it. 01:02:57 Alan German (OPCUG Meeting Coordinator): Replying to "Where do you look on your email for autofowarding settings?" For G-mail it is in Settings (gear icon) 01:03:39 Natalie: For bingo card: you get one, and then need it for all challenges in the future? 01:03:45 France Picard Ottawa: Replying to "I use the CRA bingo ..." I set this up for mom when she was alive. Annoying but it worked and she could use it. 01:04:03 France Picard Ottawa: Replying to "For bingo card: you ..." Yes, you have to keep it in a secure place 01:07:05 Timothy: 2FA becomes harder when you leave the country. 01:07:44 Tristan: How long it takes to crack a password: https://www.imss.caltech.edu/services/security/recommendations/passwords/password-table 01:08:15 Natalie: Gmail always offers "try another way" 01:12:27 Diane P: My iPhone uses facial recognition. Can that be a second factor 01:12:45 Tristan: The recommendations from the Canadian Centre for Cyber Security: https://www.cyber.gc.ca/en/guidance/best-practices-passphrases-and-passwords-itsap30032 01:13:27 Stew Bruce: Replying to "My iPhone uses facia..." I think that is more of a first factor. 01:13:48 Darlene: I found Auto-forwarding in gmail. Nothing is listed there so can I assume I'm okay in that regard? 01:15:01 Tristan: Replying to "My iPhone uses facia..." That is usually, just to allow access to the phone or app on that device. 01:16:51 Tristan: If use passkey always set them up on at least two devices for each service. 01:18:06 Tristan: An authenticator like Ente Auth, can be synced between phone and PC for TTOP codes. https://ente.com/auth/ 01:18:21 Tom and Rex: I think all authenticators work alike, based on your email and the website 01:19:20 Stew Bruce: Apple’s passwords app syncs as well. 01:20:08 Carol: wrt using facial recognition: What if someone has/uses a picture of you? 01:20:08 Natalie: Wow, so much to take into account for 2FA. Thanks for all of the info! 01:22:16 Tom and Rex: Most apps implement the TOTP algorithm (RFC 6238): after you scan a QR code, the app stores a shared secret and, together with the current time, generates a 6‑digit code that changes every ~30 seconds. 01:22:45 Tristan: Passkeys Explained: https://www.youtube.com/watch?v=1nnOvYHwweE&pp=ygURcGFzc2tleSBleHBsYWluZWQ%3D 01:22:48 Deborah: you mean you only need one authenticator app per device? if you have an iPhone and a pc you would need two different ones/ 01:24:42 OPCUG Q&A: Replying to "you mean you only need one authenticator app per device? if you have an iPhone and a pc you would need two different ones/" Even if you have separate devices, you should be able to install an authenticator app on each device and transfer that authentication data from one authenticator app to the other. I think! 01:25:00 Stew Bruce: Replying to "you mean you only ne..." You van put the iCloud app on a pc and sync that way. 01:25:02 Deborah: Replying to "you mean you only need one authenticator app per device? if you have an iPhone and a pc you would need two different ones/" thanks 01:25:09 Tristan: Replying to "you mean you only ne..." It all depends on the Authenticator App used and if it supports multi-device sync. 01:25:24 Deborah: Replying to "you mean you only need one authenticator app per device? if you have an iPhone and a pc you would need two different ones/" thank you all 01:25:28 Carol Pearson: Thanks everyone! 01:25:29 Natalie: Thanks 01:25:32 E O'Driscoll: Many thanks - great info. 01:25:36 Mary-Lou Simac, Ottawa: Thank you!