Digital Security Best Practices

Digital Security Best Practices

Source: YouTube · a16z crypto · published Feb 7, 2025 · 50:05

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

[BLUF: Matt Gleeson outlines a practical, step-by-step approach to securing online accounts by prioritizing email recovery, using multi-factor authentication, and avoiding vulnerable recovery methods like SMS or phone numbers—emphasizing that security is about being "secure enough" not maximally secure, with key takeaways on authentication, recovery, and device hardening.]

Key Takeaways:
• Secure email as the central recovery point using password + Google Authenticator, avoiding SMS or phone number recovery due to SIM swap risks 11:55.
• Use advanced protection on services like Twitter/X to disable SMS recovery when using two-factor authentication, preventing SIM swap attacks 18:54.
• For services like Discord, AWS, and cloud storage, secure recovery via email and disable phone number recovery to avoid SIM swap exposure 21:40.
• Harden devices by using strong passcodes, disabling inbound data, and turning off radios—especially critical for storing sensitive financial or crypto data 29:41.
• SIM swaps are highly effective and common, especially during holidays, and are often preceded by targeted fishing campaigns—carriers like T-Mobile are most vulnerable 36:00.

[Security is a layered process: protect your email, eliminate weak recovery paths, and harden devices. The goal is not perfect security, but resilience against real-world attacks.]

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] we're lucky enough to have Matt gleon with us who is a security engineer on the a16z crypto team Matt's one of those amazing people who can both uh simultaneously make you feel massively paranoid about uh all the ways You're vulnerable and uh ways that uh people might be trying to attack attack you but also tell you the ways that you can uh solve it and make yourself more secure so Matt come on up so I'm Matt I'm a security security engineer what that really means is I'm a quality assurance person um which is kind of less glamorous I've worked with startups I've worked with big companies I've conducted hacks that youve probably like the types of hacks you've heard about in the news I've seen a lot of that I've been doing this for a bit over a decade and I've been doing it as a hobb…