Podcasts about fido alliance

  • 118PODCASTS
  • 187EPISODES
  • 46mAVG DURATION
  • ?INFREQUENT EPISODES
  • Feb 2, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about fido alliance

Latest podcast episodes about fido alliance

IDTheftCenter
The Fraudian Slip Podcast - 2025 Annual Data Breach Report: Takeaways and Key Findings - S7E2

IDTheftCenter

Play Episode Listen Later Feb 2, 2026 24:20


Welcome to the Fraudian Slip, the Identity Theft Resource Center's (ITRC's) podcast, where we talk about all things identity theft, fraud and scams that impact people and businesses. Last week, we published our 2025 Annual Data Breach Report by ITRC. ITRC President James E. Lee presented the findings at the Identity, Authentication and the Road Ahead Identity Policy Forum, hosted by the Better Identity Coalition, the FIDO Alliance and the ITRC. The 2025 Annual Data Breach Report by ITRC looks at the number of data compromises, the root cause of the compromises, the types of data compromised, trends, solutions and much more.   Follow on LinkedIn: www.linkedin.com/company/idtheftcenter/ Follow on Twitter: twitter.com/IDTheftCenter

Identity At The Center
#384 - The FIDO Alliance's Next Frontier: Digital Credentials and Wallets

Identity At The Center

Play Episode Listen Later Nov 10, 2025 30:36


Live from Authenticate 2025, Jeff Steadman and Jim McDonald sit down with the Cal Ripken of IDAC, Andrew Shikiar, Executive Director and CEO of the FIDO Alliance. Andrew shares exciting updates on the incredible progress of Passkeys, revealing that over 3 billion are now in use securing accounts. We discuss the key themes of the conference, including the ongoing arms race with AI in security and the critical role of identity verification. Andrew also unveils the new Passkey Index, an initiative to provide industry benchmarks for deployment success. Looking ahead, the conversation shifts to the FIDO Alliance's broadening focus on digital credentials and wallets, aiming to solve the usability and certification challenges that have held the space back. Finally, we hear about the global expansion of the Authenticate conference brand, with a new event launching in Singapore.Connect with Andrew: https://www.linkedin.com/in/andrewshikiar/Learn more about FIDO: https://fidoalliance.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comChapter Timestamps:00:00:00 - Introduction to Authenticate 2025 Themes00:02:50 - Welcoming Andrew Shikiar of the FIDO Alliance00:04:00 - Andrew's Keynote: Passkey Progress and Future Goals00:05:17 - Over 3 Billion Passkeys in Use00:06:57 - Improving the Passkey User Experience (UX)00:09:02 - Introducing the Passkey Index for Benchmarking00:10:46 - The Growth of the Authenticate Conference00:14:55 - FIDO Alliance's New Focus: Digital Credentials and Wallets00:17:25 - Overcoming Hurdles in Digital Credential Adoption00:20:03 - The Role of Major Stakeholders in FIDO's Success00:23:05 - The Future of the Authenticate Conference00:24:00 - Announcing Authenticate APAC in Singapore00:25:07 - Global Differences in Passkey Adoption00:28:19 - Closing Thoughts and FIDO Feud RecapKeywords:Andrew Shikiar, FIDO Alliance, Passkeys, Authenticate 2025, identity verification, digital credentials, digital wallets, passwordless, WebAuthn, user experience, Passkey Index, cybersecurity, authentication, mobile driver's license, multi-factor authentication, IDAC, Identity at the Center, Jeff Steadman, Jim McDonald

Identity At The Center
#383 - Navigating Identity and AI with IDPro at Authenticate 2025

Identity At The Center

Play Episode Listen Later Nov 3, 2025 52:07


Live from Authenticate 2025, Jeff Steadman and Jim McDonald sit down with Dr. Tina Srivastava, an IDPro board member and co-founder of Badge Inc., for a crucial discussion on the rapidly evolving landscape of identity and authentication.Tina shares her insights on the conference, the evolution from physical hacks to sophisticated AI-driven threats like supercharged phishing, and the current challenges facing the industry. The conversation delves into the complexities of synced Passkeys, the critical vulnerability of account recovery processes, and the slow pace of regulation in keeping up with technology.As a board member for IDPro, Tina highlights the immense value of the practitioner-focused community, the supportive culture within its Slack channels, and makes an exciting announcement about the creation of new member-driven committees to shape the future of the organization. They explore the concept of the "AI arms race" and why identity professionals cannot afford to wait for the next big thing, emphasizing that collaboration and information sharing through communities like IDPro are essential to staying ahead of adversaries.Connect with Tina: https://www.linkedin.com/in/tina-s-8291438a/Find out more about IDPro: https://www.idpro.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comChapters00:00 Introduction and Greetings00:16 Highlights from Authenticate 202501:39 FIDO Feud Rematch Discussion03:17 Guest Introduction: Tina Srivastava03:46 Conference Insights and AI Challenges06:16 Regulatory Environment and Passkeys09:11 Phishing and AI Supercharged Attacks12:28 QR Codes and Accessibility Issues13:09 The Importance of Phishing Resistant Authentication22:24 IDPro Community and Practitioner Support25:18 Community Support and Engagement26:26 IDPro's Role in Identity Events27:48 Future Directions for IDPro29:19 Introducing Committees in IDPro30:39 AI and Identity Verification37:07 The Importance of Information Sharing45:35 Public Speaking and Personal Growth50:58 Conclusion and Final ThoughtsKeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Tina Srivastava, IDPro, Authenticate 2025, Passkeys, AI, Artificial Intelligence, Cybersecurity, Phishing, Deepfakes, Authentication, Account Recovery, Biometrics, Identity and Access Management, IAM, NIST, Regulation, Identity Verification, Synced Passkeys, FIDO Alliance

Identity At The Center
#373 - Going Passkey Phishing with Nishant Kaushik

Identity At The Center

Play Episode Listen Later Sep 15, 2025 57:45


In this episode of the Identity at the Center podcast, Jeff and Jim discuss various aspects of identity access management (IAM) policies and the importance of having a solid foundation. They emphasize the need for automation, controls, and how IAM policies should be created without technology limitations in mind. The discussion also covers the implementation challenges and the evolving concept of identity verification. Jeff, Jim, and their guest, Nishant Kaushik, the new CTO at the FIDO Alliance, also delve into the issues surrounding the adoption of passkeys, highlighted by Rusty Deaton's IDPro article, and address some common concerns about their security. Nishant offers insights into ongoing work at FIDO Alliance, the potential of digital identity, and the importance of community in the identity sector. The episode concludes with mentions of upcoming conferences and an homage to the late identity expert, Andrew Nash.Timestamps00:00 Introduction and Greetings00:18 Importance of IAM Policies01:36 Challenges in Policy Implementation05:09 Conferences and Discount Codes07:59 Introducing the Guest: Nishant Kaushik08:42 The Role of the FIDO Alliance and Digital Identity10:35 Concerns and Solutions for Passkeys22:21 Final Thoughts on Passkeys and Authentication29:48 Credential Security Concerns30:03 FIDO Members and Their Contributions30:38 Getting Involved in Working Groups31:58 Conversations at Authenticate Conference32:29 Evolution of the Authenticate Conference34:32 Automotive Authentication Challenges36:04 Community and Collaboration38:33 Remembering Andrew Nash41:41 Lightning Round: Current State of AI and Identity44:21 Decentralized Identity: Current Trends49:47 Non-Human Identity: Future Perspectives52:19 New York Sports Fandom54:33 Conclusion and Upcoming EventsConnect with Nishant: https://www.linkedin.com/in/nishantkaushik/Learn more about the FIDO Alliance: https://fidoalliance.org/IDPro Article by Rusty Deaton: https://idpro.org/blackhat-and-def-con-2025-thoughts/Kill the Wallet? Rethinking the Metaphors Behind Digital Identity by Heather Flanagan: https://sphericalcowconsulting.com/2025/07/22/digital-wallet-metaphor/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com

Desde el reloj
Exportación e importación de Passkeys

Desde el reloj

Play Episode Listen Later Aug 1, 2025 10:49


Apple ha implementado ya en sus nuevos sistemas operativos (iOS 26 y hermanos) la posibilidad de exportar e importar Passkeys. A la espera de que la FIDO Alliance publique el estándar definitivo, la empresa de la manzana se ha basado en el borrador ya publicado para implementar esta funcionalidad.

Identity At The Center
#359 - Identiverse 2025 - Andrew Shikiar's FIDO Alliance Update

Identity At The Center

Play Episode Listen Later Jul 7, 2025 27:25


In this episode of the Identity at the Center Podcast, Jeff and Jim broadcast live from Identiverse 2025. Special guest Andrew Shikiar from the FIDO Alliance joins to talk about efforts to push passkey adoption and reduce reliance on passwords. Topics covered include the technicalities of passkeys, their adoption by major banks like Wells Fargo, and initiatives for adding more signals for high assurance scenarios. The episode wraps up with exciting news about the upcoming Authenticate conference and plans for an Authenticate APAC edition in Singapore.00:00 Introduction and Greetings00:16 Podcast Highlights and Recent Activities01:38 Guest Introduction: Andrew Shikiar from FIDO Alliance01:58 FIDO Alliance and Passkey Adoption07:13 Technical Insights on Passkeys14:52 Authenticate Conference and Community20:20 Global Adoption and Regional Differences25:13 Conclusion and Wrap-UpConnect with LinkedIn: https://www.linkedin.com/in/andrewshikiarLearn more about the FIDO Alliance: https://fidoalliance.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com

IT Privacy and Security Weekly update.
Broken Windows. The IT Privacy and Security Weekly Update for the Week Ending June 17th., 2025

IT Privacy and Security Weekly update.

Play Episode Listen Later Jun 18, 2025 18:55


EP 247. ... and in this update, Microsoft has updated Windows Hello to require both infrared and color cameras for facial authentication, improving security by addressing a spoofing vulnerability, though it now requires visible lighting. This increases biometric reliability and inconvenience to users in low-light settings. Consider exploring alternative operating systems like Linux for flexible authentication options. Aim Labs identified and helped patch 'EchoLeak,' a zero-click vulnerability in Microsoft 365 Copilot that risked data exfiltration via malicious emails, highlighting the need for stonking great AI guardrails.Denmark is shifting from Microsoft Office and Windows to LibreOffice and Linux to enhance digital sovereignty and reduce reliance on foreign technology, driven by security, economic, and geopolitical priorities.Chinese AI companies are bypassing U.S. chip export controls by processing data in third countries like Malaysia, using suitcases of hard drives to transport AI-training data.Mattel has teamed up with OpenAI to develop AI-enhanced toys, promising safe, engaging, and age-appropriate experiences, with the first product set to launch later this year.Apple's new passkey import/export feature, built on FIDO Alliance standards, enables secure credential transfers across platforms, boosting interoperability while maintaining biometric security.This advances user convenience and cross-ecosystem flexibility. Now you can adopt passkeys to streamline secure authentication across your devices and platforms. A data broker owned by major U.S. airlines sold passenger flight data to DHS, prompting privacy concerns as agencies track travel without disclosing data sources.WhatsApp will begin displaying ads in its Updates section, using limited user data like location for targeting, while preserving end-to-end encryption for chats and messages.INTERPOL's Operation Secure dismantled over 20,000 malicious IPs linked to 69 malware variants, arresting 32 suspects and seizing significant data to curb phishing and fraud.Find the full transcript for this podcast here.

The Future of Security Operations
LastPass's Christofer Hoff on navigating incidents while rebuilding the security org from scratch

The Future of Security Operations

Play Episode Listen Later Apr 1, 2025 55:59


The Future of Security Operations podcast is back for a sixth season, and, to kick it off, Thomas is joined by Christofer Hoff. Christofer has over 30 years of experience in network and information security architecture, development, engineering, operations, and management, including security leadership roles at Bank of America, Citadel, and Juniper Networks. He's currently Chief Secure Technology Officer at LastPass, a unique role that combines the duties of CSO and CTO, while also serving on the board at FIDO Alliance. In this episode: [02:00] How blogging landed Christofer his first couple of jobs in security [06:50] Taking a more holistic approach to security through collaboration [09:40] Rebuilding LastPass's security org from scratch [12:03] Reflecting on incidents - what LastPass did right [16:12] Communicating with customers and the broader community during incidents [20:15] Navigating tech debt as a security leader [23:55] The biggest challenges AI has produced for his team [25:16] How LastPass uses an AI working group for decision-making [29:00] The evolving challenges of browser security [35:05] Passkeys, passwords and the future of secure authentication [41:40] Tips on hiring and structuring effective security teams [46:47] How LastPass creates efficiency through automation [50:38] The biggest changes he'd like to see in security [54:44] Connect with Chris The Future of Security Operations is brought to you by Tines, the orchestration, automation, and AI platform that powers some of the world's most important workflows. Where to find Christofer Hoff: LinkedIn Chris's Rational Survivability blog Where to find Thomas Kinsella: LinkedIn Tines Resources mentioned: Chris on Google's Cloud Security Podcast LastPass Security Incident Summary

IDTheftCenter
The Fraudian Slip Podcast - ID Crime Sucks: What Can Be Done in an Era of Deregulation and Smaller Government

IDTheftCenter

Play Episode Listen Later Feb 27, 2025 46:46


Welcome to the Fraudian Slip…the Identity Theft Resource Center's podcast, where we talk about all things identity compromise, crime, and fraud that impact people and businesses. Typically, on this podcast, we'd introduce a topic, a guest expert, and our CEO, Eva Velasquez. This month, we're listening in on “Identity Crimes Suck. So What Can We Do About it in an Era of Deregulation and Smaller Government?”, a special panel from the Identity, Authentication, and the Road Ahead Cybersecurity Policy Forum last month hosted by the Better Identity Coalition, the FIDO Alliance and the ITRC. Guests on the panel include Kemba Walden, President of Paladin Global Institute; John Breyault, Vice President of Public Policy, Telecommunications, and Fraud at the National Consumers League; Dan Lips, Senior Fellow at the Foundation for Research on Equal Opportunity; and the moderator, ITRC President, James E. Lee. Follow on LinkedIn: www.linkedin.com/company/idtheftcenter/ Follow on Twitter: twitter.com/IDTheftCenter

Easy Prey
Next-Gen Account Security with Christiaan Brand

Easy Prey

Play Episode Listen Later Jan 22, 2025 43:50


With phishing and password breaches on the rise, passkeys could offer a more secure, user-friendly solution that could reshape how we protect our online identities. Today's guest is Christiaan Brand. Christiaan is the co-founder of Entersekt, a financial services security firm and a key player at Google in their security and identity teams.  A respected voice in cybersecurity, Christian co-chairs the FIDO2 technical working group focusing on standardizing robust online security protocols in advancing the use of passkeys. He has been at the forefront of the shift toward more secure, password-free systems. We'll hear his insights on the challenges and opportunities of implementing passkeys to create safer online environments for users and organizations. Show Notes: [00:52] - Christiaan is part of the security team for Google accounts. He's been with Google for 9 years. Prior to that he had a startup. [01:30] - He joined the FIDO Alliance around the same time Google joined in 2013. When he joined Google, he was able to continue with the same type of work. [02:35] - Each of the big tech companies represents a portion of the market when it comes to how we interact with the web and apps. [04:06] - He became interested in security when he started thinking about what could go wrong with new technology solutions. He wanted users to be able to access their financial information in a safe and secure way. [05:06] - 2FA began gaining traction with Google in 2011. It coincided with the launch of Google Authenticator. 2FA was also used by a gaming company. [07:54] - Usability is important, that's why having an app that displays the codes was one of the first forays into making the technology more accessible. [08:34] - Passkeys allow us to move beyond passwords, leaving the extra hassle of traditional multi-factor authentication behind. [11:05] - Key fobs were one of the earlier ways to try and bring usability to security. Now the technology is being moved to smartphones. [12:33] - Passkeys are a replacement for a password manager. [13:35] - Passkeys are extremely long and asymmetric in nature. You and the site you're going to both have the passkey. [14:27] - The service will have the public part of the passkey, and you'll have the private part. Even if the public part leaks out, your passkey will still be secure. Passkeys can never be revealed to phishing sites. [15:47] - FIDO brings the second authentication step in. The service also has to identify themselves. [20:04] - Password managers try to balance security and convenience. Logging in or accessing a passkey is a unique challenge for providers. [22:20] - Phone numbers are a way to get users back into their accounts. [25:19] - Single device users have extra challenges. [26:08] - There are pros and cons to external sources of identity. [29:44] - The FIDO website has many certified solutions. [33:21] - To get passkeys into daily users' lives, we need to start using them on daily applications where we log in frequently. [35:49] - Hopefully this passkey solution will stand the test of time. [37:34] - Attacks are beginning to shift to session hijacking. [38:24] - DBSC or device-based session credentials is a new standard parallel to FIDO. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Entersekt Christiaan Brand on LinkedIn Christiaan Brand on Twitter Christiaan Brand on Facebook FIDO2 Technical Working Group Learn More About Passkeys Passkeys.Dev FIDO Alliance Passkeys

Tech News Weekly (MP3)
TNW 367: Best of 2024 - Tech News Weekly's Best Moments in 2024

Tech News Weekly (MP3)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Tech News Weekly (Video HI)
TNW 367: Best of 2024 - Tech News Weekly's Best Moments in 2024

Tech News Weekly (Video HI)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

All TWiT.tv Shows (MP3)
Tech News Weekly 367: Best of 2024

All TWiT.tv Shows (MP3)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Tech News Weekly (Video LO)
TNW 367: Best of 2024 - Tech News Weekly's Best Moments in 2024

Tech News Weekly (Video LO)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Tech News Weekly (Video HD)
TNW 367: Best of 2024 - Tech News Weekly's Best Moments in 2024

Tech News Weekly (Video HD)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

All TWiT.tv Shows (Video LO)
Tech News Weekly 367: Best of 2024

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Total Mikah (Video)
Tech News Weekly 367: Best of 2024

Total Mikah (Video)

Play Episode Listen Later Dec 26, 2024 106:03 Transcription Available


A look back at some of our favorite interviews from the past year: Emily Forlini of PCMag and her story about the AI "dating scene" AI through ChatGPT Plus and AI boyfriends and her somewhat lackluster experience. Jennifer Pattison Tuohy and the breaking news that the U.S. Department of Justice is suing Apple for claims that the company has an illegal monopoly over the smartphone market. Amanda Silberlng and her story that she wrote about how how AI images have entered this year's Met Gala's online discourse through celebrities who "appeared" on the Met Gala carpet. Abrar Al-Heeti and her story about how Harvard students created an app called I-XRAY that uses Meta's Ray-Ban smart glasses and facial recognition to find personal data on people in real-time, raising privacy concerns. Leah Nylen of Bloomberg talks with Mikah about the Google Antitrust Case and The Department of Justice's recommendations that could reshape the tech giant. And Nick Steele and David Turner from the FIDO Alliance join Mikah to discuss the Alliance's new specifications involving passkeys and their portability. Host: Mikah Sargent Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Paul's Security Weekly
The 2024 Cybersecurity Market Review - Mike Privette, Rew Islam - ESW #387

Paul's Security Weekly

Play Episode Listen Later Dec 13, 2024 107:09


For our second year now, Mike Privette, from Return on Security and the Security, Funded newsletter joins us to discuss the year's highlights and what's to come in the next 12 months. In some ways, it has been a return to form for funding, though some casualties of a tough market likely had to seek acquisition when they might have otherwise raised another round and stayed independent a while longer. We'll cover some stats, talk 2025 IPO market, and discuss the likelihood of (already) being in another bubble, particularly with regards to the already saturated AI security market. It won't be all financial trends though, we'll discuss some of the technical market trends, whether they're finding market fit, and how ~50ish AI SOC startups could possibly survive in such a crowded space. In this segment, we discuss two new FIDO Alliance standards focused on credential portability. Specifically, if passwordless is going to catch on, we need to minimize friction and maximize usability. In practice, this means that passkeys must be portable! Rew Islam of Dashlane joins us to discuss the new standards and how they'll help us enter a new age of secure authentication, both for consumers and the enterprise. Segment Resources: Elevating Passwordless Security With AWS Nitro Synced Passkeys Will Be Portable FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys This week, in the enterprise security news, NOTE: We didn't get to 2, 3, 5, or 7 due to some technical difficulties and time constraints, but we'll hit them next week! The show notes have been updated to reflect what we actually discussed this week: https://www.scworld.com/podcast-segment/13370-enterprise-security-weekly-387 Snowflake takes security more seriously Microsoft takes security more seriously US Government takes telecom security more seriously Cleo Capital takes security more seriously EU's DORA takes effect soon Is phishing and security awareness training worthless? CISOs need financial literacy Supply chain firewall is basic but useful All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-387

Enterprise Security Weekly (Audio)
The 2024 Cybersecurity Market Review - Mike Privette, Rew Islam - ESW #387

Enterprise Security Weekly (Audio)

Play Episode Listen Later Dec 13, 2024 107:09


For our second year now, Mike Privette, from Return on Security and the Security, Funded newsletter joins us to discuss the year's highlights and what's to come in the next 12 months. In some ways, it has been a return to form for funding, though some casualties of a tough market likely had to seek acquisition when they might have otherwise raised another round and stayed independent a while longer. We'll cover some stats, talk 2025 IPO market, and discuss the likelihood of (already) being in another bubble, particularly with regards to the already saturated AI security market. It won't be all financial trends though, we'll discuss some of the technical market trends, whether they're finding market fit, and how ~50ish AI SOC startups could possibly survive in such a crowded space. In this segment, we discuss two new FIDO Alliance standards focused on credential portability. Specifically, if passwordless is going to catch on, we need to minimize friction and maximize usability. In practice, this means that passkeys must be portable! Rew Islam of Dashlane joins us to discuss the new standards and how they'll help us enter a new age of secure authentication, both for consumers and the enterprise. Segment Resources: Elevating Passwordless Security With AWS Nitro Synced Passkeys Will Be Portable FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys This week, in the enterprise security news, NOTE: We didn't get to 2, 3, 5, or 7 due to some technical difficulties and time constraints, but we'll hit them next week! The show notes have been updated to reflect what we actually discussed this week: https://www.scworld.com/podcast-segment/13370-enterprise-security-weekly-387 Snowflake takes security more seriously Microsoft takes security more seriously US Government takes telecom security more seriously Cleo Capital takes security more seriously EU's DORA takes effect soon Is phishing and security awareness training worthless? CISOs need financial literacy Supply chain firewall is basic but useful All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-387

Paul's Security Weekly TV
Pondering Portable Passwordless Passkeys in 2025 - Rew Islam - ESW #387

Paul's Security Weekly TV

Play Episode Listen Later Dec 13, 2024 35:04


In this segment, we discuss two new FIDO Alliance standards focused on credential portability. Specifically, if passwordless is going to catch on, we need to minimize friction and maximize usability. In practice, this means that passkeys must be portable! Rew Islam of Dashlane joins us to discuss the new standards and how they'll help us enter a new age of secure authentication, both for consumers and the enterprise. Segment Resources: Elevating Passwordless Security With AWS Nitro Synced Passkeys Will Be Portable FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys Show Notes: https://securityweekly.com/esw-387

Trust Issues
EP 67 - The Password Problem

Trust Issues

Play Episode Listen Later Dec 6, 2024 34:56


In this episode of the Trust Issues podcast, host David Puner sits down with Andrew Shikiar, the Executive Director and CEO of the FIDO Alliance, to discuss the critical issues surrounding password security and the innovative solutions being developed to address them. Andrew highlights the vulnerabilities of traditional passwords, their susceptibility to phishing and brute force attacks, and the significant advancements in passwordless authentication methods, particularly passkeys. He explains how passkeys, based on FIDO standards, utilize asymmetric public key cryptography to enhance security and reduce the risk of data breaches. The conversation also covers the broader implications of strong, user-friendly authentication methods for consumers and organizations, as well as the collaborative efforts of major industry players to make the internet a safer place. Additionally, Andrew highlights the importance of identity security in the context of these advancements, emphasizing how robust authentication methods can protect personal and organizational data. Tune in to learn about the future of authentication and the steps being taken to eliminate the reliance on passwords.

Identity At The Center
#320 - Authenticate 204 - FIDO Feud

Identity At The Center

Play Episode Listen Later Dec 2, 2024 22:51


In this special episode of Identity at the Center, hosts Jim McDonald and Jeff Steadman kick off the inaugural FIDO Feud—a game show packed with fun and informative challenges about digital identity. Team Glitterati, led by Megan Shamas, and Team Identifriends, led by Jim, face off in a series of rounds centered around common passwords, identity trends, and future threats to IAM. Enjoy witty banter, audience interaction, and a spirited competition, all while diving deep into the world of Identity and Access Management. Special thanks to the FIDO Alliance and RSM US LLP for making this special event possible! 00:00 Introduction to Identity at the Center 00:20 Welcome to FIDO Feud 01:18 Meet the Team Captains 01:47 Team Names and Random Members 02:46 Game Rules and Setup 04:22 Round 1: Easy-to-Guess Passwords 07:37 Round 2: Tired Trends in IAM 11:44 IAM Metrics Showdown 12:22 Successful Logins and Password Resets 13:04 User Satisfaction and Breaches 13:44 Enrollment and Abandon Rate 14:33 Final IAM Metrics 15:45 Biggest Future Threats to IAM 17:29 Unexpected Answers and Final Round 21:16 Winners and Closing Remarks Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com

Apple @ Work
FIDO Alliance's plan for Passkey migration

Apple @ Work

Play Episode Listen Later Nov 19, 2024 15:26


Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional-grade platform all the solutions necessary to seamlessly and automatically deploy, manage & protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple. In this episode of Apple @ Work, I talk with Rew Islam from Dashlane about the plans from the FIDO Alliance to allow for Passkey migration between various password managers. Links FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys Synced Passkeys Will Be Portable Connect with Bradley Twitter LinkedIn Listen and subscribe Apple Podcasts Overcast Spotify Pocket Casts Castro RSS Listen to Past Episodes

Tech News Weekly (MP3)
TNW 359: FIDO Alliance Explains Passkeys Portability - AI Chatbots, Passkeys, Apple Intelligence

Tech News Weekly (MP3)

Play Episode Listen Later Oct 24, 2024 82:31


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele and David Turner Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

Tech News Weekly (Video HI)
TNW 359: FIDO Alliance Explains Passkeys Portability - AI Chatbots, Passkeys, Apple Intelligence

Tech News Weekly (Video HI)

Play Episode Listen Later Oct 24, 2024 82:31


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele and David Turner Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

All TWiT.tv Shows (MP3)
Tech News Weekly 359: FIDO Alliance Explains Passkeys Portability

All TWiT.tv Shows (MP3)

Play Episode Listen Later Oct 24, 2024 82:31


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele, David Turner, and Dan Moren Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

Tech News Weekly (Video LO)
TNW 359: FIDO Alliance Explains Passkeys Portability - AI Chatbots, Passkeys, Apple Intelligence

Tech News Weekly (Video LO)

Play Episode Listen Later Oct 24, 2024 82:31


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele and David Turner Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

Tech News Weekly (Video HD)
TNW 359: FIDO Alliance Explains Passkeys Portability - AI Chatbots, Passkeys, Apple Intelligence

Tech News Weekly (Video HD)

Play Episode Listen Later Oct 24, 2024 82:31


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele and David Turner Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

All TWiT.tv Shows (Video LO)
Tech News Weekly 359: FIDO Alliance Explains Passkeys Portability

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Oct 24, 2024 82:31 Transcription Available


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele, David Turner, and Dan Moren Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

Security Now (MP3)
SN 997: Credential Exchange Protocol - DJI Sues DoD, Quantum Vs. RSA, Lost MS Logs

Security Now (MP3)

Play Episode Listen Later Oct 23, 2024 138:35


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

All TWiT.tv Shows (MP3)
Security Now 997: Credential Exchange Protocol

All TWiT.tv Shows (MP3)

Play Episode Listen Later Oct 23, 2024 138:35


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

Security Now (Video HD)
SN 997: Credential Exchange Protocol - DJI Sues DoD, Quantum Vs. RSA, Lost MS Logs

Security Now (Video HD)

Play Episode Listen Later Oct 23, 2024


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

Security Now (Video HI)
SN 997: Credential Exchange Protocol - DJI Sues DoD, Quantum Vs. RSA, Lost MS Logs

Security Now (Video HI)

Play Episode Listen Later Oct 23, 2024


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

Radio Leo (Audio)
Security Now 997: Credential Exchange Protocol

Radio Leo (Audio)

Play Episode Listen Later Oct 23, 2024 138:35


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

Security Now (Video LO)
SN 997: Credential Exchange Protocol - DJI Sues DoD, Quantum Vs. RSA, Lost MS Logs

Security Now (Video LO)

Play Episode Listen Later Oct 23, 2024


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

All TWiT.tv Shows (Video LO)
Security Now 997: Credential Exchange Protocol

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Oct 23, 2024


Did Chinese researchers really break RSA encryption? What did they do? What next-level terror extortion is being powered by the NPD breach data? The EU to hold software companies liable for software security? Microsoft lost weeks of security logs. How hard did the try to fix the problem? The Chinese drone company DJI has sued the DoJ over its ban on DJI's drones. The DoJ wishes to acquire "DeepFake" technology to create fake people. Microsoft has bots pretending to fall for phishing campaigns, then leading the bad guys to their honeypots. It's diabolical and brilliant. A bit of BIMI logo follow-up, then... A look at the operation of the FIDO Alliance's forthcoming Credential Exchange Protocol which promises to create passkey collection portability Show Notes - https://www.grc.com/sn/SN-997-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: threatlocker.com for Security Now flashpoint.io lookout.com bitwarden.com/twit

Business of Tech
AI Adoption Challenges, Passkey Innovations, and Zero Trust Security in Business Strategies

Business of Tech

Play Episode Listen Later Oct 17, 2024 11:36


A recent MIT report revealing that 78% of businesses face challenges in AI adoption due to weak data foundations. Despite high aspirations for AI, such as enhancing efficiency and fostering innovation, only a small percentage of business leaders feel adequately prepared to engage with AI technologies. The report highlights that data governance and quality are significant obstacles, emphasizing the need for organizations to address underlying data issues before embarking on AI projects.The episode also covers the FIDO Alliance's announcement at the Authenticate conference regarding the Credential Exchange Protocol (CXP), which aims to make passkeys portable across different digital ecosystems. This initiative, supported by major tech companies like Apple, Google, and Microsoft, seeks to standardize secure transfer processes for passkeys, reducing concerns over vendor lock-in. The growing acceptance of passwordless technology is underscored by Amazon's report of over 175 million customers activating passkeys, indicating a shift towards more secure digital practices.Host Dave Sobel contrasts the approaches of OpenAI and Anthropic in the realm of AI development. OpenAI's new O1 model family focuses on structured prompt generation for efficiency and accuracy, while Anthropic emphasizes a more conversational and engaging AI experience. This divergence in methodologies reflects the differing priorities of the two companies, with OpenAI aiming for structured outputs and Anthropic fostering a personable interaction style. Additionally, a study by Apple researchers reveals limitations in mathematical reasoning within large language models, stressing the importance of human oversight in decision-making processes.Finally, the episode highlights the need for organizations to modernize their cybersecurity strategies by adopting an identity-centric zero trust model. As hybrid work environments and AI technologies challenge traditional security practices, a zero-trust approach ensures that all access requests are verified, protecting sensitive resources from unauthorized access. Sobel also discusses the importance of fostering AI experimentation within organizations to bridge the gap between individual productivity gains and overall performance, encouraging a cultural shift towards embracing AI as an integral part of business strategy. Four things to know today00:00 78% of Businesses Struggle with AI Adoption Due to Weak Data Foundations, Says MIT Report02:12 FIDO Alliance Unveils New Protocol to Make Passkeys Portable Across Platforms03:56 OpenAI's Structured AI vs. Anthropic's Conversational AI: What It Means for Business Efficiency06:23 Why AI Experimentation and Zero-Trust Security Are the Future of Organizational Strategy   Supported by:  https://mspradio.com/engage/ Event: www.smbTechFest.com/Go/Sobel  All our Sponsors: https://businessof.tech/sponsors/ Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/ Support the show on Patreon: https://patreon.com/mspradio/ Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com Follow us on:LinkedIn: https://www.linkedin.com/company/28908079/YouTube: https://youtube.com/mspradio/Facebook: https://www.facebook.com/mspradionews/Instagram: https://www.instagram.com/mspradio/TikTok: https://www.tiktok.com/@businessoftechBluesky: https://bsky.app/profile/businessoftech.bsky.social

Cyber Security Today
53% would switch banks if their institution had a data breach: Cyber Security Today for Thursday, October 17, 2024

Cyber Security Today

Play Episode Listen Later Oct 17, 2024 13:06 Transcription Available


In this episode, host Jim Love delves into sophisticated phishing attacks, cybersecurity initiatives, and significant changes in data security protocols. Listeners will learn about a national survey revealing that 53% of Canadians would switch banks after a data breach and hear insights on Apple's proposal to shorten SSL/TLS certificate lifespans. The episode also covers 23andMe's data breach and settlement, and introduces the FIDO Alliance's new protocol designed to enhance passkey portability across platforms. Emphasizing the importance of robust cybersecurity measures and user education, the discussion highlights advancements in passwordless authentication, as demonstrated by major implementations from companies like Amazon. This episode offers an in-depth look at current cybersecurity challenges and forward-thinking solutions in the realm of user authentication. 00:00 Introduction and Show Format Update 00:48 Canadian Banking Cybersecurity Concerns 01:14 Survey Insights and Financial Sector Responses 03:25 Customer Concerns and Communication Gaps 04:17 Financial Impact of Data Breaches 05:13 Apple's SSL/TLS Certificate Lifespan Proposal 06:20 Google's Push for Shorter Certificate Lifespans 07:24 23andMe Data Breach Settlement 09:55 FIDO Alliance and Passwordless Authentication 12:38 Conclusion and Show Notes

Windows Weekly (MP3)
WW 903: Absolutely Seamless! - Swag store, x86 Ecosystem Advisory Group, Jameson

Windows Weekly (MP3)

Play Episode Listen Later Oct 16, 2024 158:34


On this episode, Leo Laporte shows off his new Snapdragon Dev Kit to Paul Thurrott and Richard Campbell. He also tries setting it up, and the process is TOTALLY "seamless." AMD has revealed the Ryzen AI PRO 300 Series alongside Intel's launch of the Core Ultra 200S desktop processors. The FIDO Alliance has published new credential exchange specifications. Sarah Bond announces that Xbox games will be purchasable on Android. And Paul unveils his new "get rich" scheme... as he looks for some feedback. x86's Last Stand? Intel and AMD announce partnership that is clearly aimed at taking on Arm. Intel was already working on simplifying the x86 architecture by removing older, unused bits Don't worry, Intel and AMD will still compete. And AMD just released new AI processors, with Intel also announcing first Core Ultra chips for Desktop Which raises a question: Why do the desktop chips not meet the Copilot+ PC spec? Windows Redmond, we have a quality problem: 24H2 is besieged by a curious number of issues despite several months of gestation and a shared feature set with 23H2. Dev and Beta: Beta is minor, but Dev has some Taskbar updates Release Preview: New builds for 23H2 and 24H2 hint at this month's Week D preview updates - since this announcement, some features have been delayed Microsoft 365/Surfac Google Workspace is adding a OneDrive (for Business) data migration capability Is there some new cloud interoperability thing going on? We're seeing this in the consumer space too. Wondering if this is related to regulatory attention A Lunar Lake Surface Laptop? Probably not Passkeys Get Real As expected, FIDO Alliance will standardize passkey portability Two sides to this: Portability between devices but also import/export between password managers Amazon has 175 million customers using passkeys - one year after initial unveil Xbox With Google antitrust loss, Microsoft vaguely reveals that Xbox games are coming to Android Long-forgotten ability to stream games you purchased over Cloud Gaming is now coming soon Microsoft settles BS "Gamers' lawsuit" for what we hope was a pittance The only gamers with a case to sue Microsoft are Xbox fans - one year this week Call of Duty: Black Ops 6 and more are headed to Game Pass if anyone still cares Microsoft's Xbox Series X|S mid-season replacements are here, and they come with a fun surprise New Xbox wireless headset is incoming Microsoft to host Xbox Partner Preview tomorrow, October 17 Steam forced to communicate that you don't own anything you buy Tips and Picks Tip of the week: Check out the Thurrott swag App pick of the week: Arc browser, now native on Windows 11 on Arm! RunAs Radio this week: Pen Testing Yourself with Paula Januszkiewicz Brown liquor pick of the week: Jameson Irish Whiskey Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to this show at https://twit.tv/shows/windows-weekly Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Sponsors: lookout.com threatlocker.com 1password.com/windowsweekly uscloud.com

All TWiT.tv Shows (MP3)
Windows Weekly 903: Absolutely Seamless!

All TWiT.tv Shows (MP3)

Play Episode Listen Later Oct 16, 2024 158:34 Transcription Available


On this episode, Leo Laporte shows off his new Snapdragon Dev Kit to Paul Thurrott and Richard Campbell. He also tries setting it up, and the process is TOTALLY "seamless." AMD has revealed the Ryzen AI PRO 300 Series alongside Intel's launch of the Core Ultra 200S desktop processors. The FIDO Alliance has published new credential exchange specifications. Sarah Bond announces that Xbox games will be purchasable on Android. And Paul unveils his new "get rich" scheme... as he looks for some feedback. x86's Last Stand? Intel and AMD announce partnership that is clearly aimed at taking on Arm. Intel was already working on simplifying the x86 architecture by removing older, unused bits Don't worry, Intel and AMD will still compete. And AMD just released new AI processors, with Intel also announcing first Core Ultra chips for Desktop Which raises a question: Why do the desktop chips not meet the Copilot+ PC spec? Windows Redmond, we have a quality problem: 24H2 is besieged by a curious number of issues despite several months of gestation and a shared feature set with 23H2. Dev and Beta: Beta is minor, but Dev has some Taskbar updates Release Preview: New builds for 23H2 and 24H2 hint at this month's Week D preview updates - since this announcement, some features have been delayed Microsoft 365/Surfac Google Workspace is adding a OneDrive (for Business) data migration capability Is there some new cloud interoperability thing going on? We're seeing this in the consumer space too. Wondering if this is related to regulatory attention A Lunar Lake Surface Laptop? Probably not Passkeys Get Real As expected, FIDO Alliance will standardize passkey portability Two sides to this: Portability between devices but also import/export between password managers Amazon has 175 million customers using passkeys - one year after initial unveil Xbox With Google antitrust loss, Microsoft vaguely reveals that Xbox games are coming to Android Long-forgotten ability to stream games you purchased over Cloud Gaming is now coming soon Microsoft settles BS "Gamers' lawsuit" for what we hope was a pittance The only gamers with a case to sue Microsoft are Xbox fans - one year this week Call of Duty: Black Ops 6 and more are headed to Game Pass if anyone still cares Microsoft's Xbox Series X|S mid-season replacements are here, and they come with a fun surprise New Xbox wireless headset is incoming Microsoft to host Xbox Partner Preview tomorrow, October 17 Steam forced to communicate that you don't own anything you buy Tips and Picks Tip of the week: Check out the Thurrott swag App pick of the week: Arc browser, now native on Windows 11 on Arm! RunAs Radio this week: Pen Testing Yourself with Paula Januszkiewicz Brown liquor pick of the week: Jameson Irish Whiskey Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to this show at https://twit.tv/shows/windows-weekly Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Sponsors: lookout.com threatlocker.com 1password.com/windowsweekly uscloud.com

Radio Leo (Audio)
Windows Weekly 903: Absolutely Seamless!

Radio Leo (Audio)

Play Episode Listen Later Oct 16, 2024 158:34 Transcription Available


On this episode, Leo Laporte shows off his new Snapdragon Dev Kit to Paul Thurrott and Richard Campbell. He also tries setting it up, and the process is TOTALLY "seamless." AMD has revealed the Ryzen AI PRO 300 Series alongside Intel's launch of the Core Ultra 200S desktop processors. The FIDO Alliance has published new credential exchange specifications. Sarah Bond announces that Xbox games will be purchasable on Android. And Paul unveils his new "get rich" scheme... as he looks for some feedback. x86's Last Stand? Intel and AMD announce partnership that is clearly aimed at taking on Arm. Intel was already working on simplifying the x86 architecture by removing older, unused bits Don't worry, Intel and AMD will still compete. And AMD just released new AI processors, with Intel also announcing first Core Ultra chips for Desktop Which raises a question: Why do the desktop chips not meet the Copilot+ PC spec? Windows Redmond, we have a quality problem: 24H2 is besieged by a curious number of issues despite several months of gestation and a shared feature set with 23H2. Dev and Beta: Beta is minor, but Dev has some Taskbar updates Release Preview: New builds for 23H2 and 24H2 hint at this month's Week D preview updates - since this announcement, some features have been delayed Microsoft 365/Surfac Google Workspace is adding a OneDrive (for Business) data migration capability Is there some new cloud interoperability thing going on? We're seeing this in the consumer space too. Wondering if this is related to regulatory attention A Lunar Lake Surface Laptop? Probably not Passkeys Get Real As expected, FIDO Alliance will standardize passkey portability Two sides to this: Portability between devices but also import/export between password managers Amazon has 175 million customers using passkeys - one year after initial unveil Xbox With Google antitrust loss, Microsoft vaguely reveals that Xbox games are coming to Android Long-forgotten ability to stream games you purchased over Cloud Gaming is now coming soon Microsoft settles BS "Gamers' lawsuit" for what we hope was a pittance The only gamers with a case to sue Microsoft are Xbox fans - one year this week Call of Duty: Black Ops 6 and more are headed to Game Pass if anyone still cares Microsoft's Xbox Series X|S mid-season replacements are here, and they come with a fun surprise New Xbox wireless headset is incoming Microsoft to host Xbox Partner Preview tomorrow, October 17 Steam forced to communicate that you don't own anything you buy Tips and Picks Tip of the week: Check out the Thurrott swag App pick of the week: Arc browser, now native on Windows 11 on Arm! RunAs Radio this week: Pen Testing Yourself with Paula Januszkiewicz Brown liquor pick of the week: Jameson Irish Whiskey Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to this show at https://twit.tv/shows/windows-weekly Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Sponsors: lookout.com threatlocker.com 1password.com/windowsweekly uscloud.com

Windows Weekly (Video HI)
WW 903: Absolutely Seamless! - Swag store, x86 Ecosystem Advisory Group, Jameson

Windows Weekly (Video HI)

Play Episode Listen Later Oct 16, 2024 158:34


On this episode, Leo Laporte shows off his new Snapdragon Dev Kit to Paul Thurrott and Richard Campbell. He also tries setting it up, and the process is TOTALLY "seamless." AMD has revealed the Ryzen AI PRO 300 Series alongside Intel's launch of the Core Ultra 200S desktop processors. The FIDO Alliance has published new credential exchange specifications. Sarah Bond announces that Xbox games will be purchasable on Android. And Paul unveils his new "get rich" scheme... as he looks for some feedback. x86's Last Stand? Intel and AMD announce partnership that is clearly aimed at taking on Arm. Intel was already working on simplifying the x86 architecture by removing older, unused bits Don't worry, Intel and AMD will still compete. And AMD just released new AI processors, with Intel also announcing first Core Ultra chips for Desktop Which raises a question: Why do the desktop chips not meet the Copilot+ PC spec? Windows Redmond, we have a quality problem: 24H2 is besieged by a curious number of issues despite several months of gestation and a shared feature set with 23H2. Dev and Beta: Beta is minor, but Dev has some Taskbar updates Release Preview: New builds for 23H2 and 24H2 hint at this month's Week D preview updates - since this announcement, some features have been delayed Microsoft 365/Surfac Google Workspace is adding a OneDrive (for Business) data migration capability Is there some new cloud interoperability thing going on? We're seeing this in the consumer space too. Wondering if this is related to regulatory attention A Lunar Lake Surface Laptop? Probably not Passkeys Get Real As expected, FIDO Alliance will standardize passkey portability Two sides to this: Portability between devices but also import/export between password managers Amazon has 175 million customers using passkeys - one year after initial unveil Xbox With Google antitrust loss, Microsoft vaguely reveals that Xbox games are coming to Android Long-forgotten ability to stream games you purchased over Cloud Gaming is now coming soon Microsoft settles BS "Gamers' lawsuit" for what we hope was a pittance The only gamers with a case to sue Microsoft are Xbox fans - one year this week Call of Duty: Black Ops 6 and more are headed to Game Pass if anyone still cares Microsoft's Xbox Series X|S mid-season replacements are here, and they come with a fun surprise New Xbox wireless headset is incoming Microsoft to host Xbox Partner Preview tomorrow, October 17 Steam forced to communicate that you don't own anything you buy Tips and Picks Tip of the week: Check out the Thurrott swag App pick of the week: Arc browser, now native on Windows 11 on Arm! RunAs Radio this week: Pen Testing Yourself with Paula Januszkiewicz Brown liquor pick of the week: Jameson Irish Whiskey Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to this show at https://twit.tv/shows/windows-weekly Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Sponsors: lookout.com threatlocker.com 1password.com/windowsweekly uscloud.com

All TWiT.tv Shows (Video LO)
Windows Weekly 903: Absolutely Seamless!

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Oct 16, 2024 158:34 Transcription Available


On this episode, Leo Laporte shows off his new Snapdragon Dev Kit to Paul Thurrott and Richard Campbell. He also tries setting it up, and the process is TOTALLY "seamless." AMD has revealed the Ryzen AI PRO 300 Series alongside Intel's launch of the Core Ultra 200S desktop processors. The FIDO Alliance has published new credential exchange specifications. Sarah Bond announces that Xbox games will be purchasable on Android. And Paul unveils his new "get rich" scheme... as he looks for some feedback. x86's Last Stand? Intel and AMD announce partnership that is clearly aimed at taking on Arm. Intel was already working on simplifying the x86 architecture by removing older, unused bits Don't worry, Intel and AMD will still compete. And AMD just released new AI processors, with Intel also announcing first Core Ultra chips for Desktop Which raises a question: Why do the desktop chips not meet the Copilot+ PC spec? Windows Redmond, we have a quality problem: 24H2 is besieged by a curious number of issues despite several months of gestation and a shared feature set with 23H2. Dev and Beta: Beta is minor, but Dev has some Taskbar updates Release Preview: New builds for 23H2 and 24H2 hint at this month's Week D preview updates - since this announcement, some features have been delayed Microsoft 365/Surfac Google Workspace is adding a OneDrive (for Business) data migration capability Is there some new cloud interoperability thing going on? We're seeing this in the consumer space too. Wondering if this is related to regulatory attention A Lunar Lake Surface Laptop? Probably not Passkeys Get Real As expected, FIDO Alliance will standardize passkey portability Two sides to this: Portability between devices but also import/export between password managers Amazon has 175 million customers using passkeys - one year after initial unveil Xbox With Google antitrust loss, Microsoft vaguely reveals that Xbox games are coming to Android Long-forgotten ability to stream games you purchased over Cloud Gaming is now coming soon Microsoft settles BS "Gamers' lawsuit" for what we hope was a pittance The only gamers with a case to sue Microsoft are Xbox fans - one year this week Call of Duty: Black Ops 6 and more are headed to Game Pass if anyone still cares Microsoft's Xbox Series X|S mid-season replacements are here, and they come with a fun surprise New Xbox wireless headset is incoming Microsoft to host Xbox Partner Preview tomorrow, October 17 Steam forced to communicate that you don't own anything you buy Tips and Picks Tip of the week: Check out the Thurrott swag App pick of the week: Arc browser, now native on Windows 11 on Arm! RunAs Radio this week: Pen Testing Yourself with Paula Januszkiewicz Brown liquor pick of the week: Jameson Irish Whiskey Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to this show at https://twit.tv/shows/windows-weekly Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Sponsors: lookout.com threatlocker.com 1password.com/windowsweekly uscloud.com

The CyberWire
A “must patch” list in the making.

The CyberWire

Play Episode Listen Later Oct 15, 2024 36:23


CISA adds a Fortinet flaw to its “must patch” list. Splunk releases fixes for 11 vulnerabilities in Splunk Enterprise. ErrorFather is a new malicious Android banking trojan. New evidence backs secure-by-design practices. CISA warns that threat actors are exploiting unencrypted persistent cookies. The FIDO Alliance standardizes passkey portability. Cybercriminals linger on Telegram. On our Industry Voices segment today, our guest is Matt Radolec, Vice President, Incident Response and Cloud Operations at Varonis, discussing how AI amplifies the need for data privacy regulation and opens doors for abuse. We mark the passing of the co creator of the BBS. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment today, our guest is Matt Radolec, Vice President, Incident Response and Cloud Operations at Varonis, discussing how AI amplifies the need for data privacy regulation and opens doors for abuse. Selected Reading Tens of thousands of IPs vulnerable to Fortinet flaw dubbed 'must patch' by feds (CyberScoop) Fortinet FortiGuard Labs Observes Darknet Activity Targeting the 2024 United States Presidential Election (Fortinet) Splunk Enterprise Update Patches Remote Code Execution Vulnerabilities (SecurityWeek) Cerberus Android Banking Trojan Deployed in New Multi-Stage Malicious Campaign (Infosecurity Magazine) Organizations can substantially lower vulnerabilities with secure-by-design practices, report finds (CyberScoop) Eight Million Users Download 200+ Malicious Apps from Google Play (Infosecurity Magazine) TrickMo malware steals Android PINs using fake lock screen (Bleeping Computer) CISA: Hackers abuse F5 BIG-IP cookies to map internal servers (Bleeping Computer) FIDO Alliance is Standardizing Passkey Portability (Thurrott) So far, cybercriminals appear to be just shopping around for a Telegram alternative (The Record) Ward Christensen, BBS inventor and architect of our online age, dies at age 78 (Ars Technica) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.  Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Identity At The Center
#302 - Authenticate 2024 Preview with Andrew Shikiar

Identity At The Center

Play Episode Listen Later Sep 2, 2024 51:36


In this episode of the Identity at the Center podcast, Jeff and Jim discuss the intricacies of authentication with Andrew Shikiar, Executive Director and CEO of the FIDO Alliance. The conversation covers various aspects of authentication including different use cases, the importance of passkeys, and regional adoption trends. They also highlight the upcoming Authenticate 2024 conference in Carlsbad, California, emphasizing its unique value for identity experts and practitioners. Listeners are encouraged to take advantage of early bird pricing and discount codes for the event linked below. 00:00 Welcome to the Identity at the Center Podcast 01:36 Podcast Milestones and Schedule 02:42 Engaging with the Audience 04:35 Introducing the Guest: Andrew Shikiar 07:34 FIDO Alliance and Passkeys Overview 10:12 The Importance of Passwordless Authentication 18:23 Authenticate Conference Highlights 22:07 Conference Details and Registration 26:19 Networking and Conference Challenges 26:35 Session Tracks and Remote Participation 28:02 FIDO APAC Summit in Kuala Lumpur 29:38 Highlights of the Authenticate Conference 32:21 Identity Verification and Adjacent Technologies 34:28 Live Podcasts and Interactive Sessions 35:59 Fun Activities and Networking at Authenticate 39:52 Travel Experiences and Final Thoughts Connect with Andrew: https://www.linkedin.com/in/andrewshikiar/ Learn more about the FIDO Alliance: https://fidoalliance.org/ Authenticate Conference - Use code IDAC15 for 15% off: https://authenticatecon.com/event/authenticate-2024-conference/ FIDO Alliance Shop - https://shop.fidoalliance.org/ - Use code IDAC10 for a discount on your purchase! Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter.

RunAs Radio
Implementing Passkeys with Tarek Dawoud

RunAs Radio

Play Episode Listen Later Aug 14, 2024 39:15


Are you ready for passkeys? Richard talks to Tarek Dawoud from Microsoft about the evolution of passwordless access with passkeys. Tarek talks about the FIDO alliance and the ongoing effort to create authentication strategies that are mathematically impossible to phish - no password stuffing under the covers that might get exploited by a man-in-the-middle attack. The conversation also dives into the passkeys name and how it's a rebranding of passwordless authentication to make it easier for everyone to understand that you'd rather have a passkey than a password. The products involved are still evolving, but there's plenty you can take advantage of today and make your organization more phishing-resistant than ever!LinksFido AllianceYubicoWindows Hello for BusinessMicrosoft Digital Defense Report 2023Accenture Passwordless JourneyConditional AccessTemporary Access PassEnable Passkeys For Your OrganizationWeb AuthenCTAPMicrosoft Password GuidanceRecorded June 3, 2024

Payments on Fire
Episode 242 - From the Vault: Who Are You, Really? FIDO's Biometric Authentication (Episode 28)

Payments on Fire

Play Episode Listen Later Jul 3, 2024 23:25


As scams, ransomware, account takeovers, and old-fashioned data breaches persist in our personal and business lives, we are all pondering how to get ahead in the cat-and-mouse game that global fraud rings seemingly have mastered. With this episode, we're setting the stage for a series of discussions on authentication and identity, the critical components of tackling this pervasive issue. We're embarking on a journey of perspective gathering from some of the industry's leaders in risk management, authentication, and digital identity with this 2015 “from the vault” episode of Payments on Fire. Listen as Philip Andreae converses with George Peabody about the FIDO Alliance and its mission to bolster and streamline authentication. As you listen to this episode, consider the progress made since 2015 — have we come far enough, fast enough?

The CyberWire
A hacking keeps you humble.

The CyberWire

Play Episode Listen Later Jun 14, 2024 38:39


Microsoft's President admits security failures in congressional testimony. Paul Nakasone joins OpenAI's board. The feds hold their first AI tabletop exercise. CISA reports on the integration of space-based infrastructure. Cleveland city hall remains closed after a cyber attack. Truist commercial bank confirms a data breach. Rockwell Automation patches three high-severity vulnerabilities. University of Illinois researchers develop autonomous AI hacking agents. Arynn Crow, Sr Manager of AWS User Authentication Products, talks with N2K's Brandon Karpf about security through MFA and FIDO Alliance passkeys, and her work on the Digital Identity Advancement Foundation. Can an AI run for mayor? Our 2024 N2K CyberWire Audience Survey is underway, make your voice heard and get in the running for a $100 Amazon gift card. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest In the first of our interviews captured during the AWS re:Inforce event this past week, guest Arynn Crow, Senior Manager of AWS User Authentication Products, talks with N2K's Brandon Karpf about security through MFA and FIDO Alliance passkeys, and her work on the Digital Identity Advancement Foundation. Selected Reading Microsoft Admits Security Failings Allowed China's US Government Hack (Infosecurity Magazine) OpenAI adds Trump-appointed former NSA director Paul M. Nakasone to its board (The Washington Post) CISA leads first tabletop exercise for AI cybersecurity (CyberScoop) New CISA report addresses zero trust in space, boosting security for satellites and ground infrastructure (Industrial Cyber)  CISA adds Android Pixel, Microsoft Windows, Progress Telerik Report Server bugs to its Known Exploited Vulnerabilities catalog (Security Affairs) Insurance giant Globe Life investigating web portal breach (Bleeping Computer) Cleveland remains paralyzed by cyberattack (News 5 Cleveland) Truist Bank confirms breach after stolen data shows up on hacking forum (Bleeping Computer) Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE (SecurityWeek) Researchers at the University of Illinois have developed AI Agents that can Autonomously Hack Websites and Find Zero-Day Vulnerabilities (MarkTechPost) Wyoming mayoral candidate wants to govern by AI bot (Ars Technica)   Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.  Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Identity At The Center
#287 - Identiverse 2024: Andrew Shikiar from the FIDO Alliance

Identity At The Center

Play Episode Listen Later Jun 6, 2024 49:23


In this episode, hosts Jim McDonald and Jeff Steadman welcome Andrew Shikiar, Executive Director & CEO at the FIDO Alliance, for his 7th appearance on the Identity at the Center Podcast. They discuss what's new with the FIDO alliance and what to expect from the upcoming Authenticate event. The conversation also includes some yet to be determined topics. Don't miss out on this insightful discussion! In this episode of Identity at the Center, hosts Jim McDonald and Jeff Steadman sit down with Andrew Shakira, Executive Director of the FIDO Alliance, at Identiverse 2024. They explore the myths and realities of FIDO adoption in the banking sector, discuss the growth and impact of the FIDO Alliance, and delve into the latest developments in passwordless authentication and passkeys. Andrew shares insights into how FIDO is reducing identity-related fraud and the role of certifications in ensuring security and interoperability. The conversation also covers the importance of usability in multi-factor authentication (MFA) and the challenges and opportunities of implementing FIDO in various environments, from first responders to prisons. The episode wraps up with a look ahead to the Authenticate conference, emphasizing the collaborative and supportive nature of the identity community. Tune in for a comprehensive discussion on the state of identity authentication and the future of passwordless security. Connect with Andrew: https://www.linkedin.com/in/andrewshikiar/ Learn more about the FIDO Alliance: https://fidoalliance.org/ Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com and watch at https://www.youtube.com/@idacpodcast

Identity At The Center
#282 - IDAC Sponsor Spotlight - RSM Digital Identity

Identity At The Center

Play Episode Listen Later May 22, 2024 81:50


On this episode of Identity at the Center, Jim McDonald and Jeff Steadman are joined by Chad Wolcott, Managing Director at RSM US LLP, to peel back the layers of the identity industry. They delve into the complexities of identity consulting, discussing the challenges and triumphs of implementing and managing IAM solutions. From Chad's early days of designing robots to Jim's arcade escapades, the trio shares their most unusual jobs and the lessons learned from their unique experiences. They also tackle pressing topics like the future of passwordless authentication, the role of AI and analytics in identity, and the evolution of authorization from RBAC to dynamic access models. The conversation takes a turn into the realm of IAM horror stories, highlighting the pitfalls of over-engineering solutions and the importance of aligning with organizational change. As they gear up for Identiverse, they share their excitement for reconnecting with industry peers, diving into sessions on AI and identity security, and enjoying the Vegas experience. Tune in for an insightful and candid discussion on the state of identity security, the potential of AI, and the power of automation in the ever-evolving IAM landscape. Connect with Chad: https://www.linkedin.com/in/chad-wolcott/ Meet up with our RSM team at Identiverse 2024! Schedule at https://rsmus.com/events/2024-events/join-rsm-at-identiverse-2024.html Learn more about RSM Digital Identity consulting: https://rsmus.com/services/risk-fraud-cybersecurity/cybersecurity-business-vulnerability/identity-and-access.html Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter.