POPULARITY
Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting. The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it. Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices. What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network. Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one. For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Kevin Surace, Chief Executive Officer at TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about TokenCore: https://www.tokencore.com TokenCore products: https://www.tokencore.com/products Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access
(Disclaimer: erstellt mit ChatGPT)Hallo liebe Community,
Passwords protect our digital online lives but they keep getting more complicated and there is so many of them, people start getting lazy so that they can actually remember their passwords. This makes passwords unreliable as a security feature. Passwords are the first line of defense for your personal information but there are other options including password managers and Passkeys. Mark and Jeff discuss online security and what your options are to protect yourself.
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-605
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-605
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-605
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-605
ChainDrop attack hits npm Pass-ta-key attacks target passkeys AI accounts for most cybercrime in Africa Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/ Huge thanks to our episode sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.
El programa 2915 de Radiogeek repasa las novedades tecnológicas más importantes del día: Passkeys de Google, vulnerables al ataque «Pass-ta-key»; Microsoft advierte que los hackers están falsificando las páginas de inicio de sesión de Wi-Fi de los hoteles; WhatsApp lanza tres nuevas funciones para mejorar los chats grupales; Google Health finalmente admite la sincronización bidireccional de datos de salud con Apple Health y por último El director ejecutivo de Telegram afirma que un "extorsionador" fue el responsable de que Apple retirara brevemente la aplicación de su catálogo. Toda esta información la pueden encontrar desde nuestra web www.infosertec.com.ar o bien desde el canal de Telegram/Whastapp, o Instagram. Esperamos sus comentarios.
Sam and Joe discuss Microsoft's plan to retire Microsoft-provided SMS and voice calls for MFA, with key dates of Sept 1, 2026 (users on SMS/voice are automatically enabled for passkeys and nudged to register) and Feb 1, 2027 (blocking enforcement for users whose only MFA is SMS/voice, no opt-out), noting paid/customer-managed telecom options and the need to warn clients, address legacy per-user MFA vs conditional access, and handle shared accounts via shared mailboxes or passkey-sharing tools. Sam recounts a prolonged Salesforce SSO/MFA issue worsened by poor vendor documentation and misleading AI guidance, ultimately tied to a Microsoft KB update. They then cover partnering with Fuji for client SOC 2 compliance support, emphasizing evidence, audits, costs, and ongoing maintenance, plus how cyber-insurance questionnaires drive security improvements. The episode also touches on residential support cases, Vision Pro support challenges with DRM blocking screen mirroring, and show wrap-up. 00:00 Show Kickoff 00:17 Microsoft MFA SMS Retirement 00:44 Key Dates and User Impact 03:28 Authenticator Backups and PSAs 04:40 Legacy MFA Cleanup Challenges 07:36 Conditional Access Licensing Risks 10:12 Shared Accounts and Passkeys 12:21 Salesforce MFA SSO Headaches 13:25 AI Missteps and Vendor Docs 17:50 SOC 2 Help from Fuji 21:23 SOC 2 Costs and Maintenance 22:49 Easy Buttons and Real Audits 26:27 Cyber Insurance Questionnaires 27:53 Partnering for Expertise 29:07 Cyber Insurance Foot in Door 30:31 Apple Store Referral Win 31:01 Lightroom Migration Pitfalls 34:31 Blocked Contacts Mystery 38:04 Email Search and User Training 40:02 Supporting Vision Pro Clients 47:28 Amazon Returns and Exceptions 50:24 Wrap Up and Callouts
The panel debates whether giving Claude controlled access to 1Password credentials is a practical automation feature or an unnecessary security risk, weighing trust, passkeys, vault isolation, and AI limitations. The conversation then shifts to the humor of waterproof phone holders and shower tech before wrapping with a discussion of how autonomous vehicles could reshape liability, trial law, and advertising, followed by the panel's sign-offs. The panel includes Chuck Joiner, David Ginsburg, Marty Jencius, Eric Bolden, Brian Flanigan-Arthurs, Jim Rea, Web Bixby, and Jeff Gamet. This edition of MacVoices is brought to you by our Patreon supporters. Get access to the MacVoices Slack and MacVoices After Dark by joining in at Patreon.com/macvoices. Show Notes: Chapters: 00:00 AI trust and autonomous vehicle liability00:32 Claude gains access to 1Password credentials01:02 Trusting AI agents with sensitive accounts01:15 Limiting access to individual vault items01:38 Secure credential handling for automation02:41 Can Claude see the actual password?02:58 Passkeys, certificates, and temporary authentication03:55 Using a secondary vault for AI access04:38 Waterproof shower phone holders05:30 Waterproof notepads and working in the shower06:03 Listening to podcasts while showering07:21 Trial lawyers and autonomous vehicles08:23 How self-driving cars could change liability08:51 Could autonomous vehicles eliminate accidents?09:23 The future of legal billboards and television ads10:46 Closing the discussion Links: An AI just broke an 87-year-old maths problem, in a tweet sent during the World Cup finalhttps://thenextweb.com/news/jacobian-conjecture-disproved-ai-fable-5 EU Orders Google to Give Rival AI Apps the Same Android Access as Geminihttps://www.macrumors.com/2026/07/16/eu-google-ai-apps-android-access/ You can now grant Claude access to your 1Password credentialshttps://www.engadget.com/2216405/1password-anthropic-claude-integration/ Waterproof Shower Phone Holder: $8.53https://amzn.to/4vITEqy Trial Lawyers Lobby Against Autonomous Vehicleshttps://marginalrevolution.com/marginalrevolution/2026/07/trial-lawyers-lobby-against-autonomous-vehicles.html Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site:https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support: Become a MacVoices Patron on Patreon http://patreon.com/macvoices Enjoy this episode? Make a one-time donation with PayPal Connect: Web: http://macvoices.com Twitter: http://www.twitter.com/chuckjoiner http://www.twitter.com/macvoices Mastodon: https://mastodon.cloud/@chuckjoiner Facebook: http://www.facebook.com/chuck.joiner MacVoices Page on Facebook: http://www.facebook.com/macvoices/ MacVoices Group on Facebook: http://www.facebook.com/groups/macvoice LinkedIn: https://www.linkedin.com/in/chuckjoiner/ Instagram: https://www.instagram.com/chuckjoiner/ Subscribe: Audio in iTunes Video in iTunes Subscribe manually via iTunes or any podcatcher: Audio: http://www.macvoices.com/rss/macvoicesrss Video: http://www.macvoices.com/rss/macvoicesvideorss
The panel debates whether giving Claude controlled access to 1Password credentials is a practical automation feature or an unnecessary security risk, weighing trust, passkeys, vault isolation, and AI limitations. The conversation then shifts to the humor of waterproof phone holders and shower tech before wrapping with a discussion of how autonomous vehicles could reshape liability, trial law, and advertising, followed by the panel's sign-offs. The panel includes Chuck Joiner, David Ginsburg, Marty Jencius, Eric Bolden, Brian Flanigan-Arthurs, Jim Rea, Web Bixby, and Jeff Gamet. This edition of MacVoices is brought to you by our Patreon supporters. Get access to the MacVoices Slack and MacVoices After Dark by joining in at Patreon.com/macvoices. Show Notes: Chapters: 00:00 AI trust and autonomous vehicle liability 00:32 Claude gains access to 1Password credentials 01:02 Trusting AI agents with sensitive accounts 01:15 Limiting access to individual vault items 01:38 Secure credential handling for automation 02:41 Can Claude see the actual password? 02:58 Passkeys, certificates, and temporary authentication 03:55 Using a secondary vault for AI access 04:38 Waterproof shower phone holders 05:30 Waterproof notepads and working in the shower 06:03 Listening to podcasts while showering 07:21 Trial lawyers and autonomous vehicles 08:23 How self-driving cars could change liability 08:51 Could autonomous vehicles eliminate accidents? 09:23 The future of legal billboards and television ads 10:46 Closing the discussion Links: An AI just broke an 87-year-old maths problem, in a tweet sent during the World Cup final https://thenextweb.com/news/jacobian-conjecture-disproved-ai-fable-5 EU Orders Google to Give Rival AI Apps the Same Android Access as Geminihttps://www.macrumors.com/2026/07/16/eu-google-ai-apps-android-access/ You can now grant Claude access to your 1Password credentialshttps://www.engadget.com/2216405/1password-anthropic-claude-integration/ Waterproof Shower Phone Holder: $8.53https://amzn.to/4vITEqy Trial Lawyers Lobby Against Autonomous Vehicles https://marginalrevolution.com/marginalrevolution/2026/07/trial-lawyers-lobby-against-autonomous-vehicles.html Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site: https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support: Become a MacVoices Patron on Patreon http://patreon.com/macvoices Enjoy this episode? Make a one-time donation with PayPal Connect: Web: http://macvoices.com Twitter: http://www.twitter.com/chuckjoiner http://www.twitter.com/macvoices Mastodon: https://mastodon.cloud/@chuckjoiner Facebook: http://www.facebook.com/chuck.joiner MacVoices Page on Facebook: http://www.facebook.com/macvoices/ MacVoices Group on Facebook: http://www.facebook.com/groups/macvoice LinkedIn: https://www.linkedin.com/in/chuckjoiner/ Instagram: https://www.instagram.com/chuckjoiner/ Subscribe: Audio in iTunes Video in iTunes Subscribe manually via iTunes or any podcatcher: Audio: http://www.macvoices.com/rss/macvoicesrss Video: http://www.macvoices.com/rss/macvoicesvideorss
Welcome to Episode 433 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben and Scott discuss how Microsoft 365 authentication is moving from “make passwords safer with MFA” to “remove phishable authentication wherever possible.” The practical conversation for IT pros is no longer just whether MFA is enabled. It is which methods are allowed, which users are still on SMS or voice, how passkeys change the user experience, and how to balance security, accessibility, recovery, and support load. Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. Show Notes Passkeys were supposed to replace passwords, but they’re failing for the most predictable reason Microsoft Entra authentication overview Passkeys by default and retirement of Microsoft-provided SMS and voice authentication Plan a phishing-resistant passwordless authentication deployment in Microsoft Entra ID Run a registration campaign to set up a passkey or Microsoft Authenticator Practical Protection: Understanding Entra ID and Passkeys Important Change Coming for Entra ID Passkeys in November 2025 Microsoft to Stop Providing Telephony-Based Authentication Methods for MFA in February 2027 How to enable passkeys (FIDO2) in Microsoft Entra ID Sponsors TrustedTech is a leading Microsoft Cloud Solution Provider (CSP) specializing in Microsoft Cloud services, Microsoft perpetual licensing, and Microsoft Support Services for medium and enterprise-sized businesses. Their robust team of in-house, U.S.-based Microsoft architects and engineers are certified in all 6/6 Microsoft Solutions Partner Designations in the Microsoft Cloud Partner Program. M365 Licensing Consultation M365 Tenant Assessment Copilot Readiness Assessment ShareGate is your migration and governance solution for Microsoft 365. ShareGate helps your teams simplify tenant migrations, get Copilot-ready, and take control of Microsoft 365 governance. Nasuni is a leading unstructured data platform for enterprises where file data is mission-critical for both people and AI. Nasuni powers the operational file layer where work happens — helping organizations manage, protect, and activate data so teams can work smarter, reduce costs, and operate securely without limits. Intelligink — Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let us know!
Was macht Katja eigentlich, wenn sie nicht mit Marcus vor dem Mikrofon sitzt? Seit der letzten Folge zu Switch im März 2023 ist einiges passiert. Das Team um Katja hat ein Kompetenzzentrum für Human-Centred Security aufgebaut und unterstützt vor allem die Schweizer Hochschul- und Internet-Community mit Wissen und Austausch, aber auch praktischen Angeboten, wie dem Security Engagement Kit. Cornelia Puhze und Fabio Gawron, Expertin und Spezialist für Human Centred Security, geben im Gespräch mit Marcus und Katja einen Überblick über die vielseitigen Tätigkeiten des Teams, ihre Leidenschaften und ihre Umwege zum Thema, die eigentlich keine sind. Links: Switch Human Centred Security: https://www.switch.ch/de/switch-human-centred-security Cornelia auf LinkedIn: https://www.linkedin.com/in/corneliapuhze/ Fabio auf LinkedIn: https://www.linkedin.com/in/fabio-greiner-3805521a8/ Switch Security Arcade: https://www.switch.ch/en/security-arcade-puzzle-stations Human Centred Security Day: https://humancentredsecurityday2026.events.switch.ch/ Frühere Switchie-Folge mit Rolf Brugger über Passkeys: https://www.securityawarenessinsider.ch/e/passkeys/ Frühere Switchie-Folge mit Céline Neubig über Game Design: https://www.securityawarenessinsider.ch/e/gamedesign/ SRF Podcast "Wie das Internet in die Schweiz kam": https://www.srf.ch/audio/geschichte/wie-das-internet-in-die-schweiz-kam?id=AUDI20260616_NR_0003
Pablo Sabbatella is the Founder of Opsek and Louis is the Head of Operations & Audits.North Korea has an estimated 2,500 organized hackers targeting crypto right now, which is why stolen funds often don't come from smart contract bugs, they start with hacking people.In this episode, Pablo and Louis walk through the real threat landscape facing DeFi users and protocols today, including the most common attack vectors targeting crypto holders right now. We discuss what DeFi protocols must do to raise the security bar and what we as individual users can do today to meaningfully reduce the risk and protect ourselves.------
Microsoft is retiring natively provided SMS and voice authentication in Entra ID, and the clock is ticking: passkeys become the default experience on September 1, 2026, and Microsoft-provided telecom delivery is fully retired on February 1, 2027. We walk through the timeline, what admins should do now to find and migrate affected users, and when the new Security Store telecom providers make sense. We also cover the everyday struggle: moving Microsoft Authenticator to a new phone without locking yourself out.(00:00) - Intro and catching up.(05:00) - Show content starts.Show links- Passkeys by default | MS Learn- Transfer Authenticator to a new phone - SMS/voice usage analyzer script - Plan a passkey deployment - End-user communication templates- Give us feedback!
SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the upcoming transition to passkeys as the default method for multi-factor authentication (MFA) in Microsoft Entra ID. They explore the implications of this change, the importance of moving away from SMS and voice authentication, and best practices for organizations to prepare for this shift. The conversation also covers the challenges of transferring MFA codes and passkeys when upgrading phones, and introduces the YubiKey Locker, a new tool that enhances security by automatically locking devices when the YubiKey is removed. The hosts emphasize the need for organizations to modernize their identity infrastructure and adopt more secure authentication methods.----------------------------------------------------YouTube Video Link: https://youtu.be/eXqW3FAY_hE----------------------------------------------------Documentation: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-transfer-authenticator-new-phonehttps://support.okta.com/help/s/article/migrating-all-existing-mfa-codes-to-okta-verify?language=en_UShttps://www.sciber.io/sciber-blog/sciber-launches-yubikey-locker-to-defend-against-physical-attacks/----------------------------------------------------Contact Us:Website: https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: https://www.linkedin.com/company/bluesecpodYouTube: https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: https://www.linkedin.com/in/andyjaw/Email: andy@bluesecuritypod.com----------------------------------------------------Adam BrewerTwitter: https://twitter.com/ajbrewerLinkedIn: https://www.linkedin.com/in/adamjbrewer/Email: adam@bluesecuritypod.com
Christian Johnson joins Jim Collison for Home Gadget Geeks 684 to talk about passkeys, Bitwarden, Vaultwarden, managed container hosting through Maple Grove Partners and the guardrails needed when AI agents begin doing real operational work.
Christian Johnson joins Jim Collison for Home Gadget Geeks 684 to talk about passkeys, Bitwarden, Vaultwarden, managed container hosting through Maple Grove Partners and the guardrails needed when AI agents begin doing real operational work.
Christian Johnson joins Jim Collison for Home Gadget Geeks 684 to talk about passkeys, Bitwarden, Vaultwarden, managed container hosting through Maple Grove Partners and the guardrails needed when AI agents begin doing real operational work.
You asked, we answered!
Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it.A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin credentials, planted custom malware called Infinite.red directly into REDCap's upgrade process, harvested credentials for over a year, then used those credentials to log into Google Workspace as a domain admin and create fake compliance rules to silently forward sensitive research emails — military strategy, geostrategic policy, advanced tech, specific pathogens — straight to Gmail accounts they controlled. And nobody noticed for a very long time.Prasanna and I break down the full attack chain, then walk through every prevention layer that could have stopped it: inventory management, patching, password hygiene, SSO, phishing-resistant MFA, passkeys, DBSC, context-aware access, compliance rule monitoring, credential separation across security domains, and logging. We also get into what backups can and can't do for you in a long-dwell-time attack like this — and why infrastructure-as-code and truly immutable golden images matter more than you might think.If you're running any kind of research platform, academic institution, or medical network — or honestly any organization that uses Google Workspace — this one's for you.Chapters:00:00 — Intro: The attack that phishing-resistant MFA could have stopped01:03 — Show intro & woodworking banter03:26 — What is a living-off-the-land attack?04:02 — Who is UNC5608 and who did they target?05:08 — How REDCap's multi-version design was exploited06:11 — Infinite.red malware and credential harvesting09:01 — Google Workspace infiltration via fake compliance rules10:18 — The keywords they were stealing: pathogens, military strategy, and more11:50 — What could the victims have done differently?12:42 — Inventory management, patching, and legacy version removal14:00 — Why you can't trust application-level authentication alone — use SSO15:18 — Phishing-resistant MFA and why it matters16:00 — Passkeys, FIDO, and why there are zero known attacks against them17:57 — Device-bound session credentials (DBSC) and context-aware access19:38 — Monitor your compliance rules — have a compliance rule for the compliance rule20:40 — Credential separation across security domains23:00 — Get some logging — XDR, SIEM, and catching exfiltration in progress24:00 — What can backups actually do in a long-dwell-time attack?27:00 — Infrastructure-as-code and the right cyber recovery approach28:58 — Protecting your golden images with immutable storage31:59 — Wrap-up
The MacVoices Live! panel discusses Apple's updated App Store review guidelines, the challenge of filtering low-quality or AI-generated apps, and whether trusted developers should receive faster review. Chuck Joiner, David Ginsburg, Jim Rea, Marty Jencius, Web Bixby, Jeff Gamet, and Eric Bolden also debate Apple's Passwords app gaining automatic password-changing abilities, weighing convenience against account-lockout risk. They also provide reactions to Snap's new Specs and the uncertain future of smart glasses. MacVoices is supported by NordLayer. Secure your network & stay compliant with one toggle-ready platform. Get an exclusive offer: up to 22% off NordLayer yearly plans plus 10% on top with the coupon code: MACVOICES10 at NordLayer.com/macvoices. Try it risk-free—14-day money-back guarantee. Show Notes: Chapters: 00:00 Opening topics and sponsor message00:27 Tim Cook's WWDC morning video01:34 WWDC swag and Finder collectibles03:24 Apple's app submission volume03:46 Updated App Store guidelines for low-quality apps04:19 The scale problem of reviewing thousands of apps05:48 Should trusted developers get faster review?06:27 Policing successful or suspicious apps07:37 Apple Passwords app and automatic password changes08:00 Initial skepticism from the panel09:09 How automatic password changes may work10:09 Standards, automation, and website support11:10 Balancing convenience with trust12:22 Why password automation could help less technical users13:15 Implementation concerns and website complexity14:13 Comparing the feature to Face ID's early skepticism15:41 Account lockout as the biggest risk16:28 Where automatic password changes could be useful17:33 Interface design and fallbacks18:27 Security tradeoffs and password visibility19:36 Passwords as an aging technology20:10 Password managers and better password habits21:35 Passkeys and the slow path to adoption23:23 Sponsor message25:48 Snap Specs pricing and release expectations26:13 Recording indicators and privacy concerns26:34 Comparing Snap Specs to Meta smart glasses27:18 Price, style, and hardware limitations28:16 Ray-Ban Meta glasses and AI features28:35 Vision Pro comparisons and entertainment value29:20 Potential use cases for smart glasses30:45 Skepticism about current smart glasses design31:14 Are these products ready for consumers?32:06 Humor, smart glasses, and panel reactions33:39 Closing comments and event mentions34:15 Closing credits and support information Links: Tim Cook posts comedic ‘Good morning' video to mark final Apple event as CEOhttps://9to5mac.com/2026/06/08/tim-cook-posts-comedic-good-morning-video-to-mark-final-apple-event-as-ceo/ WWDC 2026 Swag Bag Includes Little Finder Guyhttps://www.macrumors.com/2026/06/08/wwdc-2026-swag-bag-little-finder-guy/ Apple Updates App Store Guidelines With Stricter Rules for Low-Quality Appshttps://www.macrumors.com/2026/06/09/app-store-guidelines-low-quality-apps/ iOS 27's Passwords app can change your passwords for you, automatically – 9to5Machttps://9to5mac.com/2026/06/08/ios-27s-passwords-app-can-change-your-passwords-for-you-automatically/ Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site:https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support: Become a MacVoices Patron on Patreon http://patreon.com/macvoices Enjoy this episode? Make a one-time donation with PayPal Connect: Web: http://macvoices.com Twitter: http://www.twitter.com/chuckjoiner http://www.twitter.com/macvoices Mastodon: https://mastodon.cloud/@chuckjoiner Facebook: http://www.facebook.com/chuck.joiner MacVoices Page on Facebook: http://www.facebook.com/macvoices/ MacVoices Group on Facebook: http://www.facebook.com/groups/macvoice LinkedIn: https://www.linkedin.com/in/chuckjoiner/ Instagram: https://www.instagram.com/chuckjoiner/ Subscribe: Audio in iTunes Video in iTunes Subscribe manually via iTunes or any podcatcher: Audio: http://www.macvoices.com/rss/macvoicesrss Video: http://www.macvoices.com/rss/macvoicesvideorss
The MacVoices Live! panel discusses Apple's updated App Store review guidelines, the challenge of filtering low-quality or AI-generated apps, and whether trusted developers should receive faster review. Chuck Joiner, David Ginsburg, Jim Rea, Marty Jencius, Web Bixby, Jeff Gamet, and Eric Bolden also debate Apple's Passwords app gaining automatic password-changing abilities, weighing convenience against account-lockout risk. They also provide reactions to Snap's new Specs and the uncertain future of smart glasses. MacVoices is supported by NordLayer. Secure your network & stay compliant with one toggle-ready platform. Get an exclusive offer: up to 22% off NordLayer yearly plans plus 10% on top with the coupon code: MACVOICES10 at NordLayer.com/macvoices. Try it risk-free—14-day money-back guarantee. Show Notes: Chapters: 00:00 Opening topics and sponsor message 00:27 Tim Cook's WWDC morning video 01:34 WWDC swag and Finder collectibles 03:24 Apple's app submission volume 03:46 Updated App Store guidelines for low-quality apps 04:19 The scale problem of reviewing thousands of apps 05:48 Should trusted developers get faster review? 06:27 Policing successful or suspicious apps 07:37 Apple Passwords app and automatic password changes 08:00 Initial skepticism from the panel 09:09 How automatic password changes may work 10:09 Standards, automation, and website support 11:10 Balancing convenience with trust 12:22 Why password automation could help less technical users 13:15 Implementation concerns and website complexity 14:13 Comparing the feature to Face ID's early skepticism 15:41 Account lockout as the biggest risk 16:28 Where automatic password changes could be useful 17:33 Interface design and fallbacks 18:27 Security tradeoffs and password visibility 19:36 Passwords as an aging technology 20:10 Password managers and better password habits 21:35 Passkeys and the slow path to adoption 23:23 Sponsor message 25:48 Snap Specs pricing and release expectations 26:13 Recording indicators and privacy concerns 26:34 Comparing Snap Specs to Meta smart glasses 27:18 Price, style, and hardware limitations 28:16 Ray-Ban Meta glasses and AI features 28:35 Vision Pro comparisons and entertainment value 29:20 Potential use cases for smart glasses 30:45 Skepticism about current smart glasses design 31:14 Are these products ready for consumers? 32:06 Humor, smart glasses, and panel reactions 33:39 Closing comments and event mentions 34:15 Closing credits and support information Links: Tim Cook posts comedic 'Good morning' video to mark final Apple event as CEO https://9to5mac.com/2026/06/08/tim-cook-posts-comedic-good-morning-video-to-mark-final-apple-event-as-ceo/ WWDC 2026 Swag Bag Includes Little Finder Guy https://www.macrumors.com/2026/06/08/wwdc-2026-swag-bag-little-finder-guy/ Apple Updates App Store Guidelines With Stricter Rules for Low-Quality Apps https://www.macrumors.com/2026/06/09/app-store-guidelines-low-quality-apps/ iOS 27's Passwords app can change your passwords for you, automatically – 9to5Mac https://9to5mac.com/2026/06/08/ios-27s-passwords-app-can-change-your-passwords-for-you-automatically/ Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site: https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support: Become a MacVoices Patron on Patreon http://patreon.com/macvoices Enjoy this episode? Make a one-time donation with PayPal Connect: Web: http://macvoices.com Twitter: http://www.twitter.com/chuckjoiner http://www.twitter.com/macvoices Mastodon: https://mastodon.cloud/@chuckjoiner Facebook: http://www.facebook.com/chuck.joiner MacVoices Page on Facebook: http://www.facebook.com/macvoices/ MacVoices Group on Facebook: http://www.facebook.com/groups/macvoice LinkedIn: https://www.linkedin.com/in/chuckjoiner/ Instagram: https://www.instagram.com/chuckjoiner/ Subscribe: Audio in iTunes Video in iTunes Subscribe manually via iTunes or any podcatcher: Audio: http://www.macvoices.com/rss/macvoicesrss Video: http://www.macvoices.com/rss/macvoicesvideorss
Passwords were built for a different era of the internet. It's time to move past shared secrets to close your organization's largest threat vector for good.Traditional passwords and legacy Multi-Factor Authentication (MFA) are no longer enough to protect your business. Automated, scaling phishing toolkits easily intercept shared secrets, leaving small and medium businesses highly vulnerable to credential breaches.In this episode, Jen sits down with Nishant Kaushik, Chief Technology Officer at the FIDO Alliance, to translate complex cryptographic standards into an actionable, resource-light deployment plan. Learn how to transition away from legacy authentication and close the hidden operational loopholes that hackers actively exploit.What You Will Learn:The Flaw in Basic MFA: Why SMS codes and standard one-time passwords (OTPs) are failing, and what true "phishing-resistant" security means.The Account Recovery Trap: Why a weak "Forgot Password" workflow accidentally gives hackers their primary attack vector back—and how to fix it.The Bottom-Line Benefit: How moving to passkeys drastically reduces internal IT helpdesk tickets, manual password resets, and overhead costs.Right-Sizing Your Passkey Deployment: How to easily segment your workforce strategy:Standard Users: Synced passkeys via platform credential managers (Apple, Google, 1Password, Bitwarden).Privileged Users: Dedicated hardware keys (YubiKeys) for root admins and high-sensitivity infrastructure.The 1-Week Action Plan: How to leverage the identity infrastructure you already own (like Google Workspace or Microsoft Entra ID) to deploy passkeys today.Resources Mentioned:Learn more about modern identity standards: FIDO Alliance WebsiteReview baseline federal security recommendations: CISA Guidance on Phishing-Resistant MFADiscover SecurityMetrics compliance resources: SecurityMetrics Official SiteThreat Intelligence Data: Read the data behind credential exploitation in the latest Verizon Data Breach Investigations Report (DBIR). Federal Passkey Standards: Review the updated identity and passkey frameworks via the NIST SP 800-63 Digital Identity Guidelines. Enterprise Identity Platforms: Learn how modern stacks integrate passwordless via Okta Verify and Microsoft Entra ID. About the Guest: Nishant Kaushik is the Chief Technology Officer at the FIDO Alliance, bringing over 25 years of leadership in digital identity and access management (IAM). He holds nine patents, frequently serves on the advisory committees for the RSA Conference and Identiverse, and is a founding member of IDPro.A note from Jen: We built Practical Cybersecurity because we were tired of the fear-mongering in this industry. Security shouldn't be a secret club.If you're trying to figure out PCI compliance or need a pen test, my team at SecurityMetrics can help you out: https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place But if you just want to learn how to protect yourself for free, start here: https://academy.securitymetrics.com/
Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksGenerate HTML Password Rules Attribute in Laravel 13.9.0Storage Cache Store in Laravel 13.10.0Scrollbar Styling and Container Size Utilities in Tailwind CSS v4.3.0Laravel Introduces First-Party Passkey Authentication SupportLaravel's AI SDK adds sub-agentsDHH Joins Laravel Live Denmark 2026 for Fireside Chat with Taylor OtwellManage Laravel Cloud Deployments Inside PhpStormMoat: A Security Review for Your GitHub AccountModel-Based Scheduling for Laravel with CadenceLarapanda: A Type-Safe Lightpanda Browser SDK for LaravelUse a Google Sheet as Your Laravel Database with the Google Sheets Database DriverDrag-and-Drop Sorting for Eloquent Models with Reorderable for LaravelPiper: Laravel-Style Array and String Helpers for PHP's Pipe OperatorSimple Feature Flags for Laravel with Laravel ToggleLaravel Paper: A Flat-File Eloquent DriverTutorialsLaravel MongoDB Full-Text Search tutorial: The Art of the RelevancyShip AI with Laravel: Real-Time Streaming Chat UI with Livewire
Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com
Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com
Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com
Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com
Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com
Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com
In our World Password Day Special, we're digging into credentials, identity, and authentication — and where security is heading next.
SummaryIn this episode, Andy and Adam discuss a recent vulnerability in the Signal messaging app that allowed the FBI to recover deleted messages from an iPhone due to a flaw in Apple's notification system. They emphasize the importance of user settings and the need for regular updates. The conversation then shifts to the UK National Cyber Security Centre's endorsement of passkeys as a preferred login method for consumers, highlighting the shift away from traditional passwords. Finally, they address the challenges of open source software security, referencing Marcus Hutchins' insights on the lack of bug bounty programs and the potential risks associated with unmonitored code.----------------------------------------------------YouTube Video Link: https://youtu.be/yXuUc32MPL4----------------------------------------------------Documentation: https://arstechnica.com/tech-policy/2026/04/apple-stops-weirdly-storing-data-that-let-cops-spy-on-signal-chats/https://www.infosecurity-magazine.com/news/ncsc-backs-passkeys-new-era-of/----------------------------------------------------Contact Us:Website: https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: https://www.linkedin.com/company/bluesecpodYouTube: https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: https://www.linkedin.com/in/andyjaw/Email: andy@bluesecuritypod.com----------------------------------------------------Adam BrewerTwitter: https://twitter.com/ajbrewerLinkedIn: https://www.linkedin.com/in/adamjbrewer/Email: adam@bluesecuritypod.com
SummaryIn this episode, Andy and Adam discuss a recent vulnerability in the Signal messaging app that allowed the FBI to recover deleted messages from an iPhone due to a flaw in Apple's notification system. They emphasize the importance of user settings and the need for regular updates. The conversation then shifts to the UK National Cyber Security Centre's endorsement of passkeys as a preferred login method for consumers, highlighting the shift away from traditional passwords. Finally, they address the challenges of open source software security, referencing Marcus Hutchins' insights on the lack of bug bounty programs and the potential risks associated with unmonitored code.----------------------------------------------------YouTube Video Link: https://youtu.be/yXuUc32MPL4----------------------------------------------------Documentation: https://arstechnica.com/tech-policy/2026/04/apple-stops-weirdly-storing-data-that-let-cops-spy-on-signal-chats/https://www.infosecurity-magazine.com/news/ncsc-backs-passkeys-new-era-of/----------------------------------------------------Contact Us:Website: https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: https://www.linkedin.com/company/bluesecpodYouTube: https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: https://www.linkedin.com/in/andyjaw/Email: andy@bluesecuritypod.com----------------------------------------------------Adam BrewerTwitter: https://twitter.com/ajbrewerLinkedIn: https://www.linkedin.com/in/adamjbrewer/Email: adam@bluesecuritypod.com
Apple's leadership shake-up, the rise of passkeys, and the future of smart security are here. Steven Scott dives into Tim Cook's departure, Apple's next moves, and Ring's innovative 4K doorbell features. [Sponsor] Entries are still open for the Double Tap competition in partnership with Pneuma Solutions, with a closing date of May 1st. Listeners have the chance to win subscriptions to powerful accessibility tools including Remote Incident Manager for accessible remote tech support and Scribe for creating screen reader-friendly documents quickly. To enter, send an email to feedback@doubletaponair.com, a WhatsApp message to (613) 481-0144, or call (877) 803-4567, making sure to include your name and contact details so the team can get in touch if you win. This episode of Double Tap Mainstream brings together breaking tech news and security insights. Steven Scott tackles Apple's major announcement: Tim Cook steps down, naming long-time hardware leader John Ternus as CEO. Technology journalist Will Guyatt joins to explore Apple's strategy, Silicon transitions, AI integration, and what's next for wearables and AR. Then, Dave Ward of Ring unveils the company's newest 2K and 4K video doorbells, complete with Familiar Faces recognition and smart video descriptions—features designed to enhance home security without compromising privacy. Closing the show, Karolis Arbaciauskas from NordVPN explains why passkeys are the future of authentication, how they improve safety over passwords, and how users can start adopting them today. Call to Action Subscribe for more in-depth tech insights and accessibility-focused tech coverage. Share your thoughts in the comments, and don't forget to hit like if you found this episode helpful! Relevant Links Ring: https://www.ring.com NordVPN: https://nordvpn.com ----Follow on:YouTube: https://www.doubletaponair.com/youtubeX (formerly Twitter): https://www.doubletaponair.com/xInstagram: https://www.doubletaponair.com/instagramTikTok: https://www.doubletaponair.com/tiktokThreads: https://www.doubletaponair.com/threadsFacebook: https://www.doubletaponair.com/facebookLinkedIn: https://www.doubletaponair.com/linkedinSubscribe to the Podcast:Apple: https://www.doubletaponair.com/appleSpotify: https://www.doubletaponair.com/spotifyRSS: https://www.doubletaponair.com/podcastiHeadRadio: https://www.doubletaponair.com/iheartAbout Double TapHosted by the insightful duo, Steven Scott and Shaun Preece, Double Tap is a treasure trove of information for anyone who's blind or partially sighted and has a passion for tech. Steven and Shaun not only demystify tech, but they also regularly feature interviews and welcome guests from the community, fostering an interactive and engaging environment. Tune in every day of the week, and you'll discover how technology can seamlessly integrate into your life, enhancing daily tasks and experiences, even if your sight is limited."Double Tap" is a registered trademark of Double Tap Productions Inc. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Unlock the ultimate guide to building a future-proof cybersecurity career and mastering the complex world of AI security! Join us for an exclusive interview with Ben Wilcox, CTO and CSO of ProArch, as he unveils his unparalleled insights forged over three decades in digital defense. This video is your essential roadmap to navigating the rapidly evolving landscape of AI security, securing enterprise AI, and understanding the critical challenges and opportunities in cyber defense.Whether you're looking to break into cybersecurity, advance your tech career, or are a seasoned IT veteran, Ben's journey—from early internet hustles to a leadership role in cloud and application security—provides invaluable, practical guidance. Discover the foundational knowledge, crucial soft skills, and continuous learning strategies vital for anyone aspiring to a successful cybersecurity career. Ben highlights the immense value of professional certifications and the unique advantages gained through diverse experiences, especially within consultancies.Dive deep into what truly keeps Chief Security Officers (CSOs) awake at night, including the growing threat of identity-driven attacks and the rapidly emerging security challenges posed by sophisticated AI agents. We explore the critical importance of implementing zero trust architectures and how advanced security tools are becoming indispensable to manage the expanding AI attack surface effectively. Ben offers actionable cybersecurity career advice for newcomers: embrace every learning opportunity, cultivate strong communication and people skills, and actively network within the industry. Tune in for expert insights on cybersecurity leadership, sustainable career growth, robust security best practices, and truly securing the future in an age of artificial intelligence.This comprehensive deep dive into AI security, strategic career development, and cutting-edge security strategies is an absolute must-watch for anyone interested in AI's profound impact on cyber defense and professional growth. Learn directly from an industry leader how to not only secure your own career but also contribute to securing our digital world against advanced threats. Don't miss out on mastering AI security concepts and significantly advancing your professional journey in cybersecurity.Timestamps:0:00 Introduction: CTO Ben Wilcox & AI Security Career Map13:00 Breaking Into Cyber Today: AI's Impact & Essential Skills17:49 CSO Concerns: Identity Attacks, Passkeys & Agentic AI Risks22:41 Enterprise AI Security: Zero Trust & Attack Surface Management26:14 Career Growth Advice: Networking, Soft Skills & Future-ProofingConnect with Ben Wilcox on LinkedIn: https://www.linkedin.com/in/ben-wilcox/Learn more about Breaking Into Cybersecurity:Website: https://www.cyberhubpodcast.com/breakingintocybersecurityPodcast: https://podcasters.spotify.com/pod/show/breaking-into-cybersecuriYouTube: https://www.youtube.com/c/BreakingIntoCybersecurityLinkedIn: https://www.linkedin.com/company/breaking-into-cybersecurity/Check out our books:The Cybersecurity Advantage - https://leanpub.com/the-cybersecurity-advantageDevelop Your Cybersecurity Career Path: How to Break into Cybersecurity at Any Level - https://amzn.to/3443AUIHack the Cybersecurity Interview: Navigate Cybersecurity Interviews with Confidence - https://www.amazon.com/Hack-Cybersecurity-Interview-Interviews-Entry-level/dp/1835461298/Hacker Inc.: Mindset For Your Career - https://www.amazon.com/Hacker-Inc-Mindset-Your-Career/dp/B0DKTK1R93/About the Hosts:Renee Small, CEO of Cyber Human Capital: https://www.linkedin.com/in/reneebrownsmall/Christophe Foulon, Cybersecurity Strategist: https://www.linkedin.com/in/christophefoulon/Find out more about CPF-Coaching: https://www.cpf-coaching.comSponsored by CPF Coaching LLC - http://cpf-coaching.com
Pre-show: The new Ceramic Shield 2 in the iPhone 17 Pro is the real deal UniFi Travel Router Cascades trail Shenandoah National Park
Friday - Clark Stinks day! Christa shares Clark Stinks posts with Clark. Submit yours at Clark.com/ClarkStinks. Also today - security risks keep morphing via phone and/or account takeover attempts. Clark covers a specific threat targeting iPhone users and the simple fix, plus - the next generation of online security – Passkeys. Clark Stinks: Segments 1 & 2 Prevent Hackers: Segment 3 Ask Clark: Segment 4 Mentioned on the show: Buy Now, Pay Later: A Helpful Tool or a Debt Trap? - Clark Howard Roth IRA Withdrawal Rules What Is a Credit Union? - Clark Howard Why Clark Howard Thinks You Need a Digital Passport Best Free Password Managers: 10 Top Picks - Clark Howard New Ways to Keep Your Online Accounts Safe Military and Veterans Guide: Free Resources for Your Finances Charitable Contributions Deduction: What It Is and How It Works Understanding Donor-Advised Funds: Pros and Cons Clark.com resources: Episode transcripts Community.Clark.com / Ask Clark Clark.com daily money newsletter Consumer Action Center Free Helpline: 636-492-5275 Learn more about your ad choices. Visit megaphone.fm/adchoices
Leo Laporte takes to the expo floor at RSAC 2026 in San Francisco's Moscone Center for a rapid-fire series of conversations with leading security vendors and thinkers. From Thinkst Canary's honeypot deception tactics to Bitwarden's new Agent Access SDK, Tailscale's AI gateway, and Aikido Security's fully autonomous AI pen testers, the dominant theme is clear: the AI agent era has arrived and security hasn't caught up. Plus, a surprise meeting with WannaCry kill-switch hero Marcus Hutchins. Thinkst Canary, ThreatLocker, and Bitwarden are sponsors of the TWiT.tv Network. 0:29 Haroon Meer | Thinkst Canary – Honeypots & Deception Tech 6:35 Bob Boyle | Torq – AI-Powered Security Automation 9:50 Juan Quesada | Yubico – FIDO2, Passkeys & Pre-Registered YubiKeys 12:33 Rob Allen | ThreatLocker – Zero Trust & Deny by Default 25:53 Arun Singh | Drata – Trust Management & Compliance 27:34 Jelmer Snoeck | Keycard Labs – Ephemeral Tokens for AI Agents 35:26 Kasey Babcock | Bitwarden – Agent Access SDK 41:52 Roeland Delrue | Aikido Security – Autonomous AI Pen Testing 48:56 Bill Keeler | Semperis – Identity Security & "Midnight in the War Room" 52:08 MalwareTech Marcus Hutchins & Cybersecurity Girl Caitlin Sarian 54:30 Chris Hughes | Zenity – Securing AI Agents at Runtime 1:01:35 Jillian Murphy | Tailscale – Networking, Aperture & Free Forever Host: Leo Laporte Guests: Haroon Meer, Rob Allen, Bob Boyle, Juan Quesada, Arun Signh, Kasey Babcock, Roeland Delrue, Bill Keeler, Marcus Hutchins, Caitlin Sarian, Chris Hughes, and Jillian Murphy Download or subscribe to TWiT Events at https://twit.tv/shows/twit-events. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Leo Laporte takes to the expo floor at RSAC 2026 in San Francisco's Moscone Center for a rapid-fire series of conversations with leading security vendors and thinkers. From Thinkst Canary's honeypot deception tactics to Bitwarden's new Agent Access SDK, Tailscale's AI gateway, and Aikido Security's fully autonomous AI pen testers, the dominant theme is clear: the AI agent era has arrived and security hasn't caught up. Plus, a surprise meeting with WannaCry kill-switch hero Marcus Hutchins. Thinkst Canary, ThreatLocker, and Bitwarden are sponsors of the TWiT.tv Network. 0:29 Haroon Meer | Thinkst Canary – Honeypots & Deception Tech 6:35 Bob Boyle | Torq – AI-Powered Security Automation 9:50 Juan Quesada | Yubico – FIDO2, Passkeys & Pre-Registered YubiKeys 12:33 Rob Allen | ThreatLocker – Zero Trust & Deny by Default 25:53 Arun Singh | Drata – Trust Management & Compliance 27:34 Jelmer Snoeck | Keycard Labs – Ephemeral Tokens for AI Agents 35:26 Kasey Babcock | Bitwarden – Agent Access SDK 41:52 Roeland Delrue | Aikido Security – Autonomous AI Pen Testing 48:56 Bill Keeler | Semperis – Identity Security & "Midnight in the War Room" 52:08 MalwareTech Marcus Hutchins & Cybersecurity Girl Caitlin Sarian 54:30 Chris Hughes | Zenity – Securing AI Agents at Runtime 1:01:35 Jillian Murphy | Tailscale – Networking, Aperture & Free Forever Host: Leo Laporte Guests: Haroon Meer, Rob Allen, Bob Boyle, Juan Quesada, Arun Signh, Kasey Babcock, Roeland Delrue, Bill Keeler, Marcus Hutchins, Caitlin Sarian, Chris Hughes, and Jillian Murphy Download or subscribe to TWiT Events at https://twit.tv/shows/twit-events. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Is Apple's Passwords app a true contender for your digital life, or does it fall short for tech-savvy households? Find out how it stacks up against premium managers and where it still leaves power users wanting more. How shared password groups work in the Passwords app Step-by-step walkthrough: creating and managing shared groups Apple Passwords sharing vs. third-party apps like 1Password, Bitwarden (TWiT sponsor) Wi-Fi password management and sharing via QR codes Passwords app limitations: organization, secure notes, file storage, platform support Migration challenges from other password managers Travel needs and sensitive data: third-party travel mode vs. Passwords app Who should use Apple's Passwords app and who needs more advanced tools Hybrid approaches: combining Apple Passwords with third-party managers Host: Mikah Sargent Download or subscribe to Hands-On Apple at https://twit.tv/shows/hands-on-apple Want access to the ad-free audio and video and exclusive features? Become a member of Club TWiT today! https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: threatlocker.com/twit
Is Apple's Passwords app a true contender for your digital life, or does it fall short for tech-savvy households? Find out how it stacks up against premium managers and where it still leaves power users wanting more. How shared password groups work in the Passwords app Step-by-step walkthrough: creating and managing shared groups Apple Passwords sharing vs. third-party apps like 1Password, Bitwarden (TWiT sponsor) Wi-Fi password management and sharing via QR codes Passwords app limitations: organization, secure notes, file storage, platform support Migration challenges from other password managers Travel needs and sensitive data: third-party travel mode vs. Passwords app Who should use Apple's Passwords app and who needs more advanced tools Hybrid approaches: combining Apple Passwords with third-party managers Host: Mikah Sargent Download or subscribe to Hands-On Apple at https://twit.tv/shows/hands-on-apple Want access to the ad-free audio and video and exclusive features? Become a member of Club TWiT today! https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: threatlocker.com/twit
What if logging in didn't mean juggling passwords and SMS codes? This episode demonstrates how Apple's Passwords app could make passkeys your new security upgrade and what may help protect your digital life. Understanding and setting up two-factor authentication codes in Passwords How to scan and autofill TOTP codes on macOS and iOS Best practices for migrating 2FA codes from other authenticator apps Passkeys setup, security benefits, and workflow Passkey vs. password: what to expect when logging in Apple security recommendations: flagged, reused, weak, and leaked passwords Prioritizing which flagged passwords to fix first Homework: add verification codes, create a passkey, and fix at-risk accounts Host: Mikah Sargent Download or subscribe to Hands-On Apple at https://twit.tv/shows/hands-on-apple Want access to the ad-free audio and video and exclusive features? Become a member of Club TWiT today! https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: outsystems.com/twit
What if logging in didn't mean juggling passwords and SMS codes? This episode demonstrates how Apple's Passwords app could make passkeys your new security upgrade and what may help protect your digital life. Understanding and setting up two-factor authentication codes in Passwords How to scan and autofill TOTP codes on macOS and iOS Best practices for migrating 2FA codes from other authenticator apps Passkeys setup, security benefits, and workflow Passkey vs. password: what to expect when logging in Apple security recommendations: flagged, reused, weak, and leaked passwords Prioritizing which flagged passwords to fix first Homework: add verification codes, create a passkey, and fix at-risk accounts Host: Mikah Sargent Download or subscribe to Hands-On Apple at https://twit.tv/shows/hands-on-apple Want access to the ad-free audio and video and exclusive features? Become a member of Club TWiT today! https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: outsystems.com/twit
Apple's standalone Passwords app gives Keychain a proper home! Ready to clean up your secure digital life? This episode walks you through using Apple's Passwords app to spot weak logins, organize old accounts, and take control of your online security with tools already built into your devices. Quick history: Keychain to iCloud Keychain to Passwords app How to access the Passwords app on iPadOS, iOS, and macOS Passwords app interface tour: categories, search, and shared groups What autofill and notifications options you can enable in Passwords Exploring the main categories: All, Passkeys, Codes, Wi-Fi, Security, Deleted Viewing, editing, and sharing individual logins in the Passwords app Manually adding, updating, or deleting passwords and usernames Using search and sort to find and organize your saved logins How autofill password suggestions work in Safari and system settings Tweaking autofill and 3rd-party password manager integration Homework: review and clean up your Passwords app before next episode Host: Mikah Sargent Download or subscribe to Hands-On Apple at https://twit.tv/shows/hands-on-apple Want access to the ad-free audio and video and exclusive features? Become a member of Club TWiT today! https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: Melissa.com/twit
Apple's standalone Passwords app gives Keychain a proper home! Ready to clean up your secure digital life? This episode walks you through using Apple's Passwords app to spot weak logins, organize old accounts, and take control of your online security with tools already built into your devices. Quick history: Keychain to iCloud Keychain to Passwords app How to access the Passwords app on iPadOS, iOS, and macOS Passwords app interface tour: categories, search, and shared groups What autofill and notifications options you can enable in Passwords Exploring the main categories: All, Passkeys, Codes, Wi-Fi, Security, Deleted Viewing, editing, and sharing individual logins in the Passwords app Manually adding, updating, or deleting passwords and usernames Using search and sort to find and organize your saved logins How autofill password suggestions work in Safari and system settings Tweaking autofill and 3rd-party password manager integration Homework: review and clean up your Passwords app before next episode Host: Mikah Sargent Download or subscribe to Hands-On Apple at https://twit.tv/shows/hands-on-apple Want access to the ad-free audio and video and exclusive features? Become a member of Club TWiT today! https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: Melissa.com/twit
Can Microsoft's push for cloud PCs and AI-powered agents redefine where and how we work? If you keep to the defaults, Windows 11 is secure. Copilot+ PC is even more secure. But you can take additional steps to secure it either way, and you should. Plus, Paul's been trying to play different types of games, and Resident Evil Requiem is better (in his opinion) than Silent Hill f and Silent Hill 2 remake... if you want a horror game. Also, there's a cheaper new Audible plan thanks to Spotify! Windows 11 Shenanigans? If you use a third-party AI client in Edge Canary... you will not be amused. Bitwarden (TWiT sponsor) is (possibly the 1st?) third-party password manager to support passkey sign-ins on Windows 11 New Canary, Dev, and Beta builds last Friday- Canary is more of the same, Dev/Beta get shared audio improvements, narrator improvements, new IT policies ASUS and Dell will soon sell Windows 365 Cloud PCs Google is moving Chrome to a two-week dev schedule. Should we assume Microsoft will follow suit with Edge? Dell is up 39 percent, but because of AI servers not PCs NVIDIA revenues up 73 percent to $68.1 billion AI/dev OpenAI closes $110 billion funding round as the AI circle jerk continues Microsoft brings Copilot Tasks to consumer Copilot Google introduces AppFunctions for Android, it's way to make mobile apps work like MCP (be semantic), similar to what Microsoft is doing in Windows Windows App Development CLI updated to 0.02 with Store CLI integration and .NET project support Build 2026 is in San Francisco, as expected, but in June - overlap with WWDC? Xbox and gaming Here come the first Game Pass titles of March Microsoft highlights some indie games to consider Xbox ROG Ally gets AI-based game recaps Legion Go Fold is the star of the new PCs at MWC Sony might be backtracking on its PC games plans Developing: Epic/Google settlement was approved Tips & picks App pick of the week: Resident Evil Requiem Tip of the week: Secure your Windows 11 PC RunAs Radio this week: Hiring in 2026 with Suzi Edwards-Alexander Brown liquor pick of the week: St. Augustine Florida Straight Bourbon Hosts: Paul Thurrott, Richard Campbell, and Mikah Sargent Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: threatlocker.com/twit
Can Microsoft's push for cloud PCs and AI-powered agents redefine where and how we work? If you keep to the defaults, Windows 11 is secure. Copilot+ PC is even more secure. But you can take additional steps to secure it either way, and you should. Plus, Paul's been trying to play different types of games, and Resident Evil Requiem is better (in his opinion) than Silent Hill f and Silent Hill 2 remake... if you want a horror game. Also, there's a cheaper new Audible plan thanks to Spotify! Windows 11 Shenanigans? If you use a third-party AI client in Edge Canary... you will not be amused. Bitwarden (TWiT sponsor) is (possibly the 1st?) third-party password manager to support passkey sign-ins on Windows 11 New Canary, Dev, and Beta builds last Friday- Canary is more of the same, Dev/Beta get shared audio improvements, narrator improvements, new IT policies ASUS and Dell will soon sell Windows 365 Cloud PCs Google is moving Chrome to a two-week dev schedule. Should we assume Microsoft will follow suit with Edge? Dell is up 39 percent, but because of AI servers not PCs NVIDIA revenues up 73 percent to $68.1 billion AI/dev OpenAI closes $110 billion funding round as the AI circle jerk continues Microsoft brings Copilot Tasks to consumer Copilot Google introduces AppFunctions for Android, it's way to make mobile apps work like MCP (be semantic), similar to what Microsoft is doing in Windows Windows App Development CLI updated to 0.02 with Store CLI integration and .NET project support Build 2026 is in San Francisco, as expected, but in June - overlap with WWDC? Xbox and gaming Here come the first Game Pass titles of March Microsoft highlights some indie games to consider Xbox ROG Ally gets AI-based game recaps Legion Go Fold is the star of the new PCs at MWC Sony might be backtracking on its PC games plans Developing: Epic/Google settlement was approved Tips & picks App pick of the week: Resident Evil Requiem Tip of the week: Secure your Windows 11 PC RunAs Radio this week: Hiring in 2026 with Suzi Edwards-Alexander Brown liquor pick of the week: St. Augustine Florida Straight Bourbon Hosts: Paul Thurrott, Richard Campbell, and Mikah Sargent Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: threatlocker.com/twit
From generating passkeys and payment autofill to dark web monitoring, today's password managers aren't what you remember. Paul Thurrott breaks down the must-have features and surprising pitfalls for anyone using Windows 11. Host: Paul Thurrott Download or subscribe to Hands-On Windows at https://twit.tv/shows/hands-on-windows Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord. Sponsor: bitwarden.com/twit