Podcasts about passkeys

  • 291PODCASTS
  • 696EPISODES
  • 1h 7mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Apr 8, 2025LATEST

POPULARITY

20172018201920202021202220232024


Best podcasts about passkeys

Show all podcasts related to passkeys

Latest podcast episodes about passkeys

NZ Tech Podcast
Microsoft at 50, Passkeys, Privacy, and the Tech Ecosystem with Justin Soong

NZ Tech Podcast

Play Episode Listen Later Apr 8, 2025 57:26


Hear from host Paul Spain and Justin Soong founder and technical director at Authsignal, as Justin shares about fortifying online security through innovative authentication solutions. They discuss the challenges and triumphs surrounding identity protection and the latest cybersecurity breaches. Plus, tech news from the week including:2025 Hi-Tech Awards finalists revealedCanadian Tech company buys majority in SeratoQuantifi Photonics acquired2degrees fined $325k for misleading claimsMicrosoft turns 50Trump's tariffs may mean paying more for gadgets in USAmazon can now buy from other websites for youWhy military planning shouldn't be on SignalThanks to our Partners One NZ, 2degrees, HP, Spark and Gorilla Technology

The Future of Security Operations
LastPass's Christofer Hoff on navigating incidents while rebuilding the security org from scratch

The Future of Security Operations

Play Episode Listen Later Apr 1, 2025 55:59


The Future of Security Operations podcast is back for a sixth season, and, to kick it off, Thomas is joined by Christofer Hoff. Christofer has over 30 years of experience in network and information security architecture, development, engineering, operations, and management, including security leadership roles at Bank of America, Citadel, and Juniper Networks. He's currently Chief Secure Technology Officer at LastPass, a unique role that combines the duties of CSO and CTO, while also serving on the board at FIDO Alliance. In this episode: [02:00] How blogging landed Christofer his first couple of jobs in security [06:50] Taking a more holistic approach to security through collaboration [09:40] Rebuilding LastPass's security org from scratch [12:03] Reflecting on incidents - what LastPass did right [16:12] Communicating with customers and the broader community during incidents [20:15] Navigating tech debt as a security leader [23:55] The biggest challenges AI has produced for his team [25:16] How LastPass uses an AI working group for decision-making [29:00] The evolving challenges of browser security [35:05] Passkeys, passwords and the future of secure authentication [41:40] Tips on hiring and structuring effective security teams [46:47] How LastPass creates efficiency through automation [50:38] The biggest changes he'd like to see in security [54:44] Connect with Chris The Future of Security Operations is brought to you by Tines, the orchestration, automation, and AI platform that powers some of the world's most important workflows. Where to find Christofer Hoff: LinkedIn Chris's Rational Survivability blog Where to find Thomas Kinsella: LinkedIn Tines Resources mentioned: Chris on Google's Cloud Security Podcast LastPass Security Incident Summary

Marsha Collier & Marc Cohen Techradio by Computer and Technology Radio / wsRadio
Navigating Privacy and Technology: Passkeys, IRS PINs, and Your 23andMe Data

Marsha Collier & Marc Cohen Techradio by Computer and Technology Radio / wsRadio

Play Episode Listen Later Mar 30, 2025 41:35


What about Signal messaging? The Government and Technology Disconnect; Email Masking for Privacy; How to download and delete your 23andme data NOW; The shift from passwords to passkeys; HP wins ink Cartridge class action suit; Cleaning your electronic devices; Protect your identity with IRS PINs; Top in streaming

Fringe Radio Network
Google Passkeys - JACKED UP DAILY!

Fringe Radio Network

Play Episode Listen Later Mar 26, 2025 34:00


March 26, 2025Google Passkeys-JACKED UP DAILY!On today's episode, Tim discusses google and the way they push passkeys on us users. Google is pushing so hard to get the public to have biometric passkeys. Here is the Video that Tim is watching during this episode...https://youtu.be/C4qNBLDpmss?si=8QEIyPAZXwt7lBJCOur website is www.LetsGetJackedUp.com Welcome to Jacked Up Daily with Tim, Jack, Bobby, and Karen, a dynamic daily podcast on the Fringe Radio Network. Tune in Monday through Friday at 7 AM for conservative commentary, Bible prophecy, and insights from a modern American Christian perspective. Based in Fresno, California, in the heart of the Central Valley, Jacked Up Daily brings a unique West Coast viewpoint to everything from politics and social issues to fringe topics like aliens, ghosts, and the anti-Christ. Whether discussing the rapture, end times prophecy, or offering analysis on current events, this show is perfect for your morning drive. Catch the latest episode on FringeRadioNetwork.com and join us as we explore the mysteries of the world from a bold, Christian viewpoint. Don't miss a moment of this thought-provoking and engaging show, where no topic is off-limits!FringeRadioNetwork.com LetsGetJackedup.com  E-mail us at letsgetjackedup@gmail.comFollow us on X @LetsGetJackedUp  and Facebookgo to www.StrawHatPizza.com to order your pizza if you live in Clovis or Fresno Californiamusic for this episode was from Back to the 80'shttps://youtu.be/0QKQlf8r7ls?si=dOoU1o_-HRiNm0Pv 

Day[0] - Zero Days for Day Zero
Extracting YouTube Creator Emails and Spilling Azure Secrets

Day[0] - Zero Days for Day Zero

Play Episode Listen Later Mar 24, 2025 44:04


This episode features some game exploitation in Neverwinter Nights, weaknesses in mobile implementation for PassKeys, and a bug that allows disclosure of the email addresses of YouTube creators. We also cover some research on weaknesses in Azure.Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/278.html[00:00:00] Introduction[00:00:35] Exploiting Neverwinter Nights[00:08:48] PassKey Account Takeover in All Mobile Browsers [CVE-2024-9956][00:22:51] Disclosing YouTube Creator Emails for a $20k Bounty[00:31:58] Azure's Weakest Link? How API Connections Spill Secrets[00:39:02] SAML roulette: the hacker always wins[00:40:56] Compromise of Fuse Encryption Key for Intel Security FusesPodcast episodes are available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosecYou can also join our discord: https://discord.gg/daTxTK9

Cyber Bites
Cyber Bites - 21st March 2025

Cyber Bites

Play Episode Listen Later Mar 20, 2025 7:33


* Sydney Law Firm Targeted by Foreign Cyber Attackers in Extortion Attempt* AI Coding Assistant Refuses to Generate Code, Suggests User Learn Programming* Widely Used GitHub Action Compromised, Leaking Secrets* Fake "Security Alert" Phishing on GitHub Hijacks Accounts* MyGov Passkey Adoption Surges in AustraliaSydney Law Firm Targeted by Foreign Cyber Attackers in Extortion Attempthttps://www.smh.com.au/national/nsw/prominent-sydney-law-firm-hit-with-cyberattack-massive-data-breach-20250313-p5ljd8.htmlBrydens Lawyers, a prominent Sydney law firm with ties to major sports leagues, has been targeted by foreign cyber attackers who stole over 600 gigabytes of confidential data. The data includes information related to the firm, its clients, cases, and staff.The firm discovered the security breach around February 20th and immediately took its digital systems offline, engaging external advisors, lawyers, and security experts. The attackers are now extorting the firm for a ransom.Brydens has reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. The firm has also restored its IT system's security and is conducting investigations to determine the full extent of the breach and notify affected individuals. This incident highlights the vulnerability of legal firms, which handle highly sensitive information, to ransomware attacks.AI Coding Assistant Refuses to Generate Code, Suggests User Learn Programminghttps://arstechnica.com/ai/2025/03/ai-coding-assistant-refuses-to-write-code-tells-user-to-learn-programming-instead/An AI coding assistant, Cursor, has surprised users by refusing to generate code and instead advising them to learn programming. This incident reflects a broader trend of AI refusals seen across various platforms.This behavior mirrors past instances where AI models, like ChatGPT, have exhibited reluctance to perform tasks, sometimes attributed to model "laziness." Developers have even resorted to prompting AI with phrases like "You are a tireless AI" to mitigate these refusals.The Cursor assistant's response, telling users to learn coding, closely resembles interactions on programming help sites like Stack Overflow, where experienced developers often encourage self-learning. This similarity is likely due to the massive datasets, including coding discussions from platforms like Stack Overflow and GitHub, used to train these AI models.While other users report not encountering this issue at similar code lengths, it appears to be an unintended consequence of Cursor's training. The developers of Cursor have been contacted for comment.Widely Used GitHub Action Compromised, Leaking Secretshttps://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066The widely used GitHub Action "tj-actions/changed-files" was compromised before March 14, 2025, injecting malicious code that leaked secrets from affected public repositories into workflow logs. This supply chain attack, tracked as CVE-2025-30066, exposed sensitive information like AWS access keys, GitHub Personal Access Tokens, and private RSA keys.The compromise occurred when an attacker gained access to update tags, pointing them to malicious code. While the malicious commits have since been reverted and the associated GitHub gist has been deleted, the risk of leaked secrets in logs remains.The primary risk is to public repositories, where secrets were exposed in plain view. Security teams are urged to identify affected repositories, review workflow logs for base64 encoded secrets, and immediately rotate any compromised credentials. It is recommended to stop using the compromised action, pin GitHub Actions to specific commit hashes, audit past workflow runs, and use GitHub's allow-listing feature to prevent future attacks.Fake "Security Alert" Phishing on GitHub Hijacks Accountshttps://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/A widespread phishing campaign is targeting GitHub users with fake "Security Alert" issues, attempting to trick them into authorizing a malicious OAuth app. The campaign has targeted nearly 12,000 repositories, warning users of unusual login attempts from Iceland.The fake alerts provide links that lead to an OAuth authorization page for a "gitsecurityapp" app, which requests extensive permissions, including full access to repositories, user profiles, and GitHub Actions workflows. If authorized, the app gains complete control over the user's account and code.The phishing campaign, which began recently, directs authorized users to callback addresses hosted on onrender.com. Users who have authorized the malicious app are advised to immediately revoke its access through GitHub Settings, check for unfamiliar GitHub Actions or gists, and rotate their credentials and authorization tokens.MyGov Passkey Adoption Surges in Australiahttps://www.itnews.com.au/news/over-200000-mygov-users-disable-passwords-in-passkey-shift-615664Over half a million myGov users have adopted passkeys as their login method since the feature launched in June 2024, with over 200,000 users exclusively relying on passkeys and abandoning traditional passwords. The Australian government implemented passkeys to enhance security and combat phishing attacks, investing $5.6 million in the project.Passkeys utilize biometric authentication, PINs, swipe patterns, or physical USB devices, leveraging cryptographic keypair technology. This approach makes myGov accounts resistant to phishing, as passkeys are specific to the website or app they are created for. Australia is among the first countries to implement passkeys for government services. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

Roja, con Ophelia Pastrana
¿Se acaban las contraseñas? /Roja, En Vivo

Roja, con Ophelia Pastrana

Play Episode Listen Later Mar 19, 2025 210:00


Las contraseñas están quedando obsoletas y la autenticación sin claves es el futuro. Descubre cómo funcionarán las Passkeys y la biometría. Hablemos de esto El show es en vivo así que no me responsabilizo por... mucho.

Der Zeitenwende Podcast
Ransomware, Cyber-Angriffe und Hacktivisten - vorbeugen, abwehren oder zurückschlagen?

Der Zeitenwende Podcast

Play Episode Listen Later Mar 14, 2025 35:30


Vertrauliche Daten geleakt? E-Mail-Server lahmgelegt? Daten verschlüsselt und dann erpresst? Cyberangriffe betreffen und bedrohen Unternehmen, Organisationen und Regierungsbehörden jeder Größe und in allen Branchen. Was können wir dagegen tun? Wie können wir uns schützen? Nico Lange und Ulrike Strauß sprechen mit Claudia Plattner, Präsidentin des Bundesamts für Sicherheit in der Informationstechnik und Bernd Geissler, Präsident des Landesamtes für Sicherheit in der Informationstechnik in Bayern über Cybersicherheit, Hacktivismus und digitales Dynamit. Sie klären dabei auch, ob die Cybersicherheitschefs selbst Zwei-Faktor-Authentifizierung und Passkeys nutzen.Checklisten, Flyer und Schritt-für-Schritt Anleitungen des Bundesamts für Sicherheit in der InformationstechnikBSI - Checklisten, Flyer & Schritt-für-Schritt-AnleitungenTipps für den digitalen AlltagBSI - Digitaler Verbraucherschutz – sicherer Umgang mit InformationstechnikPasskeys - Schafft die Passwörter ab?BSI - Passkeys - anmelden ohne Passwort Hosted on Acast. See acast.com/privacy for more information.

Security Now (MP3)
SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back

Security Now (MP3)

Play Episode Listen Later Mar 12, 2025 176:45


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

All TWiT.tv Shows (MP3)
Security Now 1016: The Bluetooth Backdoor

All TWiT.tv Shows (MP3)

Play Episode Listen Later Mar 12, 2025 176:45


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

Security Now (Video HD)
SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back

Security Now (Video HD)

Play Episode Listen Later Mar 12, 2025 176:45


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

Security Now (Video HI)
SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back

Security Now (Video HI)

Play Episode Listen Later Mar 12, 2025 176:45


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

Radio Leo (Audio)
Security Now 1016: The Bluetooth Backdoor

Radio Leo (Audio)

Play Episode Listen Later Mar 12, 2025 176:45


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

Security Now (Video LO)
SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back

Security Now (Video LO)

Play Episode Listen Later Mar 12, 2025 176:45


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

All TWiT.tv Shows (Video LO)
Security Now 1016: The Bluetooth Backdoor

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Mar 12, 2025 176:45 Transcription Available


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

Radio Leo (Video HD)
Security Now 1016: The Bluetooth Backdoor

Radio Leo (Video HD)

Play Episode Listen Later Mar 12, 2025 176:45 Transcription Available


Utah passes age verification requirement for app stores. The inside story on fake North Korean employees. Is that a Texas accent? An update on the ongoing Bybit cryptoheist saga. The industry may be making some changes in the wake of the Bybit attack. Apple pushes back legally against the UK's secret order. Did someone crack Passkeys? The UK launches a legal salvo at an innocent security researcher. The old data breach we witnessed that just keeps on giving. A bit more Bybit postmortem forensic news. A lesson to learn from a clever and effective ransomware attack. And what about that Bluetooth Backdoor discovery everyone is talking about? Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: 1password.com/securitynow uscloud.com joindeleteme.com/twit promo code TWIT zscaler.com/security canary.tools/twit - use code: TWIT

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Feb 25, 2025 6:10


Unfurl Update Released Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs. https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716 Google Confirms GMail To Ditch SMS Code Authentication Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/ Beware of Paypal New Address Feature Abuse Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters. https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/ Exim SQL Injection Vulnerability Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released https://www.exim.org/static/doc/security/CVE-2025-26794.txt https://github.com/OscarBataille/CVE-2025-26794? XMLlib patches https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 0-Day in Parallels https://jhftss.github.io/Parallels-0-day/

Como lo pienso lo digo
Desactivé todos mis accesos con Passkeys #Misc

Como lo pienso lo digo

Play Episode Listen Later Feb 20, 2025 6:27


Passkeys nos ofrece una forma muy cómoda de acceder a diferentes sitios webs o servicios sin usar nuestra contraseña, y por un tiempo, esto me funcionó perfecto en el ecosistema de Apple… pero no en Linux. Te invito a debatir sobre este tema en el Foro de la Comunidad de TuPodcast https://foro.tupodcast.com Y otras formas de contacto las encuentran en: https://ernestoacosta.me/contacto.html Todos los medios donde publico contenido los encuentras en: https://ernestoacosta.me/ Si quieres comprar productos de RØDE, este es mi link de afiliados: https://brandstore.rode.com/?sca_ref=5066237.YwvTR4eCu1

Backup Central's Restore it All
Passwords vs Passkeys: The Future of Backup Security

Backup Central's Restore it All

Play Episode Listen Later Feb 17, 2025 43:14 Transcription Available


In this eye-opening episode about passwords vs passkeys, W. Curtis Preston and Prasanna Malaiyandi expose why traditional password protection isn't enough for your backup systems anymore. They break down the evolution from basic passwords to MFA, and explain why passkeys and FIDO compliance represent the next level in security.Learn why hackers target backup systems first, how they exploit password vulnerabilities, and why even multi-factor authentication has its weak points. Discover why there hasn't been a single successful attack against FIDO-compliant systems, and why you should be pushing your backup vendors to support passkeys. Whether you're using a traditional backup system or a SaaS solution, this episode gives you the knowledge you need to better protect your last line of defense.We talked about this previous episode: https://www.backupwrapup.com/how-do-you-authenticate-with-all-new-hardware/

Cybercrime Magazine Podcast
Convenience Meets Security. Amazon Users Embrace Passkeys. Confidence Staveley, CyberSafe Foundation

Cybercrime Magazine Podcast

Play Episode Listen Later Feb 14, 2025 5:27


In October of 2024, Amazon announced that over 175 million of their customers are using passkeys to log in. Confidence Staveley, Africa's most celebrated female cybersecurity leader, is the founder of the Cybersafe Foundation, a Non-Governmental Organization on a mission to facilitate pockets of changes that ensure a safer internet for everyone with digital access in Africa. In this episode, Confidence joins host Amanda Glassner to discuss. To learn more about Confidence, visit her website at https://confidencestaveley.com, and for more on the CyberSafe Foundation, visit https://cybersafefoundation.org.

Walk In Victory
Cybersecurity EXPERT Dylan Shares Business Protection Secrets!

Walk In Victory

Play Episode Listen Later Feb 13, 2025 50:24


Is your business truly protected from cyber threats? Join host NaRon Tillman on Walk in Victory for a critical conversation with cybersecurity expert Dylan. This episode goes beyond generic advice and dives deep into the real challenges businesses face in today's digital landscape. Dylan exposes the shortcomings of traditional security practices, emphasizing the importance of understanding specific threats and tailoring solutions to your business needs. Discover why one-size-fits-all approaches often fail and learn about modern security measures like YubiKeys and Passkeys. Dylan also shares his journey from corporate disillusionment to founding a company dedicated to helping small and medium-sized businesses stay secure.Plus, just as Dylan highlights the importance of investing in robust cybersecurity, we believe in investing in quality comfort. That's why we're proud to partner with Cozy Earth, offering premium bedding and loungewear designed for ultimate relaxation. Visit cozyearth.com and use our exclusive code VICTORY1 to enjoy an incredible 40% off.Key Takeaways:The evolving landscape of cyber threats and the importance of staying informed.Why traditional security practices often fail small and medium-sized businesses.The importance of understanding specific threats and tailoring solutions.Modern security measures like YubiKeys and Passkeys as alternatives to traditional methods.Practical steps businesses can take to improve their cybersecurity posture.Timestamps:00:00 Introduction and Greetings00:09 Podcast Purpose and Warning00:49 Fear and Cybersecurity Threats02:29 The Impact of Cyber Attacks03:48 Technological Advancements and Cybersecurity04:36 Interview with Dylan: Cybersecurity Insights07:35 Common Cybersecurity Solutions11:03 The Reality of Cybersecurity Consulting16:30 Modern Cybersecurity Measures20:18 The Growing Cybersecurity Problem24:38 Bank Safety and FDIC Assurance25:04 CFPB and Fraud Protection25:35 Challenges in Monitoring Bank Accounts25:58 Business Fraud and Reporting Issues26:11 Personal Experience with Fraud28:06 Credit Card vs. Debit Card Security29:23 Cybersecurity Misconceptions30:53 Tailored Security Solutions for Businesses35:49 Entrepreneurial Journey in Cybersecurity38:46 Consumer vs. Business Protections44:34 Final Thoughts and Recommendations48:40 Closing Remarks and Call to ActionCall to Action:Want to be a guest on Walk In Victory? Send NaRon Tillman a message on PodMatch, here:https://www.joinpodmatch.com/walkinvictoryBecome a supporter of this podcast: https://www.spreaker.com/podcast/walk-in-victory--4078479/support.

The Defiant
Kain Warwick on Infinex, Synthetix, and the Future of DeFi UX and Stability

The Defiant

Play Episode Listen Later Feb 11, 2025 70:20


Kain Warwick, founder of Synthetix and Infinex, discusses the evolution of DeFi and the trade-offs required to improve user experience while maintaining decentralization. He explains how Infinex aims to offer a more accessible, centralized exchange-like interface while remaining non-custodial, addressing long-standing UX challenges in DeFi. Warwick also reflects on Synthetix's recent governance restructuring, competition from Hyperliquid, and the potential shift back to a stablecoin-focused model. Looking ahead, he highlights the importance of regulatory clarity, improved infrastructure, and greater accessibility in driving the next phase of DeFi growth.Chapters00:00 - Introduction to Kain Warwick00:15 - Kain's history in DeFi01:26 - Motivation behind Infinex and staying in crypto02:21 - Challenges of bull and bear markets05:55 - The idea behind Infinex and UX innovation08:40 - Trade-offs in building a user-friendly DeFi platform17:05 - Passkeys and the seamless user experience24:26 - Adoption metrics and user growth26:51 - Future roadmap: Bitcoin, XRP, and Doge integration33:08 - The Patron NFT sale: Lessons learned37:19 - Synthetix updates: Governance and structural changes39:27 - The role of attention in crypto success47:50 - Synthetix's stablecoin pivot and liquidity strategy51:14 - Differentiating Synthetix's stablecoin from others54:03 - Avoiding the pitfalls of past algo stablecoins✨ Check out our new website ✨https://thedefiant.io/

Reimagining Cyber
Goodbye Password Stress, Hello Passkeys - Ep 135

Reimagining Cyber

Play Episode Listen Later Feb 5, 2025 17:41


In this episode, we dive into the world of passkeys and how they're revolutionizing online security. Say goodbye to password fatigue and phishing scams—passkeys promise a more secure and seamless authentication experience. We discuss what passkeys are, how they work, and why major tech companies are adopting them.Topics Covered:What are passkeys and how do they work?The difference between passkeys and traditional passwordsHow passkeys improve security and prevent phishing attacksThe role of biometrics in passkey authenticationHow losing your phone affects access to accountsCross-device authentication and cloud synchronizationWhy big tech companies like Google, Apple, and Microsoft are embracing passkeysThe potential future of cybersecurity beyond passwordsKey Takeaways:Passkeys use cryptographic keys stored on devices for authentication, eliminating the need for passwords.They are more secure than traditional passwords and resistant to phishing attacks.Losing a device doesn't mean losing access—most platforms allow recovery through cloud-based synchronization.Biometrics, such as fingerprint or face recognition, enhance the convenience and security of passkeys.Tech giants are pushing for a passwordless future to improve online security and user experience.Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via reimaginingcyber@gmail.com

RunAs Radio
Querying for Breaches with Mark Morowcyznski

RunAs Radio

Play Episode Listen Later Jan 29, 2025 34:07


Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all log sets, telemetry, the M365 graph, and more - to help understand issues. The book provides example queries you could run today, including knowing the first and last time a user logged on and what devices they used. There are examples of calculating baseline behavior for an account so that you can see when unusual activity starts. There are a ton of excellent queries for operational excellence and cybersecurity - get started today! And for RunAs listeners, you can use code KUSTO to get 30% off the book!LinksThreat Intelligence BlogPhishing-Resistant Passwordless AuthenticationKusto Query LanguageMicrosoft SentinelMicrosoft Security CopilotKQL Guide on GitHubRecorded December 19, 2024

Easy Prey
Next-Gen Account Security with Christiaan Brand

Easy Prey

Play Episode Listen Later Jan 22, 2025 43:50


With phishing and password breaches on the rise, passkeys could offer a more secure, user-friendly solution that could reshape how we protect our online identities. Today's guest is Christiaan Brand. Christiaan is the co-founder of Entersekt, a financial services security firm and a key player at Google in their security and identity teams.  A respected voice in cybersecurity, Christian co-chairs the FIDO2 technical working group focusing on standardizing robust online security protocols in advancing the use of passkeys. He has been at the forefront of the shift toward more secure, password-free systems. We'll hear his insights on the challenges and opportunities of implementing passkeys to create safer online environments for users and organizations. Show Notes: [00:52] - Christiaan is part of the security team for Google accounts. He's been with Google for 9 years. Prior to that he had a startup. [01:30] - He joined the FIDO Alliance around the same time Google joined in 2013. When he joined Google, he was able to continue with the same type of work. [02:35] - Each of the big tech companies represents a portion of the market when it comes to how we interact with the web and apps. [04:06] - He became interested in security when he started thinking about what could go wrong with new technology solutions. He wanted users to be able to access their financial information in a safe and secure way. [05:06] - 2FA began gaining traction with Google in 2011. It coincided with the launch of Google Authenticator. 2FA was also used by a gaming company. [07:54] - Usability is important, that's why having an app that displays the codes was one of the first forays into making the technology more accessible. [08:34] - Passkeys allow us to move beyond passwords, leaving the extra hassle of traditional multi-factor authentication behind. [11:05] - Key fobs were one of the earlier ways to try and bring usability to security. Now the technology is being moved to smartphones. [12:33] - Passkeys are a replacement for a password manager. [13:35] - Passkeys are extremely long and asymmetric in nature. You and the site you're going to both have the passkey. [14:27] - The service will have the public part of the passkey, and you'll have the private part. Even if the public part leaks out, your passkey will still be secure. Passkeys can never be revealed to phishing sites. [15:47] - FIDO brings the second authentication step in. The service also has to identify themselves. [20:04] - Password managers try to balance security and convenience. Logging in or accessing a passkey is a unique challenge for providers. [22:20] - Phone numbers are a way to get users back into their accounts. [25:19] - Single device users have extra challenges. [26:08] - There are pros and cons to external sources of identity. [29:44] - The FIDO website has many certified solutions. [33:21] - To get passkeys into daily users' lives, we need to start using them on daily applications where we log in frequently. [35:49] - Hopefully this passkey solution will stand the test of time. [37:34] - Attacks are beginning to shift to session hijacking. [38:24] - DBSC or device-based session credentials is a new standard parallel to FIDO. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Entersekt Christiaan Brand on LinkedIn Christiaan Brand on Twitter Christiaan Brand on Facebook FIDO2 Technical Working Group Learn More About Passkeys Passkeys.Dev FIDO Alliance Passkeys

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

In this episode, we explore the efficient storage of honeypot logs in databases, issues with Citrix's Session Recording Agent and Windows Update. Ivanti is having another interesting security event and our SANS.edu graduate student Rich Green talks about his research on Passkeys. Extracting Practical Observations from Impractical Datasets: A SANS Internet Storm Center diary entry discusses strategies for analyzing complex datasets to derive actionable insights. https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582 Citrix Session Recording Agent Update Issue: Citrix reports that Microsoft's January security update fails or reverts on machines with the 2411 Session Recording Agent installed, providing guidance on addressing this issue. https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US Ivanti Endpoint Manager Security Advisory: Ivanti releases a security advisory for Endpoint Manager versions 2024 and 2022 SU6, detailing vulnerabilities and recommended actions. https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US Revolutionizing Enterprise Security: The Exciting Future of Passkeys Beyond Passwords: A SANS.edu research paper explores the shift from traditional passwords to passkeys, highlighting the benefits and challenges of adopting passwordless authentication methods. https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/

Tech News Weekly (MP3)
TNW 368: Facebook Hopes You'll Befriend AI Influencers - AI Phishing, Retro Tech Revival, Passkey Predicament

Tech News Weekly (MP3)

Play Episode Listen Later Jan 2, 2025 70:32


In the first episode of 2025, Mikah and Abrar discuss Meta's plans to add AI bots to their social media platforms, the rise of AI-generated phishing scams, the trend of parents giving their kids retro tech devices to reduce screen time, and the current state and future potential of passkeys for secure logins. Meta plans to populate Facebook and Instagram with AI-generated bot accounts that can create content, share posts, and interact with users, in an effort to drive engagement as user growth stagnates. Abrar and Mikah debate the pros and cons of AI bots on social media. Cybersecurity experts have seen a significant increase in sophisticated phishing scams using AI to generate hyper-personalized messages mimicking people's communication styles, with over 90% of successful cyberattacks now beginning with phishing emails. Abrar and Mikah discuss cybersecurity training and email filtering used by companies to combat this. There's a growing trend of parents gifting their kids retro tech like Walkmans, portable CD players, and MP3 players in an effort to reduce screen time. Mikah and Abrar reflect on the appeal of single-purpose devices and bonding over music. Passkeys, a new login technology aiming to replace passwords, have seen increasing adoption but face usability challenges and inconsistent implementation across sites and devices. Mikah explains how passkeys work and recommends using password managers for now, as both hosts agree passkeys aren't quite ready for mainstream adoption yet. Hosts: Mikah Sargent and Abrar Al-Heeti Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Tech News Weekly (Video HI)
TNW 368: Facebook Hopes You'll Befriend AI Influencers - AI Phishing, Retro Tech Revival, Passkey Predicament

Tech News Weekly (Video HI)

Play Episode Listen Later Jan 2, 2025 70:31


In the first episode of 2025, Mikah and Abrar discuss Meta's plans to add AI bots to their social media platforms, the rise of AI-generated phishing scams, the trend of parents giving their kids retro tech devices to reduce screen time, and the current state and future potential of passkeys for secure logins. Meta plans to populate Facebook and Instagram with AI-generated bot accounts that can create content, share posts, and interact with users, in an effort to drive engagement as user growth stagnates. Abrar and Mikah debate the pros and cons of AI bots on social media. Cybersecurity experts have seen a significant increase in sophisticated phishing scams using AI to generate hyper-personalized messages mimicking people's communication styles, with over 90% of successful cyberattacks now beginning with phishing emails. Abrar and Mikah discuss cybersecurity training and email filtering used by companies to combat this. There's a growing trend of parents gifting their kids retro tech like Walkmans, portable CD players, and MP3 players in an effort to reduce screen time. Mikah and Abrar reflect on the appeal of single-purpose devices and bonding over music. Passkeys, a new login technology aiming to replace passwords, have seen increasing adoption but face usability challenges and inconsistent implementation across sites and devices. Mikah explains how passkeys work and recommends using password managers for now, as both hosts agree passkeys aren't quite ready for mainstream adoption yet. Hosts: Mikah Sargent and Abrar Al-Heeti Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

All TWiT.tv Shows (MP3)
Tech News Weekly 368: Facebook Hopes You'll Befriend AI Influencers

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jan 2, 2025 70:32


In the first episode of 2025, Mikah and Abrar discuss Meta's plans to add AI bots to their social media platforms, the rise of AI-generated phishing scams, the trend of parents giving their kids retro tech devices to reduce screen time, and the current state and future potential of passkeys for secure logins. Meta plans to populate Facebook and Instagram with AI-generated bot accounts that can create content, share posts, and interact with users, in an effort to drive engagement as user growth stagnates. Abrar and Mikah debate the pros and cons of AI bots on social media. Cybersecurity experts have seen a significant increase in sophisticated phishing scams using AI to generate hyper-personalized messages mimicking people's communication styles, with over 90% of successful cyberattacks now beginning with phishing emails. Abrar and Mikah discuss cybersecurity training and email filtering used by companies to combat this. There's a growing trend of parents gifting their kids retro tech like Walkmans, portable CD players, and MP3 players in an effort to reduce screen time. Mikah and Abrar reflect on the appeal of single-purpose devices and bonding over music. Passkeys, a new login technology aiming to replace passwords, have seen increasing adoption but face usability challenges and inconsistent implementation across sites and devices. Mikah explains how passkeys work and recommends using password managers for now, as both hosts agree passkeys aren't quite ready for mainstream adoption yet. Hosts: Mikah Sargent and Abrar Al-Heeti Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Tech News Weekly (Video LO)
TNW 368: Facebook Hopes You'll Befriend AI Influencers - AI Phishing, Retro Tech Revival, Passkey Predicament

Tech News Weekly (Video LO)

Play Episode Listen Later Jan 2, 2025 70:31


In the first episode of 2025, Mikah and Abrar discuss Meta's plans to add AI bots to their social media platforms, the rise of AI-generated phishing scams, the trend of parents giving their kids retro tech devices to reduce screen time, and the current state and future potential of passkeys for secure logins. Meta plans to populate Facebook and Instagram with AI-generated bot accounts that can create content, share posts, and interact with users, in an effort to drive engagement as user growth stagnates. Abrar and Mikah debate the pros and cons of AI bots on social media. Cybersecurity experts have seen a significant increase in sophisticated phishing scams using AI to generate hyper-personalized messages mimicking people's communication styles, with over 90% of successful cyberattacks now beginning with phishing emails. Abrar and Mikah discuss cybersecurity training and email filtering used by companies to combat this. There's a growing trend of parents gifting their kids retro tech like Walkmans, portable CD players, and MP3 players in an effort to reduce screen time. Mikah and Abrar reflect on the appeal of single-purpose devices and bonding over music. Passkeys, a new login technology aiming to replace passwords, have seen increasing adoption but face usability challenges and inconsistent implementation across sites and devices. Mikah explains how passkeys work and recommends using password managers for now, as both hosts agree passkeys aren't quite ready for mainstream adoption yet. Hosts: Mikah Sargent and Abrar Al-Heeti Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Tech News Weekly (Video HD)
TNW 368: Facebook Hopes You'll Befriend AI Influencers - AI Phishing, Retro Tech Revival, Passkey Predicament

Tech News Weekly (Video HD)

Play Episode Listen Later Jan 2, 2025 70:31 Transcription Available


In the first episode of 2025, Mikah and Abrar discuss Meta's plans to add AI bots to their social media platforms, the rise of AI-generated phishing scams, the trend of parents giving their kids retro tech devices to reduce screen time, and the current state and future potential of passkeys for secure logins. Meta plans to populate Facebook and Instagram with AI-generated bot accounts that can create content, share posts, and interact with users, in an effort to drive engagement as user growth stagnates. Abrar and Mikah debate the pros and cons of AI bots on social media. Cybersecurity experts have seen a significant increase in sophisticated phishing scams using AI to generate hyper-personalized messages mimicking people's communication styles, with over 90% of successful cyberattacks now beginning with phishing emails. Abrar and Mikah discuss cybersecurity training and email filtering used by companies to combat this. There's a growing trend of parents gifting their kids retro tech like Walkmans, portable CD players, and MP3 players in an effort to reduce screen time. Mikah and Abrar reflect on the appeal of single-purpose devices and bonding over music. Passkeys, a new login technology aiming to replace passwords, have seen increasing adoption but face usability challenges and inconsistent implementation across sites and devices. Mikah explains how passkeys work and recommends using password managers for now, as both hosts agree passkeys aren't quite ready for mainstream adoption yet. Hosts: Mikah Sargent and Abrar Al-Heeti Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: zscaler.com/security joindeleteme.com/twit promo code TWIT cachefly.com/twit

All TWiT.tv Shows (Video LO)
Tech News Weekly 368: Facebook Hopes You'll Befriend AI Influencers

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Jan 2, 2025 70:31 Transcription Available


In the first episode of 2025, Mikah and Abrar discuss Meta's plans to add AI bots to their social media platforms, the rise of AI-generated phishing scams, the trend of parents giving their kids retro tech devices to reduce screen time, and the current state and future potential of passkeys for secure logins. Meta plans to populate Facebook and Instagram with AI-generated bot accounts that can create content, share posts, and interact with users, in an effort to drive engagement as user growth stagnates. Abrar and Mikah debate the pros and cons of AI bots on social media. Cybersecurity experts have seen a significant increase in sophisticated phishing scams using AI to generate hyper-personalized messages mimicking people's communication styles, with over 90% of successful cyberattacks now beginning with phishing emails. Abrar and Mikah discuss cybersecurity training and email filtering used by companies to combat this. There's a growing trend of parents gifting their kids retro tech like Walkmans, portable CD players, and MP3 players in an effort to reduce screen time. Mikah and Abrar reflect on the appeal of single-purpose devices and bonding over music. Passkeys, a new login technology aiming to replace passwords, have seen increasing adoption but face usability challenges and inconsistent implementation across sites and devices. Mikah explains how passkeys work and recommends using password managers for now, as both hosts agree passkeys aren't quite ready for mainstream adoption yet. Hosts: Mikah Sargent and Abrar Al-Heeti Download or subscribe to Tech News Weekly at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: zscaler.com/security joindeleteme.com/twit promo code TWIT cachefly.com/twit

Ozone Nightmare
Passing On Passkeys

Ozone Nightmare

Play Episode Listen Later Jan 2, 2025 5:01


Today on the 5: I came across an article over at Ars Technica about the issues around the deployment of passkeys as an alternative to passwords. It reminded me of whjy I've opted not to use them and why I generally wouldn't recommend themn to most people.

Windows Weekly (MP3)
WW 912: Unicornification - Real-time translation, AI steak video, The Great Circle

Windows Weekly (MP3)

Play Episode Listen Later Dec 18, 2024 163:13


Real-time translation, AI steak video, The Great Circle Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell For full show notes, visit https://twit.tv/shows/windows-weekly/episodes/912 Sponsors: uscloud.com cachefly.com/twit

All TWiT.tv Shows (MP3)
Windows Weekly 912: Unicornification

All TWiT.tv Shows (MP3)

Play Episode Listen Later Dec 18, 2024 163:13


Real-time translation, AI steak video, The Great Circle Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell For full show notes, visit https://twit.tv/shows/windows-weekly/episodes/912 Sponsors: uscloud.com cachefly.com/twit

Radio Leo (Audio)
Windows Weekly 912: Unicornification

Radio Leo (Audio)

Play Episode Listen Later Dec 18, 2024 163:13


Real-time translation, AI steak video, The Great Circle Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell For full show notes, visit https://twit.tv/shows/windows-weekly/episodes/912 Sponsors: uscloud.com cachefly.com/twit

Windows Weekly (Video HI)
WW 912: Unicornification - Real-time translation, AI steak video, The Great Circle

Windows Weekly (Video HI)

Play Episode Listen Later Dec 18, 2024 163:13


Real-time translation, AI steak video, The Great Circle Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell For full show notes, visit https://twit.tv/shows/windows-weekly/episodes/912 Sponsors: uscloud.com cachefly.com/twit

All TWiT.tv Shows (Video LO)
Windows Weekly 912: Unicornification

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Dec 18, 2024 163:13 Transcription Available


Real-time translation, AI steak video, The Great Circle Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell For full show notes, visit https://twit.tv/shows/windows-weekly/episodes/912 Sponsors: uscloud.com cachefly.com/twit

Paul's Security Weekly TV
Pondering Portable Passwordless Passkeys in 2025 - Rew Islam - ESW #387

Paul's Security Weekly TV

Play Episode Listen Later Dec 13, 2024 35:04


In this segment, we discuss two new FIDO Alliance standards focused on credential portability. Specifically, if passwordless is going to catch on, we need to minimize friction and maximize usability. In practice, this means that passkeys must be portable! Rew Islam of Dashlane joins us to discuss the new standards and how they'll help us enter a new age of secure authentication, both for consumers and the enterprise. Segment Resources: Elevating Passwordless Security With AWS Nitro Synced Passkeys Will Be Portable FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys Show Notes: https://securityweekly.com/esw-387

Trust Issues
EP 67 - The Password Problem

Trust Issues

Play Episode Listen Later Dec 6, 2024 34:56


In this episode of the Trust Issues podcast, host David Puner sits down with Andrew Shikiar, the Executive Director and CEO of the FIDO Alliance, to discuss the critical issues surrounding password security and the innovative solutions being developed to address them. Andrew highlights the vulnerabilities of traditional passwords, their susceptibility to phishing and brute force attacks, and the significant advancements in passwordless authentication methods, particularly passkeys. He explains how passkeys, based on FIDO standards, utilize asymmetric public key cryptography to enhance security and reduce the risk of data breaches. The conversation also covers the broader implications of strong, user-friendly authentication methods for consumers and organizations, as well as the collaborative efforts of major industry players to make the internet a safer place. Additionally, Andrew highlights the importance of identity security in the context of these advancements, emphasizing how robust authentication methods can protect personal and organizational data. Tune in to learn about the future of authentication and the steps being taken to eliminate the reliance on passwords.

Ask The Tech Guys (Audio)
HOT 191: Moving From Windows to Mac - dd Command, Kindle Sync, Hotspots

Ask The Tech Guys (Audio)

Play Episode Listen Later Nov 17, 2024 49:53


On Hands-On Tech, Mikah answers questions such as about a feature in Linux that can allow you to cut and paste your entire drive, about passkeys and multiple accounts on the same website, and Mikah helps a listener with the process of transferring from working on a Windows machine to a Mac mini. Ole is looking for a feature that would allow him to move his Linux system and files from one drive to another without having to reinstall the operating system. Kevin is wondering if you can log into a website using passkeys if you have multiple accounts on that website. Gary has a follow-up to Mark's question about Kindle Sync from last week that could be useful for them. Ronald is planning to switch from his Dell Windows 10 computer to the new M4 Mac mini and has a slew of questions about when he will make the switch, from which Mac mini configuration he should go with, to using external drives with the computer, and which Thunderbolt hub Mikah recommends as well. And Stephen provides a follow-up on the question about smartphone hotspots from a few episodes ago, involving Jon's problem getting older hardware to connect to his iPhone hotspot. Remember to send in your questions for Mikah to answer during the show! hot@twit.tv Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

All TWiT.tv Shows (MP3)
Hands-On Tech 191: Moving From Windows to Mac

All TWiT.tv Shows (MP3)

Play Episode Listen Later Nov 17, 2024 49:53


On Hands-On Tech, Mikah answers questions such as about a feature in Linux that can allow you to cut and paste your entire drive, about passkeys and multiple accounts on the same website, and Mikah helps a listener with the process of transferring from working on a Windows machine to a new M4 Mac mini. Ole is looking for a feature that would allow him to move his Linux system and files from one drive to another without having to reinstall the operating system. Kevin is wondering if you can log into a website using passkeys if you have multiple accounts on that website. Gary has a follow-up to Mark's question about Kindle Sync from last week that could be useful for them. Ronald is planning to switch from his Dell Windows 10 computer to the new M4 Mac mini and has a slew of questions about when he will make the switch, from which Mac mini configuration he should go with, to using external drives with the computer, and which Thunderbolt hub Mikah recommends as well. And Stephen provides a follow-up on the question about smartphone hotspots from a few episodes ago, involving Jon's problem getting older hardware to connect to his iPhone hotspot. Remember to send in your questions for Mikah to answer during the show! hot@twit.tv Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

The Tech Guy (Video HI)
HOT 191: Moving From Windows to Mac - dd Command, Kindle Sync, Hotspots

The Tech Guy (Video HI)

Play Episode Listen Later Nov 17, 2024 49:53


On Hands-On Tech, Mikah answers questions such as about a feature in Linux that can allow you to cut and paste your entire drive, about passkeys and multiple accounts on the same website, and Mikah helps a listener with the process of transferring from working on a Windows machine to a Mac mini. Ole is looking for a feature that would allow him to move his Linux system and files from one drive to another without having to reinstall the operating system. Kevin is wondering if you can log into a website using passkeys if you have multiple accounts on that website. Gary has a follow-up to Mark's question about Kindle Sync from last week that could be useful for them. Ronald is planning to switch from his Dell Windows 10 computer to the new M4 Mac mini and has a slew of questions about when he will make the switch, from which Mac mini configuration he should go with, to using external drives with the computer, and which Thunderbolt hub Mikah recommends as well. And Stephen provides a follow-up on the question about smartphone hotspots from a few episodes ago, involving Jon's problem getting older hardware to connect to his iPhone hotspot. Remember to send in your questions for Mikah to answer during the show! hot@twit.tv Host: Mikah Sargent Download or subscribe to Hands-On Tech at https://twit.tv/shows/hands-on-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

ShopTalk » Podcast Feed
641: Passkey Usage, Writing Code with a Bot, and What’s Up With Java?

ShopTalk » Podcast Feed

Play Episode Listen Later Nov 11, 2024 58:33


Show DescriptionWe've got a few leftovers from Halloween to process, what's been happening with Passkeys in late 2024, have you tried to write HTML faster than a bot can suggest it to you, CSS anchor positioning and popover polyfills, scroll driven animation thoughts, CSS nesting, and what's the reason for Java? Listen on Website →Links Auth0: Secure access for everyone. But not just anyone. Stripe Checkout | Checkout Pages for Your Website Passkeys Authentication Mundango Storytelling Developer Tools SponsorsBluehostFind unique domains, web hosting, and WordPress tools, all in one place. Empower your business or digital agency with Bluehost.

Ask The Tech Guys (Audio)
HOT 190: Operating Systems & Passkeys Follow Up - Kindle Sync, WiFi Connectivity, Location Settings

Ask The Tech Guys (Audio)

Play Episode Listen Later Nov 10, 2024 50:38


On Hands-On Mac, Mikah continues to answer more of your questions, such as why Kindle books may not stay in sync between different devices, why you can't reconnect to your WiFi network after losing connection, and how you can get a reminder or a list to open up for you when walking into specified locations. Mark has a Kindle device and the Kindle app on several Apple devices. However when Mark reads a book in Kindle, his progress within the app doesn't stay synced between his Kindle device and apps. What can Mark do to fix the issue? John has used Windows 10 for a long time and doesn't want to upgrade to Windows 11. With Windows 10 going out of support soon, he's looking for alternatives to Windows that can run Microsoft Office that isn't Mac OS. When Dylan loses connection to his WiFi network on his Windows 11 laptop, he can't reconnect unless he restarts the PC. He's looked around for possible solutions and came across others having similar issues, even with Windows 10, and is looking for any insight from Mikah into troubleshooting the problem. Robby wants to know if there's a way to get their iPhone to send a reminder or a list that opens up when they walk into specific locations, such as a Best Buy or a grocery store. Steven asks a question related to last week's show about Passkeys and how he views them as a complicated, poorly thought-out plan. Should Steven wait to switch over to using Passkeys until things are better figured out with Passkey? And Todd follows up with their question about passkeys from last week's show. Don't forget to send in your questions for Mikah to answer during the show! hot@twit.tv Host: Mikah Sargent Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

All TWiT.tv Shows (MP3)
Hands-On Tech 190: Operating Systems & Passkeys Follow-Up

All TWiT.tv Shows (MP3)

Play Episode Listen Later Nov 10, 2024 50:38 Transcription Available


On Hands-On Tech, Mikah continues to answer more of your questions, such as why Kindle books may not stay in sync between different devices, why you can't reconnect to your WiFi network after losing connection, and how you can get a reminder or a list to open up for you when walking into specified locations. Mark has a Kindle device and the Kindle app on several Apple devices. However when Mark reads a book in Kindle, his progress within the app doesn't stay synced between his Kindle device and apps. What can Mark do to fix the issue? John has used Windows 10 for a long time and doesn't want to upgrade to Windows 11. With Windows 10 going out of support soon, he's looking for alternatives to Windows that can run Microsoft Office that isn't Mac OS. When Dylan loses connection to his WiFi network on his Windows 11 laptop, he can't reconnect unless he restarts the PC. He's looked around for possible solutions and came across others having similar issues, even with Windows 10, and is looking for any insight from Mikah into troubleshooting the problem. Robby wants to know if there's a way to get their iPhone to send a reminder or a list that opens up when they walk into specific locations, such as a Best Buy or a grocery store. Steven asks a question related to last week's show about Passkeys and how he views them as a complicated, poorly thought-out plan. Should Steven wait to switch over to using Passkeys until things are better figured out with Passkey? And Todd follows up with their question about passkeys from last week's show. Don't forget to send in your questions for Mikah to answer during the show! hot@twit.tv Host: Mikah Sargent Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

Ask The Tech Guys (Audio)
HOT 189: What Are Passkeys? - Google Maps, Roku vs Fire TV, Pixel 9

Ask The Tech Guys (Audio)

Play Episode Listen Later Nov 3, 2024 49:24


On Hands-On Mac, Mikah answers questions about adjusting a setting within the Google Maps app, whether there's a difference in audio and video quality between a Roku TV and an Amazon Fire stick, what music players will work for Android to play all the songs of an individual artist, getting legacy hardware to connect to an iPhone hotspot, and what passkeys are! Martin-Guy is a retired cyclist who uses Google Maps while cycling. However, the cycling times reference speed within the app is too fast for him. He's looking for a way to adjust that setting if possible or if there's an alternative app he can use that would allow him to make such an adjustment. Michael owns a 4K TCL Roku TV and the most recent Amazon Fire TV Stick. Is there a difference in audio or video quality between the Roku TV and the Amazon Fire TV Stick? Lane just got a Pixel 9 Pro and stores his music in a folder on the device. He uses an app called Musicolet as his player and wants to know if there's a way to play all the songs of a selected artist in shuffle mode or if there's another app that can do this. Jon is trying to connect older "legacy" hardware to his iPhone hotspot but is having trouble doing this and wonders if Mikah knows of any tricks to get this older hardware to connect to the hotspot. Todd has heard Mikah talk about Passkeys on the TWiT network many times in the past. However, he doesn't understand what a passkey is and asks Mikah for any insight he can share about passkeys. Host: Mikah Sargent Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsor: cachefly.com/twit

Tech News Weekly (MP3)
TNW 359: FIDO Alliance Explains Passkeys Portability - AI Chatbots, Passkeys, Apple Intelligence

Tech News Weekly (MP3)

Play Episode Listen Later Oct 24, 2024 82:31


Would you use an AI chatbot in your disagreements with your significant other? A discussion on mental health and the complexities with AI technology and social interactions. The FIDO Alliance published new specs to help promote credential portability. And Apple releases the next wave of upcoming Apple Intelligence features in the latest developer betas of iOS, macOS, and iPadOS. Emily Forlini of PCMag joins Mikah Sargent this week to discuss a humourous story from the subreddit r/AITAH, in which a user's girlfriend consults ChatGPT to help her in their arguments. Mikah shares a tragic case of a 14-year-old who took his own life after periods of interactions with an AI chatbot from Character.AI. Nick Steele and David Turner from the FIDO Alliance join the show to discuss the Alliance's new specifications involving passkeys and their portability. Dan Moren stops by to discuss the new Apple Intelligence features rolled out to the latest developer betas for iOS, iPadOS, and macOS. latest developer betas for iOS, iPadOS, and macOS. Content Warning: One of the following stories discusses the sensitive topic of suicide involving a minor. If you or someone you know is having thoughts of suicide or self-harm, please contact the 988 Suicide & Crisis Lifeline - call or text 988 or chat online at chat.988lifeline.org. If you are located outside the United States, please visit findahelpline.com to find a helpline in your country. Hosts: Mikah Sargent and Emily Forlini Guests: Nick Steele and David Turner Download or subscribe to this show at https://twit.tv/shows/tech-news-weekly. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: threatlocker.com for Tech News Weekly shopify.com/twit uscloud.com INFO.ACILEARNING.COM/TWIT - code TWIT100

Accidental Tech Podcast
608: Boot to Toot

Accidental Tech Podcast

Play Episode Listen Later Oct 10, 2024 115:38


Follow-up: NotebookLM podcast Camera Control button material iPhone case suggestions Spigen Ultra Hybrid T MagFit Arc Pulse Leather backs Suti Nomad Atom Studios Sleep-tagging app suggestions Windows anti-malware app suggestions Adaptive Transparency report Wireless phone recovery 9to5Mac screenshot End ↔ end encryption coming for iPhone ↔ Android RCS messages More tweaks to screen recording prompts Jason’s toot Hotkey registration in Sequoia Response from Apple frameworks engineer Liquid detection in Sequoia Epic gets a win against Google Apple nopes out of OpenAI investment Ask ATP: Will John buy the new $700 Playstation Pro? Have the Vehicle Motion Cues helped John’s motion sickness? (via Justin Waring) When will the first true “built from the ground up for AI” phone be? (via Neil McGregor) Is it time to move to Passkeys? Ricky’s post Post-show: Adam’s gaming PC adventures Razer gaming laptops Marco’s “is this bad” post iFixit toolkit Members-only ATP Overtime: AI moats & trade secrets OpenAI doesn’t want anyone to know what o1 is “thinking” Sponsored by: DeleteMe: Making it quick, easy, and safe to remove your personal data online. Tailscale: A secure network that just works. Become a member for ATP Overtime, ad-free episodes, member specials, and our early-release, unedited “bootleg” feed!

Security Now (MP3)
SN 993: Kaspersky exits the U.S. - Exploding Pagers, Passkeys in Chrome

Security Now (MP3)

Play Episode Listen Later Sep 25, 2024 147:05


The case of the exploding pagers and walkie-talkies "Ford seeks patent for tech that listens to driver conversations to serve ads" Another large chunk of personal data exposed Passkeys takes a big step forward: Now supported by Chrome A nascent 9.9 Linux Unauthenticated RCE? Freezing Credit Credit Bureaus Drobo 5N SN email labeled as spam Public Wi-fi saftey SN for Certs Windows Defender Kaspersky exits the U.S. Show Notes - https://www.grc.com/sn/SN-993-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsors: GO.ACILEARNING.COM/TWIT code SN100 canary.tools/twit - use code: TWIT bigid.com/securitynow e-e.com/twit