Podcasts about passkeys

  • 359PODCASTS
  • 935EPISODES
  • 1h 3mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Sep 17, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about passkeys

Show all podcasts related to passkeys

Latest podcast episodes about passkeys

Miles to Memories Podcast
Locked Out of Chase, the Fake Credit Card in Shawn's Wallet & When a Decline Feels Personal

Miles to Memories Podcast

Play Episode Listen Later Sep 17, 2026 22:07


Amazon 4 months of Audible for $.99/mo. (affiliate) - https://milestomemories.com/audible-subscription-offer-prime-day-2026/ Shawn's personal inKind referral - https://milestomemories.com/go/inkind-referral/ Shawn walked into a Chase branch to withdraw money and walked into every points person's nightmare: account locked, suspicious activity, and a phone tree with no humans in it. What follows is the full anatomy of a lockout, from the banker with the super secret number to the moment Shawn nearly handed him the fake World of Hyatt credit card that has been living in his wallet for years. That spirals into the security conversation we all need to have: password managers and passkeys, the scams hitting travelers abroad, why your debit card should never leave your wallet, and the shutdown anxiety that makes every declined charge feel personal. Then two deals worth your time: Audible at 99 cents a month for four months ahead of Prime Day, and the Target stack that gets inKind gift cards down near 68 percent off, beating even Costco. What is your worst locked-account story, and how do you keep yourself secure? Let us know in the comments. Episode Guide: 0:00 Welcome to MTM Travel 0:30 Chase Locked Shawn's Account 3:39 The Fake World of Hyatt Card in Shawn's Wallet 6:13 Password Managers, Passkeys & the LastPass Lesson 9:18 Fraud Abroad: Apple Pay Scams & Missing Alerts 10:21 Debit Card Rules to Live By 12:26 When a Decline Feels Personal (Shutdown Anxiety) 14:01 The Mystery of the Spotless Banker Desk 17:35 Audible for 99 Cents a Month 19:10 The Target inKind Stack 21:18 Final Thoughts Links https://milestomemories.com/inkind-gift-cards-at-target/  

Identity At The Center
#447 - Authenticate 2026 Preview with Andi Hindle

Identity At The Center

Play Episode Listen Later Sep 14, 2026 76:04


Jeff Steadman sits down with Andi Hindle, conference chair for Authenticate 2026, for a preview of this year's event. Making his seventh appearance on the show, Andi walks through how Authenticate has evolved since its founding alongside Identiverse and outlines six major topic areas shaping the 2026 agenda, including passkeys in practice, regulatory pressures, security and standards architecture, digital identity wallets, and non-human authentication. The conversation moves into hardware-based identity for retail and industrial settings, age verification challenges, and a detour into 3D printing and supply chain assurance. Jeff and Andi dig into continuous identity and zero standing privilege, the shift toward non-human traffic dominating infrastructure requests, and how agentic AI is forcing organizations to rethink authorization and human-in-the-loop decisions. They close with privacy and consent questions for non-human identities, thoughts on where authentication and authorization standards are headed, and a lighter look at Authenticate team traditions and sci-fi recommendations.Connect with Andi: https://www.linkedin.com/in/ahindle/Impact of GDPR on Identity and Access Management by Andi Hindle: https://bok.idpro.org/article/id/24/Learn more about FIDO Authenticate 2026: https://authenticatecon.com/event/authenticate-u-s-2026/Non-FIDO members can use the code IDAC15 to save 15% on their in-person conference pass.Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:10 - Introduction and discount code rundown for upcoming conferences01:10 - Andi Hindle returns for his seventh appearance01:29 - Favorite episode banter and the running Andrew Shikiar joke03:08 - Origins of Authenticate and its relationship with Identiverse09:01 - Passkeys are solved, so what comes next09:53 - Lessons learned building the Authenticate agenda12:59 - The scale of effort behind running Authenticate15:29 - Adjacent topics expanding beyond the core passkeys mission16:09 - Six major topic areas planned for Authenticate 202622:13 - Identity as the foundation for everything digital23:14 - Hardware identity and non-human authentication24:53 - Retail tokens, badges, and age verification use cases28:36 - Replacing things only when the replacement is actually better29:41 - A detour into 3D printing and personal satisfaction31:39 - 3D printing, supply chain assurance, and identity problems36:38 - Introducing continuous identity37:28 - Zero standing privilege and why it matters now40:46 - The human user as the infrastructure edge case45:16 - Speed, scale, and the limits of human in the loop46:11 - Setting red lines for agentic risk50:56 - Privacy and consent questions for non-human identities56:51 - Anonymization, data logging, and GDPR parallels59:51 - A GDPR and IAM resource from the IDPro Body of Knowledge1:00:26 - What Authenticate topics might look like three years out1:04:59 - Why accounts may not make sense for agents1:06:49 - Authorization as the next hard problem to solve1:08:20 - Inside jokes from the Authenticate organizing team1:09:30 - The story behind Andi's favorite Britishism1:10:38 - Book and media recommendations1:14:39 - Closing thoughts and sign-offIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Andi Hindle, Authenticate 2026, FIDO Alliance, passkeys, identity verification, identity wallets, continuous identity, zero standing privilege, agentic identity, non-human identity, authorization, shared signals, GDPR, IDPro, Identiverse, age verification, hardware authentication

iOS Today (Video HI)
iOS 819: Passwords Are Dead-ish - When Credentials Go Seamless on iOS

iOS Today (Video HI)

Play Episode Listen Later Sep 10, 2026 28:56 Transcription Available


Are passwords really on their way out, or are we stuck with them a bit longer? Mikah Sargent and Rosemary Orchard dig into Apple's latest moves in credential management and reveal why the end of passwords is only "dead-ish." Find out why this shift matters for both convenience and security, and how it could upend your digital habits. Apple Passwords app evolves: features, security, and sharing explored Passkeys adoption, magic links frustration, and passwordless future Passkeys security benefits and everyday use cases discussed Verification code autofill and cleanup Real-world quirks and reliability of code autofill features Shared groups and Wi-Fi credentials streamline family password management Comparing Apple Passwords vs. third-party managers: features and limitations Password best practices debunked: phase out bad habits App Caps: ESR magnetic matte screen protector and Spark Daily Learning Puzzles Hosts: Mikah Sargent and Rosemary Orchard Contact iOS Today at iOSToday@twit.tv. Download or subscribe to iOS Today at https://twit.tv/shows/ios-today Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

iOS Today (MP3)
iOS 819: Passwords Are Dead-ish - When Credentials Go Seamless on iOS

iOS Today (MP3)

Play Episode Listen Later Sep 10, 2026 28:56 Transcription Available


Are passwords really on their way out, or are we stuck with them a bit longer? Mikah Sargent and Rosemary Orchard dig into Apple's latest moves in credential management and reveal why the end of passwords is only "dead-ish." Find out why this shift matters for both convenience and security, and how it could upend your digital habits. Apple Passwords app evolves: features, security, and sharing explored Passkeys adoption, magic links frustration, and passwordless future Passkeys security benefits and everyday use cases discussed Verification code autofill and cleanup Real-world quirks and reliability of code autofill features Shared groups and Wi-Fi credentials streamline family password management Comparing Apple Passwords vs. third-party managers: features and limitations Password best practices debunked: phase out bad habits App Caps: ESR magnetic matte screen protector and Spark Daily Learning Puzzles Hosts: Mikah Sargent and Rosemary Orchard Contact iOS Today at iOSToday@twit.tv. Download or subscribe to iOS Today at https://twit.tv/shows/ios-today Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

All TWiT.tv Shows (MP3)
iOS Today 819: Passwords Are Dead-ish

All TWiT.tv Shows (MP3)

Play Episode Listen Later Sep 10, 2026 28:56 Transcription Available


Are passwords really on their way out, or are we stuck with them a bit longer? Mikah Sargent and Rosemary Orchard dig into Apple's latest moves in credential management and reveal why the end of passwords is only "dead-ish." Find out why this shift matters for both convenience and security, and how it could upend your digital habits. Apple Passwords app evolves: features, security, and sharing explored Passkeys adoption, magic links frustration, and passwordless future Passkeys security benefits and everyday use cases discussed Verification code autofill and cleanup Real-world quirks and reliability of code autofill features Shared groups and Wi-Fi credentials streamline family password management Comparing Apple Passwords vs. third-party managers: features and limitations Password best practices debunked: phase out bad habits App Caps: ESR magnetic matte screen protector and Spark Daily Learning Puzzles Hosts: Mikah Sargent and Rosemary Orchard Contact iOS Today at iOSToday@twit.tv. Download or subscribe to iOS Today at https://twit.tv/shows/ios-today Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

iOS Today (Video)
iOS 819: Passwords Are Dead-ish - When Credentials Go Seamless on iOS

iOS Today (Video)

Play Episode Listen Later Sep 10, 2026 28:56 Transcription Available


Are passwords really on their way out, or are we stuck with them a bit longer? Mikah Sargent and Rosemary Orchard dig into Apple's latest moves in credential management and reveal why the end of passwords is only "dead-ish." Find out why this shift matters for both convenience and security, and how it could upend your digital habits. Apple Passwords app evolves: features, security, and sharing explored Passkeys adoption, magic links frustration, and passwordless future Passkeys security benefits and everyday use cases discussed Verification code autofill and cleanup Real-world quirks and reliability of code autofill features Shared groups and Wi-Fi credentials streamline family password management Comparing Apple Passwords vs. third-party managers: features and limitations Password best practices debunked: phase out bad habits App Caps: ESR magnetic matte screen protector and Spark Daily Learning Puzzles Hosts: Mikah Sargent and Rosemary Orchard Contact iOS Today at iOSToday@twit.tv. Download or subscribe to iOS Today at https://twit.tv/shows/ios-today Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

Paul's Security Weekly TV
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly TV

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Show Notes: https://securityweekly.com/psw-943

Paul's Security Weekly (Podcast-Only)
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly (Podcast-Only)

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-943

Total Mikah (Video)
iOS Today 819: Passwords Are Dead-ish

Total Mikah (Video)

Play Episode Listen Later Sep 10, 2026 28:56 Transcription Available


Are passwords really on their way out, or are we stuck with them a bit longer? Mikah Sargent and Rosemary Orchard dig into Apple's latest moves in credential management and reveal why the end of passwords is only "dead-ish." Find out why this shift matters for both convenience and security, and how it could upend your digital habits. Apple Passwords app evolves: features, security, and sharing explored Passkeys adoption, magic links frustration, and passwordless future Passkeys security benefits and everyday use cases discussed Verification code autofill and cleanup Real-world quirks and reliability of code autofill features Shared groups and Wi-Fi credentials streamline family password management Comparing Apple Passwords vs. third-party managers: features and limitations Password best practices debunked: phase out bad habits App Caps: ESR magnetic matte screen protector and Spark Daily Learning Puzzles Hosts: Mikah Sargent and Rosemary Orchard Contact iOS Today at iOSToday@twit.tv. Download or subscribe to iOS Today at https://twit.tv/shows/ios-today Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

Total Mikah (Audio)
iOS Today 819: Passwords Are Dead-ish

Total Mikah (Audio)

Play Episode Listen Later Sep 10, 2026 28:56 Transcription Available


Are passwords really on their way out, or are we stuck with them a bit longer? Mikah Sargent and Rosemary Orchard dig into Apple's latest moves in credential management and reveal why the end of passwords is only "dead-ish." Find out why this shift matters for both convenience and security, and how it could upend your digital habits. Apple Passwords app evolves: features, security, and sharing explored Passkeys adoption, magic links frustration, and passwordless future Passkeys security benefits and everyday use cases discussed Verification code autofill and cleanup Real-world quirks and reliability of code autofill features Shared groups and Wi-Fi credentials streamline family password management Comparing Apple Passwords vs. third-party managers: features and limitations Password best practices debunked: phase out bad habits App Caps: ESR magnetic matte screen protector and Spark Daily Learning Puzzles Hosts: Mikah Sargent and Rosemary Orchard Contact iOS Today at iOSToday@twit.tv. Download or subscribe to iOS Today at https://twit.tv/shows/ios-today Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Club TWiT members can discuss this episode and leave feedback in the Club TWiT Discord.

Paul's Security Weekly (Video-Only)
It's More Secure When It's Disabled - PSW #943

Paul's Security Weekly (Video-Only)

Play Episode Listen Later Sep 10, 2026 122:16


In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Show Notes: https://securityweekly.com/psw-943

Good Morning Portugal!
Passwords, Passkeys & Digital Friction: How to Build a Calm, Secure Digital Life

Good Morning Portugal!

Play Episode Listen Later Sep 8, 2026 29:56 Transcription Available


In this episode, Carl talks with Stephen from Digital Serenity about the growing frustration of living in a digital world where apps, passwords, and account systems create constant friction, including real examples of being locked out of essential services like parking apps.They discuss why even tech-savvy people can get trapped by company-side login loops, and why using an agnostic password manager (rather than browser-based password saving) helps across browsers and devices. Stephen advises avoiding single sign-on when possible due to privacy and identity risks, explains two-factor authentication, and describes how passkeys work and why they still often require fallback passwords. He outlines his coaching-style service, including audits, “lost phone” simulations, and five pillars of digital health, and emphasizes using tech to improve life while maintaining an analog balance.00:00 Welcome Back Stephen00:15 Digital Friction Reality02:08 Parking App Password Fail05:22 Digital Locksmith Analogy07:29 Browser Password Managers10:53 Privacy And Neural Data14:49 Passkeys And Simulations16:46 Five Pillars Coaching19:31 Password First Principles23:38 AI Search And Photos25:15 Audience Q And Wrap28:46 Portuguese Farewell Outro29:19 A Team Promo TagBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-good-morning-portugal-podcast-with-carl-munson--2903992/support.Get help moving to and living in Portugal

Grit Daily Podcast
Small Business Cybersecurity: What You Don't See Can Hurt You with Last Pass CEO Karim Toubba

Grit Daily Podcast

Play Episode Listen Later Sep 2, 2026 42:14 Transcription Available


S6:E76 Security is ultimately a promise of trust. So what happens when that trust gets broken? Karim Toubba has had to answer that question in circumstances few CEOs would choose. He joined LastPass as their CEO only months before the company experienced a significant and highly publicized 2022 security breach. In this candid conversation, Karim acknowledges that LastPass initially communicated too slowly and explains the systemic changes, transparency, investment and cultural work required afterward. Queue up this episode of Small Business Stories for a conversation that goes well beyond passwords. Because the threat itself is changing. Karim says AI is producing a meaningful productivity advantage for small businesses, but it is simultaneously allowing malicious websites and other threats to be generated at much greater velocity. Employees are also adopting AI applications faster than many organizations can establish policies around what data those applications should be allowed to access. If people don't trust you, reassuring them that you're trustworthy isn't enough. If customers cannot see credible evidence supporting what you say, they'll increasingly turn to third-party communities and other sources to interpret your credibility for themselves. And if inaccurate or incomplete information about your organization remains unchallenged, the external interpretation of your company can begin separating from the reality inside it. That's where Karim's cybersecurity experience intersects powerfully with Dr. LL's work on misinterpretation risk.

Women-in-Tech: Like a BOSS
Small Business Cybersecurity: What You Don't See Can Hurt You with Last Pass CEO Karim Toubba

Women-in-Tech: Like a BOSS

Play Episode Listen Later Sep 2, 2026 42:14 Transcription Available


S6:E76 Security is ultimately a promise of trust. So what happens when that trust gets broken? Karim Toubba has had to answer that question in circumstances few CEOs would choose. He joined LastPass as their CEO only months before the company experienced a significant and highly publicized 2022 security breach. In this candid conversation, Karim acknowledges that LastPass initially communicated too slowly and explains the systemic changes, transparency, investment and cultural work required afterward. Queue up this episode of Small Business Stories for a conversation that goes well beyond passwords. Because the threat itself is changing. Karim says AI is producing a meaningful productivity advantage for small businesses, but it is simultaneously allowing malicious websites and other threats to be generated at much greater velocity. Employees are also adopting AI applications faster than many organizations can establish policies around what data those applications should be allowed to access. If people don't trust you, reassuring them that you're trustworthy isn't enough. If customers cannot see credible evidence supporting what you say, they'll increasingly turn to third-party communities and other sources to interpret your credibility for themselves. And if inaccurate or incomplete information about your organization remains unchallenged, the external interpretation of your company can begin separating from the reality inside it. That's where Karim's cybersecurity experience intersects powerfully with Dr. LL's work on misinterpretation risk.

AI and the Future of Work
403: Nancy Wang, CTO at 1Password, on Why Identity Is the Tech Problem of the Decade

AI and the Future of Work

Play Episode Listen Later Aug 31, 2026 45:42


Send us Fan MailNancy Wang is the Chief Technology Officer at 1Password, where she leads the global engineering team securing the digital safety and identities of millions of prosumers, families, and enterprise workloads. An expert in building highly scalable systems and data protection platforms, she holds seven patents in cloud infrastructure and serves on the boards of early-stage cybersecurity leaders, including Observo AI, which was recently acquired by SentinelOne to power the data intelligence layer for its SIEM products. Prior to joining 1Password, she became the youngest person ever promoted to Director and General Manager at AWS, at age 31, leading AWS Data Protection to serve 98% of the Fortune 500 and building a multi-billion dollar business within five years. She also helped build cloud and data protection products at Rubrik, held engineering roles at Google and in the U.S. intelligence community, and now brings a rare combination of deep infrastructure expertise and security-first product thinking to the age of AI agents. In this episode, Nancy sits down with Dan to explore the massive security responsibilities of the agentic era.In this conversation, we discuss:Why the transition to autonomous AI agents doesn't require brand-new credentials, and how familiar principles of human and machine identity extend to the agentic era.How a proprietary confidential computing architecture built on specialized enclaves protects sensitive user data, even in the event of a catastrophic central breach.Why 1Password actively chose not to release a public Model Context Protocol (MCP) server despite intense market pressure.How a specialized DevOps agent trained on human incident response can learn to navigate real-time outages, runbooks, and cloud traffic monitoring.Why AI is compressing the cost of execution in software, and why the real career advantage now shifts toward taste, judgment, systems thinking, and deep fluency with AI tools.Why prioritizing potential and tenacity over traditional resumes is the key to building diverse engineering teams, and how sponsorship accelerates the rise of high-slope talent   Explore the Conversation00:00 Intro and AI Fun Fact: EvilToken and the Rise of AI-Driven Phishing03:48 Introducing Nancy Wang, CTO at 1Password and AWIT Founder09:07 Secure by Design: Inside the Origin Story and Expansion of 1Password13:32 The Business of Trust: Why 1Password Is in the Security and Relationship Game15:31 Zero-Knowledge Architecture: What Actually Happens if 1Password Faces a Breach?24:06 The Phishing-Resistant Future: Biometrics, Passkeys, and Agent Identity28:17 Inside the Machine: DevOps Agents and Real-Time Incident Response31:22 Rejecting the MCP Server: Why AI Safety Trumps Instant Velocity34:28 The T-Shaped Engineer: Why AI Compresses Execution and Elevates Human Taste39:18 Be a High Sloper: Sponsoring the Next Generation of Tech Leaders Resources:Subscribe to the AI & The Future of Work NewsletterConnect with Nancy Wang on LinkedInAI fun fact article: Hackers use AI to bypass passwords in large-scale phishing attacks Other episodes mentioned on the show:Episode 167 with Amr Awadallah, CEO of Vectara and co-founder of Cloudera, on the tech behind AI search-Join Dan Turchin and 4 seasoned technology and people leaders on Sept. 17 for an executive discussion on AI, leadership, and the future of work. Attendees will receive a complimentary personalized AI Maturity Industry Benchmarks Report ($499 value). Reserve your seat: https://go.peoplereign.io/virtual-event-when-intelligence-is-everywhere-intelligence-is-nowhere

K12 Tech Talk
Episode 279 - Meta's $18B Settlement & Microsoft's Move to Passkeys

K12 Tech Talk

Play Episode Listen Later Aug 28, 2026 58:17 Transcription Available


Josh, Chris and Mark talk back-to-school anecdotes - Chromebook rollouts, teacher tickets, and custodial tech onboarding, then dig into the news headlines of the week. First, Meta's landmark $18 billion settlement with dozens of states over youth mental health concerns tied to Facebook and Instagram. The guys talk settlement terms, default safety measures for 13–17 year-olds (two-hour daily limits, night/school modes, restricted notifications), content-moderation defaults, and uncertainty about age verification. Next, they review the growing pushback in New York City public schools against AI adoption. Next, the guys dive into Microsoft's move to make passkeys the default for Entra ID authentication. What is a passkey? How does it differ from SMS or authenticator codes? Microsoft's timeline? Finally, Chris interviews Amy Bennett, Chief of Staff at Lightspeed Systems, about screen time visibility and the product Insight. Amy demonstrates how districts can use screen-time analytics to benchmark usage by grade and app, drill down to school - and student-level views, and share transparent data with parents and boards to inform policy decisions.  FULL VIDEO OF THE INSIGHT DEMO PORTION IS HERE --> https://youtu.be/zoT2qGJonSg ———— Sponsored by: Meter Lumu Fortinet Manged Methods Extreme Incident IQ Chromebookparts.com - Contact customersupport@chromebookparts.com with the code: WELCOME TO CHROME IMPROVEMENT for an additional 10% percent off your next order! ———— Join the K12TechPro Community (exclusively for K12 Tech professionals) Buy some swag (tech dept gift boxes, shirts, hoodies...)!!! Email us at k12techtalk@gmail.com OR our "professional" email addy is info@k12techtalkpodcast.com X @k12techtalkpod Facebook Visit our LinkedIn Music by Colt Ball Disclaimer: The views and work done by Josh, Chris, and Mark are solely their own and do not reflect the opinions or positions of sponsors or any respective employers or organizations associated with the guys. K12 Tech Talk itself does not endorse or validate the ideas, views, or statements expressed by Josh, Chris, and Mark's individual views and opinions are not representative of K12 Tech Talk. Furthermore, any references or mention of products, services, organizations, or individuals on K12 Tech Talk should not be considered as endorsements related to any employer or organization associated with the guys.

ITSPmagazine | Technology. Cybersecurity. Society
Attackers Relay Codes and Approvals. TokenCore Requires a Live Fingerprint Within Three Feet | A Brand Briefing at Black Hat USA 2026 with Kevin Surace, Chief Executive Officer at TokenCore | Hosted by Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 27, 2026 17:16


Kevin Surace, Chief Executive Officer at TokenCore, opens with the attack path he says is doing the most damage right now. A phishing email carries a PDF and no links, so it clears the filters. The domain is one character off from the real one, the site is pixel perfect because AI built both the page and the message, and the employee approves an auth prompt they were already expecting. The code was real and the approval was real. Kevin Surace points out that auth apps and passkeys run over cellular and Wi-Fi, so the prompt has no way to know the request came from ten thousand miles away. Anything a person can read or hand over can be shared, and by his account an attacker needs about thirty seconds of trust to get it. Passkeys moved the target rather than removing it. Kevin Surace counts 39 separate passkey attacks in the wild within two weeks of Microsoft telling customers to migrate, and points to Michael Grafnetter of SpecterOps, who presented passkey and Entra research at Black Hat. He walks through the FIDO2 counter that WebAuthn treats as optional so shared passkeys can move between devices. What changes with TokenCore in the mix is where the proof sits. Kevin Surace describes signing into Entra in under two seconds, both passwordless and ID-less, over secure Bluetooth, with the device carrying no apps and no screen. Proximity holds it within three feet of the computer being logged into, the credential stays bound to the original domain, and fingerprints stay off the network. Agents raise the same question in a new place. Kevin Surace describes a policy where an agent action above a million-dollar check needs a person to approve it, and notes that another agent, a hacked one, or a bad actor can clear that approval just as easily. A biometric gate is what tells you the CFO was actually in the room, which is a governance answer as much as a security one. For CISOs, identity architects, and risk owners, the question worth asking is what an identity program looks like when the proof of a person becomes the control, and how much residual risk that removes from privileged access, financial approvals, and agent workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Kevin Surace, Chief Executive Officer at TokenCore LinkedIn: https://www.linkedin.com/in/ksurace/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about TokenCore: https://www.tokencore.com TokenCore products: https://www.tokencore.com/products Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Kevin Surace, TokenCore, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, biometric identity, identity assurance, passkey attacks, MFA relay attack, phishing resistant authentication, auth app compromise, FIDO2, WebAuthn, Microsoft Entra, passwordless authentication, agent authorization, privileged access

Cyber Briefing
August 26, 2026 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Aug 26, 2026 5:09


Subscribe to get cybersecurity alerts, insights, and exclusive content delivered straight to your inbox. If you're already a subscriber here on LinkedIn, you won't want to miss this.

Backup Central's Restore it All
Phishing Resistant MFA: Regular MFA Isn't Enough Anymore

Backup Central's Restore it All

Play Episode Listen Later Aug 24, 2026 41:27 Transcription Available


Phishing resistant MFA is the difference between a bad guy getting one email address and a bad guy getting your entire company's inbox. On this episode, Prasanna, Dr. Mike Saylor, and I dig into why plain old multi-factor authentication isn't the finish line anymore; it's the starting line.We open with a real attack: a vulnerable REDCap database, stolen Google Workspace admin credentials, and email forwarding rules quietly running for over a year before anyone noticed. From there Mike breaks down how social engineering actually works (the research bad guys do on you before they ever send an email) and why "report as phishing" buttons have themselves become an attack vector. I share the story of the free credit monitoring scam that got me, and why freezing your credit reports is one of the best five-minute security moves you can make.Mike then walks through FIDO2 and passkeys, why they're built on old-school public/private key encryption, and why they're transactional instead of just another code sent to your phone. We cover the Flax Typhoon espionage campaign, the Raptor Train botnet, and how hard-coded credentials on IoT devices turned into root-level access for a foreign intelligence operation.Then Mike introduces "killing the trust button," which is phrase for the idea that most networks default to open, and every one of those defaults is a decision somebody made without thinking about the risk. We talk about blocking traffic by country, limiting concurrent logins, expiring MFA tokens, and why starting with your administrative accounts is the easiest place to build momentum. And yes, we talk about just asking an AI assistant like Copilot or Claude to walk you through turning this stuff on, because you probably already have these tools and don't know it.We close on why MFA by itself still isn't enough — session token theft, MFA exhaustion attacks, and the "remember this device" setting that undoes everything you just set up. If you're the person responsible for an environment with important accounts sitting there with no MFA, we've got a name for that, and it's not a nice one.Chapters:0:00 – Cold Open1:31 – Welcome to the Show4:12 – The REDCap/Google Workspace Attack8:38 – Social Engineering: How Attackers Do Their Homework13:06 – Freeze Your Credit Reports16:55 – What Is FIDO2? (Phishing Resistant MFA Explained)18:58 – Flax Typhoon and the Raptor Train Botnet24:43 – Professional Malfeasance: No More Excuses for Skipping MFA28:05 – Killing the Trust Button32:51 – Start With Your Administrative Accounts36:36 – Why MFA Alone Isn't Enough: MFA Exhaustion39:27 – Passkeys, Impossible Travel, and Final Takeaways

Mark Reardon Show
George Rosenthal Explains the Meta Youth Safety Trial, Vendor Supply Chain Hacks, and Passkeys

Mark Reardon Show

Play Episode Listen Later Aug 18, 2026 13:35


Mark is joined by George Rosenthal, President and Founder of ThrottleNet, to discuss key developments in technology and cybersecurity. The two discussed the ongoing multi-state lawsuit against Meta regarding youth mental health and social media addiction, how hackers target smaller third-party vendors to gain indirect access to larger corporate networks, and the transition toward passkeys as a passwordless alternative for online security.

Cyberhelden
Cyberhelden 79 - Passkeys, private APN's en 88 miljoen euro in een uur verdienen

Cyberhelden

Play Episode Listen Later Aug 17, 2026 54:58


Ronald, Marco en Jelle zijn terug van de zomerstop. Marco nam zijn HackRF mee naar Noorwegen maar de verkeerde antenne, Jelle hielp Marktplaats met het verwijderen van 1.800 nepadvertenties en Ronald bouwde een eigen president's daily brief voor zijn Kindle. Daarna Patch Tuesday. Microsoft repareerde in augustus 419 kwetsbaarheden, waaronder drie zero-days. Een daarvan werd volgens Check Point actief gebruikt door Lazarus. Ook kwam de eerder aangekondigde Legacy Hive-exploit van Nightmare Eclipse voorbij, al bleek de beloofde "bone-shattering" zero-day iets minder spectaculair dan aangekondigd. Marco bespreekt vervolgens onderzoek van Unit 42 naar gesynchroniseerde Google-passkeys op Windows. De cryptografie zelf bleef overeind, maar malware op het apparaat kon misbruik maken van het vertrouwen tussen Chrome, de TPM en Googles cloud-authenticator. De onderzoekers vonden zelfs de master key waarmee alle gesynchroniseerde passkeys kunnen worden ontsleuteld eerst in logging en later in het geheugen van Chrome. Jelle kijkt mee op een AI-werkstation van Kimsuky. De Noord-Koreaanse spionagegroep experimenteerde volgens Genians met lokale modellen, RAG, transcriptie en AI-ondersteunde softwareontwikkeling. Niet het trainen van een eigen supermodel, maar bestaande open-sourcemodellen dicht bij de aanvalsinfrastructuur inzetten. Marco blijft nog even in Noord-Korea. Onderzoeker Vangelis Stykas keek 22 maanden mee in de infrastructuur van Noord-Koreaanse hackers nadat enkele operators zichzelf met hun eigen malware hadden besmet. Hij vond sporen van 1.640 organisaties in 57 landen. Opvallend: ondanks toegang tot allerlei gevoelige gegevens lag de nadruk vooral op cryptovaluta, terwijl veel gewaarschuwde organisaties niet reageerden. Het eerste grote verhaal gaat over een Poolse warmte-krachtcentrale. Een aanvaller kwam via een gecompromitteerde FortiGate bij een mobiele router die al toegang had tot een private APN. Omdat locaties binnen dat mobiele bedrijfsnetwerk niet van elkaar waren gescheiden, kon de aanvaller door naar een WAGO-controller en drie Siemens-PLC's in STOP zetten. De centrale bediende ongeveer 50.000 inwoners, maar operators herstelden de installatie voordat er maatschappelijke gevolgen waren. Tot slot: waar bewaar je eigenlijk je bitcoins? Bij Coldcard zorgde een firmwarefout ervoor dat sommige hardwarewallets seeds maakten met een voorspelbare softwarematige randomgenerator. Een aanvaller hoefde de wallets niet aan te raken, maar kon mogelijke seeds berekenen, adressen op de openbare blockchain controleren en de gevonden wallets leegtrekken. De omweg langs Cloudflares muur van lavalampen maakt meteen duidelijk waarom echte onvoorspelbaarheid zo belangrijk is. Bronnen: - Microsoft Patch Tuesday: https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/ - Unit 42 over Google-passkeys: https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ - Genians over Kimsuky's lokale AI-stack: https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm - Wired over de Noord-Koreaanse hackers: https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/ - BleepingComputer over de Poolse centrale: https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/ - CERT Polska, follow-uprapport: https://cert.pl/uploads/docs/CERT_Polska_Energy_Sector_Incident_Follow_up_Report_2025.pdf - Coldcard, technische analyse: https://blog.coinkite.com/entropy-technical-backgrounder/ - Coldcard, beveiligingswaarschuwing: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ - Cloudflare over lavalampen en entropie: https://www.cloudflare.com/learning/ssl/lava-lamp-encryption/

Consumer Tech Update
Passkeys beat passwords

Consumer Tech Update

Play Episode Listen Later Aug 14, 2026 8:32


The safest password might be none at all. Plus, we help Jim create and remember unique ones. Without writing them on paper. Learn more about your ad choices. Visit megaphone.fm/adchoices

Paul's Security Weekly
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605

Paul's Security Weekly

Play Episode Listen Later Aug 7, 2026 38:20


Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-605

Paul's Security Weekly TV
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605

Paul's Security Weekly TV

Play Episode Listen Later Aug 7, 2026 38:20


Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-605

Hack Naked News (Audio)
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605

Hack Naked News (Audio)

Play Episode Listen Later Aug 7, 2026 38:20


Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-605

Hack Naked News (Video)
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet - SWN #605

Hack Naked News (Video)

Play Episode Listen Later Aug 7, 2026 38:20


Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Doug is very dark, Josh Marpet, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-605

Cyber Security Headlines
ChainDrop hits npm, Pass-ta-key targets passkeys, AI runs amok in Africa

Cyber Security Headlines

Play Episode Listen Later Aug 5, 2026 8:16


ChainDrop attack hits npm Pass-ta-key attacks target passkeys  AI accounts for most cybercrime in Africa Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/  Huge thanks to our episode sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.  

Radiogeek
Radiogeek 2915: Passkeys vulnerables, WhatsApp y Telegram vs. Apple

Radiogeek

Play Episode Listen Later Aug 5, 2026 20:58


El programa 2915 de Radiogeek repasa las novedades tecnológicas más importantes del día: Passkeys de Google, vulnerables al ataque «Pass-ta-key»; Microsoft advierte que los hackers están falsificando las páginas de inicio de sesión de Wi-Fi de los hoteles; WhatsApp lanza tres nuevas funciones para mejorar los chats grupales; Google Health finalmente admite la sincronización bidireccional de datos de salud con Apple Health y por último El director ejecutivo de Telegram afirma que un "extorsionador" fue el responsable de que Apple retirara brevemente la aplicación de su catálogo. Toda esta información la pueden encontrar desde nuestra web www.infosertec.com.ar o bien desde el canal de Telegram/Whastapp, o Instagram. Esperamos sus comentarios.

Command Control Power: Apple Tech Support & Business Talk
680: Microsoft Retires SMS/Voice MFA, Salesforce SSO Headaches, and SOC 2 Realities

Command Control Power: Apple Tech Support & Business Talk

Play Episode Listen Later Aug 4, 2026 54:41


Sam and Joe discuss Microsoft's plan to retire Microsoft-provided SMS and voice calls for MFA, with key dates of Sept 1, 2026 (users on SMS/voice are automatically enabled for passkeys and nudged to register) and Feb 1, 2027 (blocking enforcement for users whose only MFA is SMS/voice, no opt-out), noting paid/customer-managed telecom options and the need to warn clients, address legacy per-user MFA vs conditional access, and handle shared accounts via shared mailboxes or passkey-sharing tools. Sam recounts a prolonged Salesforce SSO/MFA issue worsened by poor vendor documentation and misleading AI guidance, ultimately tied to a Microsoft KB update. They then cover partnering with Fuji for client SOC 2 compliance support, emphasizing evidence, audits, costs, and ongoing maintenance, plus how cyber-insurance questionnaires drive security improvements. The episode also touches on residential support cases, Vision Pro support challenges with DRM blocking screen mirroring, and show wrap-up.   00:00 Show Kickoff 00:17 Microsoft MFA SMS Retirement 00:44 Key Dates and User Impact 03:28 Authenticator Backups and PSAs 04:40 Legacy MFA Cleanup Challenges 07:36 Conditional Access Licensing Risks 10:12 Shared Accounts and Passkeys 12:21 Salesforce MFA SSO Headaches 13:25 AI Missteps and Vendor Docs 17:50 SOC 2 Help from Fuji 21:23 SOC 2 Costs and Maintenance 22:49 Easy Buttons and Real Audits 26:27 Cyber Insurance Questionnaires 27:53 Partnering for Expertise 29:07 Cyber Insurance Foot in Door 30:31 Apple Store Referral Win 31:01 Lightroom Migration Pitfalls 34:31 Blocked Contacts Mystery 38:04 Email Search and User Training 40:02 Supporting Vision Pro Clients 47:28 Amazon Returns and Exceptions 50:24 Wrap Up and Callouts

MacVoices Video
MacVoices #26225: Live! - AI Trust, Autonomous Vehicle Liability

MacVoices Video

Play Episode Listen Later Aug 4, 2026 20:36


The panel debates whether giving Claude controlled access to 1Password credentials is a practical automation feature or an unnecessary security risk, weighing trust, passkeys, vault isolation, and AI limitations. The conversation then shifts to the humor of waterproof phone holders and shower tech before wrapping with a discussion of how autonomous vehicles could reshape liability, trial law, and advertising, followed by the panel's sign-offs. The panel includes Chuck Joiner, David Ginsburg, Marty Jencius, Eric Bolden, Brian Flanigan-Arthurs, Jim Rea, Web Bixby, and Jeff Gamet. This edition of MacVoices is brought to you by our Patreon supporters. Get access to the MacVoices Slack and MacVoices After Dark by joining in at Patreon.com/macvoices. Show Notes: Chapters: 00:00 AI trust and autonomous vehicle liability00:32 Claude gains access to 1Password credentials01:02 Trusting AI agents with sensitive accounts01:15 Limiting access to individual vault items01:38 Secure credential handling for automation02:41 Can Claude see the actual password?02:58 Passkeys, certificates, and temporary authentication03:55 Using a secondary vault for AI access04:38 Waterproof shower phone holders05:30 Waterproof notepads and working in the shower06:03 Listening to podcasts while showering07:21 Trial lawyers and autonomous vehicles08:23 How self-driving cars could change liability08:51 Could autonomous vehicles eliminate accidents?09:23 The future of legal billboards and television ads10:46 Closing the discussion Links: An AI just broke an 87-year-old maths problem, in a tweet sent during the World Cup finalhttps://thenextweb.com/news/jacobian-conjecture-disproved-ai-fable-5   EU Orders Google to Give Rival AI Apps the Same Android Access as Geminihttps://www.macrumors.com/2026/07/16/eu-google-ai-apps-android-access/   You can now grant Claude access to your 1Password credentialshttps://www.engadget.com/2216405/1password-anthropic-claude-integration/   Waterproof Shower Phone Holder: $8.53https://amzn.to/4vITEqy   Trial Lawyers Lobby Against Autonomous Vehicleshttps://marginalrevolution.com/marginalrevolution/2026/07/trial-lawyers-lobby-against-autonomous-vehicles.html   Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site:https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support:      Become a MacVoices Patron on Patreon     http://patreon.com/macvoices      Enjoy this episode? Make a one-time donation with PayPal Connect:      Web:     http://macvoices.com      Twitter:     http://www.twitter.com/chuckjoiner     http://www.twitter.com/macvoices      Mastodon:     https://mastodon.cloud/@chuckjoiner      Facebook:     http://www.facebook.com/chuck.joiner      MacVoices Page on Facebook:     http://www.facebook.com/macvoices/      MacVoices Group on Facebook:     http://www.facebook.com/groups/macvoice      LinkedIn:     https://www.linkedin.com/in/chuckjoiner/      Instagram:     https://www.instagram.com/chuckjoiner/ Subscribe:      Audio in iTunes     Video in iTunes      Subscribe manually via iTunes or any podcatcher:      Audio: http://www.macvoices.com/rss/macvoicesrss      Video: http://www.macvoices.com/rss/macvoicesvideorss

MacVoices Audio
MacVoices #26225: Live! - AI Trust, Autonomous Vehicle Liability

MacVoices Audio

Play Episode Listen Later Aug 4, 2026 20:37


The panel debates whether giving Claude controlled access to 1Password credentials is a practical automation feature or an unnecessary security risk, weighing trust, passkeys, vault isolation, and AI limitations. The conversation then shifts to the humor of waterproof phone holders and shower tech before wrapping with a discussion of how autonomous vehicles could reshape liability, trial law, and advertising, followed by the panel's sign-offs. The panel includes Chuck Joiner, David Ginsburg, Marty Jencius, Eric Bolden, Brian Flanigan-Arthurs, Jim Rea, Web Bixby, and Jeff Gamet. This edition of MacVoices is brought to you by our Patreon supporters. Get access to the MacVoices Slack and MacVoices After Dark by joining in at Patreon.com/macvoices. Show Notes: Chapters: 00:00 AI trust and autonomous vehicle liability 00:32 Claude gains access to 1Password credentials 01:02 Trusting AI agents with sensitive accounts 01:15 Limiting access to individual vault items 01:38 Secure credential handling for automation 02:41 Can Claude see the actual password? 02:58 Passkeys, certificates, and temporary authentication 03:55 Using a secondary vault for AI access 04:38 Waterproof shower phone holders 05:30 Waterproof notepads and working in the shower 06:03 Listening to podcasts while showering 07:21 Trial lawyers and autonomous vehicles 08:23 How self-driving cars could change liability 08:51 Could autonomous vehicles eliminate accidents? 09:23 The future of legal billboards and television ads 10:46 Closing the discussion Links: An AI just broke an 87-year-old maths problem, in a tweet sent during the World Cup final https://thenextweb.com/news/jacobian-conjecture-disproved-ai-fable-5   EU Orders Google to Give Rival AI Apps the Same Android Access as Geminihttps://www.macrumors.com/2026/07/16/eu-google-ai-apps-android-access/   You can now grant Claude access to your 1Password credentialshttps://www.engadget.com/2216405/1password-anthropic-claude-integration/   Waterproof Shower Phone Holder: $8.53https://amzn.to/4vITEqy   Trial Lawyers Lobby Against Autonomous Vehicles https://marginalrevolution.com/marginalrevolution/2026/07/trial-lawyers-lobby-against-autonomous-vehicles.html   Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site: https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support:      Become a MacVoices Patron on Patreon      http://patreon.com/macvoices      Enjoy this episode? Make a one-time donation with PayPal Connect:      Web:      http://macvoices.com      Twitter:      http://www.twitter.com/chuckjoiner      http://www.twitter.com/macvoices      Mastodon:      https://mastodon.cloud/@chuckjoiner      Facebook:      http://www.facebook.com/chuck.joiner      MacVoices Page on Facebook:      http://www.facebook.com/macvoices/      MacVoices Group on Facebook:      http://www.facebook.com/groups/macvoice      LinkedIn:      https://www.linkedin.com/in/chuckjoiner/      Instagram:      https://www.instagram.com/chuckjoiner/ Subscribe:      Audio in iTunes      Video in iTunes      Subscribe manually via iTunes or any podcatcher:      Audio: http://www.macvoices.com/rss/macvoicesrss      Video: http://www.macvoices.com/rss/macvoicesvideorss

Microsoft Cloud IT Pro Podcast
Episode 433: Passkeys, Passwords, and the End of SMS MFA

Microsoft Cloud IT Pro Podcast

Play Episode Listen Later Jul 30, 2026 45:54 Transcription Available


Welcome to Episode 433 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben and Scott discuss how Microsoft 365 authentication is moving from “make passwords safer with MFA” to “remove phishable authentication wherever possible.” The practical conversation for IT pros is no longer just whether MFA is enabled. It is which methods are allowed, which users are still on SMS or voice, how passkeys change the user experience, and how to balance security, accessibility, recovery, and support load. Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. Show Notes Passkeys were supposed to replace passwords, but they’re failing for the most predictable reason Microsoft Entra authentication overview Passkeys by default and retirement of Microsoft-provided SMS and voice authentication Plan a phishing-resistant passwordless authentication deployment in Microsoft Entra ID Run a registration campaign to set up a passkey or Microsoft Authenticator Practical Protection: Understanding Entra ID and Passkeys Important Change Coming for Entra ID Passkeys in November 2025 Microsoft to Stop Providing Telephony-Based Authentication Methods for MFA in February 2027 How to enable passkeys (FIDO2) in Microsoft Entra ID Sponsors TrustedTech is a leading Microsoft Cloud Solution Provider (CSP) specializing in Microsoft Cloud services, Microsoft perpetual licensing, and Microsoft Support Services for medium and enterprise-sized businesses. Their robust team of in-house, U.S.-based Microsoft architects and engineers are certified in all 6/6 Microsoft Solutions Partner Designations in the Microsoft Cloud Partner Program. M365 Licensing Consultation M365 Tenant Assessment Copilot Readiness Assessment ShareGate is your migration and governance solution for Microsoft 365. ShareGate helps your teams simplify tenant migrations, get Copilot-ready, and take control of Microsoft 365 governance. Nasuni is a leading unstructured data platform for enterprises where file data is mission-critical for both people and AI. Nasuni powers the operational file layer where work happens — helping organizations manage, protect, and activate data so teams can work smarter, reduce costs, and operate securely without limits. Intelligink — Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let us know!

The Edge Podcast
How To Keep Your Crypto Safe from North Korea's 2,500 Hackers

The Edge Podcast

Play Episode Listen Later Jul 22, 2026 80:47


Pablo Sabbatella is the Founder of Opsek and Louis is the Head of Operations & Audits.North Korea has an estimated 2,500 organized hackers targeting crypto right now, which is why stolen funds often don't come from smart contract bugs, they start with hacking people.In this episode, Pablo and Louis walk through the real threat landscape facing DeFi users and protocols today, including the most common attack vectors targeting crypto holders right now. We discuss what DeFi protocols must do to raise the security bar and what we as individual users can do today to meaningfully reduce the risk and protect ourselves.------

Ctrl+Alt+Azure
352 - So long, SMS and voice authentication

Ctrl+Alt+Azure

Play Episode Listen Later Jul 22, 2026 34:36


Microsoft is retiring natively provided SMS and voice authentication in Entra ID, and the clock is ticking: passkeys become the default experience on September 1, 2026, and Microsoft-provided telecom delivery is fully retired on February 1, 2027.  We walk through the timeline, what admins should do now to find and migrate affected users, and when the new Security Store telecom providers make sense. We also cover the everyday struggle: moving Microsoft Authenticator to a new phone without locking yourself out.(00:00) - Intro and catching up.(05:00) - Show content starts.Show links- Passkeys by default | MS Learn- Transfer Authenticator to a new phone  - SMS/voice usage analyzer script  - Plan a passkey deployment  - End-user communication templates- Give us feedback!

Blue Security
Identity Update: Passkeys by Default, Phone Transfers, Physical Key Security

Blue Security

Play Episode Listen Later Jul 21, 2026 34:58


SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the upcoming transition to passkeys as the default method for multi-factor authentication (MFA) in Microsoft Entra ID. They explore the implications of this change, the importance of moving away from SMS and voice authentication, and best practices for organizations to prepare for this shift. The conversation also covers the challenges of transferring MFA codes and passkeys when upgrading phones, and introduces the YubiKey Locker, a new tool that enhances security by automatically locking devices when the YubiKey is removed. The hosts emphasize the need for organizations to modernize their identity infrastructure and adopt more secure authentication methods.----------------------------------------------------YouTube Video Link: https://youtu.be/eXqW3FAY_hE----------------------------------------------------Documentation: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-transfer-authenticator-new-phonehttps://support.okta.com/help/s/article/migrating-all-existing-mfa-codes-to-okta-verify?language=en_UShttps://www.sciber.io/sciber-blog/sciber-launches-yubikey-locker-to-defend-against-physical-attacks/----------------------------------------------------Contact Us:Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpodYouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠----------------------------------------------------Adam BrewerTwitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewerLinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Home Gadget Geeks (Audio MP3)
Christian Johnson on Passkeys, Self-Hosted Bitwarden and Guardrails for AI Agents – HGG684

Home Gadget Geeks (Audio MP3)

Play Episode Listen Later Jul 18, 2026 83:13


Christian Johnson joins Jim Collison for Home Gadget Geeks 684 to talk about passkeys, Bitwarden, Vaultwarden, managed container hosting through Maple Grove Partners and the guardrails needed when AI agents begin doing real operational work.

Home Gadget Geeks (Video Large)
Christian Johnson on Passkeys, Self-Hosted Bitwarden and Guardrails for AI Agents – HGG684

Home Gadget Geeks (Video Large)

Play Episode Listen Later Jul 18, 2026


Christian Johnson joins Jim Collison for Home Gadget Geeks 684 to talk about passkeys, Bitwarden, Vaultwarden, managed container hosting through Maple Grove Partners and the guardrails needed when AI agents begin doing real operational work.

Home Gadget Geeks (Video Small)
Christian Johnson on Passkeys, Self-Hosted Bitwarden and Guardrails for AI Agents – HGG684

Home Gadget Geeks (Video Small)

Play Episode Listen Later Jul 18, 2026


Christian Johnson joins Jim Collison for Home Gadget Geeks 684 to talk about passkeys, Bitwarden, Vaultwarden, managed container hosting through Maple Grove Partners and the guardrails needed when AI agents begin doing real operational work.

Backup Central's Restore it All
The REDCap Attack that Phishing-Resistant MFA Could Have Stopped

Backup Central's Restore it All

Play Episode Listen Later Jun 22, 2026 34:01 Transcription Available


Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it.A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin credentials, planted custom malware called Infinite.red directly into REDCap's upgrade process, harvested credentials for over a year, then used those credentials to log into Google Workspace as a domain admin and create fake compliance rules to silently forward sensitive research emails — military strategy, geostrategic policy, advanced tech, specific pathogens — straight to Gmail accounts they controlled. And nobody noticed for a very long time.Prasanna and I break down the full attack chain, then walk through every prevention layer that could have stopped it: inventory management, patching, password hygiene, SSO, phishing-resistant MFA, passkeys, DBSC, context-aware access, compliance rule monitoring, credential separation across security domains, and logging. We also get into what backups can and can't do for you in a long-dwell-time attack like this — and why infrastructure-as-code and truly immutable golden images matter more than you might think.If you're running any kind of research platform, academic institution, or medical network — or honestly any organization that uses Google Workspace — this one's for you.Chapters:00:00 — Intro: The attack that phishing-resistant MFA could have stopped01:03 — Show intro & woodworking banter03:26 — What is a living-off-the-land attack?04:02 — Who is UNC5608 and who did they target?05:08 — How REDCap's multi-version design was exploited06:11 — Infinite.red malware and credential harvesting09:01 — Google Workspace infiltration via fake compliance rules10:18 — The keywords they were stealing: pathogens, military strategy, and more11:50 — What could the victims have done differently?12:42 — Inventory management, patching, and legacy version removal14:00 — Why you can't trust application-level authentication alone — use SSO15:18 — Phishing-resistant MFA and why it matters16:00 — Passkeys, FIDO, and why there are zero known attacks against them17:57 — Device-bound session credentials (DBSC) and context-aware access19:38 — Monitor your compliance rules — have a compliance rule for the compliance rule20:40 — Credential separation across security domains23:00 — Get some logging — XDR, SIEM, and catching exfiltration in progress24:00 — What can backups actually do in a long-dwell-time attack?27:00 — Infrastructure-as-code and the right cyber recovery approach28:58 — Protecting your golden images with immutable storage31:59 — Wrap-up

MacVoices Video
MacVoices #26188: Live - App Store Guidelines, AI Password Changing, and Snap's Specs

MacVoices Video

Play Episode Listen Later Jun 22, 2026 55:36


The MacVoices Live! panel discusses Apple's updated App Store review guidelines, the challenge of filtering low-quality or AI-generated apps, and whether trusted developers should receive faster review. Chuck Joiner, David Ginsburg, Jim Rea, Marty Jencius, Web Bixby, Jeff Gamet, and Eric Bolden also debate Apple's Passwords app gaining automatic password-changing abilities, weighing convenience against account-lockout risk. They also provide reactions to Snap's new Specs and the uncertain future of smart glasses.  MacVoices is supported by NordLayer. Secure your network & stay compliant with one toggle-ready platform. Get an exclusive offer: up to 22% off NordLayer yearly plans plus 10% on top with the coupon code: MACVOICES10 at NordLayer.com/macvoices. Try it risk-free—14-day money-back guarantee. Show Notes: Chapters: 00:00 Opening topics and sponsor message00:27 Tim Cook's WWDC morning video01:34 WWDC swag and Finder collectibles03:24 Apple's app submission volume03:46 Updated App Store guidelines for low-quality apps04:19 The scale problem of reviewing thousands of apps05:48 Should trusted developers get faster review?06:27 Policing successful or suspicious apps07:37 Apple Passwords app and automatic password changes08:00 Initial skepticism from the panel09:09 How automatic password changes may work10:09 Standards, automation, and website support11:10 Balancing convenience with trust12:22 Why password automation could help less technical users13:15 Implementation concerns and website complexity14:13 Comparing the feature to Face ID's early skepticism15:41 Account lockout as the biggest risk16:28 Where automatic password changes could be useful17:33 Interface design and fallbacks18:27 Security tradeoffs and password visibility19:36 Passwords as an aging technology20:10 Password managers and better password habits21:35 Passkeys and the slow path to adoption23:23 Sponsor message25:48 Snap Specs pricing and release expectations26:13 Recording indicators and privacy concerns26:34 Comparing Snap Specs to Meta smart glasses27:18 Price, style, and hardware limitations28:16 Ray-Ban Meta glasses and AI features28:35 Vision Pro comparisons and entertainment value29:20 Potential use cases for smart glasses30:45 Skepticism about current smart glasses design31:14 Are these products ready for consumers?32:06 Humor, smart glasses, and panel reactions33:39 Closing comments and event mentions34:15 Closing credits and support information Links: Tim Cook posts comedic ‘Good morning' video to mark final Apple event as CEOhttps://9to5mac.com/2026/06/08/tim-cook-posts-comedic-good-morning-video-to-mark-final-apple-event-as-ceo/ WWDC 2026 Swag Bag Includes Little Finder Guyhttps://www.macrumors.com/2026/06/08/wwdc-2026-swag-bag-little-finder-guy/ Apple Updates App Store Guidelines With Stricter Rules for Low-Quality Appshttps://www.macrumors.com/2026/06/09/app-store-guidelines-low-quality-apps/ iOS 27's Passwords app can change your passwords for you, automatically – 9to5Machttps://9to5mac.com/2026/06/08/ios-27s-passwords-app-can-change-your-passwords-for-you-automatically/ Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site:https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support:      Become a MacVoices Patron on Patreon     http://patreon.com/macvoices      Enjoy this episode? Make a one-time donation with PayPal Connect:      Web:     http://macvoices.com      Twitter:     http://www.twitter.com/chuckjoiner     http://www.twitter.com/macvoices      Mastodon:     https://mastodon.cloud/@chuckjoiner      Facebook:     http://www.facebook.com/chuck.joiner      MacVoices Page on Facebook:     http://www.facebook.com/macvoices/      MacVoices Group on Facebook:     http://www.facebook.com/groups/macvoice      LinkedIn:     https://www.linkedin.com/in/chuckjoiner/      Instagram:     https://www.instagram.com/chuckjoiner/ Subscribe:      Audio in iTunes     Video in iTunes      Subscribe manually via iTunes or any podcatcher:      Audio: http://www.macvoices.com/rss/macvoicesrss      Video: http://www.macvoices.com/rss/macvoicesvideorss

MacVoices Audio
MacVoices #26188: Live - App Store Guidelines, AI Password Changing, and Snap's Specs

MacVoices Audio

Play Episode Listen Later Jun 22, 2026 35:43


The MacVoices Live! panel discusses Apple's updated App Store review guidelines, the challenge of filtering low-quality or AI-generated apps, and whether trusted developers should receive faster review. Chuck Joiner, David Ginsburg, Jim Rea, Marty Jencius, Web Bixby, Jeff Gamet, and Eric Bolden also debate Apple's Passwords app gaining automatic password-changing abilities, weighing convenience against account-lockout risk. They also provide reactions to Snap's new Specs and the uncertain future of smart glasses.  MacVoices is supported by NordLayer. Secure your network & stay compliant with one toggle-ready platform. Get an exclusive offer: up to 22% off NordLayer yearly plans plus 10% on top with the coupon code: MACVOICES10 at NordLayer.com/macvoices. Try it risk-free—14-day money-back guarantee. Show Notes: Chapters: 00:00 Opening topics and sponsor message 00:27 Tim Cook's WWDC morning video 01:34 WWDC swag and Finder collectibles 03:24 Apple's app submission volume 03:46 Updated App Store guidelines for low-quality apps 04:19 The scale problem of reviewing thousands of apps 05:48 Should trusted developers get faster review? 06:27 Policing successful or suspicious apps 07:37 Apple Passwords app and automatic password changes 08:00 Initial skepticism from the panel 09:09 How automatic password changes may work 10:09 Standards, automation, and website support 11:10 Balancing convenience with trust 12:22 Why password automation could help less technical users 13:15 Implementation concerns and website complexity 14:13 Comparing the feature to Face ID's early skepticism 15:41 Account lockout as the biggest risk 16:28 Where automatic password changes could be useful 17:33 Interface design and fallbacks 18:27 Security tradeoffs and password visibility 19:36 Passwords as an aging technology 20:10 Password managers and better password habits 21:35 Passkeys and the slow path to adoption 23:23 Sponsor message 25:48 Snap Specs pricing and release expectations 26:13 Recording indicators and privacy concerns 26:34 Comparing Snap Specs to Meta smart glasses 27:18 Price, style, and hardware limitations 28:16 Ray-Ban Meta glasses and AI features 28:35 Vision Pro comparisons and entertainment value 29:20 Potential use cases for smart glasses 30:45 Skepticism about current smart glasses design 31:14 Are these products ready for consumers? 32:06 Humor, smart glasses, and panel reactions 33:39 Closing comments and event mentions 34:15 Closing credits and support information Links: Tim Cook posts comedic 'Good morning' video to mark final Apple event as CEO https://9to5mac.com/2026/06/08/tim-cook-posts-comedic-good-morning-video-to-mark-final-apple-event-as-ceo/ WWDC 2026 Swag Bag Includes Little Finder Guy https://www.macrumors.com/2026/06/08/wwdc-2026-swag-bag-little-finder-guy/ Apple Updates App Store Guidelines With Stricter Rules for Low-Quality Apps https://www.macrumors.com/2026/06/09/app-store-guidelines-low-quality-apps/ iOS 27's Passwords app can change your passwords for you, automatically – 9to5Mac https://9to5mac.com/2026/06/08/ios-27s-passwords-app-can-change-your-passwords-for-you-automatically/ Guests: Get detailed bios and contact information about for the panel on the MacVoices Live! Panel page on our web site: https://macvoices.com/macvoiceslive/macvoices-live-panel/ Support:      Become a MacVoices Patron on Patreon      http://patreon.com/macvoices      Enjoy this episode? Make a one-time donation with PayPal Connect:      Web:      http://macvoices.com      Twitter:      http://www.twitter.com/chuckjoiner      http://www.twitter.com/macvoices      Mastodon:      https://mastodon.cloud/@chuckjoiner      Facebook:      http://www.facebook.com/chuck.joiner      MacVoices Page on Facebook:      http://www.facebook.com/macvoices/      MacVoices Group on Facebook:      http://www.facebook.com/groups/macvoice      LinkedIn:      https://www.linkedin.com/in/chuckjoiner/      Instagram:      https://www.instagram.com/chuckjoiner/ Subscribe:      Audio in iTunes      Video in iTunes      Subscribe manually via iTunes or any podcatcher:      Audio: http://www.macvoices.com/rss/macvoicesrss      Video: http://www.macvoices.com/rss/macvoicesvideorss

SecurityMetrics Podcast
Passkeys: An Upgrade You Didn't Know You Needed (ep 9)

SecurityMetrics Podcast

Play Episode Listen Later Jun 9, 2026 28:27


Passwords were built for a different era of the internet. It's time to move past shared secrets to close your organization's largest threat vector for good.Traditional passwords and legacy Multi-Factor Authentication (MFA) are no longer enough to protect your business. Automated, scaling phishing toolkits easily intercept shared secrets, leaving small and medium businesses highly vulnerable to credential breaches.In this episode, Jen sits down with Nishant Kaushik, Chief Technology Officer at the FIDO Alliance, to translate complex cryptographic standards into an actionable, resource-light deployment plan. Learn how to transition away from legacy authentication and close the hidden operational loopholes that hackers actively exploit.What You Will Learn:The Flaw in Basic MFA: Why SMS codes and standard one-time passwords (OTPs) are failing, and what true "phishing-resistant" security means.The Account Recovery Trap: Why a weak "Forgot Password" workflow accidentally gives hackers their primary attack vector back—and how to fix it.The Bottom-Line Benefit: How moving to passkeys drastically reduces internal IT helpdesk tickets, manual password resets, and overhead costs.Right-Sizing Your Passkey Deployment: How to easily segment your workforce strategy:Standard Users: Synced passkeys via platform credential managers (Apple, Google, 1Password, Bitwarden).Privileged Users: Dedicated hardware keys (YubiKeys) for root admins and high-sensitivity infrastructure.The 1-Week Action Plan: How to leverage the identity infrastructure you already own (like Google Workspace or Microsoft Entra ID) to deploy passkeys today.Resources Mentioned:Learn more about modern identity standards: FIDO Alliance WebsiteReview baseline federal security recommendations: CISA Guidance on Phishing-Resistant MFADiscover SecurityMetrics compliance resources: SecurityMetrics Official SiteThreat Intelligence Data: Read the data behind credential exploitation in the latest Verizon Data Breach Investigations Report (DBIR). Federal Passkey Standards: Review the updated identity and passkey frameworks via the NIST SP 800-63 Digital Identity Guidelines. Enterprise Identity Platforms: Learn how modern stacks integrate passwordless via Okta Verify and Microsoft Entra ID. About the Guest: Nishant Kaushik is the Chief Technology Officer at the FIDO Alliance, bringing over 25 years of leadership in digital identity and access management (IAM). He holds nine patents, frequently serves on the advisory committees for the RSA Conference and Identiverse, and is a founding member of IDPro.A note from Jen: We built Practical Cybersecurity because we were tired of the fear-mongering in this industry. Security shouldn't be a secret club.If you're trying to figure out PCI compliance or need a pen test, my team at SecurityMetrics can help you out: https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place But if you just want to learn how to protect yourself for free, start here:  https://academy.securitymetrics.com/ 

Laravel News Podcast
Passkeys, Moats, and Scheduling Models

Laravel News Podcast

Play Episode Listen Later May 28, 2026 60:06


Jake and Michael discuss all the latest Laravel releases, tutorials, and happenings in the community.Show linksGenerate HTML Password Rules Attribute in Laravel 13.9.0Storage Cache Store in Laravel 13.10.0Scrollbar Styling and Container Size Utilities in Tailwind CSS v4.3.0Laravel Introduces First-Party Passkey Authentication SupportLaravel's AI SDK adds sub-agentsDHH Joins Laravel Live Denmark 2026 for Fireside Chat with Taylor OtwellManage Laravel Cloud Deployments Inside PhpStormMoat: A Security Review for Your GitHub AccountModel-Based Scheduling for Laravel with CadenceLarapanda: A Type-Safe Lightpanda Browser SDK for LaravelUse a Google Sheet as Your Laravel Database with the Google Sheets Database DriverDrag-and-Drop Sorting for Eloquent Models with Reorderable for LaravelPiper: Laravel-Style Array and String Helpers for PHP's Pipe OperatorSimple Feature Flags for Laravel with Laravel ToggleLaravel Paper: A Flat-File Eloquent DriverTutorialsLaravel MongoDB Full-Text Search tutorial: The Art of the RelevancyShip AI with Laravel: Real-Time Streaming Chat UI with Livewire

This Week in Google (MP3)
IM 871: CTRL-F Techno King - Google's Search Overhaul

This Week in Google (MP3)

Play Episode Listen Later May 21, 2026 173:48


Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com

All TWiT.tv Shows (MP3)
Intelligent Machines 871: CTRL-F Techno King

All TWiT.tv Shows (MP3)

Play Episode Listen Later May 21, 2026 173:48


Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com

Radio Leo (Audio)
Intelligent Machines 871: CTRL-F Techno King

Radio Leo (Audio)

Play Episode Listen Later May 21, 2026 173:48


Dashlane's CTO pulls back the curtain on how password managers are actually using AI, why it's more complicated than hype suggests, and what the rise of AI-powered code review means for the next wave of digital security. Nvidia Rides Blistering Chip Sales to Another Record Quarter Mind-Blowing Growth Is About to Propel Anthropic Into Its First Profitable Quarter SpaceX Filing Starts Countdown to Massive IPO Gemini 3.5 Flash: more expensive, but Google plan to use it for everything Google's Gemini Spark is an agentic AI assistant - Engadget Anthropic's Co-Founder to Launch Encyclical on AI With Pope Leo (21) Andrej Karpathy on X: "Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time." / X Most U.S. doctors are quietly using this AI tool. Few patients know about it. Greg Brockman Officially Takes Control of OpenAI's Products in Latest Shakeup Amazon's Alexa+ Now Produces AI-Generated 'Podcasts' Featuring Chats Between Two Robot 'Co-Hosts' AI chatbots are giving out people's real phone numbers Geoffrey Fowler and the Launch of the Youth AI Safety Institute We let four AIs run radio stations. Here's what happened. | Andon Labs The last six months in LLMs in five minutes Lake Tahoe Power Crisis: How AI Data Centers Are Cutting Power to 50,000 Residents What happens when you post a real Monet and say it's AI? The coolest art social experiment I've seen in a while. Thank you @SHL0MS Book on Truth in the Age of A.I. Contains Quotes Made Up by A.I. OpenClaw's Peter Steinberger's tokenmaxxing 'Obvious markers of AI': doubts raised over winner of short story prize Man drives Cybertruck into Grapevine Lake Stewart Brand's Maintenance of Everything Sports Illustrated Just Deleted Every Article by One of Its Writers After Accusation of AI Plagiarism The great digital media valuation collapse Sperm racing Hosts: Leo Laporte, Jeff Jarvis, and Paris Martineau Guest: Frederic Rivain Download or subscribe to Intelligent Machines at https://twit.tv/shows/intelligent-machines. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit monarch.com with code IM zscaler.com/security XBOW.com

Accidental Tech Podcast
686: Write Two Letters

Accidental Tech Podcast

Play Episode Listen Later Apr 9, 2026 122:09


Pre-show: The new Ceramic Shield 2 in the iPhone 17 Pro is the real deal UniFi Travel Router Cascades trail Shenandoah National Park

The Clark Howard Podcast
04.03.26 Clark Answers His Critics on Clark Stinks / Protect Your Phone & Accounts

The Clark Howard Podcast

Play Episode Listen Later Apr 3, 2026 32:15


Friday - Clark Stinks day! Christa shares Clark Stinks posts with Clark. Submit yours at Clark.com/ClarkStinks.  Also today - security risks keep morphing via phone and/or account takeover attempts. Clark covers a specific threat targeting iPhone users and the simple fix, plus - the next generation of online security – Passkeys. Clark Stinks: Segments 1 & 2 Prevent Hackers: Segment 3 Ask Clark: Segment 4 Mentioned on the show: Buy Now, Pay Later: A Helpful Tool or a Debt Trap? - Clark Howard Roth IRA Withdrawal Rules What Is a Credit Union? - Clark Howard Why Clark Howard Thinks You Need a Digital Passport Best Free Password Managers: 10 Top Picks - Clark Howard New Ways to Keep Your Online Accounts Safe Military and Veterans Guide: Free Resources for Your Finances Charitable Contributions Deduction: What It Is and How It Works Understanding Donor-Advised Funds: Pros and Cons Clark.com resources: Episode transcripts Community.Clark.com  /  Ask Clark Clark.com daily money newsletter Consumer Action Center Free Helpline: 636-492-5275 Learn more about your ad choices. Visit megaphone.fm/adchoices