What's Up with Tech?

A Physical Key Is The Missing Layer For Modern Account Security


Listen Later

Interested in being a guest? Email us at [email protected]

Your AI account is quickly becoming your most valuable account. It can hold business context, customer details, code, research, and the day-to-day workflows you rely on. That also makes it a prime target for phishing and account takeover, especially as attacks get more convincing with AI.

We sit down with Dawn Manley, Senior Vice President of Product Management at Yubico, to unpack what “phishing-resistant MFA” actually means and why hardware-backed authentication changes the game. We compare the familiar world of SMS codes and approval prompts with a physical security key that uses strong cryptography, verifies you are signing into the real service, and requires real user presence. The goal is simple: stop attacks from succeeding instead of expecting every person to spot every scam.

We also dig into Yubico’s partnership with OpenAI to bring stronger account protection to ChatGPT through OpenAI’s advanced account security program. We talk about who it’s built for, why AI accounts are now high-risk, and how identity is shifting from “who logged in” to “who authorized this action” as agentic workflows become more common. If you care about cybersecurity, Zero Trust, and practical defenses you can actually deploy, this conversation will sharpen how you think about securing the tools you use every day.

Subscribe for more, share this with someone who still relies on SMS codes, and leave a review with the one security upgrade you want to make next.

Support the show

More at https://linktr.ee/EvanKirstel

...more
View all episodesView all episodes
Download on the App Store

What's Up with Tech?By Evan Kirstel