
Sign up to save your podcasts
Or


Interested in being a guest? Email us at [email protected]
Phishing used to be a numbers game. With AI, it’s becoming a personalization game and that’s exactly why “good enough” login security is quietly turning into a liability. We sit down with Dawn Manley, PhD, SVP, Product Management of Yubico to talk about why phishing-resistant authentication is now a must-have for anyone protecting high-value accounts, especially as AI tools become central to daily work and decision-making.
We get specific about OpenAI’s Advanced Account Security and why YubiKeys are part of the story. AI accounts can hold an incredible amount of sensitive context: drafts, strategies, internal notes, customer data, and the breadcrumbs of how you think. That makes ChatGPT account security and account takeover prevention far more than a technical checkbox. Dawn explains how hardware-backed security keys work in real life, why they’re considered phishing resistant, and how they avoid the weak points of SMS codes, intercepted OTPs, and push-notification tricks.
Then we zoom out to the next wave: AI agents and agentic commerce. When software can act on your behalf, the question shifts from “who logged in?” to “who approved this action?” We talk about proving human intent for high-risk moments, using strong cryptography as a trust anchor, and what it looks like to deploy hardware-backed passkeys across an entire organization without relying on users to spot every scam.
If you care about identity and access management, FIDO2 passkeys, enterprise security, or protecting AI workflows, you’ll walk away with a clearer model for what “strong authentication” really means now. Subscribe, share this with someone still relying on codes, and leave a review with your biggest question about phishing-resistant security.
Support the show
More at https://linktr.ee/EvanKirstel
By Evan KirstelInterested in being a guest? Email us at [email protected]
Phishing used to be a numbers game. With AI, it’s becoming a personalization game and that’s exactly why “good enough” login security is quietly turning into a liability. We sit down with Dawn Manley, PhD, SVP, Product Management of Yubico to talk about why phishing-resistant authentication is now a must-have for anyone protecting high-value accounts, especially as AI tools become central to daily work and decision-making.
We get specific about OpenAI’s Advanced Account Security and why YubiKeys are part of the story. AI accounts can hold an incredible amount of sensitive context: drafts, strategies, internal notes, customer data, and the breadcrumbs of how you think. That makes ChatGPT account security and account takeover prevention far more than a technical checkbox. Dawn explains how hardware-backed security keys work in real life, why they’re considered phishing resistant, and how they avoid the weak points of SMS codes, intercepted OTPs, and push-notification tricks.
Then we zoom out to the next wave: AI agents and agentic commerce. When software can act on your behalf, the question shifts from “who logged in?” to “who approved this action?” We talk about proving human intent for high-risk moments, using strong cryptography as a trust anchor, and what it looks like to deploy hardware-backed passkeys across an entire organization without relying on users to spot every scam.
If you care about identity and access management, FIDO2 passkeys, enterprise security, or protecting AI workflows, you’ll walk away with a clearer model for what “strong authentication” really means now. Subscribe, share this with someone still relying on codes, and leave a review with your biggest question about phishing-resistant security.
Support the show
More at https://linktr.ee/EvanKirstel