Aug. 24, 2026

Phishing Resistant MFA: Regular MFA Isn't Enough Anymore

Phishing Resistant MFA: Regular MFA Isn't Enough Anymore

Phishing resistant MFA is the difference between a bad guy getting one email address and a bad guy getting your entire company's inbox. On this episode, Prasanna, Dr. Mike Saylor, and I dig into why plain old multi-factor authentication isn't the finish line anymore; it's the starting line.

We open with a real attack: a vulnerable REDCap database, stolen Google Workspace admin credentials, and email forwarding rules quietly running for over a year before anyone noticed. From there Mike breaks down how social engineering actually works (the research bad guys do on you before they ever send an email) and why "report as phishing" buttons have themselves become an attack vector. I share the story of the free credit monitoring scam that got me, and why freezing your credit reports is one of the best five-minute security moves you can make.

Mike then walks through FIDO2 and passkeys, why they're built on old-school public/private key encryption, and why they're transactional instead of just another code sent to your phone. We cover the Flax Typhoon espionage campaign, the Raptor Train botnet, and how hard-coded credentials on IoT devices turned into root-level access for a foreign intelligence operation.

Then Mike introduces "killing the trust button," which is phrase for the idea that most networks default to open, and every one of those defaults is a decision somebody made without thinking about the risk. We talk about blocking traffic by country, limiting concurrent logins, expiring MFA tokens, and why starting with your administrative accounts is the easiest place to build momentum. And yes, we talk about just asking an AI assistant like Copilot or Claude to walk you through turning this stuff on, because you probably already have these tools and don't know it.

We close on why MFA by itself still isn't enough — session token theft, MFA exhaustion attacks, and the "remember this device" setting that undoes everything you just set up. If you're the person responsible for an environment with important accounts sitting there with no MFA, we've got a name for that, and it's not a nice one.

Chapters:

0:00 – Cold Open

1:31 – Welcome to the Show

4:12 – The REDCap/Google Workspace Attack

8:38 – Social Engineering: How Attackers Do Their Homework

13:06 – Freeze Your Credit Reports

16:55 – What Is FIDO2? (Phishing Resistant MFA Explained)

18:58 – Flax Typhoon and the Raptor Train Botnet

24:43 – Professional Malfeasance: No More Excuses for Skipping MFA

28:05 – Killing the Trust Button

32:51 – Start With Your Administrative Accounts

36:36 – Why MFA Alone Isn't Enough: MFA Exhaustion

39:27 – Passkeys, Impossible Travel, and Final Takeaways

Speaker:

Do you know how hard Russian hackers are trying to get your info?

Speaker:

And a good MFA system is often all that stands in their way.

Speaker:

Today, Prasanna, Dr. Mike Saylor, and I dig into multi-factor

Speaker:

authentication and why old school MFA really isn't enough anymore.

Speaker:

We talk about how bad guys steal your session tokens and wear you down

Speaker:

with fake MFA requests, and why even better than MFA is FIDO2 and passkeys.

Speaker:

We cover a Google Workspace attack that ran undetected for over a

Speaker:

year, and hand you some simple steps that you can be doing right now.

Speaker:

If you're still letting important accounts sit there with no MFA, uh, I got a

Speaker:

name for that, and it's not a nice one.

Speaker:

If this is your first time watching or listening to me, I'm W.

Speaker:

Curtis Preston, AKA Mr. Backup, and I've been obsessing over backup recovery, and

Speaker:

now cyber recovery, for over 30 years.

Speaker:

If that's your bag, then I'm your guy.

Speaker:

You're not gonna find anyone that cares about this topic more than me.

Speaker:

Ever since 1993, when a database died and I didn't have any backups.

Speaker:

Uh, that was not a good day.

Speaker:

Now I've written five O'Reilly books, a blog, and a podcast.

Speaker:

Here we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap Up

Speaker:

Hi, and welcome to the Backup Wrap Up.

Speaker:

I'm your host W. Curtis Preston, and today I have with me, my two best friends.

Speaker:

First off, let me just talk about the guy that's currently cooking

Speaker:

in his seat, Dr. Mike Saylor.

Speaker:

How… What's the temperature over there today, Mike?

Speaker:

today it's, I think it's close to just over 100.

Speaker:

we're, we're just getting ready and excited for tomorrow's 106

Speaker:

Ouch

Speaker:

just, that's just, and I shared with you, before the call, it's

Speaker:

also really hot here in, Oceanside.

Speaker:

It's 85, which is, for us is just really high.

Speaker:

I've never tried to cook an egg on my head, but tomorrow I might

Speaker:

And speaking of super hot, how's it going, Prasanna?

Speaker:

I'm good, Curtis.

Speaker:

Nice to see you again, Mike, and I hope you are not planning to

Speaker:

go anywhere outside tomorrow.

Speaker:

Just, like, stay indoors all day long

Speaker:

I've gotta drive to Houston.

Speaker:

I'll be on the road all day

Speaker:

At least air conditioning.

Speaker:

Yes, air-conditioned road travel

Speaker:

quick, completely unrelated story of driving to Houston.

Speaker:

I once had a, situation where I had a, I was flying American Airlines

Speaker:

and I was flying in and out of Houston, but via DFW of course, 'cause

Speaker:

that was American Airlines, right?

Speaker:

And I found myself in Dallas and I, tried to get American to say, "Hey, h- how about

Speaker:

I just hop on the second leg, instead of going all the way to, driving all the

Speaker:

way to Houston just to get on a plane just to come right back where I am at?"

Speaker:

And they go, "No, you gotta do it. You gotta do it or otherwise you're gonna pay

Speaker:

$755 or whatever." So I drove to Houston, and one mile south, or one mile shy of the

Speaker:

Houston Airport, I got a speeding ticket

Speaker:

Oh.

Speaker:

the time,

Speaker:

I really thought where this, this was gonna go is that you got off

Speaker:

the plane in Dallas and went, "Wow, this weather sucks." And then you

Speaker:

got to Houston and you went, "Oh, well maybe Dallas wasn't so bad."

Speaker:

Yeah, the, what I remember at the time was the, trooper, I don't know,

Speaker:

the, the, the cop, told me that, at the time Texas and California

Speaker:

didn't, share, computers or whatever.

Speaker:

And so he said, "You need to surrender your driver's license." And I was

Speaker:

like, "I'm going to the plane." I really don't remember the end of that

Speaker:

story, but I remember the cop took my license, and, somehow I got home.

Speaker:

so gotta love Texas.

Speaker:

anyway, and American Airlines for putting me in that position, and

Speaker:

me for speeding, but whatever.

Speaker:

It's not my fault.

Speaker:

Of course not,

Speaker:

Uh-huh.

Speaker:

Uh-huh

Speaker:

speaking of not my fault, we're gonna start, we're gonna talk about, we're

Speaker:

gonna talk about MFA, multi-factor authentication, and, I thought

Speaker:

you'd start, Prasanna, with a story that we covered not that long ago.

Speaker:

do you wanna talk about that?

Speaker:

Yeah.

Speaker:

So this was, I wanna say it was probably a month ago, maybe two months ago, where,

Speaker:

a bad actor was detected and shut down.

Speaker:

But what ended up happening is there was a software package that was used

Speaker:

mainly, I think, in medical and some of, like, the academics instances

Speaker:

called REDCap, and it basically is a database that allows you to do things.

Speaker:

Anyway, what ended up happening is there were vulnerable, vulnerable versions

Speaker:

of that database out there running, and people, bad actors were able to exploit

Speaker:

it and attack the older REDCap instances.

Speaker:

And then what they did is they just kind of waited around and saw people logging

Speaker:

in, and they somehow got credentials for the Google Workspace admin and kind

Speaker:

of then used that to log into Google Workspace as the admin and then set

Speaker:

up forwarding rules to forward pretty much all emails in the company or

Speaker:

in the institution to a random email address, and it was unmonitored, and

Speaker:

I think it was running for quite a while before they realized that it was

Speaker:

like over a year.

Speaker:

Yeah

Speaker:

yeah.

Speaker:

so this was a multi- multi-stage, it was a three-stage attack, right?

Speaker:

So the initial identification of the, vulnerable versions, which were

Speaker:

running in parallel with the newer versions, which is just bad, right?

Speaker:

and then, g- the credentials, and then using those credentials to log

Speaker:

into Gmail, and then using that to then do something else, which was

Speaker:

essentially exfiltration, right?

Speaker:

So is that, does that make it a four-stage?

Speaker:

I think that makes it a four-stage attack.

Speaker:

That is very, studious.

Speaker:

would that be the-

Speaker:

Yeah.

Speaker:

Could we also talk about the fact that they also made it such that if someone

Speaker:

tried to upgrade the RedCap instances, it would just redeploy the malware again

Speaker:

and just keep running over and over, and so you could never really fix it?

Speaker:

Good times.

Speaker:

are you impressed, Mike, with that, with that attack?

Speaker:

No.

Speaker:

it's, it's c- common progression of an attack and common creativity.

Speaker:

you know, they were, they were lucky because they found these vulnerable

Speaker:

systems that were out there and, and they were out there intentionally.

Speaker:

They, wanted these older systems out there to ensure usability and

Speaker:

accessibility from, you know, you know, the lowest common denominator.

Speaker:

so yeah, I'm not, not so impressed.

Speaker:

the same, same playbook that most, most bad guys are gonna follow, the,

Speaker:

the, the attack, you know, methodology.

Speaker:

just, they've, they've, they found a vulnerable system

Speaker:

and they took advantage of it

Speaker:

It's like going in and finding Windows XP systems out there.

Speaker:

Come on, if you're running Windows XP at this ti- date, right?

Speaker:

Yep.

Speaker:

some of the server versions, yeah

Speaker:

Could be, what was it?

Speaker:

Yeah, Windows XP.

Speaker:

But, that, that's really old, Windows XP.

Speaker:

Meantime, the compromise is less than 10 minutes if you plug it into the internet

Speaker:

I remember when, when, the, one of the most commonly exploited versions of

Speaker:

Windows Server was Windows Server 2000.

Speaker:

And, and I remember that we discovered this in 2013, and I remember saying

Speaker:

that it's a teenager at this point.

Speaker:

It's time for it to move out.

Speaker:

but, all right.

Speaker:

So old version's bad, but, let's talk about, Mike,

Speaker:

What does this have to do with MFA?

Speaker:

we're getting to the MFA.

Speaker:

So Mike, let's talk about, first why MFA is so important, right?

Speaker:

this is another story.

Speaker:

That story is if they simply had implemented MFA for their

Speaker:

Gmail instance, which by the way, I believe Gmail now requires.

Speaker:

Google Workspace

Speaker:

Google Workspace, requires MFA now, right?

Speaker:

I am… Every time I've set up, even if you don't do like the full MFA,

Speaker:

it's gonna require, you to v- verify who you are, all over the place.

Speaker:

But let's, Mike, I'd like to talk about the concept of social

Speaker:

engineering, which is a very common way that, the, the bad guys are using

Speaker:

phishing, to get, to get credentials.

Speaker:

So you want, you wanna talk about that?

Speaker:

What, what did we talk about that?

Speaker:

There's a lot of different ways.

Speaker:

So it's just, it's understanding your, your victim.

Speaker:

so doing your homework.

Speaker:

So, if you're gonna attack a particular organization or group or system

Speaker:

or you're gonna go research them.

Speaker:

what are their hobbies?

Speaker:

What, what does their social media footprint look like?

Speaker:

What does their credit look like?

Speaker:

What is, what kind of car do they drive?

Speaker:

Where do their kids go to school?

Speaker:

you're gonna find something out of all your research that

Speaker:

is common human interaction.

Speaker:

like, "Hey, my kid goes to school with your kid, and they gave me your email to

Speaker:

see if they could have a play date," or, "Timmy left his lunchbox," or something.

Speaker:

You know, that's, that's kind of, no, no pun intended, but elementary, but

Speaker:

that's, that's how you get people's first response, and that's really what you're

Speaker:

looking for, is that first response.

Speaker:

And in some cases, your social engineering, attack, y- you're

Speaker:

only, you only get one response, so sometimes you gotta be pretty good.

Speaker:

But at the same time, you know, statistically speaking, if your,

Speaker:

your target audience is large enough, statistically you've got

Speaker:

about a 20% or better success rate.

Speaker:

So if I send out a million email… Well, if I send out 10,000 emails, you know,

Speaker:

20% of 10,000 is still a good number.

Speaker:

I just need one, right?

Speaker:

In an organization, I just need one person to click on something that's gonna either

Speaker:

give me, harvest their credentials, or they are going to willingly give it to me.

Speaker:

Like, "Curtis, this is Mike from the IT department.

Speaker:

we have a new help desk, i- interface.

Speaker:

below is the link to automatically submit tickets or, or check on the

Speaker:

status of a, of, of a, of a help call.

Speaker:

here's our new 800 number.

Speaker:

it's gonna be great.

Speaker:

We're looking forward to improving service and, and solving your problems faster."

Speaker:

Mike, don't give people ideas, Mike

Speaker:

this is the old- this is one of the oldest ones, the help desk one.

Speaker:

But, you know, click here or, open this attachment to, to, for your

Speaker:

chance at winning one of 20 Starbucks gift cards for being the first one to

Speaker:

write a review on the IT department service, you know, level of service.

Speaker:

and you do.

Speaker:

And so, you know, maybe I've got a… Next, next thing that happens

Speaker:

is I've gotta enter my email address and log into the network.

Speaker:

Like, "Please verify your credentials so we know it's you and not, not your

Speaker:

kids or your neighbor." So it's, you know, email phishing is getting a user

Speaker:

to interact with the email in order to either automatically harvest or, prompt

Speaker:

them to provide, credentials because it looks legitimate or, or it appeals to

Speaker:

their humanity or, you know, I want my kid's lunchbox back or whatever it is

Speaker:

I remember one time, and, to this day I don't know if this was a successful

Speaker:

phishing attack or if this was a successful test of my ability to, or

Speaker:

inability to recognize a phishing attack.

Speaker:

When I worked at a former employer, they, they had some sort of incident

Speaker:

where we were given free, we were gonna get free credit monitoring for a while.

Speaker:

And right at that moment is when I got a, a contact from, "Hey, we're gonna,

Speaker:

sign up for your free credit monitoring.

Speaker:

All we need is what?

Speaker:

Your name, your birth date and your Social Security number." And I found

Speaker:

out that it was not, the company indeed that was contacting me.

Speaker:

But it was s- it was so expertly timed that I fell for it.

Speaker:

And to this day, I don't know if, I gave all my, the three pieces of

Speaker:

information that they want all in one go, or if it was just, them testing,

Speaker:

You… But here's a, here's a question for you, Curtis, and also Mike.

Speaker:

At this point, don't you just assume everyone has it out there?

Speaker:

Like, that information's just out there anyway?

Speaker:

Yeah, I kind of joke that I, I, I protect myself from identity

Speaker:

theft by maintaining bad credit.

Speaker:

I mean, you're- you've got access to my stuff, you just don't wanna use it

Speaker:

I like that.

Speaker:

by the way, it's technically not on topic, but I have all my

Speaker:

credit reports locked, right?

Speaker:

And that, I think that's a life, thing that everybody else should have, is

Speaker:

that, in the rare instances where you're actually opening new credit, you can

Speaker:

unlock it for 24 hours, do the thing, and, in fact, most of them allow you,

Speaker:

actually can just y- one of the choices is unlock for 24 hours just for that

Speaker:

situation, and that would at least stop those people, if they get access to that.

Speaker:

Just a note to my US listeners, all three credit reporting agencies

Speaker:

are required by law to allow you to freeze your credit report for free.

Speaker:

So I the, I can't recommend this strongly enough.

Speaker:

It's not technically related to the, um, to this situation, but

Speaker:

it's just something that a lot of people don't realize is there.

Speaker:

You log into Experian, Equifax, and transunion.com you know, get a

Speaker:

login if you don't already have one, log in, and then look for freeze.

Speaker:

You may have to look around for it.

Speaker:

Honestly, some of them really hide it.

Speaker:

But it is there, it's required by law, and then freeze it.

Speaker:

It does mean that when you apply for credit, you will get you will

Speaker:

get initially told, "Hey, you need to go unfreeze your report."

Speaker:

It's a minor inconvenience for the, hopefully, infrequent action of

Speaker:

you actually applying for new credit.

Speaker:

And this is a big identity theft thing that you can do.

Speaker:

I'd love to hear, for those of you are, that are from other countries, I'd

Speaker:

love to hear in the YouTube comments, uh, what you do in your country.

Speaker:

But so you just freeze it and it stays frozen.

Speaker:

And then some of them, and I prefer these, actually allow you to do a temporary

Speaker:

unfreeze, uh, or thaw, if you will.

Speaker:

I actually use the word a lock my c- uh, credit, uh, they actually have a credit

Speaker:

lock, and they will charge you for it.

Speaker:

It does exactly the same thing as a freeze.

Speaker:

And, and by the way, when you're logging into these pages, they all want you to

Speaker:

pay for a membership, but they all, they just immediately throw that in your face.

Speaker:

Just close that out to, These companies are already making enough off of you.

Speaker:

You don't need to, uh, sign up for a membership.

Speaker:

Um, signing up for a credit monitoring service, that's

Speaker:

an entirely different thing.

Speaker:

But anyway, so freeze your credit reports unless you are applying for credit.

Speaker:

And again, I'd love to hear comments from other listeners from other countries

Speaker:

and yeah, I agree, Prasanna, you just assume that all that stuff's out there.

Speaker:

but for the record, I do still have my Facebook birthday and my real birthday.

Speaker:

I don't wanna make it easy for them.

Speaker:

so all right.

Speaker:

So that, there's, so basically 'cause social engineering is just a, a

Speaker:

variety of tactics, as you said, to get people to, either directly give

Speaker:

you the information you're looking for or to get, or to, basically just

Speaker:

open the door in some way to develop a relationship in some way so that you

Speaker:

can then at some point eventually get the, the thing that you're looking for.

Speaker:

I can think of another, of a story that I saw Kevin Mitnick telling once where

Speaker:

he talked about, he, they had a way where they would in, they would find a person

Speaker:

of note in an, in, in an environment, and they would invite them to speak at

Speaker:

a conference, a non-existent conference.

Speaker:

and then they would say, we just need to do a quick Zoom interview with you prior

Speaker:

to the thing to talk about, whatever." And they give them a Zoom link, and it's

Speaker:

a bad Zoom link, and that link downloaded the, the, the dropper, to do the bad

Speaker:

thing, and then took them to Zoom.

Speaker:

so the person had no idea that anything had just happened, and they just, at

Speaker:

that point, they were just at, they were completely controlling their computer.

Speaker:

So yeah,

Speaker:

Yeah,

Speaker:

engineering, yeah.

Speaker:

What's that?

Speaker:

it's kinda like a s-spoof in the middle.

Speaker:

Yeah

Speaker:

bank, bank, bank account logins are the same way.

Speaker:

the most, the, the cl- the most recent one that I've seen that's pretty clever

Speaker:

is, you know, when, when you get a, a phishing email and you wanna report it

Speaker:

as phishing, know, there's the button at the top that says, "Report as phishing."

Speaker:

Yeah

Speaker:

Well, bad guys are sending phishing emails with the report

Speaker:

phishing button in the email.

Speaker:

So you, you know it's bad, it looks bad.

Speaker:

I'm gonna click the mu- button to report it as bad, but clicking that button is

Speaker:

the trigger for the malware in the email.

Speaker:

Oh, man

Speaker:

Yeah

Speaker:

Tell you what, man, that, that's just not good.

Speaker:

hang on.

Speaker:

Let me pull up my, All right.

Speaker:

let's talk about, Fido2, right?

Speaker:

do you wanna talk about what Fido Fast Identity Online

Speaker:

Well, there you go.

Speaker:

It's kinda like the one-time password stuff, but it's a little more permanent.

Speaker:

so strong, a, a good, a good FIDO, profile, and I think there's, there's

Speaker:

different versions of FIDO out now too.

Speaker:

in fact, I think it's called FIDO2.

Speaker:

the, the idea though is something more than, you know, just your

Speaker:

username and password, but also something outside of just an email

Speaker:

or a text message you would get.

Speaker:

Could you give examples, Mike?

Speaker:

Like based on what you just said, like what would that potentially encompass

Speaker:

Well, so traditional MFAs, you know, an SMS message or a

Speaker:

one-time password or, an email.

Speaker:

FIDO is, is true encrypted token.

Speaker:

you can install it on a, on your laptop or your phone, but it has to be paired,

Speaker:

so it's public and private keys.

Speaker:

So it's got a… Your, your public key's out there, so if I wanted to have a

Speaker:

communication with Prasanna, in order to encrypt that, you would get my public

Speaker:

key, I would get your public key, and then our private keys would match those up.

Speaker:

and those, those private keys are on our device.

Speaker:

so it's, it's kind of an old school asymmetric encryption approach that

Speaker:

they've just kind of put a new name on it and attached it to a new way

Speaker:

of talking and encrypting our stuff.

Speaker:

But it's, it's really re- it's, it's designed to be transactional instead

Speaker:

of like normal email communication.

Speaker:

It's, it's a, it's assigned to a authentication or a purchase or,

Speaker:

it's more transactional

Speaker:

When we get to the actual, action points or, acti- when we get to the actual ac-

Speaker:

action items, it's gonna be really simple.

Speaker:

So we just need to drive home the point here of why this is such a big deal.

Speaker:

and I think the ArcGIS story is another scary one where there was

Speaker:

an entire year that went by where they had control of something, and

Speaker:

that all started with what, Mike?

Speaker:

Well, the, the, the Flax Typhoon, and, and I think that's the, the case

Speaker:

we're talking about here, is actually the, the name of But the, the initial

Speaker:

identification of this particular attack was because of their botnet.

Speaker:

and so looking for vulnerable systems, looking for a way in, Flax Typhoon is

Speaker:

primarily a, an espionage campaign, s- so it's not so much access as it

Speaker:

is true information and, and, and more specifically government-level information.

Speaker:

So, pretty confident that Flax Typhoon is run by the Chinese government.

Speaker:

targets were primarily government organizations,

Speaker:

Taiwan, Asia, America, Canada.

Speaker:

the, the,

Speaker:

the initial compromise was VPNs and firewalls, vulnerabilities, web servers.

Speaker:

and then from there, that compromise allowed them to based on tools and

Speaker:

s- and software available to them, so living off the land, type of attack.

Speaker:

So, you know, PowerShell, Python, Sysinternals, RDP,

Speaker:

from one machine to the next.

Speaker:

one of the things that makes me smile about this, this particular campaign is,

Speaker:

is all of the fun cyber threat acronyms and, and code words, like Juicy Potato.

Speaker:

so,

Speaker:

Sweet potato

Speaker:

so, so many of the tools and, and techniques in, in, in Flax Typhoon were,

Speaker:

were pretty kind of… I, I don't know who came up with the words or the code names.

Speaker:

Mimikatz has been around for a while.

Speaker:

That's a good credential harvesting.

Speaker:

Anybody that hears Mimikatz knows it's, it's associated with,

Speaker:

with malware and cyber attacks.

Speaker:

But the privilege escalation tool that they used was called Juicy Potato.

Speaker:

and some of the web shells, like one of the web shells was called, China Chopper.

Speaker:

just so just some, some fun acronyms and, and, and terminology.

Speaker:

But, was actually big problem

Speaker:

at some, point, didn't they get access to an administrator, like

Speaker:

login again that, that again didn't seem to have any MFA on it?

Speaker:

they did, and some of those systems were like IoT devices, like cameras.

Speaker:

So if you remember back in the day, I'm talking, man, had to have

Speaker:

been almost 10 years ago or more, the Mirai, the Mirai, botnet.

Speaker:

Got it.

Speaker:

Yep

Speaker:

And so in Flax Typhoon, they w- their botnet was called Raptor Train.

Speaker:

and so the Raptor Train using the Mirai-type virus compromised hundreds of

Speaker:

thousands of IoT devices in this campaign.

Speaker:

And so that was cameras, routers, switches, network storage devices.

Speaker:

so that Mirai, i- you remember back, it, it, in that case, M- the Mirai

Speaker:

botnet was successful because some of the credentials for those devices were

Speaker:

hard-coded on the chips, and the, the manufacturer of those chips didn't care.

Speaker:

They're like, "I just produce chips.

Speaker:

It goes in something, I have no control over that." so very similarly, this

Speaker:

attack group and their botnet, were able to leverage hard-coded credentials to

Speaker:

get access to the device, and in some cases, it was root level device, access.

Speaker:

And

Speaker:

Oof

Speaker:

other cases, it got them on the device where they were then able to deploy

Speaker:

Mimikatz or use some of these other, available tools to, to harvest credentials

Speaker:

The way I would put all of that together is that the, the bad actors have a,

Speaker:

a seemingly infinite number of ways that they can harvest credentials.

Speaker:

We talked about phishing, we talked about using old versions of

Speaker:

software that have vulnerabilities, and we talked about just, botnets.

Speaker:

th- they just have a seemingly… and d- I think we pr- we've probably

Speaker:

just scratched the surface, Mike?

Speaker:

Of, a seemingly infinite,

Speaker:

Well, it is seemingly infinite, because we don't do… We don't

Speaker:

think like they do, and they do this 24 hours a day, seven days a week.

Speaker:

we only do it 8:00 to 5:00, Monday through Friday, a lot,

Speaker:

as, as a normal user, right?

Speaker:

and probably not the full eight hours.

Speaker:

We're, we're doing other stuff, or just not focused.

Speaker:

But yes, it is seemingly un- unending, and, and ever-evolving

Speaker:

ways of harvesting our credentials

Speaker:

Prasanna

Speaker:

have a question for you now.

Speaker:

Sure

Speaker:

So we've talked about all these scary ways that they're always gonna be

Speaker:

ahead of us, that we're never gonna be able to catch up because we don't have

Speaker:

the time or effort or expertise to be focused on securing things all the time.

Speaker:

S- so like, do we just like sort of call it quits, unplug

Speaker:

ourselves from the internet, and just go back to sticks and fire

Speaker:

that,

Speaker:

out in the-

Speaker:

that's a great question, Prasanna, but that is the only way to

Speaker:

have a truly system, right?

Speaker:

I think my point, and Mike, feel free to enhance this point, but my

Speaker:

point is you have to assume that the bad guys are going to get someone's

Speaker:

credentials in your environment.

Speaker:

And so the idea, this is the whole point of MFA, right?

Speaker:

The whole idea of MFA is that, that th- there is a seemingly limitless number

Speaker:

of ways, you know, that the bad guys can get, the other is, the, the purchasing

Speaker:

of the, the dumps, the credential dumps that are available online, right?

Speaker:

th- there's so many ways for them to get access to credentials that you are

Speaker:

committing, I'll say this again, you are committing professional malfeasance

Speaker:

if you are allowing access to important accounts without MFA turned on, right?

Speaker:

you're noticing this, and we're gonna go a little bit, it's, we're gonna

Speaker:

talk about phishing resistant MFA.

Speaker:

But you've noticed this happen in your personal life, Prasanna?

Speaker:

can you think of what's happened to you over the last, I wanna say

Speaker:

10 years with things like your bank, with things like Gmail, with

Speaker:

Oh, yeah, everything, yeah, everything's going multi-factor authentication, right?

Speaker:

It's you log in, it sends something, because now you also have phones, right?

Speaker:

And so everything gets sent to your phone where it's like, "Hey, did you try to log

Speaker:

in on this laptop? Accept or deny from your phone or some other device," right?

Speaker:

And so you see this happening because it's becoming easier, I guess.

Speaker:

Do you, do you think it's becoming easier to enforce MFA versus before?

Speaker:

Like I remember when I was working and you'd sort of walk around

Speaker:

with the little key fob, right?

Speaker:

With the rotating code, and that you always had to have it in order

Speaker:

to be able to log in, and if for some reason it wasn't there or

Speaker:

the battery died, you're screwed.

Speaker:

I think MFA has made it a little easier.

Speaker:

And so kind of over the last 10 years, like you're saying, yeah, I think

Speaker:

back then there was nothing, and now it's sort of become commonplace

Speaker:

now I think the difference bet- between back then and now is that we always

Speaker:

have this other thing on us now, right?

Speaker:

We always have our s- we should always have our smartphone with us,

Speaker:

Where's your phone, Curtis?

Speaker:

my phone is right here, sir. Thank you very

Speaker:

Okay.

Speaker:

and by the way my life is, I can't go anywhere without my phone.

Speaker:

My car runs from my phone, so as soon as I step… And which is perfect for me,

Speaker:

'cause I, I got serious, By the way, I've officially been diagnosed with ADHD now,

Speaker:

'cause I had to wait 60 years to find out, "Yeah, Curtis, you got ADHD." So the

Speaker:

fact that I can't leave the house without a phone, I get in my car, that means

Speaker:

I always have my phone with me, right?

Speaker:

'Cause otherwise I definitely would be the guy that's 40 miles away

Speaker:

and going, "Oh, crap, I left my phone back at my house," right?

Speaker:

but yeah, we have that device with us, and now we have a number of

Speaker:

pieces of software, commercial ones like the Symantec VIP, tool.

Speaker:

I know that a couple of my different vendors require that.

Speaker:

or, free versions from Google or Authy or, pr- Mike, you mentioned you use a- another

Speaker:

tool that, you mentioned that I think on, I don't know, a few recordings ago.

Speaker:

You use a, a, a completely different tool.

Speaker:

I don't remember what it was.

Speaker:

It doesn't matter.

Speaker:

But yeah, there are a number of tools.

Speaker:

and yes, there are also the truly secure ones are the, those things that, you

Speaker:

know, the, like the YubiKey, right?

Speaker:

The, that, that is a truly secure, one-time password thing that,

Speaker:

that isn't… the only downside to the phone is potentially somebody

Speaker:

could hack your phone, right?

Speaker:

So if you're seeing this happen in your personal life, and you're in your

Speaker:

professional life, and you're in and you care at all about cybersecurity, if

Speaker:

you've got important accounts that are just sitting there waiting for you to

Speaker:

just log in with no, other authentication, then again, professional malfeasance.

Speaker:

I don't wanna, call you nasty names, but don't know what el- I don't

Speaker:

know what else to say at that point.

Speaker:

Mike, let's talk a little bit about… I know this is something you've

Speaker:

talked about before multiple times.

Speaker:

We talk about this idea of killing the trust button, right?

Speaker:

this is something you talk a lot about.

Speaker:

You w- you wanna talk about that?

Speaker:

Sure.

Speaker:

I think a lot of organizations and a lot of systems and networks have

Speaker:

this inherent trust out in the world that, you know, we need to be able

Speaker:

to, we, we need to be accessible.

Speaker:

we want, Well, and, and there's a couple of reasons for that.

Speaker:

One is just making it easy so that I don't have to go do

Speaker:

custom rules or manage something.

Speaker:

and so that.

Speaker:

Well then, there's also a level of skill required for, in a lot of

Speaker:

cases, for implementing changes that, could filter or restrict access.

Speaker:

So it- it's just easy to, to leave the door open or the doors

Speaker:

unlocked or, or have fewer layers.

Speaker:

I see it a lot where organizations call and say, "Hey, I've got this problem.

Speaker:

I think someone's trying to get me- to me from Germany." I said, "Okay.

Speaker:

Well, we can look into that, but in the, in the meantime, do you guys care

Speaker:

about people from Germany hitting your network?" "No." Well, just block Germany.

Speaker:

Well, that's an easy problem.

Speaker:

It's solved.

Speaker:

then, you know, all right, so there's, there's website traffic,

Speaker:

there's network traffic, there's VPN traffic, there's cloud.

Speaker:

all of those things, and this goes back to, you know, how do

Speaker:

we, how do we better protect ourselves, whether it's MFA or not?

Speaker:

And, and it's, it's really about understanding the risk to us, us as

Speaker:

an individual, us as a, a company, then what kind of things can we put in

Speaker:

place to mitigate those risks, right?

Speaker:

So if, if we're concerned about people stealing our, our users'

Speaker:

credentials, what can we do to reduce the likelihood of that happening?

Speaker:

Well, we could really focus in on who should have the ability to log in.

Speaker:

So even if Curtis's were compromised, if he's logging in

Speaker:

from Germany, it won't work, right?

Speaker:

Right

Speaker:

Well then, all right, so we implement MFA so that… You know, Curtis figures

Speaker:

that out, so he compromises a, a machine in, in the US to log in from

Speaker:

the US, and now the credentials work, but he's being challenged with MFA.

Speaker:

he steals, he steals Prasanna's MFA token by phishing it, sending him a phishing m-

Speaker:

email that gets him to go to a website.

Speaker:

because he's already trusted in his browser, the website

Speaker:

scrapes that MFA token.

Speaker:

Now I have all three things, U- ID, password, MFA.

Speaker:

But I can configure my system to only allow one login, no concurrent logins.

Speaker:

Definitely no logins across, know, land speed travel distances.

Speaker:

so there's… I mean, there's tons of things you can do

Speaker:

You've

Speaker:

to mitigate all of this

Speaker:

before, right?

Speaker:

Right.

Speaker:

It just takes time and effort and skill and an understanding, and all

Speaker:

of that is great on the technical side until you implement it and then you

Speaker:

get your users going, "Well, that's too difficult, and I don't like that."

Speaker:

And so now you've got the political fight, and a lot of technical people

Speaker:

will give up on the political fight.

Speaker:

It's just like, you know what?

Speaker:

as you were talking… Oh.

Speaker:

it's not worth losing my job over

Speaker:

As you were talking through that last point, Mike, I was just thinking in my

Speaker:

head, I'm like, "Why do all products and companies just do this by default?" And

Speaker:

you hit on it at the very end, right?

Speaker:

It's like users are gonna complain.

Speaker:

There's gonna be friction in their experience.

Speaker:

They're not gonna like it, and then you're gonna get so many support tickets.

Speaker:

You're gonna be like, "Whoa, whoa, whoa, what do we do?

Speaker:

Let's go back to the old way."

Speaker:

Yep.

Speaker:

And so it, it comes down to a balance of security and usability from a, a technical

Speaker:

and controls perspective, and then a personal administrative, it's do I wanna,

Speaker:

do I wanna fight this battle or do I wanna live to, you know, work another day?

Speaker:

'cause I mean, your time's, your time's limited in either way, in either case,

Speaker:

but would you rather be fired because you, you tried to do something good, or you

Speaker:

got fired because you didn't do something good and the, the company was compromised

Speaker:

and you were fired for that reason?

Speaker:

Yeah

Speaker:

there's… I mean, it's a struggle

Speaker:

I think a place to start, I, the- I've seen that.

Speaker:

I've seen that where, and I've seen it in backups, right?

Speaker:

I've seen it where you're trying to do the thing and you get the group that's like,

Speaker:

"Ah, I don't wanna do the thing," right?

Speaker:

Whatever, whether it's, in my case, in backups, I go all the way back to

Speaker:

when I was that oil and gas company and, I was just trying to enable

Speaker:

backups for the first time this really big Oracle database, right?

Speaker:

that was really important.

Speaker:

It had never been backed up, and it involved me doing a couple of things

Speaker:

that the DBA was fighting me on.

Speaker:

I, I, it's in, in, it- I can't fathom the idea of having a m- a

Speaker:

valid system that isn't backed up and anybody being okay with that.

Speaker:

But still, that would happen.

Speaker:

The same thing happens in cybersecurity, right?

Speaker:

Ca- do you think it would be easier to at least, and perhaps more important to

Speaker:

start with administrative accounts, right?

Speaker:

privileged accounts, right?

Speaker:

It's, at first off it's a smaller number, and possibly it's a different group

Speaker:

of people that will have some better understanding of the importance of this.

Speaker:

does that sound like a good idea?

Speaker:

Absolutely.

Speaker:

You can, you can log and alert on, privileged account use, whether

Speaker:

it's an admin or a service account.

Speaker:

and all of that stuff should be tracked, both successful and failed

Speaker:

login attempts for privileged accounts

Speaker:

Now, the things that you suggested earlier, th- those all sounded great,

Speaker:

but they sounded complicated, right?

Speaker:

it sounds easy to turn off Germany.

Speaker:

It turns out easy to turn off Russia.

Speaker:

but the, some of the o- other stuff, it sounded like it starts to get complicated.

Speaker:

So my question is, you're like, it's not complicated for you, Mike," but I'm just

Speaker:

saying for maybe the aver- person, is

Speaker:

It's really not

Speaker:

are there tools that can help this be easier to do?

Speaker:

There's tons of tools, but then you've gotta go learn a tool.

Speaker:

a lot of, a lot of these, capabilities are built into stuff

Speaker:

you probably already pay for.

Speaker:

So your normal Windows machine, Windows 11 as an example, you've got a

Speaker:

firewall, you've got Windows Defender.

Speaker:

All that stuff comes with the, your Windows license.

Speaker:

watch a YouTube video on how to configure it to protect you better.

Speaker:

You'll learn, you'll learn everything you need to know in, like, 15 minutes, and

Speaker:

Could you…

Speaker:

walk you through it.

Speaker:

If you're an administrator in Office 365 as an example, there are hundreds of hours

Speaker:

of training videos for free that walk you through all this stuff step by step.

Speaker:

And if you don't wanna watch a video, it's all lined out in a nice Microsoft

Speaker:

document that'll s- take you through it, step one through whatever with links.

Speaker:

you click the link, and it takes you right into your admin console,

Speaker:

the exact right spot to do it.

Speaker:

there are tools in Office 365 that allow you to test.

Speaker:

Like, I wanna turn this on, let me test it make sure I don't, you know,

Speaker:

break the, break the environment.

Speaker:

pick a user.

Speaker:

Start with, start with your admin account

Speaker:

Yeah

Speaker:

So, so the, here's my biggest thing, like given it's 2026 and we're in

Speaker:

the age of AI, like why don't you just go ask like Claude or Gemini

Speaker:

or take your pick of AI assistant

Speaker:

even, even, more succinctly with Microsoft, you know what?

Speaker:

Buy a Copilot license, it's like $100 a year, and tell Copilot now

Speaker:

that you're the licensed- you're the admin and you've got a Copilot

Speaker:

license, ask Copilot to help you.

Speaker:

It has the same privileges that you do and can see all that stuff

Speaker:

I had a mission critical system that went down yesterday, right

Speaker:

at the very inopportune time.

Speaker:

You know what that was?

Speaker:

Your TV

Speaker:

Yeah.

Speaker:

My TV, stopped working just before we had invited a bunch of people over to

Speaker:

, watch the World Cup final, and I used AI.

Speaker:

I was like, I got three different pieces.

Speaker:

I got the Apple TV box, I got the soundbar, and it's going through the

Speaker:

soundbar up to the TV," and I hadn't used this particular TV in a while.

Speaker:

And, I d- just sat there, worked through.

Speaker:

I was like, "I got this,"… The- these are the brands of the

Speaker:

things I have, and Claude, just worked me through, fixing it, and

Speaker:

Yes, I've been replaced.

Speaker:

'Cause last time

Speaker:

I was d- done in a few minutes.

Speaker:

You b- By the

Speaker:

I helped you troubleshoot this, I remember.

Speaker:

I completely agree that, that is definitely, a, a great place to start.

Speaker:

because all of those phishing-resistant things that you talk about… And by

Speaker:

the way, d- let's just talk about, why isn't MFA by itself good enough?

Speaker:

Why can't we just turn on MFA?

Speaker:

And there are a bunch of reasons, right?

Speaker:

you talked about stealing session credentials.

Speaker:

That is a possibility, right?

Speaker:

other things are, the, the MFA exhaustion, right?

Speaker:

Which is something where, you just bombard the, you meaning the, the, the bad guy,

Speaker:

just bombard the person with so many inf- MFA requests that at some point they just

Speaker:

respond just to make it go away, which is a horrible response, but I think we

Speaker:

can agree that there's certain groups of people that would respond that way, right?

Speaker:

And that's why we have to add this extra logic behind MFA, to make

Speaker:

it more resistant to phishing.

Speaker:

there's still that, that usability and culture part behind it.

Speaker:

I mean, you talked about MFA exhaustion.

Speaker:

Do you have locking your house exhaustion?

Speaker:

Right?

Speaker:

You're gonna go back home because you forgot to lock the front door.

Speaker:

You care.

Speaker:

You have a responsibility.

Speaker:

MFA should, should be the same, if you're not requiring MFA every time they log in,

Speaker:

then you've diminished the value of it.

Speaker:

But then also on the back end, on the IT side, or the technical

Speaker:

side, there are controls for limiting the lifespan of MFA also.

Speaker:

So Mike's been logged in for 20 hours on the same MFA token.

Speaker:

That shouldn't l- you know, they should expire at some point,

Speaker:

The…

Speaker:

can configure that

Speaker:

Do you know if they, 'cause I know a lot of websites, right?

Speaker:

It's like you log into your bank and you enter and it's like, "Oh, remi-

Speaker:

reme- remember me for next time," so you don't get the MFA again.

Speaker:

Do you know, Mike, and that's like the exact opposite of

Speaker:

what you want, right, from MFA.

Speaker:

And so I guess the question I had is, Mike, in these tools that you were talking

Speaker:

about where you can set these policies, do you know if they also have that

Speaker:

ability to say, "Hey, by the way, never allow a user to say trust this device"?

Speaker:

Yeah, so that was a group policy you can push out.

Speaker:

So there's a couple things.

Speaker:

As a, as an IT administrator, I can restrict what browsers you can use.

Speaker:

I don't want you to use, Firefox, just as an example.

Speaker:

So you can only use Edge and Chrome, right?

Speaker:

So I-- there's, there… You can, you can push policies out like that, and

Speaker:

then within that policy and within MFA, you can, you can select never allow or

Speaker:

prohibit, you can prohibit users from saving, MFA credentials in browsers.

Speaker:

Yep.

Speaker:

And, and any other credentials.

Speaker:

You can prohibit them from saving credentials in, in the

Speaker:

Yeah

Speaker:

in general.

Speaker:

Yep.

Speaker:

My websites

Speaker:

Or credit, or payment

Speaker:

Explorer

Speaker:

Oops.

Speaker:

Netscape.

Speaker:

That's gave… Wow, you took us back there.

Speaker:

All right, MFA is really important.

Speaker:

and what… as long as we're talking about it, we'll just throw in passkeys is

Speaker:

actually, are actually better than MFA.

Speaker:

But, today we're talking about least have MFA, for goodness sakes.

Speaker:

And also, look into being more resistant to phishing, these extra

Speaker:

features that Mike talked about, to look for things like impossible travel.

Speaker:

how is he in both in San Diego and London all at the same time, right?

Speaker:

that's what they call impossible travel.

Speaker:

And why is he… i- if you can add some logic of like, why is he never

Speaker:

logs in at 3:00 in the morning.

Speaker:

Why is he logging in at 3:00 in the morning?

Speaker:

Perhaps, just add an extra level of security when weird things happen, right?

Speaker:

all right.

Speaker:

thanks, Prasanna and Mike, once again

Speaker:

It's always fun

Speaker:

Never enough time to say all I wanna say, but I'm glad I could contribute

Speaker:

Yeah, All right.

Speaker:

And thanks, to everyone out there listening.

Speaker:

you're why we do this.

Speaker:

That is a wrap

Speaker:

The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston.

Speaker:

If you need backup or DR consulting, content generation, or expert witness

Speaker:

work, check out backupcentral.com.

Speaker:

You can also find links for my O'Reilly books on the same website.

Speaker:

Remember, this is an independent podcast, and any opinions that

Speaker:

you hear are those of the speaker and not necessarily an employer.

Speaker:

Thanks for listening