Phishing resistant MFA stops the attacks that regular MFA can't catch, and this episode breaks down exactly how, and why it matters right now.
Regular multi-factor authentication was supposed to be the fix for weak passwords. But session token theft, MFA exhaustion attacks, and social engineering have all found ways around it. On this episode, Prasanna, Dr. Mike Saylor, and I dig into what phishing resistant MFA actually means, and how FIDO2 and passkeys close the gaps that plain old MFA leaves open.
We start with a real attack: a vulnerable REDCap database led to stolen Google Workspace admin credentials and a year of unmonitored email forwarding. From there we cover how social engineering works, why a "report as phishing" button became an attack vector itself, and why freezing your credit reports is one of the easiest things you can do for yourself today.
Then we get technical: FIDO2, public and private key pairs, the Flax Typhoon espionage campaign, and the Raptor Train botnet that compromised hundreds of thousands of IoT devices using hard-coded credentials.
In the back half, Mike introduces the idea of killing the trust button, the default-open settings most networks never bother to close. We talk about blocking traffic by country, limiting concurrent logins, expiring MFA tokens, and why starting with your administrative accounts is the easiest place to build momentum.
If you're the person responsible for an environment where important accounts are still sitting there with no MFA, we've got a name for that, and it's not a nice one.
CHAPTERS:
0:00 - Cold Open
1:31 - Welcome to the Show
4:12 - The REDCap/Google Workspace Attack
8:38 - Social Engineering: How Attackers Do Their Homework
13:06 - Freeze Your Credit Reports
15:29 - The Kevin Mitnick Fake-Conference Trick
16:29 - The "Report Phishing" Button Trap
16:55 - What Is FIDO2? (Phishing Resistant MFA Explained)
18:58 - Flax Typhoon and the ArcGIS Campaign
21:35 - The Raptor Train Botnet
23:58 - Can We Just Unplug From the Internet?
24:43 - Professional Malfeasance: No More Excuses for Skipping MFA
26:10 - Phones, YubiKeys, and Real-World MFA Tools
28:05 - Killing the Trust Button
28:55 - Blocking Countries and Reducing Risk
32:51 - Start With Your Administrative Accounts
35:17 - Tools (and AI) That Make This Easier
36:36 - Why MFA Alone Isn't Enough: MFA Exhaustion
38:13 - Locking Down Browsers and "Trust This Device"
39:27 - Passkeys, Impossible Travel, and Final Takeaways
Thanks for watching. If this helped you, subscribe for more episodes on backup and cyber recovery.