Episode Details
Back to Episodes
Phishing Resistant MFA: Regular MFA Isn't Enough Anymore
Description
Phishing resistant MFA is the difference between a bad guy getting one email address and a bad guy getting your entire company's inbox. On this episode, Prasanna, Dr. Mike Saylor, and I dig into why plain old multi-factor authentication isn't the finish line anymore; it's the starting line.
We open with a real attack: a vulnerable REDCap database, stolen Google Workspace admin credentials, and email forwarding rules quietly running for over a year before anyone noticed. From there Mike breaks down how social engineering actually works (the research bad guys do on you before they ever send an email) and why "report as phishing" buttons have themselves become an attack vector. I share the story of the free credit monitoring scam that got me, and why freezing your credit reports is one of the best five-minute security moves you can make.
Mike then walks through FIDO2 and passkeys, why they're built on old-school public/private key encryption, and why they're transactional instead of just another code sent to your phone. We cover the Flax Typhoon espionage campaign, the Raptor Train botnet, and how hard-coded credentials on IoT devices turned into root-level access for a foreign intelligence operation.
Then Mike introduces "killing the trust button," which is phrase for the idea that most networks default to open, and every one of those defaults is a decision somebody made without thinking about the risk. We talk about blocking traffic by country, limiting concurrent logins, expiring MFA tokens, and why starting with your administrative accounts is the easiest place to build momentum. And yes, we talk about just asking an AI assistant like Copilot or Claude to walk you through turning this stuff on, because you probably already have these tools and don't know it.
We close on why MFA by itself still isn't enough — session token theft, MFA exhaustion attacks, and the "remember this device" setting that undoes everything you just set up. If you're the person responsible for an environment with important accounts sitting there with no MFA, we've got a name for that, and it's not a nice one.
Chapters:
0:00 – Cold Open
1:31 – Welcome to the Show
4:12 – The REDCap/Google Workspace Attack
8:38 – Social Engineering: How Attackers Do Their Homework
13:06 – Freeze Your Credit Reports
16:55 – What Is FIDO2? (Phishing Resistant MFA Explained)
18:58 – Flax Typhoon and the Raptor Train Botnet
24:43 – Professional Malfeasance: No More Excuses for Skipping MFA
28:05 – Killing the Trust Button
32:51 – Start With Your Administrative Accounts
36:36 – Why MFA Alone Isn't Enough: MFA Exhaustion
39:27 – Passkeys, Impossible Travel, and Final Takeaways