Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

EP40 2021: Phishing is Solved?

EP40 2021: Phishing is Solved?

FromCloud Security Podcast by Google


EP40 2021: Phishing is Solved?

FromCloud Security Podcast by Google

ratings:
Length:
32 minutes
Released:
Oct 25, 2021
Format:
Podcast episode

Description

Guests Elie Bursztein, security, anti-abuse and privacy researcher @ Google Kurt Thomas, security, anti-abuse and privacy researcher @ Google Topics: Can we say that “Multi-Factor Authentication - if done well - fixes phishing for good” or is this too much to say? What are the realistic and seen-in-the-wild bypasses for MFA as a protection? How do you think these controls fare vs top tier attackers (clearly, they work vs commodity threats)? What do we know about burden vs value of MFA today? What can we realistically do to increase MFA/2FA adoption to the 90%s? Can we share anything about what we’re seeing as industry benchmarks on MFA adoption so far?  We’ve seen a lot of ugly debates over the value of SMS as MFA, what is your research-based take on this? Resources: Google Titan Security Key “Malicious Documents Emerging Trends: A Gmail Perspective” (RSA 2020) “New research: How effective is basic account hygiene at preventing hijacking” “New Research: Lessons from Password Checkup in action” “New research reveals who’s targeted by email attacks” “New research: Understanding the root cause of account takeover” “"Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaigns” "Tales from the Trenches: Using AI for Gmail Security" (ep28)
Released:
Oct 25, 2021
Format:
Podcast episode

Titles in the series (100)

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit. We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.