The Passwords Are the Problem with Thierry Gagnon and Philippe Desmarais
Release Date: 10/18/2023
Easy Prey
The intersection of AI and cybersecurity is changing faster than anyone expected, and that pace is creating both incredible innovation and brand-new risks we’re only beginning to understand. From deepfake ads that fool even seasoned security professionals to autonomous agents capable of acting on our behalf, the threat landscape looks very different than it did even a year ago. To explore what this evolution means for everyday people and for enterprises trying to keep up, I’m joined by Chris Kirschke, Field CISO at Tuskira and a security leader with more than two decades of experience...
info_outlineEasy Prey
Publicly available data can paint a much clearer picture of our lives than most of us realize, and this episode takes a deeper look at how those tiny digital breadcrumbs like photos, records, searches, even the background of a Zoom call can be pieced together to reveal far more than we ever intended. To help break this down, I’m joined by Cynthia Hetherington, Founder and CEO of The Hetherington Group, a longtime leader in open-source intelligence. She also founded Osmosis, the global association and conference for OSINT professionals, and she oversees OSINT Academy, where her team trains...
info_outlineEasy Prey
Sometimes we forget how much trust we place in the little things around us like a lock on a door or a badge on someone’s shirt. We see those symbols and assume everything behind them is safe, but it doesn’t always work that way. A person with enough confidence, or the right story, can slip through places we think are locked down tight, and most of us never notice it’s happening. My guest today is Deviant Ollam, and he’s one of the rare people who gets invited to break into buildings on purpose. He talks about how he fell into this unusual line of work, the odd moments that shaped his...
info_outlineEasy Prey
Fraud today doesn’t feel anything like it used to. It’s not just about somebody skimming a credit card at a gas pump or stealing a check out of the mail. It has gotten personal, messy, emotional. Scammers are building relationships, earning trust, and studying the little details of our lives so they can strike when we’re tired, distracted, or dealing with something big. And honestly, most people have no idea how far it’s gone. My guest, Ian Mitchell, has spent more than 25 years fighting fraud around the world and leading teams in the financial sector. He’s the founder of The Knoble,...
info_outlineEasy Prey
AI has brought incredible new capabilities into everyday technology, but it’s also creating security challenges that most people haven’t fully wrapped their heads around yet. As these systems become more capable and more deeply connected to the tools and data we rely on, the risks become harder to predict and much more complicated to manage. My guest today is Rich Smith, who leads offensive research at MindGard and has spent more than twenty years working on the front lines of cybersecurity. Rich has held leadership roles at organizations like Crash Override, Gemini, Duo Security, Cisco,...
info_outlineEasy Prey
Ransomware isn’t a lone hacker in a hoodie. It’s an entire criminal industry complete with developers, brokers, and money launderers working together like a dark tech startup. And while these groups constantly evolve, so do the tools and partnerships aimed at stopping them before they strike. My guest today is Cynthia Kaiser, former Deputy Assistant Director of the FBI’s Cyber Division and now the Head of the Ransomware Research Center at Halcyon. After two decades investigating global cyber threats and briefing top government leaders, she’s now focused on prevention and building...
info_outlineEasy Prey
Criminals are always adapting. Whether it’s copper wiring stripped from job sites or porch pirates grabbing deliveries in broad daylight, they keep finding new ways to take what isn’t theirs. But maybe prevention isn’t about harsher punishment or more cameras. Maybe it’s about smarter design and understanding what drives people to steal in the first place. My guest today is Dr. Ben Stickle, a professor of criminal justice at Middle Tennessee State University and one of the country’s top researchers on property crime. Before entering academia, he worked in law enforcement, which gives...
info_outlineEasy Prey
Fraud usually gets talked about in numbers like how much money was stolen, how many people were affected, how many cases got filed. But behind every one of those numbers is a person who’s been blindsided, manipulated, or left trying to rebuild trust in others and in themselves. This episode shifts the focus back to those human stories and the fight to protect them. My guest, Freddie Massimi, has spent more than a decade helping scam victims find both financial and emotional recovery, bringing empathy and understanding to a field that too often feels cold and procedural. As a certified...
info_outlineEasy Prey
You think you’d never fall for a scam until you meet someone like Kitboga. He’s a software engineer who’s turned his curiosity about online fraud into a full-time mission to outsmart scammers and protect the people they target. His YouTube channel, The Kitboga Show, has millions of followers and nearly a billion views, thanks to his mix of humor, empathy, and clever ways of exposing how scams really work. In our conversation, Kit opens up about how this all started, what it’s really like to spend hours pretending to be a scam victim, and how organized crime has turned fraud into a...
info_outlineEasy Prey
Everywhere you turn, someone’s trying to fake something like an image, a voice, or even an entire identity. With AI tools now in almost anyone’s hands, it takes minutes, not days, to create a convincing fake. That’s changed the game for both sides. The fraudsters have new weapons, and the rest of us are scrambling to keep up. The real question now isn’t just how to stop scams, but how to know who or what to trust online. My guest today, Bala Kumar, spends his days on the front lines of that battle. He’s the Chief Product and Technology Officer at Jumio, a company working to make...
info_outlineWith the use of passwords, we’re hoping to ensure privacy and security, but sometimes it is at the expense of convenience. As technology changes and biometric databases become more utilized, we need to remember that they may also be hacked.
Today’s guests are Philippe Desmarais and Thierry Gagnon. Philippe is a tech entrepreneur who co-founded Kelvin Zero and currently serves as its CEO, overseeing the company’s strategic direction. He is also a member of the Next Generation Advisory Council at Rockefeller Capital Management. Before creating Kelvin Zero, Philippe played a significant role in various start-ups, focusing on data analytics for political campaigns, remote hardware device management, and cybersecurity.
Thierry Gagnon is co-founder and Chief Technology at Kelvin Zero. He is an expert in software development, malware analysis, cryptography, and reverse engineering. He has been actively involved in the cybersecurity community, participating in renowned competitions and projects such as Malware Information Sharing Platform.
Show Notes:
-
[1:18] - Philippe and Thierry share their backgrounds and their roles in the company they co-founded together, Kelvin Zero.
-
[2:34] - Thierry’s expertise is in cybersecurity but Philippe’s interest was more in crime. They combined their strengths and passions to create Kelvin Zero.
-
[6:18] - Passwords have been around for millennia.
-
[7:24] - We often confuse being smarter with being faster.
-
[9:45] - Passwords are not often attached to an individual. We have so many passwords and can’t actually know them all.
-
[11:53] - We can compromise passwords at scale.
-
[13:20] - The attackers only need to be right once. The defenders need to be right 100% of the time. How can we flip this?
-
[15:47] - The average person is tasked with trying to keep up with cybersecurity and, in most cases, they are not qualified to do this.
-
[17:11] - What does it look like to take a password-less approach?
-
[19:20] - If cybersecurity is done successfully, the opportunities are massive. But regulation holds us back.
-
[21:51] - Once a tech company can serve protection, then companies can focus on their services and products.
-
[24:46] - There are differences between the physical world and the logical world.
-
[28:41] - How do you convince people to share medical data for research when there are constant breaches?
-
[31:33] - Is privacy the same as anonymity?
-
[33:52] - Technology should be able to do what we want it to do, but that’s not the case.
-
[36:36] - In a password-less environment, how can we validate a user?
-
[39:40] - Thierry believes we should get away from the server authenticating because then it is the responsibility of the organization.
-
[43:18] - Sci-fi movies sound far-fetched, but a lot of them predict technology.
-
[46:35] - Thierry and Philippe share their thoughts on what we should be putting our focus on now.
-
[49:40] - Stay away from single-factor authorization.
Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.