loader from loading.io

Identity without Passwords

Easy Prey

Release Date: 03/25/2026

Ransomware Evolution show art Ransomware Evolution

Easy Prey

Ransomware has changed dramatically over the years. What started as criminals locking up individual computers and demanding relatively small payments has grown into a much larger operation involving stolen data, entire networks, third-party vendors, and increasingly sophisticated ways of pressuring victims to pay. Now AI is adding another wrinkle, giving criminals new tools while also creating some unexpected problems for them. Joining me to talk about how ransomware has evolved is Allan Liska, a ransomware researcher and Field CISO at Recorded Future. Allan has more than 30 years of...

info_outline
The Counterfeit Economy show art The Counterfeit Economy

Easy Prey

A counterfeit handbag may leave someone disappointed. A counterfeit medication, airbag, or child’s car seat can do far more damage. Fake products now reach into nearly every part of daily life, and many of them arrive through online stores that look completely legitimate. Kari Kammel saw the danger firsthand when a pharmacist overseas offered her several versions of the same medication. Some were authentic, while others were openly described as counterfeit. That experience stayed with her. She now directs the Center for Anti-Counterfeiting and Product Protection at Michigan State University,...

info_outline
The Internet is Playing You show art The Internet is Playing You

Easy Prey

A convincing lie no longer needs to look suspicious. It can appear in a familiar social media feed, come from someone who seems real, or arrive as a video that looks almost impossible to fake. By the time doubt sets in, the post may already have been shared thousands of times. Few people understand that online environment better than today’s guest. Nina Jankowicz has spent more than a decade studying what she calls the bad things that happen on the internet. She is an internationally recognized expert on disinformation and online harassment. She was also named one of Time magazine’s 100...

info_outline
The Psychology of Yes show art The Psychology of Yes

Easy Prey

It is easy to say you would never fall for a scam when you are looking at the situation from the outside. In the moment, though, things can feel much less obvious. A request may sound reasonable, the person may seem trustworthy, and saying no can feel awkward enough that you go along with something you would normally question. Today’s guest studies exactly why that happens. Vanessa Bohns is the Bronstein Family Professor and Chair of Organizational Behavior at Cornell University’s ILR School. Her work focuses on social influence, compliance, and the pressure people feel to cooperate, even...

info_outline
Drink Spiking show art Drink Spiking

Easy Prey

A drink can be out of your sight for only a moment, but that may be all it takes for someone to tamper with it. Spiking can happen in bars, restaurants, festivals, and even among people who already know and trust each other. It also goes far beyond alcohol. Drinks, food, vapes, cigarettes, and other substances can be altered without someone’s knowledge, leaving them vulnerable before they fully understand what is happening. Dawn Dines has spent more than 20 years working to change how people understand and respond to spiking. She is the founder and CEO of Stamp Out Spiking, a UK charity...

info_outline
Love, Lies and Locked Up show art Love, Lies and Locked Up

Easy Prey

What sounds like the plot of a crime thriller was Sharon Armstrong’s real life. An online romance drew her into an elaborate web of lies involving overseas contracts, invented emergencies, and several people playing carefully planned roles. By the time she arrived at an airport in Argentina with five kilograms of cocaine hidden inside her suitcase, she still believed she was carrying business documents for the man she loved. Sharon was arrested and spent more than two years in an Argentinian prison before returning home without a conviction. During that time, she had to confront the truth of...

info_outline
The Recruitment Trap show art The Recruitment Trap

Easy Prey

Everybody is searching for ways to increase income. Unfortunately, MLMs often look like an easy way to start a business without taking on the cost of a traditional company. The pitch sounds simple. Buy the product, follow the plan, and put in the work. The numbers behind those promises often tell a different story. Today’s guest, Stacie Bosley, has spent years studying what really happens inside MLMs. She is a professor at Hamline University in Minnesota and holds a Ph.D. in applied economics. Her research covers multi-level marketing, consumer protection, income claims, and pyramid scheme...

info_outline
Convincing Deepfakes show art Convincing Deepfakes

Easy Prey

A familiar voice on the phone or a recognizable face on a video call used to offer some reassurance that you knew who you were dealing with. AI has changed that. Voice cloning, face swaps, and real-time video impersonation now allow scammers to convincingly pose as executives, job candidates, romantic interests, or even family members. Understanding how these attacks work and where they may be headed is a central part of Tom Cross’s work as Head of Threat Research at GetReal Security. Tom has spent more than 30 years studying cybersecurity threats, software vulnerabilities, and the methods...

info_outline
When Trust Becomes a Trap show art When Trust Becomes a Trap

Easy Prey

Most people use technology all day without giving much thought to what is happening behind the screen. We trust routers that may not have been updated in years, depend on internet systems few of us understand, and now turn to artificial intelligence for everything from travel plans to home repairs. That convenience comes with tradeoffs. In this episode, we look at the weaknesses built into our connected world and what happens when our technical knowledge fails to keep pace with the technology surrounding us. Sherrod DeGrippo leads threat intelligence for Unit 42 at Palo Alto Networks, where...

info_outline
Scam Compounds show art Scam Compounds

Easy Prey

When most people think about online scams, they picture criminals sitting behind a screen and stealing from victims around the world. But in Southeast Asia, many of the people sending those messages are victims too. Some were promised legitimate jobs, flown across borders, trapped inside guarded compounds, and forced to scam others while trying to survive.  In this episode, I talk with Ivan Franceschini, a lecturer in Chinese Studies at the Center for Contemporary Chinese Studies Asia Institute. After years of studying labor rights, civil society, and Chinese investment in Cambodia,...

info_outline
 
More Episodes

Every day, employees at hotels, restaurants, and resorts across the country are doing exactly what they were hired to do: being warm, responsive, and eager to help. It's what makes hospitality work. It's also what makes hospitality one of the most targeted industries in cybersecurity. When your entire workforce is trained to say yes, teaching them to be suspicious is an uphill battle. The smarter solution might be to take the target off their backs entirely.

Jasson Casey is the co-founder and CEO of Beyond Identity, a company built around one idea: making identity-based attacks impossible. With over 20 years of experience designing large-scale security infrastructure for global enterprises and carriers, Jasson has spent his career thinking about what happens when stolen credentials open doors they never should have. Beyond Identity's answer isn't better passwords or more authentication hoops, it's eliminating the credential that can be stolen in the first place.

Josh Johansen is the Director of IT Systems and Technology at Brandt Hospitality Group, an owner, operator, and developer of hotels under brands including Marriott, Hilton, Hyatt, and IHG. Josh came up through hotel operations, not a computer science program, and that background shapes how he thinks about security practically, from the floor up. He knows his workforce isn't looking to become cybersecurity experts. His job is to build systems that protect them anyway.

We talk about why the hospitality industry is such a rich target for phishing attacks, and what happened when one of Josh's general managers nearly paid a fraudulent invoice because she couldn't log in without a password she no longer had. Jasson breaks down how device-bound passkeys work, why most consumer passkeys aren't nearly as secure as people think, and what separates a real security system from one that just looks like one. Josh shares the lessons learned from rolling out this technology across a multi-brand hotel portfolio including what he'd do differently and what it means for an industry still wrestling with shared logins, high turnover, and workers using four different brand systems before lunch.

Show Notes:

  • [3:05] A cyber insurance mandate pushes Brandt Hospitality Group to find an MFA solution, and complaints about authentication fatigue make the obvious options the Brandt partners are already using feel like the wrong fit.
  • [4:03] After months of evaluating vendors and completing a full proof of concept, the leading candidate drops smaller accounts without warning, sending Josh back to square one and into a same-day demo with Beyond Identity.
  • [5:09] Beyond Identity moves fast, puts together a rapid proof of concept, and earns the business. Josh describes meeting Jasson in person for the first time at BeyondCon shortly after signing on.
  • [5:45] Hospitality is uniquely vulnerable to phishing attacks, and the industry's culture of helpfulness connects directly to the behaviors bad actors are counting on.
  • [6:49] A general manager calls convinced she needs her password to pay an overdue vendor invoice. When she can't get a login prompt, the situation is recognized immediately as a phishing attempt she nearly fell for.
  • [7:33] Reflecting on that moment, someone sharp and experienced nearly became a victim, and removing the password from the equation entirely turns out to be the real breakthrough.
  • [9:05] The conversation turns to the limitations of cyber awareness training, and why even well-intentioned employees with heavy workloads cannot be expected to function as a reliable last line of defense.
  • [11:13] Jasson describes how Beyond Identity works, using the analogy of a monkey in a jail cell to explain how a signing key stored in a secure hardware enclave can authenticate a user without ever leaving the device.
  • [12:06] The concept of stealable credentials expands beyond passwords to include API tokens, session cookies, SSH keys, and anything else that can be copied and lifted from a system.
  • [17:33] The discussion shifts to agentic identity and AI-driven workflows, with customers on opposite ends of the spectrum — some where agents make up the majority of their workforce, others who paused rollouts after discovering how easily prompt injections could expose sensitive data.
  • [19:17] The biggest mistake organizations make going into a passkey rollout is diving in without a clear understanding of how their identity environment is actually configured and what that means when things don't behave as expected.
  • [20:35] A lesson from their own deployment — initially limiting passkeys to senior staff and leaving line-level employees on passwords — makes clear that partial coverage leaves meaningful gaps.
  • [22:58] Most organizations under active phishing load will experience an incident during a mid-deployment window, and that moment often becomes the event that accelerates full adoption.
  • [24:33] The shared workstation challenge in hospitality comes into focus, along with how the device-bound passkey differs from the consumer versions employees may already be familiar with through Google or Facebook.
  • [29:14] Jasson draws a clear line between consumer passkeys optimized for conversion and enterprise passkeys built for security, explaining how sync fabric trades credential protection for convenience in ways that matter in a corporate environment.
  • [31:07] One enrolled device can cryptographically authorize the enrollment of another, allowing organizations to scale without moving keys or introducing new vulnerabilities.
  • [33:33] The passkey model changes accountability inside a hotel operation — device-bound credentials and role-based access make it significantly harder for well-meaning managers to share login access with staff informally.
  • [36:55] As the conversation wraps, a simple test is offered for evaluating any passkey system: if the passkey can move, it is not a security product.

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review. 

Links and Resources: