loader from loading.io

Identity without Passwords

Easy Prey

Release Date: 03/25/2026

When Trust Becomes a Trap show art When Trust Becomes a Trap

Easy Prey

Most people use technology all day without giving much thought to what is happening behind the screen. We trust routers that may not have been updated in years, depend on internet systems few of us understand, and now turn to artificial intelligence for everything from travel plans to home repairs. That convenience comes with tradeoffs. In this episode, we look at the weaknesses built into our connected world and what happens when our technical knowledge fails to keep pace with the technology surrounding us. Sherrod DeGrippo leads threat intelligence for Unit 42 at Palo Alto Networks, where...

info_outline
Scam Compounds show art Scam Compounds

Easy Prey

When most people think about online scams, they picture criminals sitting behind a screen and stealing from victims around the world. But in Southeast Asia, many of the people sending those messages are victims too. Some were promised legitimate jobs, flown across borders, trapped inside guarded compounds, and forced to scam others while trying to survive.  In this episode, I talk with Ivan Franceschini, a lecturer in Chinese Studies at the Center for Contemporary Chinese Studies Asia Institute. After years of studying labor rights, civil society, and Chinese investment in Cambodia,...

info_outline
Sports Betting show art Sports Betting

Easy Prey

Sports betting is everywhere now. It is in the commercials, on the apps, wrapped into game broadcasts, and sold as a fun way to make sports more exciting. But behind the easy sign-ups and “risk-free” offers is an industry built on odds most people do not fully understand, fine print that can cost real money, and a business model that depends on customers losing. In this episode, I talk with Danny Funt, an investigative reporter and the author of Everybody Loses: The Tumultuous Rise of American Sports Gambling. His reporting on sports betting, politics, news, and sports media has appeared...

info_outline
Google Maps Scams show art Google Maps Scams

Easy Prey

Most people are not thinking clearly when they need a locksmith or a plumber. They are locked out, water is leaking, something broke, and they just want somebody nearby who can fix it. So they open Google, tap one of the first businesses that comes up, and assume the listing is real. Unfortunately, that is exactly the kind of situation scammers count on.  In this episode, Mike Blumenthal, co-founder and analyst at Near Media, talks about fake local business listings and the ways bad actors have learned to game Google Maps. Mike has been following this problem for years, going back to the...

info_outline
Job Recruiter Scams show art Job Recruiter Scams

Easy Prey

Job hunting is hard enough without having to stop and ask whether the recruiter in your inbox is even real. My guest today, Jay Jones, ran into that problem firsthand after being laid off in December 2023. With his daughter due to be born just weeks later, Jay began receiving messages from recruiters that looked promising at first, but quickly turned out to be fake. Jay, also known as The Profiler, decided not to ignore what was happening. He started investigating the patterns behind these scams and has since identified and helped remove thousands of fake profiles, fraudulent companies, and...

info_outline
Bail Bonds Scams show art Bail Bonds Scams

Easy Prey

Getting a call that someone you love has been arrested is scary enough. Getting that call from someone who sounds official, knows just enough to seem credible, and says you have to send money right away is exactly the kind of moment scammers are counting on. Julie Henderson is the president of the North Carolina Bail Agents Association and has spent 24 years working in the bail bond industry.  She started in the field almost by accident after applying for what she thought was a legislative assistant job, and she has stayed because she cares about helping people get through one of the most...

info_outline
Confessions of a Fraudster show art Confessions of a Fraudster

Easy Prey

Technology keeps changing, but many of the most effective scams still come down to something very human: trust. My guest today is Tony Sales, co-founder of We Fight Fincrime and Underworld TV. Tony has a perspective most people in fraud prevention will never have. Earlier in his life, he was involved in organized financial crime and was once described in the UK press as Britain’s greatest fraudster.  After years in that world, and after serving time in prison, Tony made the decision to use what he knew to help stop the very crimes he had once been part of. Today, Tony works with...

info_outline
Personal Safety show art Personal Safety

Easy Prey

Scams and safety threats don’t always announce themselves. Sometimes they start quietly, with a moment of distraction, a strange feeling you ignore, or a situation that shifts just enough to test whether you’re paying attention. My guest today is S. Gale Bleth, a personal safety educator, certified RAD self-defense instructor, speaker, and author of Aware: A Personal Safety Playbook for Leaving the Nest. Gale brings a deep background in crime prevention and safety education, including 16 years at Cal State East Bay and 16 years as a crime prevention specialist with the Hayward Police...

info_outline
Data For Sale show art Data For Sale

Easy Prey

Everyday conveniences ask for tiny pieces of information all the time like a phone number at checkout, a zip code at the register, an email address for a receipt, or a loyalty account for a small discount. At the moment, it can feel harmless. But those small details can add up quickly, creating a personal profile that businesses, data brokers, scammers, and even people with bad intentions can use in ways most of us never agreed to or fully understood. My guest today is Ron Zayas, CEO of Ironwall by Incogni. Ron is an online privacy expert, speaker, and author who has helped the judiciary, law...

info_outline
Exploiting Psychology show art Exploiting Psychology

Easy Prey

Scams are often explained as a failure of judgment, but the truth is far more human. People are not fooled because they are foolish. They are manipulated at the exact moment emotion overrides logic, whether that emotion is fear, loneliness, hope, urgency, financial stress, or the desire to believe something better is finally possible. My guest today is Dr. John Demartini, one of the world’s leading authorities on human behavior, perception, resilience, and personal development. For more than five decades, he has researched, written, and taught in the fields of human awareness and potential....

info_outline
 
More Episodes

Every day, employees at hotels, restaurants, and resorts across the country are doing exactly what they were hired to do: being warm, responsive, and eager to help. It's what makes hospitality work. It's also what makes hospitality one of the most targeted industries in cybersecurity. When your entire workforce is trained to say yes, teaching them to be suspicious is an uphill battle. The smarter solution might be to take the target off their backs entirely.

Jasson Casey is the co-founder and CEO of Beyond Identity, a company built around one idea: making identity-based attacks impossible. With over 20 years of experience designing large-scale security infrastructure for global enterprises and carriers, Jasson has spent his career thinking about what happens when stolen credentials open doors they never should have. Beyond Identity's answer isn't better passwords or more authentication hoops, it's eliminating the credential that can be stolen in the first place.

Josh Johansen is the Director of IT Systems and Technology at Brandt Hospitality Group, an owner, operator, and developer of hotels under brands including Marriott, Hilton, Hyatt, and IHG. Josh came up through hotel operations, not a computer science program, and that background shapes how he thinks about security practically, from the floor up. He knows his workforce isn't looking to become cybersecurity experts. His job is to build systems that protect them anyway.

We talk about why the hospitality industry is such a rich target for phishing attacks, and what happened when one of Josh's general managers nearly paid a fraudulent invoice because she couldn't log in without a password she no longer had. Jasson breaks down how device-bound passkeys work, why most consumer passkeys aren't nearly as secure as people think, and what separates a real security system from one that just looks like one. Josh shares the lessons learned from rolling out this technology across a multi-brand hotel portfolio including what he'd do differently and what it means for an industry still wrestling with shared logins, high turnover, and workers using four different brand systems before lunch.

Show Notes:

  • [3:05] A cyber insurance mandate pushes Brandt Hospitality Group to find an MFA solution, and complaints about authentication fatigue make the obvious options the Brandt partners are already using feel like the wrong fit.
  • [4:03] After months of evaluating vendors and completing a full proof of concept, the leading candidate drops smaller accounts without warning, sending Josh back to square one and into a same-day demo with Beyond Identity.
  • [5:09] Beyond Identity moves fast, puts together a rapid proof of concept, and earns the business. Josh describes meeting Jasson in person for the first time at BeyondCon shortly after signing on.
  • [5:45] Hospitality is uniquely vulnerable to phishing attacks, and the industry's culture of helpfulness connects directly to the behaviors bad actors are counting on.
  • [6:49] A general manager calls convinced she needs her password to pay an overdue vendor invoice. When she can't get a login prompt, the situation is recognized immediately as a phishing attempt she nearly fell for.
  • [7:33] Reflecting on that moment, someone sharp and experienced nearly became a victim, and removing the password from the equation entirely turns out to be the real breakthrough.
  • [9:05] The conversation turns to the limitations of cyber awareness training, and why even well-intentioned employees with heavy workloads cannot be expected to function as a reliable last line of defense.
  • [11:13] Jasson describes how Beyond Identity works, using the analogy of a monkey in a jail cell to explain how a signing key stored in a secure hardware enclave can authenticate a user without ever leaving the device.
  • [12:06] The concept of stealable credentials expands beyond passwords to include API tokens, session cookies, SSH keys, and anything else that can be copied and lifted from a system.
  • [17:33] The discussion shifts to agentic identity and AI-driven workflows, with customers on opposite ends of the spectrum — some where agents make up the majority of their workforce, others who paused rollouts after discovering how easily prompt injections could expose sensitive data.
  • [19:17] The biggest mistake organizations make going into a passkey rollout is diving in without a clear understanding of how their identity environment is actually configured and what that means when things don't behave as expected.
  • [20:35] A lesson from their own deployment — initially limiting passkeys to senior staff and leaving line-level employees on passwords — makes clear that partial coverage leaves meaningful gaps.
  • [22:58] Most organizations under active phishing load will experience an incident during a mid-deployment window, and that moment often becomes the event that accelerates full adoption.
  • [24:33] The shared workstation challenge in hospitality comes into focus, along with how the device-bound passkey differs from the consumer versions employees may already be familiar with through Google or Facebook.
  • [29:14] Jasson draws a clear line between consumer passkeys optimized for conversion and enterprise passkeys built for security, explaining how sync fabric trades credential protection for convenience in ways that matter in a corporate environment.
  • [31:07] One enrolled device can cryptographically authorize the enrollment of another, allowing organizations to scale without moving keys or introducing new vulnerabilities.
  • [33:33] The passkey model changes accountability inside a hotel operation — device-bound credentials and role-based access make it significantly harder for well-meaning managers to share login access with staff informally.
  • [36:55] As the conversation wraps, a simple test is offered for evaluating any passkey system: if the passkey can move, it is not a security product.

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review. 

Links and Resources: