
Identity at the Center #383 - Navigating Identity and AI with IDPro at Authenticate 2025
Nov 3, 2025
Dr. Tina Srivastava, PhD, a board member of IDPro and co-founder of Badge Inc., dives into the world of identity and AI. She explores the shift from physical hacks to AI-driven threats like supercharged phishing, emphasizing the urgent need for security evolution. Tina discusses the challenges of synced passkeys and vulnerabilities in account recovery. Additionally, she highlights the supportive IDPro community's role in combating these threats and announces new member-driven committees aimed at enhancing engagement and governance.
AI Snips
Chapters
Transcript
Episode notes
Passkeys Solve Portability But Create Provenance Gaps
- Synced passkeys solved device portability but introduced provenance and verification gaps that regulators flagged.
- Failure to tie use-time user verification back to keys weakens passkey trust and drives some payment providers to revert to device binding.
Fix Account Recovery Before Device Loss
- Close account-recovery gaps so users can move devices without falling back to insecure methods.
- Implement cross-vendor recovery flows to let users regain passkeys across Google, Microsoft, and Apple.
AI Supercharges Phishing Attacks
- AI massively scales and tailors phishing attacks, turning once-detectable scams into highly convincing targeted attacks.
- This escalation makes phishing-resistant authentication critical across consumer and workforce systems.
