Risky Business #752 -- Apple announcements thrill and terrify at the same time
Jun 12, 2024
auto_awesome
Former NSA boffin, Rob Joyce, joins to discuss Apple's leap into cloud computing, privacy concerns with iPhone-Mac integration, Snowflake breach, credit ratings impacted by cyber incidents, Microsoft Azure flaw fix, and more cybersecurity news. Yubico's COO shares insights on hardware authentication challenges.
Yubico enhances mobile app security with hardware keys
Balancing recovery process security with regulatory compliance
Deep dives
Ability to Sync Multiple Passkey Implementations on a Single Device
Platforms need to allow multiple passkey implementations on a single device, yet currently, it is restrictive, especially on Apple devices, where Yubico's syncable Passkey approach competes with Apple's Passkey solution.
Challenges in Implementing Mobile App for FIDO2 Authentication
Yubico aims to enable a secure recovery process for mobile apps using hardware-bound security keys, a unique feature that integrates hardware keys with mobile devices for safe key transfer and recovery.
Addressing Recovery Flow Challenges with Syncable Authenticators
The industry needs a measured approach to organize the sync fabric in syncable authenticators to ensure secure key storage, encryption, and access control, balancing easy recovery with regulatory compliance.
Balancing Risk with Syncable Authenticators in Organization
Organizations need to assess their risk profile and decide how to manage syncable authenticators while addressing the challenges of recovery flows to avoid outsourcing security to consumer help desks.
Ensuring Physical Verification and Secure Recovery Processes
Implementing physical recovery processes, such as issuing recovery passkeys via mail, can strengthen enterprise security by ensuring in-person identity verification and secure key recovery methods.
On this week’s show Patrick Gray and Adam Boileau are joined by long-time NSA boffin Rob Joyce. Now Rob’s left the government service, he’s hobnobbing with us pundits, talking through the week’s news:
Apple announces a big leap for confidential cloud computing into the mass market
While at the same time, letting you just mosey around your iPhone from your Mac
Mandiant reports in about the Snowflake breach
Moody’s say credit ratings might consider cyber incidents
Microsoft fixes an Azure flaw with a… “comprehensive documentation update”
And much, much more.
This week’s show is sponsored by Yubico, maker of the Yubikey hardware authentication token. Jerrod Chong, Yubico’s COO and President joins to talk about the challenges of the passkey and hardware authenticator ecosystem.