
Summation with Auren Hoffman SecureAuth CEO Geoff Mattson on the coming fraudpocalypse and the death of the password
22 snips
Aug 25, 2026 Geoffrey Mattson, CEO of SecureAuth and identity security leader, explains why AI agents can impersonate people and how that creates a deepfake-driven fraud crisis. He discusses passkeys killing passwords, continuous authentication instead of one-time checks, and practical defenses like scoped delegation, provenance, and simple family safe words.
AI Snips
Chapters
Transcript
Episode notes
Authentication Needs Continuous Escorting
- Authentication must move from a single login check to continuous escorting that watches for account takeover after initial entry.
- Geoffrey Mattson explains passwords/phones/biometrics are all compromisable and authentication needs to escort sessions, not just open the door.
Agents Must Use Scoped Delegated Tokens
- Agents should never hold full user identity; they must receive tightly scoped delegated tokens that limit actions.
- Mattson highlights token exchange and scoping as long-known theory now urgently needed for agent safety.
Translate Intent To Policy And Monitor Behavior
- Use intent-to-policy translation and add behavioral analytics rather than building ever-more complex static policies.
- Mattson suggests AI can convert natural intent into policy and analytics catch non-deterministic LLM behavior you can't pre-specify.
