Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
The All Things Auth Podcast

The All Things Auth Podcast

Conor Gilsenan

Every 2 weeks, Conor Gilsenan hosts a conversation with creators, researchers, founders, and advocates who are working to improve the usability of security and privacy technologies. Guests share what they are currently working on, how they got to where they are today, who they are trying to help, and what keeps them motivated to overcome challenges along the way. The goal is for the rest of us to learn from their experiences and go on to promote usable security and privacy within our own projects and organizations.
bookmark
Share icon

All episodes

Best episodes

Top 10 The All Things Auth Podcast Episodes

Goodpods has curated a list of the 10 best The All Things Auth Podcast episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to The All Things Auth Podcast for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite The All Things Auth Podcast episode by adding your comments to the episode page.

Social media & website

Resources mentioned in episode

  • Jon Camfield published an article titled "Where did USABLE come from?" that explains the motivation for starting the organization.
  • The free USABLE Guidebook contains resources and activities to help trainers and facilitators to collect relevant and useful feedback from high-risk users.
  • The USABLE blog has a ton of posts about their mission and interviews with their partner organizations.
  • Ashley explained how USABLE gets hands-on help from design and user experience partners (Simply Secure and OKTHANKS) and accessibility partners (Accessibility Lab).
  • Ashley shared the story of working with Thomas, the lead developer of Mailvelope, an app that allows you to send end-to-end encrypted emails. Also, check out the Mailvelope Blog.
  • USABLE created detailed personas to help developers understand how to make their products more usable for at-risk communities around the world.
  • USABLE has also recently supported the Secure Drop, Orbot, and KeePass XC projects. The USABLE blog has great interviews with these projects.

You can find the host of The All Things Auth Podcast on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/010-ashley-fowler-of-usable-tools.

bookmark
plus icon
share episode

Simon Moffatt, a Technical Product Manager at ForgeRock, joins me to discuss why a Product Manager is a critical role within any organization that aims to create usable security and privacy technologies. We discuss what, exactly, a PM actually does and why they are the critical hub between all departments, teams, and areas of the business.

While most companies have a never ending list of TODO items, Simon explains why it is important to have a DO NOT list.

Should PMs come from a technical background, a sales background, or is it better to be a polyglot with a range of experience? How can companies create product road maps that they will actually stick to and avoid the trap of sales-driven engineering?

We also discuss security compliance and how market failures lead to standards and regulation to protect end-users.

Social media & website

Resources mentioned in episode

  • Simon mentions how The Lean Startup advocates a quick learning cycle to capitalize on user feedback to improve your products.
  • Simon also writes articles on The Cyber Hut.

You can find the host of The All Things Auth Podcast on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/004-simon-moffatt-of-forgerock

bookmark
plus icon
share episode

Keybase is a Slack-like app that supports chat and file sharing, but it is fully end-to-end encrypted. You might be familiar with other well known apps that support end-to-end encryption, like WhatsApp and Signal, but Keybase has a fundamentally different security architecture. Max explains why this is so important and helps us understand the cryptography that makes the service work.

Before starting Keybase, Max was the co-founder of OkCupid. He shares the story about how he went from running a dating app to focusing on making public key cryptography approachable for the average internet user. Towards the end of our conversation, we discuss how Keybase approaches user research, how Keybase makes enough money to keep the lights on, and how they plan to grow the service in the future.

Social media & website

Resources mentioned in episode

You can find Conor, the host, on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/003-max-krohn-of-keybase

bookmark
plus icon
share episode
The All Things Auth Podcast - #009 - How to be an #MFAally with Tanya Janca of Microsoft
play

09/27/19 • 48 min

Social media & website

Resources mentioned in episode

  • Tanya talks about enabling MFA on Tangerine Bank, WealthSimple, and PayPal.
  • Tanya wrote a blog post titled "Multi-Factor Authentication (MFA)" that explains what MFA is for people who are not familiar with the term.
  • The site twofactorauth.org is a community maintained database of which sites support 2FA and which do not.
  • Conor built an open-source browser extension called 2FA Notifier, which alerts you anytime you visit a site that is known to support 2FA and helps you enable it.
  • During Microsoft Ignite 2018, Azure shared that adoption rate of MFA among admins was only 1.7%. “The rate increased from 0.7% in 2017 to 1.7% in 2018. Yes, it doubled, but it is still terrible.”
  • Tanya mentioned Jessy Irwin’s mantra “If you liked it, then you should have put some crypto on it” and multi-Raptor authentication.

You can find the host of The All Things Auth Podcast on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/009-tanya-janca-of-microsoft.

bookmark
plus icon
share episode

Michal Špaček shares the story of how the Password Storage project has convinced hundreds of companies to publicly disclose their password storage practices and assigned each a grade based on how well they follow best practices.

We discuss hashing algorithms and the technology behind storing passwords securely. Learn why a company who follows the technical best practices might still not earn an A grade if they do not have a public disclosure, or if they rely on an Invisible Disclosure.

We compare the Password Storage project to other fantastic security tools, including SSL Labs and Mozilla Observatory.

Michal outlines how the grading criteria will change in the short term, highlights the desire to get more companies included in the data set, and contemplates how the project will continue to grow over time.

This episode was initially published in August 2019, the 5 year anniversary of Michal’s talk at BSides Las Vegas 2014, which planted the seeds that eventually grew into the Password Storage project. Happy birthday, Password Storage!

Social media & website

Resources mentioned in episode

  • Michal launched Password Storage at BSides Las Vegas in 2016. You can see the slides from his talk here.
  • Bruce K. Marshall is a researcher and consultant dedicated to improving the application of authentication technologies, products, and good practices. He founded PasswordResearch.com to better share the password information he was collecting.
  • Michal’s wrote an article titled “Upgrading existing password hashes” that explains how to gracefully migrate passwords hashed with a legacy algorithm to a secure and modern algorithm.
  • To get your website listed in the Password Storage project, check out the FAQ.

You can find the host of The All Things Auth Podcast on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/005-michal-spacek-of-password-storage

bookmark
plus icon
share episode

Conor explains what security keys are and why they provide a stronger level of security than other methods of 2FA. He shares the story about how he created and sold his first open-source security key on Amazon while he was an undergraduate studying Computer Engineering and how that project evolved into a wildly successful Kickstarter project that launched SoloKeys the company.

Towards the end of the conversation, Conor shares his thoughts on the recent trend of using phones as security keys and highlights Somu, the next exciting product that he and his team are working on right now.

Social media & website

Resources mentioned in episode

Canonical URL: https://allthingsauth.com/podcast/001-conor-patrick-of-solokeys

bookmark
plus icon
share episode

Social media & website

Resources mentioned in episode

You can find the host of The All Things Auth Podcast on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/008-pilar-garcia-of-1password.

bookmark
plus icon
share episode

Alex shares the story of how Krypton first started as a secure messaging app, then evolved to help developers manage SSH keys, and today aims to make phishing resistant two factor authentication a realistic option for average internet users.

We get Alex’s thoughts on Google’s recent focus on allowing Android phones to be used as security keys, what happens if you lose your phone, and different approaches to account recovery.

Social media & website

Resources mentioned in episode

You can find Conor, the host, on Twitter @conorgil.

Canonical URL: https://allthingsauth.com/podcast/002-alex-grinman-of-kryptco

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does The All Things Auth Podcast have?

The All Things Auth Podcast currently has 10 episodes available.

What topics does The All Things Auth Podcast cover?

The podcast is about Security, Founder, Research, Startup, Podcasts, Technology, Business, Privacy, Computer and Cybersecurity.

What is the most popular episode on The All Things Auth Podcast?

The episode title '#010 - Making Open-Source Software Usable with Ashley Fowler of USABLE.tools' is the most popular.

What is the average episode length on The All Things Auth Podcast?

The average episode length on The All Things Auth Podcast is 56 minutes.

How often are episodes of The All Things Auth Podcast released?

Episodes of The All Things Auth Podcast are typically released every 13 days, 15 hours.

When was the first episode of The All Things Auth Podcast?

The first episode of The All Things Auth Podcast was released on Jun 6, 2019.

Show more FAQ

Toggle view more icon

Comments