Published Mar 24, 2021

Big breaches (and how to avoid them)

Renowned security expert Neil Daswani delves into the complexities of major cybersecurity breaches, emphasizing proactive threat detection and enhanced organizational accountability to mitigate attacks. He unveils the significance of robust authentication measures and leadership responsibility in fortifying defenses against breaches like those experienced by Equifax and SolarWinds.
Episode Highlights
The Changelog logo

Popular Clips

Episode Highlights

  • 2FA Methods

    Two-factor authentication (2FA) methods vary in security, with some more vulnerable than others. explains that SMS-based 2FA is susceptible to SIM swapping, while app-based methods like Google Authenticator offer better protection against such attacks 1. However, even these can be compromised through phishing sites that mimic legitimate login pages. A more secure alternative is using security keys, which are tamper-proof hardware devices that eliminate the risk of phishing by not requiring manual code entry 2.

    A security key is a piece of Tamper's hardware which you have to either plug in to your laptop or your mobile phone.

    ---

    Security keys have proven effective in preventing phishing attacks, as demonstrated by companies like Google and Salesforce, which have successfully used them to protect against breaches 2.

       

    Phishing Threats

    Email phishing attacks continue to evolve, posing significant threats to cybersecurity. recounts the infamous phishing attack on John Podesta, where attackers exploited a simple mistake to access 60,000 emails 3. Despite the implementation of two-factor authentication, phishing remains a challenge as attackers develop more sophisticated methods. Daswani notes that while basic attacks persist, the complexity of cyber threats is increasing, requiring constant vigilance and adaptation 4.

    There's a saying in the security community that attacks only get better.

    ---

    Organizations must stay ahead of these evolving threats by employing advanced security measures and educating users on recognizing phishing attempts 3.

Related Episodes