Passwords Are Dead: Why I Demand MFA on Every Session
In this opinion piece, I argue that passwords alone are obsolete and that multi-factor authentication (MFA) must be the absolute minimum for any acces...
3 articles in this category
In this opinion piece, I argue that passwords alone are obsolete and that multi-factor authentication (MFA) must be the absolute minimum for any acces...
MFA alone won't stop credential phishing. You need phishing-resistant authenticators at AAL2 or higher, plus PAM and least privilege, to actually secu...
Most MFA fails to stop phishing. NIST's AAL2 standard demands two factors and phishing resistance. Here's why your org should require it.