#320 - Authenticate 204 - FIDO Feud - podcast episode cover

#320 - Authenticate 204 - FIDO Feud

Dec 02, 202423 minEp. 320
--:--
--:--
Download Metacast podcast app
Listen to this episode in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episode description

In this special episode of Identity at the Center, hosts Jim McDonald and Jeff Steadman kick off the inaugural FIDO Feud—a game show packed with fun and informative challenges about digital identity. Team Glitterati, led by Megan Shamas, and Team Identifriends, led by Jim, face off in a series of rounds centered around common passwords, identity trends, and future threats to IAM. Enjoy witty banter, audience interaction, and a spirited competition, all while diving deep into the world of Identity and Access Management.

Special thanks to the FIDO Alliance and RSM US LLP for making this special event possible!

00:00 Introduction to Identity at the Center 00:20 Welcome to FIDO Feud 01:18 Meet the Team Captains 01:47 Team Names and Random Members 02:46 Game Rules and Setup 04:22 Round 1: Easy-to-Guess Passwords 07:37 Round 2: Tired Trends in IAM 11:44 IAM Metrics Showdown 12:22 Successful Logins and Password Resets 13:04 User Satisfaction and Breaches 13:44 Enrollment and Abandon Rate 14:33 Final IAM Metrics 15:45 Biggest Future Threats to IAM 17:29 Unexpected Answers and Final Round 21:16 Winners and Closing Remarks

Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at http://idacpodcast.com

Transcript

This is identity at the center if it has anything to do with IAM. This is the go to podcast now your hosts Jim McDonald and Jeff Stedman. Welcome to the Fido feud. Thank you very much. So I'm going to give buy us a little bit of time while we're getting the stage set up here. This is a game show that's all about digital identity. It doesn't have anything to do with feuding families. So if you're looking to

litigate, please look elsewhere. My name is Jeff Steadman, I'm the host of the Identity of Center podcast. I'm also going to be your host for the inaugural Fido feud. So hopefully this goes well and we come back again next year. If it doesn't, then you won't see that again. We're going to have some fun up here. We're going to kick off the Expo and the reception a little bit, but first we're going to do this.

You can see we've got some buzzers being set up, we've got surveys, we've got a very charismatic host skilled at Winnie banter. So any resemblance to any other similarly named game shows is purely coincidental. So with that, let me get my team captains up here. Let me introduce Megan Seamus from the Fido Alliance and my Co host on the Identity of the Center podcast, Jim McDonald. All right, so Megan's already bringing the swag. See that here. All right Megan, yes, thanks for

being on the 1st Fido feud. Tell me about your team name. My team name is the Glitterati. OK, all right, we got some glitterati fans out there. And Jim, how about your team name? 1st I got to say Steve, you look different on TV. Little bit shorter and with less mustache, that's for sure. What's your team name? Jim, We. Are the identity friends? The identity friends you. Could say identity friends at the center I was. Going to say that was a missed opportunity to promote the podcast.

IDC podcast.com, like and subscribe. OK, so why don't we go ahead and get some random team members, totally random from the crowd. I'm going to come up here. I think I'm supposed to hit a slide, but I'm not sure. Let's see if that worked. No. Are there slides? There we go. OK, so Jim's team and Megan's team. Pam, Ian, Teresa, Shane, Jamie, Christian. Come up and join your team captain, please. All right, while we're getting set up here, let's go over the

rules. So we surveyed the Fido Authenticate audience, that's you guys, asked a bunch of digital identity questions and got those answers back. We're going to have the top answers on the board. Each team's going to have a buzzer that they're going to be able to. OK, let's switch sides. Yes, go back on that side. All right, little stage direction. So we're good. All right, Megan, your team goes on the other side. All right, we want, we want symmetry, folks.

All right, so you're going to get chance to buzz in with the answer. If you get 3 wrong answers, the other team's going to have a chance to steal and take all the points on the board. Whoever has the most points at the end, wow, we've got props coming up their shots. I mean, come on. Is this the best session of the day or what? All right, there will be some judges in the back to help with the answers. And if you don't like the answers that you see, you have

only yourself to blame. These are your answers. You came up with them. Please do not take it out on me or anyone else up on stage. OK, so I think we've got totally random how all these people with shirts matching came up all at the same time. That's interesting. I've never met these people before. Never met these people before. OK. All right. So team glitterati, you guys ready? Yeah. OK. All right. We're ready. You guys are ready.

Audience, you guys ready? All right, OK, question #1 give an example of a password that's easy to guess. All right, Looks like literati got it. Can. I have the bike password. Password is password up on the screen #2 So Jim, you've got a chance here if you can get the number one answer. What give an example of a password that's easy to guess. Admin. Admin is admin up on the board? We're doing we're doing shots. Do you guys want to pass or play? We would like to play Jeff.

You want to play OK, we're. Supposed to. Do this now. There's shots being poured. I'm not sure how this is going to work, but Christian and All right, all right, let's get you're going to go. OK, so give me an example of a password that's easy to guess. Pet's name, a pet's name. Is that on the list? Show me pet's name. No. OK, you're doing a shot back of the line for you. Who's next? Let's go with Andrew.

Andrew. OK. So, Andrew. Oh, OK, shocking that that's not a popular password, but sorry, Mr. Shakira, where you are. All right, who's next? Christian ABC123ABC123. Is that up on the list? Oh, OK, you're still alive. We got still 3 answers left on Megan. We're back to you. Give an example of a password that's easy to guess. Cordy. QWERTY. OK, so top row there on the keyboard is QWERTY on the list? It is. All right, we got 2 answers left.

Who's next? Hey, there's no. Yeah, here we go. Give an example of a password that's easy to guess. No. ASDFGASDFG. OK, very random. Is a SDFG up there? No. OK, all right, I done it. Friends, you've got a chance to steal, so give an example of a password that's easy to guess. If it's up there, you take the round you have. To spread out. Birthday. Birthday. Is birthday on the list? No. All right, so the glitterati take the round. Let's see number six. Show me #6 let me in. OK?

And #1 123456 OK, All right. So I think we're hopefully getting a feeling of how this is going to go here. I see shots board over here and I don't know what if we're the losers, take the shots, OK? We'll move those out of the way for now, OK? Tell them we did or this is a real survey. So again, these are answers from the survey that you answered, and we took your answers and put them up here. OK, question #2 what trend are you most tired of in the identity and access management

space? That was quick on a draw, glitterati. Can I ask the audience? No. Oh, that's cool. This is the wrong game show for that. We'll have to try that next time. Account recovery. Account recovery, is that a trend that we're tired of in identity and access management space? No, it's a. Very applicable sound effect. No, I will say decentralized identity. Decentralized identity. OK. Is that a trend that we're tired of? No. OK, we're going to go down the line then.

Zero trust. Zero trust. OK, that's a crowd favorite, apparently. Is zero trust a trend that we're tired of? There it is number one. OK, Zanker glitterati, you guys are on the board. Do you guys want to pass or play? We're going to pass. We're going to pass. OK all right because you you're not identity friends. She she's going to cover from the shot here. All right.

What trend are you most tired of in the identity and axis management space IT. Dr. ITDR Identity Threat Detection and Response. Is that on the list? No. OK, Teresa, what's a trend you're tired of? Password reset. Password resets. We're tired of password resets. We're at a conference all about passkey, so it makes sense. Let's see. Is that on the board? Password resets? No. All right, Jim, you got 2 strikes. 3 strikes and you're

out. I know you like the baseball analogies, So what trend are you most tired of in identity and access management? I'm thinking. AIAI OK artificial intelligence, is that on the list? It is OK, you guys are still alive. You have 3 Lancers left. You already have two strikes, so the next wrong 1 is going to go back to the other side. Pam, what trend are you most tired of in identity and access

management looking for? Help help me, help me somebody help me I'm going to say OK I'm going to try a different but same idea your. Audience here. Let's try. Hey, no heckling. Oh wait, no Heckle. We'll try wallets. Wallets like a password wallet or like an identity wallet of some sort? OK, Wallet is wallet up on the list? No. OK. All right, so glitterati, you've got a chance to steal. Give me a trend that you're most tired of in the identity access management space.

Megan, you're the team captain, so you got to make the decision. Password list. Password list. Wow. OK, that's a bold statement at a password list conference. So let's see his password list on this. On the list. No. All right, identity friends, you're on the board. You got some points. Let's see. What else are we tired of? Show me #4 passwords. OK. All right, show me #3 MFA and biometrics, OK? And then #2 Fido and passkeys. OK, Andrew, where is is is Mr.

Shiki are in the audience. Where? OK, He's waving. I'm very sorry. If you want to like, you know, yell at people around you, Remember, the answers came from out there, not over here. I have a. Thing. To say. OK, I have a thing to say to the judges in the back. I'm pretty sure password list is. This should fit in the pass keys category, but that's fine David. It's rigged.

It's rigged. OK, there's already drama and controversy at the first ever Fido feud, so I'm not sure how we're going to recover, but let's keep moving. We've got, oh, Ian, too cool for the room. All right, third question. Here we go. Name a metric used to measure the effectiveness of an IM program. I think it I I saw you do it. Yes. OK, we'll go with you. Yes. Next year's budget we'll have. But. Oh, there we go. All right. Only a little bit of a delay.

So there we go. Ian, what is the answer? Yeah, sure, sure, sure. Good. You pressed a button. Good job. Successful logins. Successful logins. Is successful logins on the list? It is number one. All right, so do you guys want to pass or play? We're going to play that one. OK. All right, Teresa, you're up. Name a metric used to measure the effectiveness of an IM program. Password reset again. Password reset. So password resets is password resets on the list? It is OK reduce resets.

All right Jim, we got a clean board here. 4 answers. Name of metric used to measure the effectiveness of an IAM program. User satisfaction. User satisfaction. Are are your users happy with your IAM program? Is that on the list? User satisfaction? It is number 2. All right, we're going to go back down here to Pam name a metric used to measure the effectiveness of an IM program number of. Breaches. Number of breaches. So this is a number you want to

be very small. So number of breaches, is that on the list? No, it was even a even a bad sound effect for that one. All right, Ian, give me another metric used to measure effectiveness of an IM program enrollment like new user sign up, new user sign up enrollment. So like for MFA enrollment or something like that or OK, so MFA enrollments or something along those lines. All right, 2 answers left. Let's see, Teresa, we're back to you name of metric used to measure the effectiveness of an

IM program, the. Abandoned rate. Abandoned rate OK is abandoned rate on the list? Judges are thinking about it and no, not on the list. Jim, it always comes down to you, you know, 2 strikes. Can you, can you bail things out here? If you get this wrong, it's going to go over to the glitterati who are there powwowing with their cool sunglasses and green shirts and all their swag. Nanometric used to measure the effectiveness of an IM program. Account lockouts. Account lockouts.

OK, so how effective is your program? Account lockouts? Is account lockouts not on the list? All right, so we're going to go over here to the glitterati. Give me a metric that's used to measure the effectiveness of an IM program. Sign in speed. Sign in speed. So how quickly you can log in. OK, sign in speed is sign in speed on the list? It is time to response. So glitterati is going to take that one. Let's see what was number six Secure practices.

OK, I, I'm, I'm, I'm just, I'm just the messenger folks, that's all. OK, all right, let's go. We've got one more question. Here we go. So let's pull the next person up. We got Christian versus Teresa. No pressure, guys. This is the last one we've got. He's just going to do the shot. He's already either conceded or he's got some other problems. So the biggest here we go number question. All right, last question for the game. The biggest threat to I am in the future will be Blank.

You guys even let me finish the question. OK, we'll be Blank. Who got it. Generative AI. Generative AI is going to be the biggest blank for hacking into systems and demanding a ransom of unlimited cat memes. OK, well, yeah, it cut off there, but it is cat memes, so just FYI. All right, is AI on the list? It is number 2. Teresa, you got a chance to steal. The biggest threat to I in the future will be what? Hacking into systems and demanding a ransom of unlimited

cat memes. Social engineering. Social Engineering. Social engineering. OK, that's common today. Let's see, is it still going to be common in the future? What do we think? Social engineering is not on the list. OK, glitterati, you've got a chance here. Do you want to pass or play? You want to play? OK, All right. There seems to be some confusion, but we're going to go for it, all right? The biggest threat to I am in the future will be what?

Hacking into systems and demanding demanding a ransom of cat memes. Nigerians. Nigerians OK, apologies to all of Nigeria as part of that answer, but let's see. And if you're a Prince AA policy, I'm happy to bring your money into the US for you. So is Nigerians on the list? Government entities? OK, All right, The judges have spoken and they have said that Nigeria is a government and we're going to allow it. OK. All right, The biggest threat to

I am in the future will be what? Hacking into systems and demanding a ransom of unlimited cat memes. Criminals. Criminals. OK, and that's different from government entities, right? OK, just double checking there. OK, so are criminals up on the board? It is hackers APT advanced persistence threats. All right, who's next? The biggest threat to I am in the future will be what? Hacking into systems and demanding a ransom of unlimited cat memes. Next deal. Nick Steele, Nick. Steele.

Nick Steele. OK, I don't know who you're going to have to explain to me. What is Nick Steele? A person. A person. OK, if you're Nick Steele, are you on the board? A celebrity. OK, All right, so now we've got to watch out for celebrities hacking his house for the future, apparently. All right, you got one answer left on the board. Let's see who's next here. Christians, back to you. I think the biggest threat to I

am in the future will be what? Hacking into systems and demanding a ransom of unlimited cat memes. Teenagers. Teenagers. OK, are teenagers on the list? No. OK, you still got 2 strikes. We can keep going. So we're going back around are. You sure I can't ask the audience we're going to go with? We've already had bots and you said children. They just said what demographic does that leave dude cover? Nigeria, Yeah, yeah. Yeah, Oh my goodness. IoT devices.

IoT devices. So our devices are going to hack ourselves as IoT devices on the list. Judges No. OK, two strikes left Jamie, it's up to you Biggest threat to I am in the future will be what hacking into systems and demanding a ransom of unlimited cat memes. She said she's stressed out. We're we're trying to you know, goose Frappa. Let's be calm. Let's think about it here for a second. The future. What is what are these people? Look, look at this guy right

here. What do you think he thought is going to hack us in the future? Celebrity, don't do that. Oh, so just so she said Andrew. And then Jamie said he's not a celebrity. Sorry, Andrew. Oh, no, no. Megan said that. Sorry. Yeah. Right. OK. All right. We need an answer. Biggest threats I am in the future will be what? Hacking into systems and demanding a ransom of unlimited cat memes? Yeah. Yeah. Big tech.

Big tech. OK, so if you're big tech, you know, like a like a Google maybe or an IBM or something like that, are you on the list? Big tech? No. OK, all right. You guys have a chance to steal. There's one answer left on the board. The biggest threat to I am the future will be what? Hacking into systems and demanding a ransom of unlimited cat memes? Jim. Unlimited cat? We have to think Hello Kitty. Hello Kitty wants their cat memes back and they're going to hack the planet essentially to

get that back. OK all right, so Hello Kitty was the answer. Is that on the board animals. OK judges judges have have deemed that that's appropriate. So points are going to go over to the identity friends. It was a close game, but the winner is actually still glitterati, the first ever Fido Alliance. I've got some prizes for you, the tiniest awards ever. So here's one for everyone on the team. So you might have to come closer if you want to get pictures

because or zoom in right? So we've got that. So congratulations to the Glitterati team for being the first ever winner. Let's give them a round of applause. All right, thank you all for being here. Want to give a shout out to Adrian and the production crew for helping make all this possible. If you like this, submit the feedback so you can hopefully see us next year with better buzzers and hopefully better answers from some of our teammates. So with that, we've got the Expo

and the reception kicking off. We'll see you out there. Thank you everybody. You've been listening to Identity at the Center. We hope you've enjoyed the show. Make sure to like, rate and review, and we'll be back soon. But in the meantime, hit the website at identity@thecenter.com. See you next time on Identity at the Center.

Transcript source: Provided by creator in RSS feed: download file
For the best experience, listen in Metacast app for iOS or Android