The Inverted Podcast · 2026-06-17 · 40 min
Key moments - from our scoring
Substance score
54 / 100
Five dimensions, 20 points each
Account recovery is frequently treated as an afterthought, but it may be the single weakest link in authentication systems and deserves the same rigor as primary login mechanisms. Dean Sachs, principal security engineer at Remitly and longtime contributor to the FIDO Alliance, joins hosts Dario and Dana to explore why recovery is so dangerous and how to design it properly. The conversation covers real-world attacks - from scattered spider's MGM Grand breach to SIM swaps targeting telco operators - and explains why weak recovery flows undermine strong primary credentials like passkeys. The hosts introduce Dean's "iron triangle" framework, which balances three competing priorities: security, privacy, and availability. For product managers and security leaders, the episode makes a business case beyond compliance: poor recovery mechanics drive customer churn when people get locked out after device changes, eroding customer lifetime value. Whether you're building for fintech, consumer platforms, or enterprise systems, this episode clarifies why recovery decisions belong in architecture planning, not patch management.
Account recovery is often the weakest entry point because attackers will target whichever authentication pathway is easiest to compromise. If primary authentication is strong but recovery relies on weak factors like email verification or secret questions, bad actors will exploit the recovery flow instead, potentially taking over accounts completely.
The framework balances three competing priorities: security, privacy, and availability. Designers must choose how to position their recovery system within this triangle - moving toward stronger security typically requires reducing privacy or accessibility, and vice versa, so organizations must decide what trade-offs fit their risk profile.
Attackers targeted help desk recovery flows by calling in claiming they forgot their OTP or other credentials. This worked because the recovery process relied on social engineering vulnerable help desk staff rather than automated, non-human decision-making.
Strong recovery reduces churn from locked-out customers (especially after device changes) and preserves customer lifetime value. Every dollar spent acquiring a customer is wasted if they abandon the account because recovery is too difficult, making recovery a direct driver of retention metrics.
Secret questions are inherently weak knowledge factors that users often reuse or can be compromised through targeted research about a user's background. Dean described storing randomized answers in password managers, but this breaks when users must answer them verbally during help desk calls, exposing the weakness.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers several genuinely useful practitioner insights - especially the claim that recovery must be as strong or stronger than primary auth, and the link between phishing-resistant credentials and shifted attack surface - but these are interspersed with significant conversational filler, repeated reframings of the same point, and generic end-user advice that dilutes the signal.
your account recovery system needs to be as strong or stronger than your primary authentication system. Because if I'm a bad actor, if I'm malicious, I'm going to go after the weakest entry point
if I move to these, these phishing resistant credentials, uh, whether it's consumer or enterprise, and I'm not updating my account recovery processes and policies to account for that, that strengthened front door, then we're just going to shift attackers to that side door of account recovery
Most content is solid practitioner knowledge rather than genuinely contrarian thinking; the iron triangle framework is already published in the ID Pro BoK and is correctly cited as such, and the DPRK-to-recovery-anchor connection is the sharpest original synthesis. The 'crappy login' framing and Reddit's zero-recovery policy are notable but not deeply developed.
I used to call recovery in a lot of my teams I've worked with, I used to call it crappy login, because if it implemented in a bad way, it's often just a crappy way to log in
we've seen the fake worker scam coming out of North Korea. And so in order to deflect that, we now should be doing identity proofing and verification at onboarding. And that gives us a great anchor for recovery
Dean Sachs is a genuine practitioner - 25 years in security and identity, 9-year FIDO Alliance contributor, Amazon veteran who ran root-cause analyses on account recovery failures, and current IAM Principal Engineer at a live fintech - which gives the episode real credibility, though he is an individual contributor rather than an executive, and the two regular co-hosts add additional practitioner depth.
I'm Dean Sachs. I've worked in security and identity for 25 plus years now, about 15 of those in identity. Uh, currently I'm principal security engineer for identity and access management at a company called Remitly
I've been a member of the FIDO alliance for about nine years, uh, where I did work in the Enterprise Deployment working group
The episode earns marks for named real-world incidents (Scattered Spider / MGM Grand / Marks & Spencer / TfL), specific policy examples (Reddit zero-recovery for MFA accounts), and a concrete personal failure story involving a YubiKey and 1Password, but it is almost entirely devoid of quantitative data - no metrics, conversion rates, lockout rates, or cost figures appear anywhere.
scattered spider and the attacks that have happened against MGM grand and uh, Marks and Spencer and Tube for London. And a lot of... a lot of those came through an account recovery flow through the help desk
I was dependent upon a hardware security key, a yubikey, to unlock my 1Password account. And the hardware security key that I stored in my safety deposit box was the one that I forgot to put the credential on
The host makes some effort to reframe questions from a business-value angle (the startup with 80 engineers framing is reasonable) but repeatedly answers his own questions, asks generic consumer-facing softballs, and never meaningfully challenges a claim or pushes for quantification; the conversation meanders and the three-person regular panel often talks over the guest's thread.
why should companies care? Ah, if I'm a startup with 100 people, maybe I have like 80 Swiss, 80 software engineers. And building good recovery might cost me one or two software engineers out of the 80
how is it really different? It's just like sign in but we allow more weak things to still get the user in
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of the Inverted Podcast, we dive into one of the most overlooked - and risky - aspects of modern digital systems: account recovery . Joined by security expert Dean H. Saxe , the conversation explores why recovery isn’t just a backup feature, but often the weakest link in your entire authentication system . From real-world examples of compromised accounts to the surprising ways attackers exploit recovery flows, the team breaks down how even the most secure login systems can fail.
Transcribed and scored by The B2B Podcast Index.
Dana: Foreign.
Host: And welcome to another episode of the Inverted podcast where we discuss products, businesses, services, where successes when nothing happens, when you don't have to use them, uh, when they, when you don't see them. And everything is different for us. And because we've learned that over time, everything is different for us. We want to share with the world and help others engage with Inverted products. And with me, as always, my friends Dario and Dana. How are you both? Dana, did you recover well?
Dana: Still recovering from, from uh, surgery. But uh, we'll see if I can sit in this chair for 45 minutes.
Host: Nice. Well, very good to see you back and with us today. Dean, welcome. Thanks for joining.
Dean Sachs: Good morning. Thank you for having me. It's uh, great to be here and join you guys.
Host: Yeah. And uh, we asked Dean to join. It's a bit of a challenge for me today because I have Dean, Dario and Dana. So I hope I won't mess up the first names. But today we want to talk about something really special. We recently recorded an episode that you can find on our normal channels, um, about a person that got their account hacked and then they had to go back in their account. We call this account recovery. And Dean has worked a lot on account recovery and also digital, ah, legacy. And that's why we invited Dean to come. Dean, why don't you start by just introducing yourself to those who don't know you that are listening.
Dana: Sure.
Dean Sachs: Thank you very much for uh, the brief introduction. Um, uh, I'm Dean Sachs. I've worked in security and identity for 25 plus years now, about 15 of those in identity. Uh, currently I'm principal security engineer for identity and access management at a company called Remitly. Uh, we do cross border remittances. Uh, really a lot of it is focused on immigrants in countries who want to send money back home. Uh, and obviously there's a significant identity component to that. Not only on the customer side, but on the internal user and the workload side. And I have a responsibility for ah, a bit of all of those. Um, but I've also been a member of the FIDO alliance for about nine years, uh, where I did work in the Enterprise Deployment working group. I've done some work within the ietf and as ah, uh, was said, I've also spent a lot of time thinking about this idea of um, account recovery, uh, and most recently been working on a problem of uh, digital estates and digital legacies. And how do you manage your own digital legacy proactively before you die? Um, so that when you do die that data is transferred to the people that you want to transfer it to, or if you wish, destroyed, um, because you may have data that you don't wish to outlive you.
Host: Wow, that's amazing. And for those of you who don't know, uh, they're listening. The FIDO alliance is an industry alliance that basically, uh, has a bunch of brilliant people that define how all of our stuff works from day to day. So whenever you use your phone and you sign in or everything works, it's because there is a group of people behind the scenes that are making sure that everything can talk to each other and it's still safe. And, um, I'm really grateful for your contribution, but also Danon and special Dario, who are very active in those places. And before we go in it, as every time, um, we represent ourselves, not the companies or the clients we work for, um, but we do represent all the things we've learned. And, um, today we want to talk about account recovery. I want to start with you, Dana, because, um, you of course have worked a lot on account recovery also. Um, and what are kind of the two biggest problems you saw in account recovery?
Dana: I think, um, one of them is like, when. When you look at securing an account for, you know, authentication, and people always focus on that, like, how secure is the login? Like, can it get compromised? Um, but on the flip side, if the user loses their password or doesn't have access to their passkey, they need a way to get into their account, right? Because it happens all the time. You drop your phone in the water or, uh, you know, you somehow you don't have access to your password manager. You need a way to get into your account, but unfortunately, the weakest link in the chain, um, you have to look at what is the weakest link, right? And if you have strong authentication, but then you rely on, um, like email verification for recovery, then that means recovery is the weakest point of the. Of the chain. And it means bad actors can easily compromise that account just through the recovery flow. So it's a very hard problem and people kind of give it it sometimes it's an afterthought where really it has to be, um, uh, something front and center. The. The other thing is, it's a very hard problem because if a user's going through account recovery, they're usually in distress, right? Like, like they can't get into their account. Yet you try to make recovery as hardened as possible. You might, you know, you might want to use as much, um, you know, automation so that decisions Are like well defined and, and not arbitrary and. And that means cold usually. And users run into that when they're distressed. And so it could leave a really bad taste about your organization or your service, um, going through recovery. And that's just one like too small. There's a lot to it. But the bottom line is a lot of people think of recovery after the fact, and it's actually might be one of the most important parts of authentication and authorization that you have. Right.
Host: So Dana or Dean, I have a question for you then. Like, Dana just described recovery for us. And one of the things he said is that it sounds like login, but we're just a little bit more lenient. Or maybe that's not what he said, but it's like, how is it. How is it really different? It's just like sign in but we allow more weak things to still get the user in. Or like, can you help us with the difference?
Dean Sachs: Yeah, um, I think Dana described it well, in some ways it is like another authentication pathway, um, or another way to look at it is it's another onboarding or re. Onboarding pathway. And so Dan, um, nailed it, um, when he said that, um, you need to think about account recovery upfront. It needs to be part of your design of your authentication systems. Because I've long argued that, um, your account recovery system needs to be as strong or stronger than your primary authentication system. Because if I'm a bad actor, if I'm malicious, I'm going to go after the weakest entry point. And if the weak entry point is a, uh, reused password that I find, uh, somewhere on the web, I'm going to use that. If I can't use that, then I'm going to go after something else. I'm going to go after potentially phishing or potentially the account recovery mechanism. And I'll give you a great example from my own history, and I've talked about this one before. Um, back when my wife and I, uh, were early in our relationship, we were married, had no kids yet. Uh, she had some stock in a company, um, that was held by a small provider, not like a E trade or something large. Um, and this small provider, I went in to try and pick up some of the tax documents so I could file our taxes and I couldn't remember the password. And this was before the days of password manager, so early 2000s. So I tried account recovery. It wanted to know a couple of things. It wanted to know the email address, uh, and uh, uh, my wife's mother's maiden name and of course, I know these two pieces of information, and it logs me in. It didn't force me to change the credential. I didn't have to rotate the password. I didn't have to do anything. But I was logged into a fully fledged session where I could trade stock, I could get the tax stocks, et cetera. And for the next couple of years, I used that mechanism because it was the easy button to get into the system. And I think that was really instructive to me because it showed how not thinking about this upfront can lead to bad consequences. And so that, I think, is really the key that we need to focus on is keeping the strength high. And a little bit later, maybe we'll talk a bit about a framework that I kind of developed to think about how to balance, uh, the three concerns, which are really security, privacy, and availability of this mechanism when dealing with account recovery. Because being able to balance those, to meet the needs of your customers in your organization is the way that you develop a successful account recovery strategy. Um, you have to be thinking about this upfront and putting this into your planning early.
Host: So maybe there's a question for you, Dario, that I have because it's very important to build this, right? It's different from sign in, but the user state of mind is also different. And, Dana, you said a, uh, user is in a state of elevated panic when they are going through recovery. But to be honest, most times I go through recovery, I'm just in a state of raised annoyance because I forgot my password and it's not urgent. And so I actually have to get in, so I have a bit more time. So, Dario, can you talk a bit more about how people that go through sign in are in a different state of mind than people who are going through recovery?
Dario: Um, yeah, I think that's really one of the aspects to look at. And the danger when you ask people on what is or their expectations is their expectations are often the same. Uh, they just want to get stuff done. Now, um, I used to call recovery in a lot of my teams I've worked with, I used to call it crappy login, because if it implemented in a bad way, it's often just a crappy way to log in. Um, it's the second citizen of login. But when you really look into it as a part of your authentication or whole system, you have to ask yourself as a platform and be opinionated about what are the qualities of those different entry points. And then, yeah, we all probably agree that login has to be um, well, most agree that login has to be simple, login has to be fast and almost work in real time. And recovery can take longer and sometimes it takes longer for safety reasons, for regulatory reasons, and for good reasons. But what I also see happening in the minds of many people is that, that, that might change and maybe in some situations even swap. Because if I'm thinking about services like my bank account where I have to log in every time I need to do something, like every freaking time I need to, I want to check if somebody paid an invoice, I have to go through a full login process. Yes, that login process should be fast. If I'm looking at services like, like my Gmail account where I log in once when I get a new computer and then I've never log in back again, sometimes I have to do reauth there. My expectations will be different when it comes to recovery. That is a different expectation. So yeah, sometimes it helps to tell people ahead of time that recovery will take a while because yeah, it helps you as a system to check certain things, uh, to see if recovery is being initiated by a bad actor. Then you wait a few hours or a few days and then see if there's still activity from the good user. Then you just drop the recovery request. So I, uh, think it's really like anything else. You have to really think about what is the problem you want to solve and how do you position those things against each other. It's useless to have the most expensive lock in your front door, but then have the side gate of your house just be protected with uh, some cable ties and uh, silk string.
Host: Or even when you see some of those expensive villas with a really nice front door and then two glass windows left and right of them that look like you can easily just tap them and get in. Dana, how do people attack recovery? Is the attack on recovery different than the attack on signing?
Dana: Um dep Like I, I think it's um, like you can use intelligence and um, you know like AI and, and recovery policies and things like that against it. But it, it depends on, I think it depends on i1 it is different because they're different flows, right? So, so by nature you have to construct a different attack, but it also depends on like what credentials are, what types of things are used for authentication, right? Because if you're only using password, then you could do like brute force and you could potentially brute force a recovery flow, um, if there's not enough protections on it. But again you need to protect your recovery froze from Brute force attacks, um, and then targeted attacks. A lot of the recovery flows are targeted attacks as well. Right? So find out information about a user and then go and try to go through a recovery flow. Like traditional, like old school recovery flows are secret question, secret answer. Right? So you go and figure out what your knowledge about your user and then go and use those, um, uh, information, um, to try to get in for recovery. So, um, but I think each attack is an attack. Like, is it like it's all crafted for. You have to target your attack and it's crafted, um, uh, so I think it depends on, I think it is different per flow, I guess.
Dean Sachs: I love that you mentioned the secret question and answer because, uh, for years I have answered those incorrectly. Um, and what I mean by that is when I'm asked to enter a question and answer, I give the most bullshit answers ever. I just create some random string, I store it in my password manager and it has nothing to do with the question. So if the question is, you know, what is your favorite color? The answer is some 60 character random string. Um, and one time it bit me in the ass. So I was trying to actually get a mortgage, um, and had to move some money from one bank to another and I had to call the bank to do the wire transfer. And they actually asked me the secret question and this answer is some long string. I'm like, hang on a second. And I go into the password manager and I change it and I go into the account and change it there. And I'm like, can you reload your page and ask me that question again? And so they reload their service, they ask me the question, I can give them an answer that I can read out in English and then go back and change it to something unintelligible again. Um, but yeah, it's a real problem because we are looking at these things as alternative credentials and they are inherently especially as knowledge factors, uh, or something I'm storing in my credential manager. They are inherently weak. And this is a real problem when it comes to security, especially for these remote recovery use cases. If I can show up in person, it's a different story than the remote case.
Host: Dean, I have a question for you specifically. Um, why should companies care? Ah, if I'm a startup with 100 people, maybe I have like 80 Swiss, 80 software engineers. And building good recovery might cost me one or two software engineers out of the 80, but they could also be pushing out new features that generate revenue, et cetera. Um, like how do you articulate the business Value of spending a quarter to build really robust recovery flows.
Dean Sachs: I would turn the question around and say how do you um, justify building strong authentication for your users? Right. Uh, because it is part and parcel of the same thing. This is all about how we get into our, get access to our accounts and do work. And so if we build, as we've discussed, if we build a weak recovery flow, then we're going to see that abused. Um, and um, the evidence is there right now. We look at uh, scattered spider and the attacks that have happened against MGM grand and uh, Marks and Spencer and Tube for London. And a lot of. Right. A lot of those came through an account recovery flow through the help desk. Hey, I forgot my otp. Can you reset this thing for me? And that's a real problem. And I think Dana said earlier something around uh, uh, automation and automation is so critically important because humans are fallible, we make mistakes and we are socially engineerable. And so one of the things I focus on when building account recovery systems and thinking about account recovery systems is how, how do I take as many humans out of the loop as possible? Because I've seen uh, in my own work at organizations I worked at, how account recovery fails. Um, I've had to do um, uh, so I worked at Amazon for a number of years and if you're familiar with Amazon culture, you're familiar with the CoE or correction of error process which is root cause analysis. I've done many uh, root cause analysis or coe on account recovery and how it fails. And so I have, have seen the badness, uh, I've seen what good looks like. And the reality is I think most account recovery systems that I see in the wild are actually not very good. They're not user friendly, they're not necessarily as secure as the primary set of credentials. And as we move into this world of uh, highly phishing resistant credentials that are not reusable, I'm really talking about Fido here and Passkeys. As we move into that world more and more m improving the account recovery process uh, is very much aligned with um, moving to these better credentials. Because if I move to these, these phishing resistant credentials, uh, whether it's consumer or enterprise, and I'm not updating my account recovery processes and policies to account for that, that strengthened front door, then we're just going to shift attackers to that side door of account recovery to attack our services and take over accounts and that would be uh, a net negative for everybo.
Dario: Yeah, I think there's also uh, maybe an even more Fundamental business element to it.
Host: Exactly.
Dario: I've worked at platforms with hyper growth phases and while you just grow more than in your wildest dream, as you could imagine, and even more than you predicted to your investors, recovery can be a bit of an, is an afterthought. But the moment the growth slows down and you're losing more people because of they change the devices, their phone flushed down the toilet, whatever the reason might be, the more then the pressure gets on. Account recovery, like in so many industries, especially more mature digital industries, we're measuring things like customer acquisition rate where we see it as successful while we reduce the customer acquisition rate, but then we ignore can't lockout rate because, because that's not in the same flow. But if somebody gets locked out and talking about consumer, uh, accounts, for example, the big consumer platforms, they have all about the same issue that when people abandon their old phone, their chance that they will have to go through account recovery on the new phone is significantly bigger, which then means it will be expensive and the chances that somebody that people are not successful recovering are bigger. So you lose your customer relationship and losing that customer relationship means that the customer, that the money you spend to acquire that customer is, well, is drained down the toilet with the phone that was flushed down or with the session or with the cookies. And so that means it's also a business element of how do you reduce your costs, how do you extend the long term, uh, customer value? Because not all of them will create a new account and start from scratch. And even if they do, the value that that account has for you as a company is going to be lower for at least the beginning.
Host: Yeah. So basically you're saying we've been saying like account recovery, it is the right thing to build, but it actually also makes business sense because it brings value. And um, before we go to the next subject, um, Dean, you mentioned you have a framework. So let's say I'm a product manager at a new company and my boss has listened to this podcast and he says, hey, so and so we need to build account recovery as well, not just have a failed sign in with a password recovery. Can you give us a one minute summary of what that framework is and how should I approach that as this junior PM that's building this?
Dean Sachs: Sure. Um, so the framework is, I call it an iron triangle of account recovery. And if you go to the ID Pro, uh, body of knowledge, bok.idpro.org, you can look up an account recovery article where it's well described. Um, but In a nutshell, um, we have three things that we care about in account recovery. We care about the privacy of the user, we care about the security of the recovery event, and we care about um, the availability of the recovery event or the accessibility of the recovery event. And if you think of these three things in a triangle, I can move closer to the security vertex of the triangle or I can move closer to the privacy security, uh, uh, a privacy vertex of the triangle. But I do. So, uh, if I move towards security I have to reduce privacy or I have to reduce accessibility or availability. And so we have to keep these three things in balance. And so you might say that um, you do not support any account recovery whatsoever, as Reddit does. Uh, once you've assigned multi factor authentication to a Reddit account, they have zero account recovery if you have MFA enabled on the account. And so they have dropped availability to zero and focused on privacy and security. And that may not be the right choice for everybody. Um, maybe you want a very high security process where say you are doing um, uh, remote, ah, identity proofing. Maybe you've done that at onboarding and now you're doing that again during recovery. And if you're doing um, this identity proofing, you've dropped the privacy, um, you've really reduced the privacy aspect, but you've increased the availability because most of us have some sort of ID and you've increased the security assuming you're using a very good identity proofing provider, which maybe not all of them are as good as one another. Um, but you keep these things in balance, right? And so it is a product decision point about what are we going to focus on here and do we keep all three in balance? Do we focus more toward one end of the spectrum than the other? And I think that's the push and pull when designing these systems and it is influenced by the primary credentials that you have. Uh, the security of those primary credentials and the overall security of the account in financial services is going to be very different than say social media.
Host: And I think also we should tell companies to not pretend that they are more than they are. Because if McDonald's is pushing me to go through account recovery again, I'm like, you're McDonald's. Please stop acting like you're my bank. Or I've had um, some loyalty programs that want me to, I don't know. And I'm like, you're not, you don't have any money. The only thing you have my points, you know, if someone wants to have my points, have at it. But, um, other times, you know, when. When you're my telco operator, I had to order a new sim. And then they said, well, we'll send you the SIM with a letter. Then you get a separate letter. You have to call us with both letters, and then we activate the sim, which is great because obviously we all know this very famous. I think it's. Was it Engadget or TechCrunch, sorry, TechCrunch article of this journalist that was SIM swapped. And, uh. So, yeah, I guess as a company, we also have to maybe be honest and be like, we're probably not the most important system out there, so let's focus on getting people back in rather than making it. I love this triangle idea. And, um, we'll link to the article that you mentioned in the. In the description. Dana, before we go to the next
Dana: step, m. Uh, talking about all this and thinking about where the industry is now. Um, I, you know, as a consumer user of passkeys, right. Like, every site I go to now is asking me, do I want to enable passkeys? Um, but what they. They don't tell me is how that impacts recovery, which is like, now, I don't know. And I was thinking about it the other day because I was at, like, a major site and they're like, hey, you should just use pass keys. I was like, great, enable it. And then. But they never clarified, like, what does that mean for my account recovery? Is password no longer available to use to log in anymore? Um, have you strengthened the recovery? Because I'm now using passkeys. Um, because on some accounts, some of the things we did at Microsoft is when you opted into strong auth. And we'd say, hey, that's great, but you no longer have these recovery mechanisms available to you. You need to, you know, use recovery codes on. But with passkeys, that's not really happening because things are happening so, so quick and the dialogues are just coming up and everything. And. And I. And so I'm not really what. Sure what's going on in the back of these systems in terms of their recovery. And the thing is, some things might not change at all. Right?
Host: Yeah. And Dana, you're technical and you've designed some of these systems, but remember the hijacking victim we interviewed? They don't even know. When we said, do you use passkeys? She said, oh, I just use my fingerprint on my phone. They don't even know what that means. So can you imagine, you know, if it's complex for us, what it's going to be like for the average person on the street. They have, they have no clue, Dario.
Dario: Yeah, and I think that's, that's a really important point. It's, it needs to be explained clear because people are afraid of losing access to their accounts. Like, uh, as much as product managers on the sign inside think that, well, this is an exception. It's an edge case. Um, it's easy to downplay. But people are worried. That's one of the things that holds people back from enabling two factor authentication on their accounts. That's one of the things that prevents people from clicking no on the push notification that asks, uh, or yes, no on the push notification that asks them, was it you that got that signed in on this new device or not? It's all of those fears of losing access. And we need to understand what that fear means to these users. I mean, we spoke to Olivia, the YouTuber for her losing access to a Gmail account to that specific Gmail account is much more worrisome than, um, me losing one of the spam Gmail accounts I have where I just.
Host: You have a spam Gmail account, Dario? I didn't know.
Dean Sachs: That explains all the email I get from Dario now.
Dario: From Dario.
Host: And by the way, I'm suggesting let's do another episode on Digital Legacy because we're running out of time so we can talk.
Dario: I would love to have Dean again.
Host: You're coming back?
Dean Sachs: Um, all right, I will do that for sure.
Host: For Digital Legacy, um, maybe just for. Did you want to finish your point?
Dario: Yeah. Just to add, like endless companies, we a need to understand that consequence for the cost for that, for people, what it would mean to lose access to the account. And also then we have to understand it's not the same for everybody. Like account recovery, just like sign in and other policies. I've worked for companies with billions, um, of users where on one side you have um, somebody who hasn't used their account for years and wouldn't even remember their credentials or that they have it. And on the other side you have advertisers who. Business model depends on being able to advertise on that, on that platform. Account login and recovery should not be the same for those, for those users or. I've done a lot of work around protecting people who are being highly targeted. If you know that somebody is highly targeted because they're in a marginalized community, they're a human rights defender, elected official, whatever you name it, or have bragged about their bitcoins on Reddit, those people have different requirements on recovery. And I think platforms need to understand their users better and adjust that because.
Host: And what are some innovations we're seeing? Right, because we have username passwords and then we can ask for phone number and then we have. What are some other things we could do in recovery that you all have seen that are kind of novel?
Dana: Sure.
Dean Sachs: Well, there's a couple of things. So Dana brought up passkeys, and I think passkeys are an interesting example here because, um, normally we think about account recovery, it's because I forgot my password or I don't really lose credentials out of my password manager. If I did, I'd have a big problem with my password manager. Um, the same would be true with passkeys. Right. You're not going to lose a passkey unless you lose access to the credential manager or, um, because of some of the nuances of. Yeah, but because of some of the nuances of, uh, how passkeys work in the wild, uh, you may have put it in the wrong credential manager and not know where you put it. That's a way you could potentially lose it. But let's assume that the user has passkeys. Um, recovery now takes two forms. I can recover through my provider, so through Google, through Apple, whatever, or I can recover the credential through my password manager. Because my password manager, if I have a mechanism to log in to my password manager, and so I have a, uh, recovery kit that's in my safety deposit box at my bank, if I can gain access to that password manager, that credential manager through some mechanism, that is my account recovery pathway now. So I think that's one important thing we have to keep in mind with passkeys. Um, on the other side though, as far as other recovery mechanisms, there's, uh, a lot of them out there, a lot of them are really bad. It's confirmed you got this SMS OTP or you got an email otp, which then depends on the security of those, uh, devices, uh, or those pathways. And uh, it also depends on your susceptibility to being phished. Um, so that's obviously weak. We don't want to do that. Um, I mentioned identity proofing and verification. So if you have a flow that requires some identity proofing and verification, say you're working in a fintech, uh, and your customers need to do idv, then, uh, you can redo that flow for your employees. Um, now I'm recommending that um, uh, employers do identity proofing at onboarding because we've seen, um, dprk that North Koreans, uh, we've seen the fake worker scam coming out of North Korea. And so in order to deflect that, we now should be doing identity proofing and verification at onboarding. And that gives us a great anchor for recovery for those same users later. But it may not always be through that same pathway. It may be that we give them an alternative credential. What if I give you as a user, um, here's a vc. Stick it in the wallet in your phone. A verifiable credential. Sorry, just put it in the wallet in your phone. And then if you need to do account recovery, can you present that verifiable credential to me?
Host: You mean like a little card or a USB stick or. What do you mean?
Dean Sachs: Oh, no, sorry. I literally mean like a digital credential, um, that we as a business. So, um, let's say, you know, you're working at Dean's House of Widgets, and I onboard you and I go through some identity proofing to onboard onboard Dario into my team. And as part of that onboarding, I say, okay, Dario, I'm going to issue you a digital credential, a verifiable digital credential that you're going to put in Apple, ah, Wallet or Google Wallet or whatever it is that you might have on your. On your device. And when Dario comes to me six months later and says, I lost my credentials, I broke my Yubikey, whatever it is, I, uh, can then say, okay, cool. Dario, can you, um, re. Authenticate through another pathway, and that's using or re. Identify yourself through another pathway? And, And I'd be using this verifiable digital credential, which is bound to his phone and unlocked by his face or his thumbprint. So there, There are lots of new and emerging mechanisms. Uh, I, uh, prior to starting at Remitly, was advising a company in this space, um, uh, that's doing some interesting things here. You've got face Tech doing some interesting things with QR code, or, sorry, I think they call them UR codes. Um, so there's lots of interesting developments in the space right now, and I think you're going to see more and more happening here because the necessity for account recovery and strong account recovery, uh, exists in every industry, whether it's uh, uh, consumer, ah, focused or enterprise focused. It is something that exists and we need to be taking care of this to reduce the risk of attack through, uh, the account recovery pathways, which are very real and exist in every space. We Operate today.
Host: Yeah, yeah. And Dana, if, if you are like, um, if there's people listening that are not maybe working on this stuff, but they're consumers or they have accounts, what should they do to protect themselves?
Dana: I think you have to regularly, and some services prompt you for this, but regularly review your recovery mechanisms. Make sure your phone numbers are correct. You're, you know, if you have, uh, backup codes, uh, make sure you back goes up someplace safe. Like, you should continue, you should always try to use the strongest authentication you can and just review your, um, all the recovery mechanisms regularly to make sure that it's up to date so that if something happens, you're able to recover.
Host: So I think as an end user,
Dario: sorry, like, account, like contact point freshness is a huge topic. Like, yeah, we always think that our digital identity, these are forever. But, uh, I mean, do we remember our first email address? And how long ago, I mean, how long ago have I used my first email address that I registered? It's been more than a decade and I wonder how many accounts might be linked to that. And so there's a. Like, I have an example, like when we moved from the US to the uk, um, my wife forgot to change some notifications from her mobile provider and so she didn't pay for the mobile for three or four months. And like four months later I went back to the us I wanted to port that number for her to another SIM card. And by then the number has been recycled already and, uh, another person owns that new number. So when I gave the number, they addressed me as Jose because they thought I'm the current owner of that number. And so you lose so fast, you lose control over your contact points through which people can reach you, which is another example of why they're just so imperfect. Like sending these things via email or sms, uh, is not just less secure, can be phished. I mean, there's all types of security factors, but yeah, we tend to change. Like, we tend to change employers. And so everybody who signs up or their first LinkedIn account through their company address has gone through that nightmare of creating a new one or recovering it. Um, we leave universities at some point or schools, so we lose access to these contact points or we move countries. And that makes them all very imperfect for recovery methods. We think that phone numbers are for life, but they're just not.
Host: Yeah, I think, um, Dana, in the beginning you said something earlier like, we're all scared of losing access to your, to our accounts or one of you, Dario. Dana, the left side of my screen said, It. But in reality, most people don't think about it. If I go on the street and I'd be like, are you scared of. Of losing your Google account? The first one will be. First reaction will be like, not really. And then they think about it and in 30 seconds takes them to realize, oh, wait, wait a minute, I authenticate to this, that such. Such wait, that would actually be really bad. And they start panicking. And then they might ask you, wait, should I be doing something? Should I be worried? And that's why I don't mind when customers actually prompt their users to say, hey, don't lose access. Uh, review your recovery stuff. Uh, um, but yeah, maybe it's because I work in this industry that I'm a bit more.
Dana: The problem is your grandmother just hits skip.
Dean Sachs: That's right.
Dana: Making sure that it's like gamified or like the user experience is good to review those. The account freshness is. Is important.
Dario: I hit skip. I hit skip.
Dana: So do I.
Dario: Because I think I'll do it in five minutes. And then my ADHD kicks in and
Host: I will keep walks into the office.
Dean Sachs: Yeah, yeah. And everything goes to crap at that point. But I think one of the things that we forget about in this space, um, and I spoke about this at Authenticate last year, and eventually that video will show up online, is, um, uh, we forget about the fact that we don't just lose accounts because we forgot the password or we forgot the credential somewhere or because it got taken over. We lose access because life happens. Uh, the Pacific Palisades fire a year and a half ago. How many people lost their homes and all of their digital data with that and then had no way to get back into those accounts. And so I actually did an experiment where I set up a new Mac and I tried to recover my digital life. And again, this is that authenticate talk that will hopefully show up online at some point. But, um, went, uh, through the process of trying to actually recover all of my digital assets, and I failed. And I thought I was good at this, but I failed because I was dependent upon a hardware security key, a yubikey, to unlock my 1Password account. And the hardware security key that I stored in my safety deposit box was the one that I forgot to put the credential on. And so at the first step of my recovery, I failed. And I had to go to another Yubikey I had on my keychain in order to do recovery. So we have to really think about this hard and think about the durability of not only the mechanisms that we use with the companies that we use, the Gmails, the Apples, et cetera, but also how do we get back to um, that password safe that has all the credentials as we are now as humans, moving more and more of our credentials into those because of the rise of passkeys.
Host: I think that's a really good, a really good point maybe to end this week. So we've talked about a lot of things, right? We've talked about why recovery is important. It's not only the right thing to do, but it also makes business sense. We've talked about how it's different from sign in, how the user has maybe a bigger attention span, but also different emotion. We've talked about the framework, Dean, that you mentioned. We will link to have like uh, a triangle of, you said privacy, safety and availability or accessibility. Those three. Right. And picking the right spot on that three dimensional or that space and how to be might be different from McDonald's versus Bank of America. Um, or at least it should be. I Hope you're listening, McDonald.
Dean Sachs: Let's hope so.
Host: Um, and then we've talked about a whole bunch of recovery factors and we sort of ended on not just recovery factors, but also the place where we store those that we should think about those. And yeah, it's been amazing, Dean, to have you. And we've already decided to have you back to talk about what happens if you are actually no longer there to access your account. Right. And other people are there to recover your stuff. So we'll do that in another, um, episode. So thank you for joining us and also, um, thank you Dario and Dana, as always for um, an amazing episode. And thank you all for viewing, listening, wherever you are. And remember that it's a really, really great thing to work on the safety, security, um, for the people that we care about because saving one is worth it. See you in the next one. Bye. Bye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.