
What's Up with Tech? · 2026-07-01 · 15 min
Key moments - from our scoring
Substance score
22 / 100
Five dimensions, 20 points each
Yubico's SVP of Product Management Dawn Manley discusses how physical security keys address the gaps in modern account protection, particularly as AI systems become repositories for sensitive business data. YubiKeys are hardware-based authentication devices that use cryptographic verification to prevent phishing attacks - unlike SMS codes or authenticator apps that can be intercepted or spoofed. The device requires physical presence and a touch gesture, eliminating bot-based attacks and ensuring human intent behind critical actions. Yubico recently partnered with OpenAI to integrate phishing-resistant authentication into ChatGPT's advanced account security program, targeting high-value users like journalists, researchers, executives, and sensitive data handlers. The partnership signals a broader industry shift: as AI agents increasingly act autonomously on behalf of users, identity verification must evolve beyond login authentication to authorize individual transactions. Enterprises considering deployment learn that YubiKeys provide a cryptographic anchor for high-consequence moments, addressing the sophistication of AI-enhanced phishing attacks that users alone cannot detect.
YubiKeys use cryptographic authentication to verify the user is signing into the real service, not a fake site, and they require physical presence - a touch gesture - making it impossible for remote bots or attackers to approve actions. Unlike codes or prompts that can be tricked or stolen, the hardware-based approach uses technology to prevent attacks from succeeding rather than asking users to spot sophisticated attacks.
Yubico and OpenAI partnered to bring phishing-resistant hardware authentication to ChatGPT users through OpenAI's Advanced Account Security program. It's designed for people at higher risk of targeted attacks - journalists, researchers, public figures, executives, and those handling critical sensitive information - because AI accounts now contain business context, intellectual property, code, and customer data that require stronger protection.
Hardware-based security keys require user presence and a physical touch to authenticate, providing proof of human presence that cannot be automated by bots. Software apps like authenticator codes or QR codes lack this physical verification requirement and can be compromised if the device is remotely accessed or the codes are intercepted.
AI accounts hold sensitive business context, research, code, intellectual property, customer information, and workflows that support important decisions. As AI systems transition from tools users interact with to autonomous agents acting on behalf of users, the accounts controlling these systems become critical attack surfaces that require stronger authentication and authorization controls.
As AI agents act as proxies for users, YubiKeys provide a cryptographic anchor to verify true human intent at high-risk, high-consequence moments. They ensure a real person physically authorized actions, not just an automated system, which becomes essential when AI systems execute transactions or access sensitive data autonomously.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is essentially a product marketing segment that recaps well-known security concepts (physical MFA, phishing resistance, cryptography) without adding anything a B2B operator in tech or security wouldn't already know. Filler and basic definitions dominate the 15 minutes.
strong security only matters if people actually can use it
a Yubi key is a small physical security key that helps prove it's really you when you access your account
The only mildly novel framing is positioning AI agent workflows as a new identity problem requiring human-touch authorization, but this insight is stated once and not developed. Everything else is recycled industry messaging about phishing resistance.
identity is no longer about just who logged in, it becomes who authorized this action and can we trust that a real person approved it
the Yubi keys can provide a cryptographic anchor for those high-risk, high quantity, high consequence moments
Dawn Manley holds a legitimate senior practitioner title (SVP Product Management at Yubico) and has real domain expertise, but this appearance is a vendor PR slot, not an independent operator sharing hard-won lessons at scale. Her answers stay at a marketing altitude.
I'm Senior Vice President of Product Management at Ubico. And my role is focused on connecting emerging security needs with practical solutions that customers can actually deploy in their environments
Almost no concrete data, metrics, customer numbers, breach statistics, or deployment timelines are offered. The only tangible specifics are the OpenAI partnership announcement and the physical form factor descriptions, which are product marketing details rather than evidence.
for open AI users in particular, this partnership includes a custom two-pack of Yubi keys
OpenAI actually already uses YubiKeys internally to protect their employees and their infrastructure from sophisticated phishing attacks
The host openly identifies as a YubiKey fan, asks no challenging questions, and when the guest explicitly deflects on enterprise deployment ('I won't try to cover them all here'), he drops the thread entirely. The interview functions as a scripted product demo rather than a substantive conversation.
I won't try to cover them all here
Why did OpenAI feel that Ubico was the right fit for this program
Computed from the transcript - who did the talking, and the words that came up most.
Interested in being a guest? Email us at admin@evankirstel.com Your AI account is quickly becoming your most valuable account. It can hold business context, customer details, code, research, and the day-to-day workflows you rely on. That also makes it a prime target for phishing and account takeover, especially as attacks get more convincing with AI. We sit down with Dawn Manley, Senior Vice President of Product Management at Yubico, to unpack what “phishing-resistant MFA” actually means and why hardware-backed authentication changes the game. We compare the familiar world of SMS codes and approval prompts with a physical security key that uses strong cryptography, verifies you are signing into the real service, and requires real user presence. The goal is simple: stop attacks from succeeding instead of expecting every person to spot every scam. We also dig into Yubico’s partnership with OpenAI to bring stronger account protection to ChatGPT through OpenAI’s advanced account security program. We talk about who it’s built for, why AI accounts are now high-risk, and how identity is shifting from “who logged in” to “who authorized this action” as agentic workflows become more common.
Transcribed and scored by The B2B Podcast Index.
1 - > SPEAKER_01: Hey everybody, fascinating chat. 2 - > Today we're talking about stronger account security in the 3 - > age of AI with Yubico and how their UBTs can help protect 4 - > access to the tools we use every day. 5 - > Dawn, how are you? 6 - > SPEAKER_00: I'm great.
7 - > Thanks for having me, Evan. 8 - > SPEAKER_01: Thanks for being here. 9 - > For those who may not be familiar, how would you describe 10 - > Yubico? 11 - > What do you focus on?
12 - > And a little bit about yourself. 13 - > SPEAKER_00: Well, thanks again, Evan. 14 - > I'm Dawn Manley. 15 - > I'm Senior Vice President of Product Management at Ubico.
16 - > And my role is focused on connecting emerging security 17 - > needs with practical solutions that customers can actually 18 - > deploy in their environments. 19 - > So what I love about this work is that it sits at the 20 - > intersection of security, usability, and trust. 21 - > Because strong security only matters if people actually can 22 - > use it. 23 - > SPEAKER_01: And usability is key.
24 - > I have an extra Ubi key here that I travel with. 25 - > You never know when uh one could come in handy. 26 - > What is the YubiKey and exactly what is the value prop behind 27 - > Yubico? 28 - > SPEAKER_00: Well, so for those who aren't familiar, um I I 29 - > actually have one right here.
30 - > In fact, I have two. 31 - > You could see that one is uh, you know, it's smaller than a 32 - > house key, and the other one is almost so tiny you can't see it 33 - > behind my fingernails. 34 - > It's intended to be something that you could keep in your 35 - > laptop or your desktop at all times. 36 - > So a Yubi key is a small physical security key that helps 37 - > prove it's really you when you access your account.
38 - > So, I mean, like I said, it's smaller than a house key, but 39 - > think of it like a house key for your digital accounts, but 40 - > smaller and even more secure. 41 - > So you could plug it in or tap it when you access a device or 42 - > system from your computer, and it uses strong cryptography to 43 - > confirm your identity. 44 - > So it's like uh it's like a physical start button for 45 - > critical workflows and AI sessions. 46 - > You're proving that you are physically present and you're 47 - > authorized to access your account.
48 - > SPEAKER_01: So critical. 49 - > And many of us have learned, uh, some of us the hard way that you 50 - > know simple two-factor authentication isn't enough 51 - > these days in this world of frauds, uh fraudulent phone 52 - > numbers and phishing. 53 - > And um tell us how does phishing resistant multi-factor 54 - > authentication work together with Ubigo? 55 - > Why are you considered the gold standard for security?
56 - > SPEAKER_00: Yes. 57 - > Oh, well, thanks for asking the question. 58 - > Yubi Keys are phishing resistant because they don't rely on a 59 - > user typing in a code or approving a prompt that can be 60 - > um that can be tricked or stolen. 61 - > Uh the keys use cryptographic authentication to verify that 62 - > the user is signing into the real device or the real service 63 - > and not a fake uh or look-alike site.
64 - > So uh what the YubiKey does is it enables us to, we're not 65 - > asking the user to spot every sophisticated attack. 66 - > We're using the technology to help prevent the attack from 67 - > happening in the first place. 68 - > So that is the role of what YubiKeys have in phishing 69 - > resistant MFA. 70 - > SPEAKER_01: Interesting.
71 - > So hardware-based security, again, I I have a few of these. 72 - > And you know, for those techies watching, including myself, how 73 - > how is hardware-based security maybe different from 74 - > fundamentally codes and texts and QR codes and other 75 - > authentication apps that are so widely deployed out there. 76 - > SPEAKER_00: Well, I think that it one of the key differences is 77 - > that it actually requires user presence. 78 - > So I mentioned that you have to physically have the key, but 79 - > when you're actually authenticating an action, you 80 - > have a physical, physical touch that you give the key.
81 - > So you have proof of human presence. 82 - > So it can't be a bot out there somewhere on the broader 83 - > internet that is approving actions for you. 84 - > You actually need to have the key and be physically present to 85 - > signify that you have authorized that transaction. 86 - > SPEAKER_01: Yeah, so important.
87 - > Um, so let's dive in a little deeper. 88 - > Obviously, UV key is relevant to your entire digital footprint, 89 - > but increasingly to AI and AI apps, tell us about your 90 - > announcement, your partnership with OpenAI. 91 - > What was the background? 92 - > How did that come together and why?
93 - > SPEAKER_00: Yes. 94 - > So, well, let me tell you about the partnership. 95 - > So UVCo and OpenAI are partnering to bring 96 - > phishing-resistant hardware-backed authentication 97 - > to Chat GPT users through OpenAI's advanced account 98 - > security program. 99 - > So the simple version is this.
100 - > As you mentioned, AI accounts are becoming high-value 101 - > accounts. 102 - > They can hold business context, sensitive research, you know, 103 - > code that you're writing, your intellectual property, customer 104 - > information, and you know, all of those business workflows that 105 - > people depend on. 106 - > That makes protecting access to those accounts incredibly 107 - > important. 108 - > A YubiKey protects access with a physical security key.
109 - > So even if an attacker steals a password, they can't get into 110 - > the account without the physical key. 111 - > And for open AI users in particular, this partnership 112 - > includes a custom two-pack of Yubi keys. 113 - > Um, one for mobile use that we've shown here, and another 114 - > low-profile key that can stay in your laptop, the one that's the 115 - > size of my fingernail. 116 - > SPEAKER_01: Brilliant.
117 - > So does this apply to any open AI user? 118 - > Or uh how does the open uh advanced security uh program 119 - > work? 120 - > Who is the right audience or user for that? 121 - > SPEAKER_00: Yes, so advanced account security is designed for 122 - > people who are at higher risk of targeted digital attacks.
123 - > Think of journalists, researchers, major public 124 - > figures, executives, and others handling very critical sensitive 125 - > information. 126 - > But I think that advanced account security reflects a 127 - > broader shift. 128 - > AI accounts are becoming more important because they contain 129 - > sensitive data, business context, intellectual property, 130 - > and workflows that support those important decisions. 131 - > So the goal of this program is to give those users a stronger 132 - > foundation of trust by protecting their accounts with 133 - > these phishing-resistant authentication and authorization 134 - > capabilities.
135 - > SPEAKER_01: Amazing. 136 - > And why Ubico? 137 - > Why did OpenAI feel that Ubico was the right fit for this 138 - > program, given the different technologies and keys that are 139 - > out there in the marketplace? 140 - > SPEAKER_00: Yeah.
141 - > Well, OpenAI actually already uses YubiKeys internally to 142 - > protect their employees and their infrastructure from 143 - > sophisticated phishing attacks. 144 - > You can imagine how this is important for such a significant 145 - > company. 146 - > You know, the partnership was a natural step. 147 - > Let's bring that same strong protection to their ChatGPT 148 - > users.
149 - > So UbiCo has deep experience helping organizations move 150 - > beyond legacy authentication to phishing resistance security. 151 - > So what's exciting here is the scale and timing. 152 - > AI is becoming a cornerstone of everyday work, and stronger 153 - > account protection needs to be practical and accessible. 154 - > SPEAKER_01: Yeah, I think accessibility is key and 155 - > transparency.
156 - > I love how seamless uh the UBK is. 157 - > You don't really think about it. 158 - > You're not memorizing passcodes and passwords and uh and 159 - > versions of apps and that kind of thing. 160 - > And I think it has implications for the broader AI ecosystem.
161 - > I mean, I certainly am a power user, so OpenAI literally knows 162 - > everything about me, my personal and professional life, which is 163 - > a little sad in one way, but on the other hand, a little scary. 164 - > Uh, what are what are some of the big picture impacts you 165 - > think this might have across the industry in keeping all of our 166 - > digital assets safe? 167 - > SPEAKER_00: Well, Evan, I'm glad to hear that you're a power user 168 - > and you've mastered the art of using the YubiKey and using uh 169 - > ChatGPT and OpenAI services.
170 - > So when I think about the ultimate goal of bringing OpenAI 171 - > and Yubico together, it's really to make the strongest possible 172 - > account protection easier to adopt. 173 - > And as you said, as AI becomes more central to the way people 174 - > work, we need to ensure that all of that sensitive information is 175 - > protected appropriately. 176 - > And as you said, AI is moving from a tool we use to something 177 - > that can actually act on our behalf. 178 - > So you can automate a lot of these actions through uh agentic 179 - > workflows.
180 - > So, what does this mean? 181 - > It means that identity is no longer about just who logged in, 182 - > it becomes who authorized this action and can we trust that a 183 - > real person approved it? 184 - > So the Yubi keys can provide a cryptographic anchor for those 185 - > high-risk, high quantity, high consequence moments. 186 - > And that's what we're really excited about and look forward 187 - > to um being able to support longer term.
188 - > SPEAKER_01: Yeah, and it sounds like uh, you know, these are 189 - > critical for individual power users like myself, but 190 - > enterprise-wide, it seems like YubiKey should be fundamental to 191 - > an employee as their uh employee ID card or their company-issued 192 - > laptop. 193 - > Uh, is that the case in the industry yet, or do we have a 194 - > ways to go? 195 - > SPEAKER_00: I think it's beginning to percolate 196 - > throughout the industry. 197 - > And so as we think about how this launch impacts the broader 198 - > AI ecosystem, it really sends an important signal that security 199 - > has to evolve alongside the development and widespread use 200 - > of AI.
201 - > So, as you mentioned, AI systems are becoming places where 202 - > sensitive information, decision making, and automation come 203 - > together. 204 - > If you can't trust the identity behind the account, it becomes 205 - > much harder to trust the actions connected to that account. 206 - > So, this launch is about more than securing Chat GPT logins, 207 - > for example. 208 - > It points to a future where phishing-resistant 209 - > authentication becomes part of the infrastructure layer for AI.
210 - > It helps establish trust before sensitive data is accessed or 211 - > high impact actions are taken. 212 - > It has that extra layer of production, yes. 213 - > SPEAKER_01: Yeah, absolutely. 214 - > And you know, so so many companies are thinking about 215 - > security.
216 - > They've they've they've got uh better passwords, for example, 217 - > and password management tools, and they've got some of the 218 - > basics, but it seems like we need to move beyond just 219 - > thinking about passwords and two-factor enablement, which is 220 - > you know, table stakes now. 221 - > Um, what is the practical step to deploying uh a YubiKey 222 - > enterprise-wide? 223 - > I mean, can this be done in hours and days? 224 - > I mean, could how can you get a thousand keys into the hands of 225 - > a large enterprise?
226 - > And how much work is involved in sort of provisioning and 227 - > deploying this? 228 - > SPEAKER_00: Well, there are many different options for 229 - > deployment. 230 - > I won't try to cover them all here. 231 - > And I think that rather like let's think about the big 232 - > picture here.
233 - > How will this uh change the game as digital threats continue to 234 - > evolve, especially in enterprises? 235 - > And so what we really need to do here is ensure that we're moving 236 - > away from relying upon users to detect threats and to use just 237 - > their best judgment because these phishing attacks are 238 - > becoming increasingly sophisticated and much more 239 - > personalized. 240 - > AI can make those attacks even harder to recognize. 241 - > And so with phishing resistant authentication, we can help stop 242 - > the attacks from succeeding.
243 - > As AI agents become uh proxies for users, we'll need to weigh a 244 - > way to verify that there was true human intent at those 245 - > high-risk moments. 246 - > And that's where hardware-backed authentication becomes 247 - > incredibly powerful. 248 - > SPEAKER_01: Really compelling. 249 - > So we have a number of industry events coming up this summer, 250 - > Black Hat and DEF CON, uh, where these topics will be top of 251 - > mind.
252 - > Um, where do you see the future of hardware like UbiKey headed? 253 - > Uh, I I guess you know, we're getting new form factors, new 254 - > kinds of devices. 255 - > You we saw all the different varieties and integrations you 256 - > have. 257 - > I imagine this will only continue as uh we get more 258 - > devices in hand and USB-C becomes ubiquitous, and perhaps 259 - > wireless becomes ubiquitous.
260 - > I I in Sweden, for example, I know there it's popular to get 261 - > an implant of an RFC chip for security. 262 - > I wouldn't go that far. 263 - > Uh, but what is the future? 264 - > What does it look like for hardware-based authentication?
265 - > SPEAKER_00: Well, we're not yet in the business of implants of 266 - > Ubi keys in in humans, but we do believe that we want to make 267 - > these keys as easy and effective to use as possible. 268 - > So the convenience of being able to have multiple form factors, 269 - > the ability to um expand upon different sorts of use cases is 270 - > important to us. 271 - > So we're learning a lot from our customers and how they need to 272 - > protect their accounts and the decisions they make.
273 - > And so we're constantly evolving the YubiKey and expanding its 274 - > capabilities so that we can meet those needs. 275 - > SPEAKER_01: Brilliant. 276 - > Well, uh, congratulations on the success uh of the product as 277 - > well as helping so many individuals and companies 278 - > develop that uh fishing resistance. 279 - > And uh thanks for joining.
280 - > I look forward to hearing more about uh the strategy and the 281 - > deployments and the scale up of YubiKeys. 282 - > SPEAKER_00: Thanks, Devin. 283 - > It's a pleasure to meet you. 284 - > SPEAKER_01: And thanks everyone for listening and watching.
285 - > Pick up a YubiKey, it really is a lifesaver. 286 - > If you work in healthcare or hospitals, health IT, it can be 287 - > literally a lifesaver when it comes to uh data protection and 288 - > that kind of thing. 289 - > Also check out our TV show, techimpact.tv, now in Bloomberg 290 - > and Fox Business.
291 - > Thanks, everyone. 292 - > Thanks, John. 293 - > SPEAKER_00: Thank you. 294 - > unknown: Bye-bye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.