Voice Phishing und das Problem sitzt nicht vorm Rechner - mit Prof. Angela Sasse
Oct 7, 2026 · 1h 6m
Summary
Die Folge beleuchtet den Hacking-Vorfall bei der niederländischen Telekom, bei dem Angreifer per Voice Phishing ohne KI sechs Millionen Kundendaten erbeuteten. Im Interview mit Professorin Angela Sasse wird diskutiert, warum IT-Sicherheit oft fehlschlägt, da sie unmenschliche Anforderungen an Nutzer stellt. Sasse plädiert für menschenzentrierte Lösungen wie Passkeys und technische Verifizierung statt reiner Awareness-Schulungen, um Sicherheitslücken wirksam zu schließen.
Topics discussed
Introduction: Purpose of work and IT security issues
Overview of recent data breaches and hacked institutions
Voice phishing vs. AI deepfakes in social engineering
Case study: The Dutch telecom call center attack
MFA bypass techniques and data extortion methods
Personal experiences with data leaks and false data
Arrest of Shiny Hunters suspect and law enforcement trends
FBI data breach and the rise of cybercrime
Oracle PeopleSoft vulnerability and patching failures
Introduction of guest Angela Sasse
Angela Sasse's background in human-centered security
The problem of password overload and human limits
Passkeys and modern authentication alternatives
Users are not the enemy: Corporate security failures
Cost of security rules and resistance to behavior change
Adapting technology to human capabilities
Eva's experience with test phishing and workplace stress
The flaw in relying on user vigilance for email security
The absurdity of constant email scrutiny and awareness training
Collaboration over blame in hybrid warfare contexts
Investing in technology vs. formal policies and training
Selling satisfaction: Compliance-driven security measures
Practical measures: Mutual authentication and QR codes
FIDO2 framework and user choice in authentication
Barriers to adopting new security standards
Internet relics and the lack of trusted identity protocols
EU Digital Identity Wallet (EUDI) and user experience
Business incentives for user-friendly security
Leadership responsibility and long-term security planning
Short-term thinking and compliance checkbox culture
AI in software development: Risks and vulnerabilities
AI for finding security flaws: A double-edged sword
Resilience of critical systems in the digital age
The importance of cash for digital resilience
Research focus on resilience and survival
Education programs: Law for School and digital safety
Optimism for future digital safety education
Challenges in implementing human-centered security
The need for stronger collaboration between researchers and tech
Conclusion and final thoughts on transformation
Listen ad-free on Castria