They Talk Tech – mit Eckert und Wolfangel They Talk Tech – mit Eckert und Wolfangel

Voice Phishing und das Problem sitzt nicht vorm Rechner - mit Prof. Angela Sasse

Oct 7, 2026 · 1h 6m

Summary

Die Folge beleuchtet den Hacking-Vorfall bei der niederländischen Telekom, bei dem Angreifer per Voice Phishing ohne KI sechs Millionen Kundendaten erbeuteten. Im Interview mit Professorin Angela Sasse wird diskutiert, warum IT-Sicherheit oft fehlschlägt, da sie unmenschliche Anforderungen an Nutzer stellt. Sasse plädiert für menschenzentrierte Lösungen wie Passkeys und technische Verifizierung statt reiner Awareness-Schulungen, um Sicherheitslücken wirksam zu schließen.

Topics discussed

Introduction: Purpose of work and IT security issues Overview of recent data breaches and hacked institutions Voice phishing vs. AI deepfakes in social engineering Case study: The Dutch telecom call center attack MFA bypass techniques and data extortion methods Personal experiences with data leaks and false data Arrest of Shiny Hunters suspect and law enforcement trends FBI data breach and the rise of cybercrime Oracle PeopleSoft vulnerability and patching failures Introduction of guest Angela Sasse Angela Sasse's background in human-centered security The problem of password overload and human limits Passkeys and modern authentication alternatives Users are not the enemy: Corporate security failures Cost of security rules and resistance to behavior change Adapting technology to human capabilities Eva's experience with test phishing and workplace stress The flaw in relying on user vigilance for email security The absurdity of constant email scrutiny and awareness training Collaboration over blame in hybrid warfare contexts Investing in technology vs. formal policies and training Selling satisfaction: Compliance-driven security measures Practical measures: Mutual authentication and QR codes FIDO2 framework and user choice in authentication Barriers to adopting new security standards Internet relics and the lack of trusted identity protocols EU Digital Identity Wallet (EUDI) and user experience Business incentives for user-friendly security Leadership responsibility and long-term security planning Short-term thinking and compliance checkbox culture AI in software development: Risks and vulnerabilities AI for finding security flaws: A double-edged sword Resilience of critical systems in the digital age The importance of cash for digital resilience Research focus on resilience and survival Education programs: Law for School and digital safety Optimism for future digital safety education Challenges in implementing human-centered security The need for stronger collaboration between researchers and tech Conclusion and final thoughts on transformation
Listen ad-free on Castria