Token eliminates stolen-credential risk with hardware-anchored, biometric-bound authentication. Phishing-resistant. Zero Trust ready. Identity assured.

Rochester, NY, USA
There probably wasn't an #Azure breach. Someone logged in. Millions of #Entra directory records reportedly for sale. Infrastructure intact. The platform authenticated the wrong person. Attackers rarely defeat #MFA. They get someone to complete it. hubs.la/Q04y6Tys0
234
Generative AI removed every signal phishing training taught employees to spot. Grammar. Formatting. Branding. Tone. There is nothing obviously fake about the message anymore. Training people to recognize what AI made unrecognizable is not a strategy. hubs.la/Q04y6Tkq0
98
MFA confirms someone completed the challenge. It cannot tell you it was the wrong person. Domain-bound credentials. A live fingerprint on dedicated hardware. Keys that never leave the secure element. How the Apollo attack worked: hubs.la/Q04xx1-l0
102
Apollo wasn't hacked. Their own employees authenticated the attackers. Attackers impersonated internal IT. Employees entered credentials on a fake login page, then approved the MFA prompt. No exploit. No malware. Authentication was the attack. hubs.la/Q04xx1F90
1
153
Some IdPs accept assertions from credentials whose signature counter never advances. A copy signs alongside the original and nothing looks unusual. What enterprises should require for privileged access: hubs.la/Q04x4yrl0 #IdentitySecurity
114
#AI agents can recommend, prepare, and execute routine work. Irreversible actions get approved by a human — trusted device, biometric verification. Email confirmations, basic pop-ups, and second agents don't clear that bar. hubs.la/Q04xfYJ50
1
167
Your passkey is phishing-resistant. That does not mean you would know if it had been copied. Most synced passkeys return a signature counter of zero. Zero cannot regress. There is nothing to compare. Phishing resistance is not clone detection. hubs.la/Q04x4xQW0
150
They never got inside. They didn't need to. A DDoS campaign has disrupted Norway's national identity gateway since 3:38am Monday. Kevin Surace, Token CEO: "Keeping people from getting in is enough." hubs.la/Q04vsdsJ0
267
~850,000 files leaked from one water-sector supplier. "Protecting the water utility itself is only half the problem," says @Token CEO Kevin Surace. CISA's ask is the least glamorous one: get OT off the public internet when it doesn't need to be there. hubs.la/Q04vs02f0
228
They never got inside. They didn't need to. A DDoS campaign has disrupted ID-porten, MinID and Altinn since Monday. No breach — just Norway locked out of its own government. Kevin Surace, Token CEO: "Keeping people from getting in is enough." hubs.la/Q04vsgJP0
227
CISA logged more than 100 internet-exposed water systems attacked in a single month. Most were PLCs wired straight to a cellular modem. Reachable by anyone who knows where to look. Not a run of bad luck. A structural problem. hubs.la/Q04vs2qS0
202
#MFA is not failing. It is doing exactly what it was designed to do. Prompt bombing. SIM swapping. AiTM proxies. Session theft. OAuth consent abuse. None of them break #MFA. They go around it. Possession is not identity. hubs.la/Q04tJJBM0
180
Sept 1: Microsoft starts auto-enabling SMS and voice users for passkeys. Enrollment is where attackers are working. Restrict by AAGUID. Enforce attestation. Require device-bound biometric hardware. Entra supports it today. hubs.la/Q04t41pw0 #BiometricAuthentication
158
A stolen password and an intercepted code do not authenticate an employee. They authenticate two pieces of compromised data. Biometric match. Domain binding. Proximity. Keys in hardware. Each #MFA bypass, and what closes it: hubs.la/Q04tJSQY0
1
1
168
Attackers aren't breaking passkeys. They're getting organizations to trust theirs. The pretext is the migration itself. "This is IT. We need to finish your Microsoft passkey enrollment." The cryptography held. The enrollment ceremony did not. hubs.la/Q04tlpQK0
1
1
168
Credential compromise is still the leading cause of enterprise breaches. Not because the attacks got smarter. Because the credential never changed. AI moved phishing to machine speed. The secret underneath still works the way it did a decade ago. hubs.la/Q04sylnB0
1
144
AI didn't invent a new way in. It used the old one at machine speed. Exposed identity data. Predictable password variations. Authentication that automation can compromise at scale. Bind access to a verified human who is physically present. hubs.la/Q04t50Pb0
160
Taiwan confirmed an AI-assisted attack on government systems. Token CEO Kevin Surace, in SC Media: "near-autonomous rather than completely independent." Humans picked the targets and built the framework. The AI had real latitude inside the mission. hubs.la/Q04t3--50
181