World Congress 2026 Europe Jul 10, 2026 Session details

MFA? Game over! Watch your protection collapse – live

Christoph Menzel

Think your MFA setup is foolproof? Watch a live hack bypass traditional authenticators in minutes, and learn why FIDO2 passkeys are your only real defense against session hijacking.

Pause
Mute Enter Fullscreen
#1 about 5 min

Statistics on password hygiene at home and work

Poor credential management across personal and professional environments creates broad vulnerability architecture.

#2 about 4 min

Common password vulnerabilities and human behavior risks

Easily guessed credentials and a willingness to share information make traditional authentication inherently vulnerable.

#3 about 2 min

Overcoming barriers to passwordless authentication adoption

Replacing traditional credentials with biometrics and cryptographic physical tokens securely shifts the authentication paradigm.

#4 about 5 min

Setting up a man-in-the-middle phishing proxy

Configuring an open-source proxy server automates the creation of convincing fake login portals.

#5 about 4 min

Capturing plain text credentials and session cookies

Interception proxies reliably extract unencrypted usernames and session cookies during the login process.

#6 about 4 min

Bypassing multi-factor authentication with stolen session cookies

Stealing active session tokens allows attackers to bypass secondary application-based authentication measures.

#7 about 4 min

Defending against phishing with hardware passkeys

Using cryptographic hardware keys completely prevents proxy attacks by binding authentication to the real domain.

#8 about 5 min

Shifting organizational security toward phishing-resistant authentication standards

Implementing modern cryptographic protocols neutralizes the inherent weaknesses of traditional password policies and behaviors.

Matching moments

3:06 min

The vulnerability of two-factor authentication to live phishing attacks

Paweł Łukaszuk · LIVE

6:36 min

Defensive strategies against AI-driven social engineering

Wolfgang Ettlinger +1 · WWC 2023

4:13 min

Hardware keys and mitigating persistent password vulnerabilities

Chris Heilmann +2 · LIVE

1:22 min

Securing application access with WebAuthn and physical FIDO keys

Gift Egwuenu · WWC 2023

3:27 min

Introduction to modern authentication and web password vulnerabilities

Gift Egwuenu · WWC 2023

3:23 min

Shortcomings of passwords and secondary authentication factors

Clemens Hübner Clemens Hübner · WWC 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash