AI made the careful attack cheap. Authentication has to change.

AI hasn’t invented new weaknesses. It has made the old ones cheap to find and cheap to use. That’s the core argument our founder and CEO, Thi Nguyen-Huu, makes in a new interview with TechMediaGlobal.

“AI makes the careful attack repeatable at almost no extra cost.”

If you run security or IT, that sentence changes your math. A well-researched phishing lure used to cost an attacker real effort, so they saved it for a few targets. Now every employee can get one, written for them. The interview covers where that leaves passwords, MFA and session security. Below are the points we think matter most for security leaders, and the full conversation is worth your time.

Key takeaways for CISOs and CTOs

  • AI changes the cost of attacks, not the weaknesses. Weak authentication, excess permissions and misconfigurations are the same problems. They’re now far cheaper to exploit.
  • AI-written phishing gets clicked far more. Microsoft measured a 54% click-through rate for AI-tailored phishing emails, against about 12% for ordinary ones.
  • Attackers move faster once inside. CrowdStrike puts average breakout time in 2025 at 29 minutes, 65% faster than the year before.
  • MFA alone isn’t holding. Proofpoint found that almost half of the accounts attackers took over had MFA configured.
  • The fix is cryptographic, and the device does it. Thi’s argument: humans can’t do cryptography, so the endpoint has to prove identity for them, with a key that never leaves the device.

Why does a stolen login matter more than a stolen permission?

Because the attacker who logs in as a real user doesn’t need to break anything else. As Thi puts it, that attacker “gets that user’s permissions, correctly granted.” Your access controls work exactly as designed. They just work for the wrong person.

That’s why he calls weak authentication the biggest of the three problems. Least privilege and good configuration still matter. But neither one helps once the login itself is compromised.

Why are passwords and MFA falling behind AI-driven attacks?

A password works for anyone who has it, anywhere. The whole model rests on a person spotting a fake at the moment they sign in. AI makes that fake more convincing every time, and it never gets tired.

MFA raised the bar. Adversary-in-the-middle (AiTM) relay kits lowered it again. In the interview, Thi walks through what one of these kits costs to rent and how many organizations a single campaign reaches each month. The numbers are worth seeing in full, and they explain why an MFA prompt isn’t the finish line.

Where do attackers actually get in?

In the gap between two layers. TLS sets up the encrypted connection. Authentication happens separately, on top of it.

“Attackers do not break either one; they work in the space between them.”

Thi explains how mutual TLS (mTLS) removes that gap by producing the proof of identity and the session key in one handshake. A relayed message is useless without the key. The interview covers the mechanics.

How does WinMagic take the human out of the cryptography?

Cryptography is the best defense, and humans can’t do cryptography. So the endpoint does it for them.

That’s the principle behind MagicEndpoint. The user signs in to their own device once, with strong MFA. After that, the device proves a key at every sign-in. No password, no code, no push to approve. It covers web apps, remote access, RDP and SSH, and it works with the identity provider you already run, such as Entra ID, Okta or Ping.

The key, which we call the Live Key, is generated on the endpoint and anchored in its TPM where there is one. It never leaves the device, and it’s usable only while the verified user is using it. The result is one proof: this user, on this device, under these conditions, now.

Thi is also clear about what this doesn’t do yet. It doesn’t close the session after the login. We’ve published the technical work at the IETF and W3C, and the reference implementation is open at github.com/WinMagic/LIT.

What security leaders can do now

The industry’s warning is that the window is short. Four questions worth taking to your next security review:

  1. Which of our sign-ins still depend on a person spotting a fake?
  2. Could our MFA be relayed by an AiTM kit today?
  3. Is the proof of identity tied to the device and the session, or does it travel?
  4. How long do our sessions last, and what is a stolen cookie worth to an attacker?

If a key proves who is there at every sign-in, sessions can stay short and renew silently. A stolen cookie is then worth much less.

Read the full interview with Thi Nguyen-Huu on TechMediaGlobal →

The interview also ran on Fintech360Hub.

Want to see device-bound, passwordless sign-in on your own identity provider? Talk to our team.

Frequently asked questions

How are AI-enabled cyberattacks different from traditional attacks?

They exploit the same weaknesses at far lower cost. AI lets attackers personalize phishing and scale careful, targeted attacks to every employee. Microsoft measured 54% click-through for AI-tailored phishing versus about 12% for ordinary phishing.

Does MFA stop AI-driven phishing?

Not on its own. Adversary-in-the-middle kits relay MFA in real time, and Proofpoint found almost half of taken-over accounts had MFA configured. What closes that gap is authentication where the device proves a key inside the same connection, so a relayed message is useless without the session key.

What makes authentication phishing-resistant?

It can’t depend on a person spotting a fake. Passkeys (FIDO2) are the common form today. The stronger form proves the device’s key inside the same connection, so a relayed message is useless without the session key.

How does mutual TLS (mTLS) stop adversary-in-the-middle attacks?

Both ends prove who they are inside the same handshake that creates the session key. An attacker relaying the messages never gets that key, so the relayed session is useless.

What is a device-bound key?

A cryptographic key generated on the endpoint and anchored in its TPM where there is one. It never leaves the device, so a stolen password or cookie alone can’t reproduce it.

Does MagicEndpoint replace Entra ID, Okta or Ping?

No. It works alongside the identity provider you already have, so nothing is ripped out.

Source: Thi Nguyen-Huu, interview with TechMediaGlobal (also on Fintech360Hub), published September 24, 2026. Statistics: Microsoft, CrowdStrike 2026 Global Threat Report, Proofpoint.

 

Previous Post
AI Cyberattacks. The Industry Gives Warning. WinMagic Gives the Fix.
Next Post
Security Uses Cryptography in Pieces. WinMagic Says That Gap Is What AI Attacks.
keyboard_arrow_up