# Why friction is a security risk, with Dustin Heywood

DevFeed: [Why friction is a security risk, with Dustin Heywood](<https://devfeed.tech/articles/why-friction-is-a-security-risk-with-dustin-heywood-1919.md>)

Original publisher: [Read original article](<https://1password.com/blog/friction-is-a-security-risk-with-dustin-heywood>)

Author: info@1password.com (Dave Lewis)

Published: 2026-04-30T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [identity](<https://devfeed.tech/tags/identity.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

A podcast episode examining how agentic AI exposes existing access-control weaknesses, especially broad permissions and the lack of intent-based authorization.

## Source excerpt

Listen to this episode on Apple Podcasts null Listen now Listen to this episode on Spotify null Listen now If cybersecurity teams were rock bands, offensive security professionals would be the cool drummers; they don't just have a fun job, they help show the rest of the team where to go. In this episode of TheChasing Entropy Podcast by 1Password, Dave Lewis speaks with a legend of offensive security, Dustin Heywood, known to many as EvilMog. Heywood is an executive managing hacker and senior technical staff member at IBM, and the conversation runs the gamut from password cracking and Active Directory abuse to AI privilege creep and quantum planning. The through line is simple: most security failures start with access, trust, and bad assumptions about how systems behave under pressure. Heywood's background explains why he sees the problem this way. He came up through network engineering, military communications, enterprise infrastructure, and offensive security. That path matters because his view of security is operational, not theoretical. As he continually reiterates, businesses are not trying to be secure for the sake of security. They are trying to keep operating, and security has to support that goal or it gets bypassed. Rethinking access for the agentic world A big part of the episode focuses on the risks of agentic AI, although Heywood argues that AI is exposing access problems that were already there. He runs through some of the weaknesses he encounters in his day-to-day job that AI agents are set to exploit, like overpermissioned service accounts and broad integrations. Heywood's main concern, and where he sees the biggest opportunity to make a difference, is the gap between identity and intent. He gives the example of a person using an agent to buy concert tickets at a specific time and with a specific budget, but A user might want an agent to buy concert tickets under a clear budget and time window, but today's systems rarely encode that level of permissio