The Password Problem: Protecting Your Flower Shop in the Age of AI
Think of your password as the key to your flower shop, and multi-factor authentication as the alarm code. Someone might steal or copy the key — but they still can't walk in without setting off the alarm. That's the line that frames this whole episode, and it arrives after a week Vonda and Lori spent doing exactly what they're about to recommend: changing passwords, updating security levels, moving Flower Clique's bank accounts, and fighting their way back into a CRM that had quietly raised its requirements. As one of them puts it, the layers keep changing right after you've finally figured out the last set.
The three factors, and why everything wants all of them now
MFA comes down to three kinds of proof. Something you know — a password, a PIN, a passphrase. Something you have — your phone, an authenticator app, a physical security key. Something you are — a fingerprint, Face ID, some other biometric. A password answers "do you know a secret?" MFA asks the harder question: "can you prove you're actually you?"
The hosts are honest that the proving part is genuinely painful. One shares a nine-month standoff with the VA on behalf of her 92-year-old father, who has Alzheimer's: completely locked out, no one authorized to fix it over the phone, and the only remaining path is standing in line at the post office for an in-person identity verification. They've gone back to paper calendars and phone calls instead. Another story: an elevator down at her father's residence because of a software issue, and four residents who couldn't get upstairs to chapel — it took finding a fourth woman before anyone had an iPhone rather than a flip phone.
The point isn't that security is bad. It's that plenty of shop owners live one step removed from this world. They use computers, but they aren't sitting in front of one all day, and the rules keep moving.
Where a flower shop is actually exposed
Why would anyone bother hacking a flower shop? Because of what's sitting in the systems. The point-of-sale holds encrypted customer credit card numbers that the shop is responsible for. But the one that stopped both hosts mid-conversation was email — the account most likely to have no second layer on it at all. If someone controls your inbox, they can reset the password on everything else you own. Neither host was certain, live on the recording, whether their own email had two layers. That's the honest version most owners will recognize.
The rest of the list they work through: banking (worth checking your profile — one host found the second layer wasn't switched on by default and turned it on immediately), social media, your website's back end, your Google Business Profile, HR and payroll systems, and vendor accounts. On websites specifically, they mention shops whose back ends were broken into, which prompted extra layers of protection on that side.
Then there's the one nearly every shop is guilty of: the shared login. Everyone on staff knows the password. It's convenient right up until you can't tell who did what, or someone leaves and you're resetting everything. Lori makes the same point about Prep School enrollments — she asks owners for each person's own name and email rather than one shared account, partly so progress can actually be tracked, and partly because employees who move on to other shops have been known to keep logging into training the original owner paid for.
What AI changed
The reason this episode exists now rather than five years ago is that the attacks got better. Phishing emails used to give themselves away; now they're perfectly formed and sound like someone you know. The hosts bring up a widely covered story about AI security agents being tested in a sandbox — and one getting outside it. Their read isn't panic, it's respect: AI has enormous good in it and real danger too, and putting your head in the sand because you don't like it or don't trust it isn't a strategy. It's the same pattern as any innovation, they note — the technology does real good, and a few bad actors bend it.
Four things to do this week
They close with a short, doable list. Protect your email first — it's the master key, and it's the one most likely to be unprotected. Most people have already secured their bank accounts, partly because banks force the issue. Use the strongest MFA available, and stop using your mother's maiden name, your kids' names, or birthdays. A password manager will generate and store the impossible ones for you; the hosts mention LastPass, where you remember one master password and the tool handles the rest. Run an MFA audit across the team — not just your own logins, but every system in the shop. And Vonda adds a fourth: embrace it. It's annoying, and it's what keeps the business as safe as it can be.
The closing reframe is the useful one. Next time the pop-up appears and you can't get in, remember that the extra twenty seconds is standing between you and a compromised credit card, a drained bank account, or someone inside your point of sale. The hosts say a Flower Clique member calls most weeks needing to update a compromised card — and those owners don't have time for it.
Key takeaways
- A password proves you know a secret; MFA proves you're you. Assume the password alone is not enough.
- Secure email before anything else — whoever controls your inbox can reset every other account you have.
- Audit the whole shop: POS, banking, website back end, Google Business Profile, payroll, and vendor accounts.
- Kill shared logins. Individual accounts tell you who did what, and protect you when someone leaves.
- Use a password manager to generate and store strong passwords, so "I'll never remember it" stops being the reason you don't.
- AI-written phishing is convincing now. The extra twenty seconds at login is cheap insurance.