Passwordless Authentication with Graeme Speak of BankVault Cybersecurity | AWS re:Invent 2023
Join us for a glimpse at the cutting-edge of cyber innovation. Shira interviews Graeme Speak, who led the innovation team behind an intelligent new approach to passwordless authentication. BankVault MasterKey ensures frictionless access to website login portals. More than just a security feature, it is a SaaS business accelerator that increases user engagement and trust, and reverses customer login abandonment. This intriguing technology is invisible to users (no software or setup), creates MFA in 1-step, and deploys in minutes without backend changes. Could this become the trusted default for web security? This interview delves into the technology, implications and impact.
Transcript
This is Textron tv. Hi, this is Shera Rubinoff. I'm here at Amazon Reinvent 2023.
I'm here with Graham speak, CEO, and founder of Bank Vault. Graham, it's such a pleasure to be with you here today. Thanks.
She, it's really exciting to be here too. Well, thank you. So Graham, I'd love you to share with the audience a little bit about who you are, what you've done a little bit in the past, and then we're gonna dive deep into MasterKey.
So please share with our audience a little bit about yourself. So, I'm the, uh, the founder and CEO of Bank Vault, uh, cybersecurity. So we're a technology innovation company.
So we run an innovation team that actually develops new cybersecurity products. So we've got probably 25 innovations, six patent families, five products in market. Um, but the really big one that we're focused on is, is called MasterKey, which provides passwordless access to web login portals.
Um, yeah, we were developing originally cloud computing platform technology and literally just took those ideas and pivoted it into this cybersecurity realm. So our thinking's been quite different. Um, we've kind of settled into, into the industry backwards and, uh, the, the idea actually really solid.
So we've, we keep on building on the shoulders of what we've done before. So hence we have these 25 innovations now. That's wonderful.
And can you explain a little bit to our audience how your product, how MasterKey differs from everything else out there? 'cause we certainly have heard about passwordless logins and the like and different in the ecosystem, the cybersecurity world, but your certainly is different than other things that I've heard about. So please share with our audience a little bit about that.
It is, um, I mean, so Passwordless in the last Yeah. Since 2021 has become, you know, one of the hottest sectors in cybersecurity, um, the approach that we've taken was specifically around, around web logging portals. Mm-Hmm.
You know, SaaS companies, um, where a user is logging in through their browser, uh, onto a site. So typically a large enterprise with a beta business to consumer interface or a SaaS company. Um, what's different about our solution is that, um, you can integrate this, it's a cosmetic change effectively to the front end of the website.
So the integration is extremely shallow and we'll integrate with whatever backend is there. But the most important thing is that there is nothing for the user to see. There's nothing to download and install a configure.
So it's essentially invisible to the user. It just starts working. It looks like magic.
But what this means is that you could actually deploy this on mass virtually overnight. Um, so the really key thing that we realized is more than just a cybersecurity solution, um, this is gonna provide seamless access for users, which is gonna increase engagement. It is stronger than a username, password, normal login.
So that builds trust. Mm-Hmm. And we're essentially gonna reverse login abandonment.
And this is a major issue for any online services. Well, certainly we talk a lot about no extra steps for users. When we talk about the human factors piece of cybersecurity.
When you get put the onus on the user, they're responsible to do certain steps. And when people are working at warp speed and they're multitasking, the last thing they wanna do is think about the different steps they have to do to be secure. And certainly we've heard about in read in the industry that if there are steps, they'll circumvent it, they'll go around it, they won't do it, and then people are left vulnerable.
So the no extra steps, I think is a very pivotal speed, uh, spot for your organization. The fact that it does work, you can deploy on mass, it doesn't take a long time to deploy, and really there's no training. And that talks about the different areas about training your users and training people on how to utilize the system, the fact that there's no steps and it works.
That's pretty amazing. So could you describe how you're able to do this? Like, what is your secret sauce, if you can share that with us?
Yeah. So yeah, it's, it's actually very clever. So, yeah.
And, and in fact, if you can, uh, you know, I mean, change management education is never zero, but ours trends towards nil, which is such a strong advantage. Okay. Uh, so we have customers that literally can now deploy within minutes instead of months.
Um, so the, the, the trick here is actually, um, quite clever. It's, um, it's a decentralized protocol. Um, uh, we're generating three security secrets behind the scenes.
Mm-Hmm. It's typically a usable login with their mobile phone, uh, direct to the website. It just recognizes them logs in.
If you're on a workstation, we wanna harness the mobile phone. And so we're presenting a QR code on the screen. If you scan it with your phone camera, it pairs your phone's browser to the same web service sessions on the screen authenticates and log in logs in.
So there's actually nothing installed on any device, and there is no setup. And what we're doing is, um, with these three security secrets, uh, one's in the mobile phone, uh, one's in the web server, and the trick here is there's some infrastructure in between which can run on-prem or run in the Amazon in the cloud anywhere. It doesn't matter.
Um, it's decentralized, meaning that these secrets are never released. There is no singular attack service. It works as a vector.
So it can only ever be resolved by the organization's web server when that process is initiated by the user's mobile phone, perhaps their face ID for proof of presence, et cetera. And I think what I would say is, if you look at the market, um, the addressable market that we're looking at, which is, which is web services, you know, pretty much 99% of all websites on the planet today use username passwords or social media. The social media authentication is, you know, a really poor idea.
What happens when Amazon, sorry, not Amazon. No. Say Facebook blocks your account, you know, do you really want Facebook knowing everything that you do?
Of course you don't. Right? So what we are doing is we are providing, uh, we're basically securing the user from the weakest part of the network, which is always their own device.
We are giving them a seamless login experience, which is gonna increase engagement. We're uplifting this to multifactor authentication in one step that's invisible to the user. And an organization can deploy this in minutes.
An organization talk talk similarly about this, and they ask, what about man in the middle attacks? How do you circumvent that? Um, yeah, this really sidesteps the man in, in the middle.
I mean, it would be, I mean, no single cybersecurity solution is ever gonna be, you know, you could never say it's not unhackable, but it would be incredibly unlikely. So we are probably not the, the attack surface, right. That attack is gonna try to get to the back end somehow, but it won't be through the use device anymore.
Well, that's, so we're addressing I think the, the, the, the, the major attack surface on any, in any network, which is always the end user device. Exactly. That is very true.
And let's talk about, again, more, more dealing with the market. Who would be your perfect ideal customer when we talk about solutions? You know, I talk all about the nice to have, need to have a must have, nice to have is pretty much everything out there need have is when we have the dollars, we'll spend it.
Why are you a must have, why are the, why should the dollars be spent on your product now and who would be an ideal customer for you? So our, our target customers are typically gonna be an organization that has a interface to an external customer. Okay.
Uh, so typically a business to consumer interface. Um, what we're doing is providing seamless access for the users. It's gonna increase engagement.
Uh, it's stronger security. We're reversing login abandonment. I mean, these are really strong benefits for the end users.
So this actually becomes a business driver. It's a, it is a, it's an accelerator for SaaS companies. Um, the, the reason that you would do it is basically if you don't, honestly, in the next year or so, you'll see a lot of the world moving towards passwordless.
It's already here. It's like a scenario that's already hit the shore. It's happening around us.
The solutions on the market today, whether it's the Fido system, Fido standard, you know, web or or others are always complicated for the user. You know, you've gotta download in store, you've gotta configure software. You've got this massive change management project.
I mean, even with the Fido, I mean, we, we are Fido compliant ourselves. So we'll provide that. We can go up to five or six factors of authentication.
The market isn't asking for that. The market just needs seamless. And, and we can do this in a way that's invisible to the user.
So if an organization, um, wants to basically provide a better user experience, or if security is a major issue, and of course it is, then here's a solution that you could literally deploy straight away without a lot of fuss. I, I'll actually just also add, there is no technology risk or security risk. Um, there's no technology risk because there is no single point of failure in the worst possible situation where for some reason the passwordless technology has stopped working.
Right. Who knows why the users can still log in within, you know, original credentials. Okay.
And there is no tech technology, uh, sorry, uh, uh, security risk here because we're already, this is the user's normal input only. We've abstracted away. They no longer need to enter it through the weakest part of the network, which is their own device.
It's now controlled by the enterprise, by the organization. Well, I will say one of the things also that I like about your system is the users are behaving like they normally would. You don't have to retrain them.
They don't really have to think about it. It's just a natural continuous login the way they always have. Yet they're secure.
And I think that is something very interesting that people should take note of. And, you know, something else I'd like to ask you. In the cybersecurity world, I always ask my interviewees when we speak, what is a helpful hint you could talk about for a moment to the global audience here about something you'd let them know that they should take note of or they should think about when they're dealing with their everyday life in cybersecurity?
Oh, goodness me. Um, I keep coming across people and I, this audience, I mean, already well informed, but there are, so, there is so much naivety out there about the, the actual risk that's occurring. Yeah.
People think they're a small fish and it's not gonna bother me. And I'm not really clicking on anything on the internet. Um, I'm, I'm using, you know, I hadn't met literally a guy friend that met the street the other day.
He's using an old Mac that he doesn't upgrade because he thinks that that's more secure. And it's just like, you know, these people are clueless. Of course, we need to educate the people.
Um, and it's, yeah, it's just basic, basic. It's like when we were kids, we were taught to be careful when you cross the street because the street is dangerous. You know, look to the right, look to the left.
You know, today the internet is dangerous and we need to be educating people that you don't just go out there. You've gotta be super careful. I mean, every I, I give a lot of talks and every time I start, I normally explain to the audience how I'll hack them.
And I'll do this in like 30 seconds. I'll have a hundred percent of their attention. 'cause they had no idea.
It's so simple. Sure, Sure. I'm now in the right to actually go into a bit more detail about how you can actually protect yourself and, um, yeah.
So yeah, education, Education is key. A hundred percent. Well inform people, make the right decisions.
And I would even say, you know, to further on what you're saying is stop and pause. Think before you act, think before you're doing and almost looping that back into your technology, you're taking away that piece of something that people have to think about to be secure. You're making them secure without thinking.
So that's one extra thing they don't have to worry about. Yes. Any, any further things, Graham, that you'd like to share with our audience about MasterKey?
Um, you know, the, if any organization would be interested in trialing this, um, honestly we can set this up in, in a few moments. Um, I can, it's, I can literally set up a demo in, in, in 60 seconds. This is so simple for the user.
You can experience it in your own hands. Um, within moments. Um, as I said, there's nothing to download, install a configure, it literally just starts working.
I have people say, this looks like magic. How do you do this? Mm-Hmm.
And it is very, very, it's deep tech. It's very clever. That's excellent.
Um, and so it's not trivial on the in, in inside, but the experience for the user, um, is, is essentially seamless. So this will scale massively. Um, so it can be hosted on-prem if you need it.
Uh, you can just use the cloud version, which is simple and cheap. It's not expensive. Sure.
Um, and yeah, we'd love to partner. Um, we are expanding rapidly now. I would just say we are, one of our go-to markets is actually through online SaaS marketplaces.
So SaaS marketplaces, um, we are one right now called odu, ERP. Uh, we're the only passwordless option in that marketplace. There is some 300,000 businesses use odu and I can deploy this in three to five minutes.
That's wonderful. Yeah. There's dozens and dozens of these marketplaces.
So generally our competitors can't reach these markets because they've got hefty integration at the backend. Mm-Hmm. And every user has gotta download, install software, whereas ours, ours doesn't.
Great. So it's a pretty sharp competitive edge that elevates us in a very large marketplace. So, and I'll just say one more thing too.
Yeah. We are raising more investment rounds. If anybody's interested, we'd be loving to talk.
Well, I encourage our audience, if you'd like a demo, please reach out to MasterKey or uh, sorry to bank Vault, uh, with their wonderful technology. Uh, MasterKey and Graham will be happy to speak with you. And Graham, thank you.
It was wonderful speaking to you today here at the Amazon Reinvent Conference here in Vegas. And I look forward to speaking to you again soon. Thanks so much.
She Thank you.





