Enhancing Browser Security with Push Security | Black Hat 2025
Tyrone Erasmus, co-founder and CTO, introduces Push Security, a company dedicated to browser detection and response, highlighting the significance of browser security. Tyrone emphasizes practical defenses over AI hype and shares user feedback on their browser integration, which effectively detects stolen credentials.
Transcript
Hey everyone. Welcome back to our Techstrong TV Coverage of Black Hat. This is actually the last scheduled interview.
We're gonna do a black hat 2025. So if you've caught our previous ones, great. If you haven't, you know, through the magic of the internet, you could go back and uh, click on them.
But let me introduce you, uh, to my next guest. We are here at the Push security booth, that's Push Security, and my guest is Tyran Tyn. Erasmus, That's right.
Yeah. Hey, how you doing? You know what?
After two days and 30 interviews, I got your name right? You Did. I'm Impressed.
I'm doing damn good. Damn good. Tyn, welcome to Techstrong tv.
It's great to have you on here. Cool. Thanks very much.
So besides the cool name, tell us more about yourself. Cool. So yeah, I am, I kind of am a, a computer engineering graduate from, uh, quite a while ago.
And really I've, I started my career in, uh, pen testing. So I worked for pen testing companies and really kind of worked on the red teaming and offensive security side of, of security for probably about half of my career. Uh, yeah, did a lot of security research, one mobile phone to own written books.
So kind of done all the things on the offensive side. Uh, and then really kind of got to a point where I, I always, always enjoyed, um, writing hacking tools. Um, and then I kind of switched focus onto the defensive side and started making cybersecurity products.
Uh, and uh, yeah, that's kind of led me into my journey into, into push security as well. I love it. What a, and that is, so that profile right there is almost the perfect black hat profile, isn't it?
That's probably, that's 19,000, 20,000 people here. 5,000 of them. Well, maybe not writing the book, but 5,000 of them have done that Red team journey.
Offense defense, they've switched from vendors to, to end users. Yeah. And, and everything And in between.
What's your current role here at Push? Cool. So I'm one of the co-founders of, of push security.
I wear the CTO hat. And so yeah, day to day it's really just about, uh, building a product with a team that actually matters and, and makes an impact and, uh, stops the attacks. And so, yeah, it's a day to day is really kind of in the, in the weeds with a team and, uh, building the product.
Well, with your background, I would expect that. Yeah, right. You, you.
But, you know, being a cofo, I've co-founded four companies myself. Wow. Venture backed and, um, you know, being a co-founder, you don't always get the opportunity to do those kinds of things that you like.
Mm-hmm. 'cause you're busy doing co-founder things like talking to investors Yep. And boards key customers.
Yep. Chief people officers and, and playing all of that game that, you know, even now I'm the CEO at Techstrong and it's not my favorite things to do. Yeah.
We, we always joke and say we get the jobs that, uh, no one else wants when, uh, you know, the hardest thing in the company, that's your job, uh, for the next few months. And, uh, Well, no, no. Sometimes it's the lowest, you know, I'll tell you a quick story.
When I was a little boy, my dad, my dad owned a, uh, a restaurant and one summer I was young, maybe 12, 13, 14 years old, and I got the bright idea I was gonna work that summer and make some money. And he said, sure. Come in.
And that first day he said, uh, you gotta go mop the bathroom. And I said, dad, I'm your son. I don't mop the bathroom.
You got people. He said, no, if it's going to be your business, you gotta be prepared to do every job there. Yeah.
Yeah. Because that's what it is when you have your own business. Yeah, yeah.
The chef and the dishwasher and Everything in between. Exactly. Yeah.
And I'm sure you're living that. Um, anyway, let's talk about push security. There aren't a lot of, you know, there aren't a lot that we, I, they can't see 'cause they're looking this way.
As you and I look out, there's a sea of of security companies here. Yeah. And not everyone at home knows every company.
Some may know push, some may not. Mm-hmm. For those of us who are not familiar with push security, tell us about push.
Cool. So Push Security is a browser detection and response company. So it's a, a lot of, uh, words to say that basically we see ourselves as an EDR in the browser.
And, uh, you know, you may ask yourself why do, why does anyone even need that? What does that mean? And, uh, yeah, I, I suppose this really comes down to the trends that we've been seeing over the last few years.
Um, EDR has really matured. Um, and yeah, it's, you know, so attacking endpoints has become quite difficult and attackers are really opportunistic. They always go the past of, of least resistance.
Yep. And so really what we've started seeing is that attackers try their best now to stay off the endpoint. And because there's, you know, the, the, the tooling there is really mature.
And so they've started executing attacks that don't touch the endpoint at all. And, and really what that boils down to is, is identity attacks. They're finding really unique ways to fish users to do MFA downgrade attacks, to deliver malware in very, uh, you know, unique ways using the browser.
But yeah, at the end of the day, a lot of the attacks that people are seeing end up happening in the browser. And so that's why we are a browser extension that people deploy out into the browser. And so yeah.
We we're kind of just stopping attacks where they happen. Absolutely. And that's the kind of premise.
Yeah. Well, look, You get in a world where people sometimes work on Chromebooks mm-hmm. Or tablets Yeah.
That, you know, are, let's call them non-traditional endpoints. Yeah. It's not the OS per se, Chrome os Yeah.
But it's not Windows, it's not Mac. Yeah. And when the browser is the interface for the applications that we and use.
Exactly. Yeah. It only makes sense that, that you, you gotta go where the, where the bad guys are.
Exactly. And, and, and, you know, work kind of happens in the browser now. I, I'd say like the majority of people's everyday work is just no doubt in the browser.
Uh, and so really what we've seen is kind of this shift as well from having internal networks where people kind of log in over VPNs to basically people just being, having a laptop connected to, you know, 50 or a hundred whatever SaaS applications. And so really we see ourselves as that kind of layer between the user and the apps that they use. We can see where they're logging in, how they're logging in, do they have MFA enabled on all of these things.
Um, that's kind of on the proactive side. And then on the reactive side, are there applications or websites out there trying to phish them? Um, yeah.
And do all of these kind of novel attacks against them. And because we're in the browser, we can see all of that stuff. Absolutely.
Now you mentioned this is an extension for the browser. That's right. So I'm gonna assume it works in Chrome.
Oh, yes, yes. It works on all the browsers. Uh, yeah, we, Well, I'm glad you brought that up because it works on all the browsers today.
Yeah. Chrome, safari mo, Firefox, yeah. Et cetera.
But we're about to see a new generation of browsers mm-hmm. Right, perplexity. Yep.
What, what is it called? Cosmo or, Yes, yes, yes. Uh, I know what you mean.
All those kind of a AI browsers, Open AI is coming out with a browser. If you believe the hype, it's gonna redefine Yeah. The browser experience.
Yeah. Have you guys looked at that yet? Yeah, definitely.
We, we, we keep a, a close eye on all the new browser variants that come up, but yeah, I, I suppose like all of these things at the end of the day are all just chromium based browsers. Yes. And so, you know, they may have a different setting that you need to set in order to force install extensions, but at the end of the day, they're all just chromium.
And so we all support them too. And that, That's the beautiful thing about open source Exactly, isn't it Exactly. Is they all have that base.
We kind of, we develop it once and you, you kind of end up hitting a lot of browsers and all of these new browsers that are based on chromium as well. Yeah, Absolutely. Alright, a couple other questions then I wanna jump in.
Yeah. Uh, so they, I'm assuming you could just get this in the, in, whether it's the Chrome store or the, or the Safari, uh, marketplace or whatever, it's just a quick download install done. Yeah, So, so actually, um, in order to install it, people would have to kind of sign up on the website first, and then you can, you present it with a few options of different ways to install it.
You can see, uh, I want to use MDM or GPO or one of the many ways to install extensions, and then it kind of guides you through the process. Okay. And so, yeah, uh, it's generally not, So it's primarily through the push website?
Exactly. Not the marketplace. If You'll, yeah, so, so the marketplace, the, the, um, push security extension is on the marketplaces, but kind of, uh, if you go that route, you don't really get the, the guided tour on how to extension, but on how to install it.
But yeah, exactly. There are on the, on the, the stores. Excellent.
But it does beg the question of what is the website? Yeah. com, so you can go check it out.
It's also free to sign up. Um, we give 10 free licenses for people to go have a play around, see if it's suit to, uh, you know, try some identity attacks, uh, try some SaaS discovery, kind of hit the use cases you're looking for. And, uh, yeah, I love it.
Alright, I'm going to switch gears a little bit. Let's come back here to Black Hat. Yeah.
How's the show been? What are you seeing? What are you hearing?
What is Push security? Talking about a black hat? Yeah, so it's, uh, it's uh, been an interesting one.
It's been a big one. We've seen a lot of foot traffic through the booth, which has been good. Um, yeah, I, I suppose from, from our perspective, the, the things that we're really seeing is that people are really starting to pay attention to the browser.
Um, you know, in, in, in previous years, I think it was, uh, quite a foreign concept to people. You know, people think of the, the, the magical triad there, network logs, endpoint, uh, and then maybe some cloud. Um, and yeah, I think it's really becoming quite commonplace for people to see the browser as a unique place to get telemetry from a unique enforcement point.
And yeah, there's, there's actually been quite a few players kind of popping up in this space as well. So, um, yeah, it's definitely been interesting from, from that perspective for us. But yeah, our, our, um, kind of what we've brought to Black Hat this year is just, uh, a whole new bunch of features that we're showing people.
I think, um, one of the really interesting ones is we're kind of one of the first, uh, companies now to also bring this to, uh, to mobile devices as well. So this, uh, we're, so we've got a, a Safari extension, uh, that runs on iOS devices that we've been demoing as well. So yeah, we we're kind of, um, yeah, been kind of showcasing some of the, some of the new stuff.
Uh, oh, but I gotta ask you about ai, what anything there would push using in regarding ai? Yeah, yeah. So I, I must say, like we, uh, if you kind of look around our booth as well, uh, we don't really like to push AI narratives.
I think, I think at this point it's, uh, it's kind of become a, a bit of a nothing word to add onto things. So we, we try to, uh, stick, uh, clear of that and just really give practical, uh, you know, does what it says on the tin, uh, type, uh, defenses You. So you're, you're not trying to surf that wave?
No, I, I would say not like, you know, we, we, we do a lot with AI in the product. Uh, we can detect usage of ai, uh, for, for customers. So yeah, I suppose there are ui ai use cases that we cover, but, um, no, we're certainly not trying to, trying to ride that wave.
I Got it. Um, what are you hearing from people? You said there's a lot of booth traffic.
I've seen a lot of booth traffic. I was here this morning actually and talking to my friend Chris, and, uh, what are you hearing from people coming by, coming in and talking? Yeah, I, I think one of the, kind of the coolest things that, that I've seen is, um, you know, once you've that of seen this data, you can't unsee it.
You know, I, I, I think we provide a really unique, um, vantage point as well. Um, and so once people see like, okay, so across all of these apps I can see, you know, MFA status, I can see people reusing passwords, I can see stolen credentials, like people are using credentials in that same credentials have been stolen on, on, on the dark web. Um, and kind of just the way that we can detect and respond to attacks and the telemetry that comes out.
It's been really cool. We've, uh, had some really positive feedback on just, you know, like it's such an obvious, um, insertion point, uh, to be in, in the browser. And so I, I think people are really kind of having their, their eyes open to the possibilities of, of being inside the browser, which has been cool.
Excellent. Yeah, I think we've covered, whoop, sorry, I dropped my mic there a little bit. I think we've covered, I think everything I wanna say, but is there anything else you think we wanna share with the audience?
Yeah, there's some really novel attacks happening out there. Um, go give us a try. You'll, you'll probably have your eyes opened and, uh, yeah, yeah.
com. com. Yeah, you Heard it.
com. Hey, that's gonna wrap up our, uh, coverage at Black Hat 2025. We are here on the floor.
Thank you very much. Let me say this right? Try out, try Tyron Tyron, ty.
Yeah, thanks very much man. Ty Rasmus, co-founder CTO at Push Security.