Mike Nelson, DigiCert | DigiCert Trust Summit
Mike Nelson, VP of IoT Security at DigiCert, discusses with Alan the Matter standard for interoperability and security of smart home devices. They talk about Matter’s progress, its adoption, the role of the Connectivity Standards Alliance (CSA), and the importance of security in smart home devices. The discussion also touches on the challenges of software supply chain security, software bill of materials (S-bombs), and the need for dynamic monitoring and control of software vulnerabilities. The conversation emphasizes the importance of consumers becoming aware of the Matter standard and the ongoing efforts to enhance security in the IoT industry.
Transcript
This is Textron tv. Hey, everyone. We're back here.
Live in Las Vegas for the DigiCert Trust Summit. We're at Resort World. Resort World or Resort World.
Got it. Resort world. Resort world here in, uh, on the strip.
And, uh, man, it's good to be back in person at the DigiCert event. We were here, you know, pre, pre covid, pre plague. Then we, you know, it was digital a few years.
Yep. And, uh, virtual, whatever you want to call it. And, and we're back here in person again.
And some things don't change, though. I'm not, like, I'm happy to have my friend Mike Nelson, who's VP or global VP of Digital Trust for DigiCert here with us talking this morning. Mike is gonna be chairing a panel today and doing some other things.
He has his hands in anything that's around digital trust and certificates. Mike Mike's involved in. Mike, it's great to have you back here in person.
Thank you. Hey, we love having you here. It's, uh, We love having, we like being here.
It's always fun to catch up with you. With you, man. So, Mike, excuse me.
I mentioned that you're chairing a, a panel today. Yeah. Not everyone watching this is at the event, obviously.
Tell us about the panel and, and let's talk about it. Yeah, I'm, I'm excited for the discussion today. I, I think it will be, it'll be a lively discussion.
We've got, uh, Stacey Higginbotham, who, um, is an, I has been an IOT podcaster. She's coming in to moderate the panel, and then the topic of the panel is matter. So you and I have talked about Matter in the past.
Right. Um, it's the, it's the new standard for interoperability and security for smart home devices. Yep.
We're a year in, so the first spec of Matter was released a year ago. I Think I interviewed you. You did.
Right, right. At that time. And so we're a year in, you know, millions of devices have been provisioned, um, in that ecosystem.
And we're kind of getting an update. How are things working? We've got, I think, um, we've got Chris Labra from the C S A who's gonna be joining, and then a handful of influential manufacturers who are producing the devices just to talk about how things are going.
So I, I guess, you know, look, just between us, how are things going? Yeah, I mean, I think, um, we're year in. Lots of devices are going.
And, you know, from our experience with our customers, it's been good. I think, um, I think there's good adoption. I think C S A has continued to see more of the members, the, the number of members in the ecosystem grow.
Um, I think we've seen more maturity globally. Also, we have customers now coming online in Japan and China, um, through India. And so it's neat to see the global growth as well.
And so, you know, I think that there, there are things that the C S A is still working on that need to be addressed, but I think for the most part it's being adopted. Um, and, and that's good. It's growing.
You know. If you don't mind, I'm gonna take us down a couple notches here because I realize not everyone watching this is gonna be up on all of these things. Yeah.
When we say C S A, what's CS a? Yeah. Thank you.
Yeah. So that's the Connectivity Standards Alliance. They're in industry standards body that helps develop standards.
They're most, uh, people are familiar with like ZigBee. Sure. Um, they were formerly known as the ZigBee Alliance rebranded a few years ago.
And Matter was launched under the umbrella of the Connectivity Standards Alliance. So they're organizing all of the working groups and things that are going on. So if you're a smart home manufacturer, you wanna get involved in matter.
The Connectivity Standard Alliance is the place where you go. Got it. And, and how do you spell matter?
M A t t E R? 'cause it matters. 'cause it matters.
That's right. And, and really what this is, again, for people who never heard the term before, an unfamiliar, this is for all of your smart home products, whether it's your refrigerator, your air fryer, your lights, your doors, your cameras, whatever. If it's connected, and you would primarily use it, you know, at, at home, it provides a level of security so that these devices don't get hacked.
That's right. They get zombie. They used for mal.
Yep. For, for evil purposes. Um, and it sounds like no brainer.
Duh. We want, we want in on this every, you know, we should be building secure Yeah. Smart homes.
Yeah. 'cause the road to perdition is, is lined with good intentions. Yeah.
Paved with good intentions. It, it's what, about a year now? Mm-hmm.
Got millions of devices. Not, and I should mention not every manufacturer is on board yet. Yeah.
And if I'm not mistaken, didn't some manufacturers now decide maybe to go a different route or that this wasn't for them? Yeah. So, so a handful of things are going on.
I mean, I think they're always organizations who sit in the back. Yeah. Please.
Every they're everyone. They're like, Hey, we're gonna let them figure it out. Get through the messy part.
'cause when you, whenever you develop a standard like this in a collaborative way, it's messy. Yeah. And it takes time.
They Max v h s, right? Yeah, exactly. They've, they've been working on the standard for, you know, three and a half, four years.
And so it's been a long time and coming and there's still things that they're working on. I mean, they've been working on, um, the latest release for some improvements on the security components to do things like certificate revocation and make that a requirement instead of an optional thing. That will be a great improvement Sure.
To be able to manage security. You need to be able to do that. Um, there are other things that I think that they need to work on.
I mean, they still have, you know, like, um, DigiCert, we were the first certificate authority that was approved to distribute device attestation certificates. And it has, it comes from a trusted route. And in order to be a provider of that, we have to, to meet a handful of security requirements to demonstrate that we can be trusted.
Sure. Trust is important. Um, they've done some things around, you know, to help drive adoption where they allow some of the manufacturers to do self attestation of some of those requirements.
To me, that's, that's a little concerning, right? Yeah. Self attestation for security sets you up for, um, uh, for, for challenges in the security space.
You know, I, uh, I hear that and I, and I, I, I'm, I get a deja vu, P c i Okay. Level four merchants, lower level merchants. So this isn't your big box retailers.
They were allowed to sell, test testify, you know, to their P C I compliance. And so you go ask a merchant, say, Hey, would you mind signing that your P P C I compliant here? Or do you want me to bring an auditor in for 10 grand to take a look?
Yeah, exactly. What are you gonna do? What are you gonna do?
I'll sign the line. Where do I sign? Yeah, exactly.
And, and the P C I council was like, look, there's never been a P C I compliant vendor who was breached. If they were breached, they were def facto, not P C I compliant. It's all these self attestations.
Yeah. But they never changed it because they knew that the level four merchant just couldn't swallow that. Yeah.
Yeah. So we Are we opening ourselves Up. Yeah.
So I mean, the same thing. So, so matter is built on the principle of trust. Mm-hmm.
Right. Um, so the first thing it tries to do is establish interoperability between the devices so that when you're going, you can have, you can control your devices, uh, through, through a more seamless, uh, experience. Uh, but then the second layer is security.
And, and, you know, they have roots of trust, um, that are common amongst the group. And the way that you create interoperability between the devices by having common routes that are in the root store. And then when a device connects, it checks to make sure it has the right trust, trust chain.
And if it does it authenticates. But the problem about operating a route is it's, it's an important business. I mean, DigiCert, that is our business.
Right? Right. We, we help not just with the creation, but the management of all that stuff.
But you need to do it the right way. And so, you know, we're working with the C S A and others are working to push for this. We're not the only ones who have that opinion.
But self attestation is a dangerous thing because someone could be running a root ca on a laptop that gets stolen. And what do you do if that compromise occurs? Right.
You need to make sure you have the right checks and balances to ensure that compliance is, um, that you have checked the boxes of compliance, not just self attest to it. Yep. So, Um, I don't know.
It's a slippery slope, Man. Yeah. Yeah.
I think we'll get there. And, and I think we'll get there. And it may not, they're looking at some other things.
You know, I think that, um, there's a lot of good things in the matter spec that are raising the bar for security. And, um, you know, and that's one of the things that are being discussed. And I love the fact that they're mature enough to actually just say, Hey, let's, let's wrestle these out in the working groups.
Let's try to figure 'em out. And hopefully we can get to a place where, uh, you know, we can get revocation included. We can get some of that self attestation stuff, uh, improved, You know, to me.
So I'm not, you know, sometimes you can't see the forest for the trees. You are clearly in the forest. I'm not.
Yeah. Excuse me. And, but I know about matter, thanks to you matter for, you know, since it first came outta your post call.
I'm surprised that I don't see more of it at the consumer awareness level. Yeah. So like for instance, when I go into Best Buy or wherever I'm buying Smart Home Yep.
On Amazon or wherever, I don't mean to be Yep. Not, you know, saying where you should go shopping, but why aren't, why don't I see that matter? Trust Yeah.
Front and center. Yeah. So you will, and it's there.
So I, I took a stroll through Best Buy, when was it, a couple months ago. And there were a couple devices that, that had the matter mark. So any device that's compliant with Matter gets a little logo matter has a seal that once you demonstrate compliance or have attested to compliant some of the compliant components, you get the matter mark.
And that is becoming more prominent. Uh, one of the manufacturers who will be on stage with me today have four products that are being sold in Best Buy today. And, um, and they have the mark.
And so it's coming, um, you know, I got an update to my Apple device recently that said, uh, the update is enabling matter and your device is now compliant with the matter standard. And so it's coming. You need to be aware of it.
'cause I, I'm trained to look for it. Right. Um, but it's coming.
So to me that's what's rubber meets the road though. Where rubber meets the road is when a consumer says, you know, I've got these two similar devices. One is matter, certified one's not, why should I care?
Yeah, exactly. And if I don't know enough to care one over the other, then it hasn't hit me yet. Yeah.
And I, I think that there's still work to do there. Uh, consumer enablement certainly is a key component. 'cause consumers are the ones that are buying, turning these on, and they're the ones that had the frustration to say, look, I have 30 smart home devices and I have to use 30 different apps to control 'em.
Right. I mean, that's the pain point matters. Trying to, yeah.
No, I, I've been there address. I mean, to me that was the whole thing with ZigBee too, though, right? Yeah, totally.
Because I, I had three different buses or whatever they call it, hubs in my house, you know, one, one for appliances, one for lights, one for the ring. Yep. One for the net.
'cause I'm a, I'D had Ring and Nest. It, it, it was a plus the wifi. Yep.
It was Crazy. Hey, I do the same thing. Yeah.
Which it's Not just me. It's okay. It's not just you.
You know. So I was hoping to have a, a, a consolidation of that to one app for all my smart devices. Yeah.
Um, you know, it's still a, it, it's still a Yeah. That's, that's where matter's. Trying to push it to, to create better interoperability so that you don't have to do that.
So we'll, we'll continue to follow the development and maturation of matter and, and yeah. I mean, sometimes you gotta break a few eggs to make an omelet. Right?
Totally. And, and so I, I think there'll be some growing pains, that self attestation thing, I think it'll play itself out and we'll go from there. But, you know, it's not dissimilar to what we're seeing also in the whole software development life cycle.
Oh, this is a good topic. Right. Did you like that segue?
Yeah, I loved that one. Um, you know, we, last year at R s a, we, it was all about SBOs and software supply chain security. And of course, you know, the, the White House and the Fed federal government's involved in this pushing it, and it, it's the same kind of thing.
We want the consumers of software to be able to have a, a, you know, the mattress label Yeah. That you're not allowed to rip off Yep. To show what are the dependencies in this software, this soft, you know, I I I I can trust this Software.
Yeah, exactly. And, you know, I think that's an even funnier issue than this matter thing. Yeah.
I mean, it's certainly an area that's getting a lot of attention. Um, I think you're right. The White House, um, has brought, uh, a large focus on the security of software in connected devices.
Um, the F D A recently, um, October 1st, the Food and Drug Administration in the US got regulatory authority to actually deny the submission of medical devices that come in that do not demonstrate, um, strong security. And they have, uh, guidance language out there. And one of the things that they specifically ask is signing of software and the creation of an SBO m software bill of materials.
Yep. So that they can say, all right, what ingredients are on this device and what vulnerabilities are associated with that. You know, in order to do security on devices, you have to have software.
And if you have software on there, that software has to be secure. Yep. Well, but it, you know, it, it's not just the mattress label where it's 64% polyester and 40% this and whatever.
Right. The thing I think that gets hairy with software and SBOs is the dependencies. Because today that piece of software running on your watch or, or this microphone is not just software I wrote, but it, it, it's probably there's APIs there Yeah.
That are calling out to third parties Yep. Which themselves are calling out to third parties and so on and so on. And so when we talk about ss o m and dependencies, it, it's, it, sometimes it's not even the code that's running on the device or on your machine.
It's, what else is that Yeah. Software calling to Yeah. And depending on and interacting with.
Yep. And so, you know, you don't want to be your brother's keeper, but you have to be three generations removed from where that a p I call is being made. Totally.
You have to have the chain, you have to, you have to be able to follow that and make sure that you have trust. And That's dynamic too. Yeah, it is.
And it's a, it's a challenging problem. And I think the other thing you point out, I mean, you know, a lot of devices are running, you know, when you're, when you're building software, you use open source software. Sure.
Your party software, you, you develop software on your own. All of those can have vulnerabilities. Some, some known, some unknown, but having scanning capabilities to be able to, you know, scan and say, all right, third party software, what are the known vulnerabilities from, you know, the, the lists that are out there.
And then also to be able to do testing on it to identify new vulnerabilities is so important. And that's a trend. I think we're seeing a lot more maturity, um, at least the discussions that we're having at DigiCert, we see a lot of organizations kind of migrating from old software signing practices and scanning and that type of stuff to trying to get more managed, um, approaches to it.
Yep. Um, because, you know, signing is usually not the problem with code signing. It's easy to take a code signing S I know they've made code signing Easy stamp.
It, it's the processes around signing where people get in trouble. SolarWinds is a good example of that. They used a valid code signing certificate to sign the software that was distributed to tens of thousands of their customers, and they had a big problem on their hand.
Yeah. But it was because they didn't, they didn't have the right scanning capabilities to detect the malware. They then signed it with the malware on it and distributed it.
And so, you know, I I always say good, good signing or software practice involves very thorough scanning, and then you need to mitigate those. So if you identify vulnerabilities, you need to be able to mitigate those. And then having, signing along the process.
So if you have different engineers developing that, you integrate signing services into your DevOps so that you can sign along the way to ensure the integrity of the build. And then of course, deployment, you have to be able to deploy the software in a way that's secure. Um, and that often includes, we're seeing more and more, uh, a software bill of materials.
Right. Yeah. Well, no, I think, I think SS farms are gonna be standard.
Yeah. But here, here's to me, SBOs have to be living, breathing dynamic. Yeah.
They are, Uh, instruments. Because as you said before, every software has vulnerabilities. Some we know Yeah.
And some we don't know today. Yeah, totally. But we may know tomorrow.
Yep. And so I could scan to the cows, come home today, and then release the software tomorrow, and then next week we discover a vulnerability. Yeah.
Or some third party dependency, discovers a vulnerability. And how do I, how am I supposed to know? It almost has to be that, that SBOs living and when it's, it sees something on, so this goes back to my neck days when I start the company that was very involved in n where, hey, I've got my, I've got my stuff here.
I've got my sbo, I've got all my, my bill of materials, I've got all my dependencies, I've got all my APIs. And now instead of scanning that software again because I just scanned it, but what anything on this SBO m triggers a, a new vulnerability found or something. Yep.
It like lights up green to red or whatever. Yeah. Right?
Yep. And, and now I know I gotta, I've gotta update this software, I've gotta do something. Scanning alone's not going to get you there.
Right, Right. And I think that to me, for SBOs to be really kind of fulfill the promise, that's the kind of capability I'm looking For. Yeah.
I love that. And those, uh, I, I agree and good tools out there. I mean, DigiCert, um, you know, we play in that space and we have some great partnerships with Reversing Labs.
Mm-hmm. Who's one of the leading scanning and SBO tools market. Yeah.
They're, they with them in text. Yeah. They're awesome.
And, um, you know, the great thing, uh, you know, this is a little producty, but, um, you know, the great thing about our solution is I believe we're one of the first vendors to bring both the scanning, the signing, and then the creation of SBO m into one platform where you can do it all together and, and in the way that you're saying, right. So it's a dynamic and you're getting updates as things are Going. That's, that's The key to it.
And that's, yeah, it's critical. And, you know, and then with your, with your signing and just, uh, I, I, I always think it's important to emphasize this point because, you know, traditionally, uh, I always say, you know, USBs with signing tokens, you know, that's the way people used to do it. And believe it or not, that's the way still a lot of people do it.
Yeah. But organizations are moving away from that to do things like rights management, access control. So you know, who do you want signing?
When can they sign? What types of files can they sign? You have to have that type of control key rotation, you know, I mean, the days where you'd hand those out, oftentimes the same key was used to sign like everything in their stack.
Today many organizations are doing more key rotation, even unique keys for each signing. You have to have a right strategy 'cause that helps protect you. Um, and those things are, are really important in finding, if you're looking for a solution, finding a solution that allows you to have that level of control, visibility.
Um, but also to make sure that you're protecting your stuff. There are things like key rotation, timestamping, all that stuff. Excellent man.
I want to come back to Matter 'cause we're gonna end up here. Love it. So people out here, they heard it now, if you haven't heard of it before, check it out.
Next time you're in Best Buy or whatever, look for the matter, uh, you know, certificate, how can they stay on top? Is there like a matter website at C S A or something Like that? Yeah, you can go to the Connectivity Standards Alliance website.
Um, they do, yeah. There's lot of information on their, on their site. They also have social media pages that you can follow, um, when new updates and things are happening.
Um, they release that. They also release when new members are joining. So if you have, if you have products in your home and you're, that product's not on the list, you can get updates, uh, on that.
But I, you know, I'm, uh, maybe we, we, I end on this, but, you know, I'm, I'm encouraged with the momentum that the C S A still has with matter and the fact that they have members joining the fact that more devices are going to market. I mean, it's, it's a good sign for the future of it. And so I'm, I'm really encouraged.
And, and also the fact that they're dealing with some of the hard questions around some of the security stuff. So it's Good. Absolutely matter.
It matters to you. Alright. Hey, Mike Nelson, it's great to see you man in person Again, Alan, always a pleasure, man.
Yeah, It's a great, great show here. For those of you who, who can't make it, look into it for next year, it's a, it's a really good stop if you're doing your, your conferences. Um, we're gonna take a break.
We are live in Vegas at DigiCert Trust and we'll be back in a moment. Thanks Alan. Thank you.





