Aembit’s David Goldschlag on the Cloud and Automation Era’s Challenges
Our industry has come a long way in ensuring user identities are secure. But with cloud adoption and automation rapidly growing within enterprises, we’re about to go through a deja vu scenario with non-human workload identities – as distributed and dynamic apps and services outpace human identities by astonishing rates.
Transcript
This is Textron tv. Hi everyone. Welcome back here to techron tv.
I have, uh, a co-founder, CEO to introduce you today. Introduce you to today. His name is David Gold Schlag.
David reminded me off camera that we originally met 10 years ago, which isn't that long ago, 10 years ago though. And, and, you know, in tech years, that's like a dog's life, um, a long time ago. And of course it was before co-founding and CEO becoming CEO of Ambit, which is his present company he's gonna tell us about today.
But it's good to see, you know, the caramel wheel go round and round and, and you meet people and you get a chance to meet them again. David, welcome to Tech Drunk tv. It's a pleasure to have you on here.
It's a pleasure to get, get together with you again, Alan. Okay. And it's nice to see that, you know, at least you haven't gotten any older.
Most. Yeah, I wish, I wish, I think about 10 years ago. Anyway, um, David, before we jump into Ambit, I mentioned, you know, we talked 10 years ago, so obviously you've been around the tech world a little bit, you know, for a minute.
Why don't you give people kind of maybe a little bit of your background and how you came to Co-found, uh, ambit. Okay. Well, that, that would be great.
Yeah. So, um, my co-founder, Kevin Sapp and I have been doing startups for a long time. Okay.
So we've been fortunate to be working together for, I think it's going on 17 years, which is like, in your, your language, it's like two dogs life. Okay? Yeah.
So, um, yeah. So that, that's been really super. So Kevin and I have been focused on security startups for the longest time.
Um, I joke with my own kids that I do security plumbing, I don't know anything else to do. Okay? Mm-Hmm.
And, um, that, that's worked out. We've done companies together across the sort of user secure access space. Now, going on 10 years though, that would be, you know, people using mobile devices to access enterprise resources.
What became the MDM space? Okay. Mm-Hmm.
Or, um, or users, um, being able to use, bring your own device to split phones into two pieces, right? Personal and work. Sure.
I'm probably familiar with all that. Uh, most recently before Ambit, Kevin and I started a company called New Edge Labs. That was one of the first zero trust network access companies, which is the replacement for S-S-L-D-P-N.
How do you connect users to applications that are behind a firewall, but do this in a world that's cloud ready, that gives you application level policies. Um, that company was acquired by Netskope. Okay.
And then, um, when kind of the backstory on ambit was when we were building New Edge Labs and at Netskope, customers would ask us, you're connecting users to applications, but can you connect applications to each other? Okay. Can you help applications log into other applications?
And, um, I think the customers were often saying, Hey, you're doing S-S-L-V-P-N, could you do IPSec VPN replacement? Okay. But we kept this in mind, that wasn't what we were doing, but we kept it in mind.
Um, and then when we were ready to start a new company, we said, why don't we focus on this application to application? We call it workload to workload. I'll explain that more later.
Um, we also decided that it wasn't a access problem, it was an identity problem, okay? Because lots of workloads, when they're going to other applications, that application is on the internet somewhere. Okay?
But how do you secure access between them? Um, instead of enabling, um, reachability network reachability. So that's what we solved at Abbot.
That's kind of the backstory. Um, one small thing that's probably maybe interesting to some of your viewers, um, early in my career, I was an inventor of what's now known as Tour at the time was called Onion Routing. So really, um, this was a, this was in the nineties.
You never do that. Okay. Yeah.
So, so this is, I don't know, three dog years ago. Okay. I think more than that, but I'll let you go.
That, that, that, that, that, that's right. So I've been on the, you know, on the, you know, privacy side of this and, um, you know, what's, what's now called the dark web a little bit. Um, but, but mainly Kevin and I have focused on helping enterprises, um, be secure and it doing security that enables you to run your business, okay?
Not security that's targeted mainly at stopping bad things, but security that enables you to do, um, do what you want. And we think authentication and identity is that sort of very positive side of the security thing. How does it enable you, um, to build your systems, um, and, and, and run your business, um, uh, safely?
No, I, look, I think IAM is, is sort of the killer app of cloud security, right? If you, if you're gonna do nothing else, you, you need to control your identity and access for, for your cloud apps and your cloud infrastructure, um, you know, I I think sometimes David people, not naive, but I don't know if they truly realize the amount of, you want to call them workload identities and machine identities, and let's call 'em non-human identities that are part of the chain, part of the system for your modern, you know, architecture today. They outnumber the human ones by like 10 to one or, you know, some such ratio.
Um, and, and so, I mean, obviously there's a lot more of them than there are of us, number one and number two, you know, it's kinda like being a vet. You, you, you, your patient doesn't talk back to you, or at least in a very easy language to understand you gotta sign it, kind of interpret what's going on there. And it's the same with with workload identities, right?
You, you, you, you know, the monitoring of 'em. The other thing I I will just quickly mention is, you know, back in the nineties and the two thou, early two thousands, you might be talking about application to application access. Where today it's, call it, let's call it intra application, right?
When you have multi-threaded applications, right? Though they need to talk to each other in a secure way or interact with each other in a secure way for, to, for the application of function, right? And, and so, you know, I think that, uh, I mean we, we, we see this in, in a ai uh, uh, application, excuse me, API security, right?
It's one thing to have an API to a third party app. It's another thing when your application has dozens of APIs and they need to communicate with each other and access each other. So this is, this is a big problem, right?
Or a big, I don't know if problem's the right word, but it, it's a problem. But it's, it's a, it's a big attack surface. It's a big surface to try to protect for, um, how did you get the idea to do it, you know, what became abit?
So, so kind of, kind of the genesis story there is exactly what you're saying, right? Is we noticed some secular trends. So one of the secular trends was applications are no longer monolithic, right?
You used to build a big app, right? And it all lived within one environment, and you didn't really have to worry about that app talking to other apps or the app, even talking to other things within itself, because you, you have that crunchy exterior, right? It's the, it's the old, the old data centers, right?
The firewall secured everything inside it, and you didn't worry about what was happening inside. I mean, That's right, right? And, and there's another analogy here is, is the apps, you know, you would include open source code, okay?
Right? And so, but it still was start of part of one holistic application, okay? But these new apps, like you said, are composed of microservices, right?
Within the same environment talking to each other. So it's no longer an monolithic app. And then you're relying upon APIs that are within your own environment, and then you're relying upon cloud APIs or third parties, and that's kind of the new version of open source, right?
You got these third party APIs that become services to your own applications, and now you have all of this exposed surface and dependencies between these components, and let me call these components workloads, okay? And if you don't secure access between these, you don't know that these workloads can depend upon one another. Okay?
And I think you also said that, um, I, we know from the user side of this world that authentication and authorization is kind of fundamental to doing everything, right? It's, you gotta do all sorts of security, but if you don't lock down and control who can access what, okay? Then a lot of other security measures that you do, you ought not, you ought not to worry about it, right?
And conversely, if you do have strong authentication, security, a lot of bad guys would find it much harder to come in your networks. And so far, you know, because the company's products, Azure, ad Okta and others, people have been focused really on user to application security and identity and access management, and Zero Trust has done giving you a lot of tools, okay? To get from where we were 12 years ago to where we are now, but now we have this problem of what you said, non-human access, right?
Workload to workload access, and it's time to start securing those access, right? Between workloads and leveraging what we learned about how to secure user access to applications, but applying it to this new domain, right. Of workload to workload.
Absolutely. Um, it's, it, like I said, it's a big job. Big job.
So let, let's hear a little bit about how you guys are solving it at Ambit. Yeah. So, so we, we, we started Ambit two years ago, okay?
And so we're a 2-year-old company. Um, we raised, um, we raised, um, our seed round, um, ballistic ventures and, um, 10 11 ventures. Um, we have some strategic investors.
Okta is an investor, and CrowdStrike is an investor. Um, and I think all of that goes to what you said, is this an important area, okay? Right?
Um, people who worry about secure access between users and applications, people will start to worry or are worrying today, right? About access between, between work lifts, between applications. Um, so we, we, we launched the company, we started the company two years ago.
We launched, um, the product this past year, and we've been focused on helping our customers, um, um, use Ambit to, to make their lives easier and make their applications more secure. Okay? io, ae MBIT io, you can learn more about our company and you can also start to use our service.
We're a SaaS service. Um, we have a free self-service tier. We're happy to help you use this self-service tier, okay?
And, um, but, but you can use this and the three tier is meant to help, uh, uh, for instance, a dev, a DevOps group, right? Who's responsible for an application or two with components that talk to each other, okay? And talk to third parties, and we can help you secure access between those components.
Um, and our design here is to let you do this with no additional burden on the developers, okay? And that probably is part of sort of, you were talking about secular trends, right? So one secular trend is this, this movement to, there's lots of workloads talking to each other, but the other one is, is developers should not have to do work, okay?
In order to do secure access, okay? Developers have enough on their plates, okay? To be able to build the business level logic, okay?
So if you have workload, A, you should build a logic and workload. A, if you have a database that it needs to talk to, and workload A is authorized to talk to that database, we should just be able to make that happen by policy. You shouldn't have to teach workload a how to authenticate to the database, and you shouldn't have to manage keys and secrets and API keys and username and passwords for service accounts, you know, the, the whole alphabet soup right?
Of problems to talk to another API. And so we take care of all of that. There's kind of a, a, a a A hope, right?
That you can have secure by design. So we, we are, ambits goal is to let DevOps make a policy workload A can access service B, and then workload A dynamically, we'll be able to access service B right when that policy checks out. I love it.
So someone out here in my audience is saying, well, that sounds great. I wonder how I get started. How can, can I test this out?
Can I get my hands on this? And, you know, give it a run before I, you know, let's see, because David's just the CEO, of course he loves his baby, but I, I wanna see for myself how, how, what's the best way for us to do that? Okay?
Yeah. io Okay? And you can get documentation and you can get, um, some demos.
You can also start to deploy for use cases. Um, what I would urge you though, reach out, right? We can help you.
Okay? Let me describe kind of briefly how, how it works, okay? And I'll give you a bit of a sense.
Okay? So, so let's say you're writing an app and it needs to go to a database or a data like, like Snowflake, okay? Or you have an app and it needs to go to an API, um, Microsoft Graph or Salesforce, some third party SaaS app.
What happens is, is in the old world, you would create a username and password for the service account to log into Snowflake, or you'd create an API key in order for that workload to access Salesforce. In our case, you do it like you would do Okta for authentication between users and applications. Okay?
So Ambit is the control plane. So workload a, when it wants to access Snowflake would go to Ambit and say, I am workload A and I wanna access Snowflake. And, um, then work Ambit would check a policies workload, a allowed to get a Snowflake.
And if so, we would issue a credential for access to Snowflake. And so workload A would get that credential only if it's authorized, okay? And only, um, dynamically when, um, when that access is required.
One other thing that we do, which is really important is, um, a lot of access today is gated by long-lived credentials like usernames, passwords. And we know that the trend on the user access side is to move to shortlived credentials and two factor authentication, right? We all know that long live username and passwords is just not the right thing to do, okay?
So we help workloads make that same transition, okay? Instead of issuing a long live credential, we can preferably issue a short-lived token, okay? And instead of relying only on the identity of the workload, we can check all sorts of contextual decisions.
Is the workload coming from the expected place? Is the workload healthy? Okay?
Does CrowdStrike say it's a secured workload? So we can start to move, co move your environment to the more secure contextual access like you would do with an IAM system or zero trust system for users. We can do that between workloads as well.
Hmm. Excellent. Excellent.
com Io ambit Io. Yes. Okay.
I'm sorry. Okay. You got it.
Fantastic. Thank you, David. This is, uh, look, as I said now a couple of times, this is, this is a big problem you're tackling here, right?
It is a big issue and growing every day. So it, it's definitely something that needs to be addressed. I think a lot of us do spend an inordinate amount of time and maybe rightfully so on people's identity and access control, but I think this is the one that sneaks up on people, and you gotta get your arms wrapped around it quickly.
So kudos to you and the team there at Ambit for, for jumping on this. It'll be interesting to see, you know, how, how this plays out. So we're, we're, we're, we're very excited about the journey, okay?
And, um, like you said, we have lots of history on the human identity side, and now it's time to take some of those learnings and apply it, um, to, to, to workload. To workload and to the modern DevOps world, right, of building highly decentralized, um, applications. No doubt about it.
David, thanks so much for coming on sharing with us. We'll be keeping an eye on ambit. Come back soon and keep us posted here, okay?
Thank you, Alan. It's a pleasure. Okay.
All right. io. Check it out here on Text Drunk tv.
We are gonna take a quick break and we'll be back with another guest in just a minute.