Authentication, Authorization and User Management – Rishi Bhargava, Descope
Transcript
This is texturing TV. Hey everyone, welcome back to techstruck TV. Our next guest here.
Today is Mr. Rishi bagava. Rishi is the cr-o chief Revenue officer and co-founder at the scope these Scopes a company that recently and announced emerged from stealth and announced the 53 million dollars seed funding round, which is substantial in today's world and Rishi is going to tell us all about the company and and all of that but first, let's welcome.
She welcome to Tech strong TV. Thank you so much Alan excited to be here and share our mission and story. Absolutely before we get into the scope.
Let's hear a little bit about Rishi bagava. What's your story? Yes, I I'm a grew up in India born and grew up in India came to us to do my masters.
I've been here for a long long time. I'll say more than 20 plus years now and by training, I'm an engineer still very Hands-On. But as you can see my title is cro as my co-founder.
Slavic says, I've been slowly degrading from check to selling but I I respond by saying hey, I'm getting closer to the money. So that's that's me. That's exactly it.
You know what it's a fighting thing. You really see people in marketing and sales and you assume they're not technical. But how many people?
In marketing, it sales actually have that technical background, right? Because it's very hard to be successful. Marketing and selling Tech if you don't know Tech.
Yeah, you got it people see through that. That's by the way actually a very good point. I think I feel I'm able to connect to a buyer and user much better because I can understand the pain Point as well.
Definitely. Say it all the time. You got to talk to talk and walk the walk.
Anyway, I appreciate it. And I and I commend you on your growth Journey. It's not a Devolution.
It's an evolution. But let's let's talk a little bit about these scope. So you guys recently came out of stealth here and well, it's your story.
I'm gonna let you tell this one tell us about the company. What do you do? Yeah.
Definitely I think a little bit of the background in the founding team as well here on so we we started disco last year in April timeframe. Try it to that all of us were together at our previous startup. That was demisco which we did 2015 got acquired by Paul.
to networks in 2019 That was an amazing journey, I think in three and a half years. We did really really well from a product growth customers growth perspective and spent three years at Palo Alto networks growing that product and that product in the security orchestration space is doing extremely well. Then we said hey, we we like each other's companies so much.
We like to spend time with each other. We all of us really good friends says let's do it again. And that's how literally I would say these scope started.
We are always a team first idea later. So we said let's start something and we looked at various different spaces and I think the biggest thing that we realized was. The number one problem from a consumer and the business perspective that pains in terms of world of security is the user Identity or passwords.
Like I have not met a single person who says no, I love passwords. I love to have the same password everywhere. And I remember every password you name it right?
It's a user problem and it's a security problem. That's that's how it came to be and says, okay, let's solve that. Given the bigger big problem given the team's background.
We we were able to kind of work with our investors raise a very nice round. Because we believe I think the challenge is huge the opportunities huge. They always come in hand in hand are just announced our product GA on February 15th earlier about a month ago.
We were able to get amazing feedback from the community. The product is now generally available to customers to try it announced off funding and now we are in that growth mode of acquiring customers getting feedback for the product. Excellent.
So look, I've been in security 25 years myself Tech 30 years. It's not a new problem. I think we've all recognized.
The password issue if you will for a long time and we've tried I mean we literally thrown the kitchen sink at it, right? We've tried password managers and and then the last couple years we've seen what happens when you trespassword managers with all your passwords. That's right.
We we've tried Biometrics and I've seen all different ones from Iris to fingerprint to Cadence of your typing all different biometrics. I there are companies out there now that I've interviewed who would taking some novel approaches around digital identity and making a password list, but some of them it reminds me back when I was in security 20 years ago. We would the big thing was.
Oh, no not another agent where agent list but really they still stuck a piece of software on your computer. They just didn't call it an agent right. So talk to me.
How how do you solve this problem? Yeah. So I think let's let's get the basics.
You have a extremely extremely good point right? We have tried it so many times. But we always tried to I believe go around the issue rather than tackle the show right?
I mean, for example, a password managers are not removing passwords, they're managing passwords. So we didn't do much with password managers at all in the in the like they of course help with security because you could have multiple different ones manage it but they didn't get around. I think the few factors that are playing right now, which says why now for me and then I'll explain what we are doing.
By the way you think I say guys we are an enabler towards the password less world. I'm not inventing a new method here, but let's let's talk the path through. So first of all, I feel that over the last seven to 10 years one thing that has happened is There has emerged a new identity for every digital citizen of the internet, right which is all of us.
Anybody has any login? What are those alternate identities one? I think our phone is an alternate identity all of us have a phone.
Most and most I mean by 90% almost these phones have some sort of biometric in place. Second the phone number is almost as unique and identity as my name barely everybody changes the phone number if they change it. They actually move to the new one very quickly.
So that that's one piece an alternate identity. By the way that has emerged is your email provider all of us have an email which by the way if I believe if it was compromised that's a huge problem. Like if email is compromised.
com to you name it right Office 365 work email addresses. But these are two different identities. And then the third is by the way as you mentioned biometric multiple different Biometrics have evolved but I think that space has now reached where there is the standard which has emerged called Fido web orthen standard along with passkeys and incredible work done by Google Microsoft and Apple over the last couple of years.
We're there all supporting the passkeys as a standard. Now what it's a long story, but what I'm trying to point out is finally we are getting to the point where there is an alternate identity between biometric and phone and email which you can use a combination to identify a user. But why is it not working?
And why are we in business is because it's very hard for an average application developer to implement this. Our promise is simple 10 lines of Code 10 minutes. I can make your app password less because I bring all of these together.
Make it really simple and enable you. So let me let me see if I get my little brain wrapped around this. So basically you're using.
Phone and email is in sort of a two-factor. Is it is it like a two-factor authentication 2fa, but you're what you're doing is you're you're not commoditizing but you are. Templating embedding a 2fa methodology that allows you to put it into any app really fast and easily and then it gets offloaded to desculpt worry about all that.
Little slightly different almost there. So the SMS are magic links. These were considered as second Factor, but the reality is you can and second factor meaning password was your first Factor.
This was the second Factor. All right, if you are building a mobile app, let's say I'm building a fashion tech company the mobile app today. Ah chances are 90 to 95% of my users are gonna come from the mobile, right?
That's how the new generation is or even if you're coming from the web wherever they're coming from. You can have the sign up with their phone number and send them an SMS. That's a secure or actually that's way more secure than putting a password in because they get an SMS they log in with that.
And that's my first Factor. For the login now, you do want a second factor, which we do recommend. By the way biometric is your second Factor, right and biometric could be multiple factors because you own the device you have your face.
So that's two factors already in there. But for that Mobile use case, I would say do OTP plus biometric and that's amazingly way more secure than password people. Don't forget anything if they need to log out log back in all they need is the phone and they're back in and everybody has the phone at all times like even if I'm logging from my laptop.
I have my phone sitting right here. Yeah, yeah, so I personally speaking now right? I haven't done any.
Studies on this personally I prefer that method versus because you know, the latest round of security incense or password managers just soured me on all that. So I don't even like to put stuff in there anymore. And the other hand like you like me People Like Us in the tech world.
Not only Tech world we all have a hundred plus Passwords, right and we put in in the security space. We're told don't use the same password twice. Don't do that.
So we you know, so we make variations on our passwords, right but we still have a hundred plus who remembers that I would much rather. I don't mind the face ID or or touch. I don't mind you sending me a code like on my iPad or my iPhone when that SMS comes in with the code.
It shows up on the bottom. I just have to pull click it it's there. So, that's me, but yet I've seen studies where people They don't embrace it like they do old-fashioned stupid passwords because they want to type password one and move on and they do it over and over until they get hacked.
I mean have you run it is the developer average developer wants to take the shortest path, right if I'm building a new app, by the way, and that is that is I think the biggest realiz. Mission that we had is you cannot change it from the consumer Behavior because consumer will do what the app asks them to do. So we need to go to the app developer and say hey.
Develop a better experience like imagine the onboarding will be so much simpler you put in the phone number and you are to complete like look at the WhatsApp WhatsApp was one of the earlier Services, which moved completely passwordless. Do you even realize that WhatsApp did not have a password and yet the one of the most secure Services have you heard people stealing? No, because to the phone ID, that's the point.
How do you convince the developer to take that step? And that's that's kind of the education we are on. Reminds me of familiar with sendgrid remember signed great.
I don't know if right. Sending shooting off an email when someone signed up used to be a whole thing. They made it really simple right just put in the sangrid code and Sangre does that for you boom your email is done.
Yeah is a very similar thing. It'll be interesting. Thank you.
Yeah, I I try to avoid analogies because it seems like I'm saying this for Uber that for Airbnb kind of scenarios Airbnb for that or Uber for that but very very good analogy Alan like I think of us enabling what send grade or twilio or stripe did in their respective areas. Yeah, because why does every application need to build the same thing again and again and again if I can really give them that piece of code they embed it and they run with it and that's the way we Cote today too. Right?
Most of our apps are stitched together component makes kind of sense. Hey, we're almost out of time here. I promise I get you out in time for people who want to get more information on this these scope.
Where do they go? They go to our website. We are big Believers and try it on your own you are not going to be bothered by repeated stuff.
Take a trial you're gonna love it fully documented and we are open to hearing feedback. So we have an open Community slack community on our website. Would love to hear feedback from your users.
com. com fantastic ready? Hey reshare appreciate you taking time out to come on here today on Tech strong TV with us.
We'll see you soon. Best of luck with the scope and do keep us posted. Okay?
Thank you so much Alan excited for our journey forward and thanks for the opportunity. com crl co-founder here on Tech strung TV. We're gonna take a break.
We'll be right back with our next guest.