Browser-Based Security – Or Eshed, LayerX
LayerX CEO Or Eshed discusses the launch of their recently launched browser security platform that’s trying to disrupt the traditional cybersecurity market by turn any browser into a protected workspace manageable by enterprise security teams.
Transcript
This is Textron TV. The great pleasure being joined by orishette or is CEO co-founder with layer X. Welcome War.
Thank you Mitch. It's great to be here good to be talking with you great topic talking about security and browsers and interesting approaches before we get there. Tell us a little bit about yourself.
Tell us a little bit about layer X. Excellent develop myself. I come from actually from experience in browser security so mean Michael founder we met each other in our military service we serve together in the Israeli information Warfare unit.
So we were researching anything Malaysia that we want to block on the worldwide web on the internet. And it brought us to expertise we were talking about the days that malware ransomware. Those were the most interesting things the top tier the Top Notch and web security was considered something basic because the browser is just for fun work is inside the perimeter and the overtime in my in my career information security.
I saw again. And again how companies get reached from simple fishing attacks or by a simple account. Take over things that happen on the web very applicative and it really bugged us me and my co-founder so we sat during covid and we were thinking what can actually be a game changer and that's why we decided to to Found lyrics and before Brothers security was a cool thing and we realized that it is a workspace worth investing in And we're trying to take the most out of it.
But with our own approach So lyrics is above like the seven-layer model. We want to be in the applicative world in the modern use cases. Well, let's explore this.
I mean sir browser vpns. That's kind of the hot thing at the moment. This has been for a while.
And yeah, there's a place for that too. Of course, we've lived in a world. I like you and in browser security, you know cross-site scripting and SQL injection and all those things are still there, right?
They haven't gone away. They're they're probably just as problem as development vulnerabilities. But what's really I think changed the most is the level sophistication of fishing and getting people to do things, you know, the fake websites, you know look like your bank.
They really look like your bank. It's it's hard to tell the difference. So I'm really curious about the approach that you're taking the in-browser approach that you're taking it for security.
Why don't you describe that for us? Okay, excellent. So I think it's actually not a trivial it description.
Then the browser is a very heavy application. It does really a lot. It takes a lot of JavaScript a lot of web code and renders it into an experience more than any other software in the world websites today modern website single page applications are more complex than software on-prem software has been a few years ago.
And it is impossible any reverse engineer by the way will say it is impossible to reverse engineer JavaScript because it's super obfuscated and complex. So the in browser approach says let's allow the browser to do the heavy lifting. The browser is compatible with the web.
But there is a significant visibility piece that's missing that can be caught with an extension. This is what we do in lyrics the browser decrypts the traffic renders it and we see the entire process a poor analogy will be boxes and boxes coming from Ikea that are near to be your new kitchen when they're in boxes. We have no idea.
What's about to be a sample even even after you open the boxes. You have no idea how it will turn into a kitchen. So we see the entire process until we have the end result and the browser is an old powerful tool but it allows much freedom for both the website and the user so we are there to remember what the system wants in terms of risk appetite and only restrict the things and events that are risky in a block the list approach.
So talk a little bit more about I like your Ikea analogy, right? Sometimes there's instructions and because I was told you need to be able to explain it to your grandmothers. So I try like I break my teeth every time trying to find a way because I make grandmother.
Apparently. She doesn't understand JavaScript. She hasn't she's not up.
You know, I had someone tell me you know, you need to make it Grandpa and Grandma simple. Sometimes that's pretty high simple as hard, right? So so tell us more about that because there's so many things of what we can look at that's happening within the browser right?
We can be looking at protecting from kind of vulnerabilities that we talked about but we also can be looking at the applications the sites the the types of use cases that end users are performing and I seem we're talking more of an Enterprise security scenario. Is that kind of use case that you're actually going after definitely first of all, the Enterprise security is much different than consumer security consumer security is just making sure that you don't download malware or get like lose your credentials Enterprise security is taking the agenda the risk appetite of the organization and actualizing it into a policy in the browser. I'll give you one small example.
Using a personal Gmail at work. Some organizations will say no. No, we just disallow it entirely.
I just will say we need the quality head count. We need to allow them Gmail, but let's restrict them from downloading files. Let's see what they are doing that maybe risking.
Let's lock the list in order to get a job done. So that's for us Enterprise browser security. In terms of use cases.
It's seeing both seeing how users consume sales applications because today 80% of the work is on the web service show that about 85% of us a companies and organizations are almost entirely browser-based. So applications need to be to be compatible with chrome Edge in Firefox. We are also compatible with chrome engine Firefox.
Thus we're able to provide governance on every application that's in the browser. Seeing what kind of data goes up and down files and even in-app actions. Talk about the data protection side of it.
So there's the applications that we can use the maybe some of the functionality that we're using within them data protection is also a big issue we talk about browser because it's obviously a big place where that can leak from. Is that something you've worked on addressing yet. Definitely a first of all this is a huge use case, which is also wanted to see those that I talk to.
Feel unsatisfied because data security is here for many many years, but it's not perfect. And what we provide is in our approach the last piece of the puzzle puzzle seeing where data goes to there is a huge difference between an application that is connected to your SSO which is sanctioned and you want to allow data to go up and down and another Shadow application that only one employee is using maybe with an organizational identity. So we label all those applications all those identities and account and allows csos out of the box to decide what goes where in a very simple out of the box manner by that by the way, we're trying to achieve a something that is very crucial in our point of view.
If you use Legacy Solutions, you have to options one to sacrifice the business for security. That is the ciso must approve each and every application before it's used and that's a bottleneck that very few ceases are willing to accept the other alternative is a full Anarchy. So it's other dictatorship or full Anarchy and we want the middle path.
We don't want to sacrifice neither security nor the business, especially in 2023. By the way being a business disabler is a very bad go-to-market. We want to balance things and the ability to secure applications that you don't manage is very appealing to our customers.
Yeah, there's insecurity. If you push it too hard against end users. They will react the opposite right and exactly other way.
You kind of need that Goldilocks approach somewhere in the middle where it's Secure but not to see not so onerous for security. I'm curious. So what it seems it seems like because you're a plug-in in the browser, right?
So you could also work one devices that are not managed by the Enterprise which seems a great and today's work for anywhere. That's a big piece of flexibility. I would think Yes, it is and it's quite common.
Eventually it goes back to my example more devices more agility. You can be available of work hours and eventually it happens. So in reality some organizations choose to allow bring your own device and those seesaws do it for not for good reason.
They know what they're doing. They want to allow the business to run here. So you can deploy extensions on non-corporate devices and turn a browser into a secure terminal without getting into deep details are deployment is what we call an Enterprise browser extension, which is quite different than a regular extension on the Chrome Store.
It just has more power. It is the equivalent of any Dr. Over the browser and you can secure the browser.
No matter if it is on a managed device and an unmanaged device. And the beauty of it. We only need to be compatible with the browser.
So any operating system that can have Chrome can have lyrics I was curious too. So when you do a plug-in for the browsers that is that going to be any interactions or activities within the browser. So all tabs within Chrome you're gonna have visibility and to be able to apply policy.
So I might have my Chrome browser that I'm using for Enterprise work and I can go up in Safari or Edge or something else to do my own stuff in that might not be managed by you that is that accurate? It is accurate, by the way. It's a great point because users are doing a mixture of work and non-work.
On the same browser on different browsers on the same identity sometimes sometimes they work on GitHub with or their own personal email again. It goes back to the risk appetite and sometimes the employee compensation website or terminal is using their personal email account. So which browser should they be using eventually they have data moving in and out based on personal web activity and none in a work related activity.
Point is we can see that in real time. Every tab is its own process? So what we bring is the ability to see what is the context of this tab, and then we enforce policies.
To tell you a secret. It doesn't really matter if it's a different browser two tabs in Chrome can be a operated differently as much as Chrome and Edge can hmm. Okay.
Yeah, they are truly independent within within the browser. They're on the wrong addresses space. Yeah.
It's on the task manager. There are different processes on the operating system. Good point excellent point so what are some things when I first entered security products into the Enterprise there were sort of this discovery.
Oh, I didn't know that was happening with my end user Community. What are some of the typical things that enterprises would learn once they've installed by your ex? So in terms of a things that they find they're known.
Yeah insights that they get that they may not have had before. so usually there is a the deployment of lyrics is on top of your existing ecosystem. So you don't have to encourage users to move to a new browser.
So you just take them as they are for the good and for them. So it typically what happens that the organization is find out about a lot of Shadow SAS not only Shadow sets but also Shadow identities personal browsing activity employees uploading work-related files to their own personal email maybe for good reason. They want to work in it on the weekend still it won't make you eyes or compliant if that's allowed no matter what the sentiment is.
so to get surprised I think that the mixture between personal activity and work-related activity are the ones that they annoy them not I don't know if you know is the right word, but they Keep them busy the most concern you see a lot of attacks coming from personal web activity. Not only from personal web meals but also from other applications and websites. Streaming websites like illegal sports streaming and in organizations lead to malphatizing so attacks are coming from anywhere.
Yeah, we do live in a world of mixed mode in everything. Right and we're not always in the office. We're not always on the VPN.
We're not always on it controlled environment not always on a corporate computer. Or even a browser that's managed by the company now, you know with a plan approach. I can definitely see that advantage.
What are so so some folks can go to layer X to your website and they download a trial is just some way they can check out your technology and your product. So first of all, we're here and we are very responsive and they can go on our website contact us and we provide a POC they get their own instance. They can deploy in their organization.
Usually the feedback is are you sure it's working. It didn't even restart the browser, which is what we want to happen. Then they get an access to a their own terminal to get a lot of insights a lot of visibility and then they pick their own process security Journey based on their risk appetite whether you like through restrict things or keep them open they get a lot of visibility a side note recently following the last bus reach we released to the community free tool to to mitigate or to to find visibility to who is using LastPass under Which con a context and we gave it away for free because we think that is a vendor today.
We need to prove relevance when things happen and we had a lot of very positive responses and a process is quite simple and we get great feedback from the community. So we're very happy for it CISO that POC the product eventually find a lot of value in the POC itself because it's actually full GRC reports. They know what's happening.
That's that's an important part of it, too. We didn't talk about compliance and Reporting and attestation of Of that information that you need to provide which is a whole nother benefit category or it's been fascinating talk with you congrats on on the product and the company or excited to see where you go with things and in browser and how this is adopted and where you take Slayer X. So congratulations Thank you very much me she was very nice talking to you and thank you for the audience for listening.
You bet. com, by the way, so check it out.