Confidential Computing Adoption with Anjuna Security’s Ayal Yogev
Anjuna Security CEO Ayal Yogev explains why the rise of generative artificial intelligence (AI) is going to push more organizations toward adopting confidential computing platforms to ensure data security and privacy.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with AAL Yoga, who is CEO for Injun of Security, and we're talking about confidential computing, which I think may be getting a boost from ai, but we'll explain.
Hey, aal, how you doing? Hey, good, thanks. Thanks for having me.
For those who are not well versed, what exactly is confidential computing? 'cause I don't think it's as well known or as common as a lot of different services there are out there, but you're starting to hear the term more and more lately. Yeah, I'd say the, maybe the best way to to explain coverage computing, um, is, is to explain what it enables and the, the best security solutions were always enables, right?
Firewalls. What enabled all of us to connect to the internet without having to worry about, you know, security and privacy concerns. Confidential computing essentially, uh, enables collaboration.
And what I mean by that is every workload is running, you know, has the data it's running on, it has the code or the, the model, and it has the infrastructure it's running on. Uh, every time you have more than one entity, uh, that is involved in that process, you have a security or privacy concern. And what confidential computing allows you to do is to run things where, you know, somebody else might be owning the infrastructure or you wanna run your data in somebody else's code, or you wanna merge data across different stakeholders without anybody getting access to anybody else's, you know, code data.
And that's what computational computing enables. Uh, in terms of the technology itself, computational computing is essentially, instead of things that were added to the silicon, you know, to, to the CPUs and the GPUs by the harbor vendors, by, you know, Intel and a MD and ARM and Nvidia. And essentially it's two things.
One, it's protecting the, the memory itself while you know what's being used. While Quoing data is in memory, which has always been one of the last spaces where data was not protected. And these, the second thing is something called attestation, which is the ability to prove that they coded the data haven't been tampered with.
But what these two features essentially allow is that collaboration across the board. And where does AI factor? And I think people are more cautious of the sensitivity of their data because they're using these LLMs.
But, um, how do I kind of marry LLMs in confidential computing? Yeah, so it's funny because I think for the last maybe, you know, 20, 30 years, a lot of the, you know, Accentures and the McKinsey of the world, I've been telling their customers, you know, I'm sure you've heard all of this, right? Data is the new oil and data is the new goal, data is the new frontier.
Mm-Hmm. And people have been collecting data in order to use it. Uh, but there hasn't really been, you know, a really good way to leverage that data.
There's been some business intelligence, some things were, you know, people are trying to do that data, but it hasn't really kind of lived up to the expectation. Uh, when people started seeing the new AI models and lms everybody's eyes, you know, open. So, okay, now finally, there's, there's something we can do, we can do with that data.
The problem though, became that in many large enterprises, that data is sensitive or regulated or, you know, it's privacy related. So they couldn't really leverage that data to the extent that they could. And that's where confidential computing came in to enable you to essentially leverage any type of data for, you know, training for, you know, Russia to, for, for referencing, for whatever you you want to do with that data, uh, without having to worry about security and privacy.
And let me maybe give you just a couple of examples, uh, of, of projects that we're involved in. Uh, one is a healthcare, uh, a large healthcare company. They obviously have a lot of patient data that's extremely sensitive and regulated, and obviously they wanna keep that safe and private.
Uh, but they wanna work with a lot of, uh, new AI startups that do things like early cancer detection or early pregnancy detection to be able to, to identify those things. The problem is they can really leverage that data in these companies models because of primacy and regulatory concerns. What confidential computing enables them to do is finally kind of run that data in these models without having to worry about, you know, the, that data getting, uh, into the hand of somebody that's not ready to, to, to get access to that data.
And also the AI model company doesn't have to worry about their AI model, which is obviously their ip, uh, getting into the hands of anybody else. Well, confidential computing ultimately become the standard thing that we're using for everything else, because sometimes I talk to folks and they were like, well, you only use that for very rare instances. But, you know, I scratched my head a little bit and I'm like going, well, why not use it everywhere?
No, that, that's, I couldn't agree more. Basically what we're seeing in security in general is every time there is a security solution that has two characteristics, one, it's very, very easy to use, and two, it doesn't have a performance impact or any kind of impact on the, you know, on the, you know, essentially the performance of what you're doing, the, it just becomes the default. Um, and the reason is once it has these two characteristics be be crazy, you know, not to use it.
Right? And that's, you know, the firewall kind of had that same path where it started with the large, if you remember in the nineties, it started with the large banks and large enterprises, you know, governments. And then now, you know, we're talking through firewalls at both end, right?
Like there's almost, you know, you can't find somebody connecting to the internet without a firewall today, and they'd be crazy to, to do. So. Um, we've kind of seen the same when it comes to data security, you know, that there's kind of three places where data resides, right?
There's data at rest and, um, databases and, and file system. There's data and transit, you know, on the network. And then there's data and news, which is essential confidential computing, protect data transit.
You know, 10 years ago, almost nothing with H-A-T-P-S, right? It was just, you know, banks and, you know, very sensitive websites using it today. You know, you can't go to a personal blog, you can't go to a news websites without going through HT PS.
Everything is encrypted because why, why wouldn't you turn it on? It's so, so simple. And the performance impact is so low.
Uh, we see the same with this encryption. Or, you know, five years ago it was only, you know, banks and these types of organizations using it. But today, you're not gonna be able to buy a laptop without this encryption being, being turned on.
Uh, data use is the last frontier. And yet today it's going on that same path. It's being, you know, banks and healthcare organizations, governments that are using it.
These tend to be our customers today, but over time, confidential computing will just become computing. 'cause why wouldn't you use it for everything if it's essentially that simple and the performance impact is still low. On the other side of that, it seems like a lot of the bad guys are just targeting the credentials of people who work in it.
And then they're using that, they gain access to whatever they want. So if I have confidential computing, does that kind of reduce that whole threat factor? Because I'm not really worried about somebody using their credentials to go see data and, uh, in memory as it's readily available because it's all encrypted now.
This actually confide integration reduces that risk significantly. Um, and I'll, I'll give you, again, I'll use an example. I think one of the most famous examples probably is, is what happened with Edward Snowden.
Um, Edward Snow was essentially an, um, an an admin in the, the federal government. Uh, and because 'cause he was an admin, he obviously he didn't really need, again, he was there to, to manage, you know, the, the, you know, as servers we essentially do the kind of the it tasks of, of an admin, but he, he wasn't supposed to have any access to the data. The problem that we're getting is if you are an admin, if you have route access, you essentially have access to everything, all the data, all the keys, everything you, you essentially can get.
And that's, that shouldn't be the case. One of the things that confidential computing solves is exactly that. It's the, the workload itself has access to data, it needs to, to, to process.
But the admins, the, your own internal admins, the admins of the cloud, the admins of the infrastructure that you're running on don't have a, they can do their job, they can manage the, the infrastructure, but they don't have any access to the data. So now there's a lot less concern of, you know, either insider threat like the, the snowing use case or you know, somebody else getting the credentials of one of your insiders through phishing versus some other mechanism, and then using those credentials to go steal data. What is the, um, the hurdle then?
I mean, is it just a perception that it's costly or, um, is there a notion of what it was four or five years ago versus what it is today? What keeps people from kind of just going whole hog here? Yeah, it, I think, yeah, this is what we're seeing from, you know, from the more regulated ones, financial services, healthcare, manufacturing, um, oil and gas government.
They are, this is basically becoming part of their standard way of doing things. Or we're seeing is this, is, this is top of mind, you know, for, um, again, the, the large financials have been in, you know, by CTOs of, you know, the largest credit card companies. An example, this was a, a public, um, event where they're basically saying, what are our top priorities for 2020?
You know, 20 24, 20 25. And Consci Computing is there at the top. So it is coming in those organizations, I think organizations that are less security conscious or less security, you know, aware and usually are less of the target.
I think for them, it's, it's still not, you know, bubbled up to the, to the top. But again, it's, it's gonna get there the same as, you know, TLS, you know, or HT PS wasn't at the top of their list, but now everybody, they, it, if you're a CISO and you're not enabling, you know, https, you're probably not in the right T profession. I think the same thing is gonna happen with confidential computing for, for essentially for everyone.
'cause it's, it's just going to become the default. Are we also spending money elsewhere on security initiatives that we wouldn't have to spend if we had confidential computing in the first place? A hundred percent.
It's funny 'cause I think one of the best examples of this that I, I just, uh, started, uh, talking about was, I dunno if you remember, but we used to u uh, to use, you know, VPNs to be able to access our corporate email or used to, you know, to be access corporate resources. And once, you know, TLS and, you know, HTPS became more and more widespread once we started having, you know, SaaS solution, suddenly the VPN became less important. Uh, and we see a lot less of a VPN usage because you just don't need it.
Everything's encrypted, you know, from the browser all the way to the, to the server. So you don't need a VPN to connect your essentially, um, uh, internal environment to get access to resources. And, and the, the reason I'm making this point is when security is part of the infrastructure, it just simplifies a lot of things.
One, it might just makes your lives a lot simpler. Again, you can go, you know, you can send an airport and connect to your corporate email without having to, to start a VPN. You can go into your bank account without having to worry about security and privacy because everything is encrypted.
So, so it makes your life easier, but also it allows you to eliminate a lot of the complexity, A lot of the tools that we, you know, traditionally used to try to maintain security and confidential computing has that exact same effect. Uh, it essentially baked security into the infrastructure and everything is encrypted, everything is protected in use, in transit, at rest. Data is never exposed, which essentially allows you to slowly take away other security tools that we traditionally use to try to then actually solve the problem.
But just reduce the rest. Once that problem is completely solved, you can just remove all those tools that just used to reduce the rest. Mm-Hmm.
Uh, and I'll give you kind of an example where I think this is going, because when confidential computing is the default and it's, it is computing and everything is running confidential computing, you know, do we even need a firewall anymore? Do we need, you know, HTT PS anymore? Because essentially the, you know, you can take a machine, connect it to the internet, you know, no firewall, unpatched, you know, hacker probably gonna be all over it, you know, with root access.
But even with root access, you're not gonna have any access to the data. So again, you might need a, you might need to to prevent it, you know, just because of you don't wanna get the developed service, but your data is gonna be static if you're not gonna have to worry about the security of your data. And again, you know, HTTPF is another great example because if you're running in confidential computing, data is born and used when the application is up in memory, the data is protects that and then can automatically encrypt the data coming out, uh, of, of the application to the network.
So you don't really need that TLS connection anymore. You can just encrypt the data at, you know, layer seven, uh, versus lower layer five, if that makes sense. So again, I think compass computing, I guess it's a long way of saying it's going to simplify security in a very, very big way.
Like we've seen other infrastructure, um, security solutions. How much of this is a cultural issue? 'cause I sometimes think that the security people are kind of aware of confidential computing, but the IT people and the developers not so much.
I think you're touching on probably one of the most important things that are happening in security right now. And I think a lot of, uh, security vendors are seeing this. And that is basically, traditionally the CSO used to own security, right?
And they just only were able to make decision. The buying decision is deploying, you know, running things. Uh, what we're seeing now, especially with the move to the, you know, the SecOps and lot of securities shifted away from the CISO and moved to kind of the DevOps space that doesn't necessarily report to the ciso.
And what we're seeing is that you kind of see a lot of security companies becoming more, you know, observability companies, right? Where they give you is just, you know, just knowing what's broken, knowing, you know, um, uh, like, uh, all the data security, posture management essentially, that just giving you observability to what's going on, and then you have to go fix it. And that's still very easy for the CISO to buy, deploy, to manage everything, but all the prevention solutions, they don't just give you observability, don't just gonna give you kind of a map of what's wrong, but actually try to fix things.
You need consensus from both the, the CISO as well as the DevOps or the c you know, the CTO, the CIO, whoever's kind of managing the DevOps piece. And that's exactly one of the challenges that I think the entire security community is dealing with. And it's one of the things that we're seeing as well is that we need to get buy-in for both the CISO as well as the DevOps or the the CTO team.
But once you deploy something like this in place, this is actually prevention. It's more than just detection. You actually block things from happening, you know, and, and you don't need to, there's nothing to detect if you just prevent upon happening in the first place.
And how much of this, it just seems like it's human nature to me, but, um, if I'm gonna hold the DevOps team or a cloud team more accountable for security, they'll go out of their way to find solutions so that they're not gonna be called to account for it someday. Whereas if the security people are in charge of it, it's a bolt on and it never quite gets the level of traction required A hundred percent. And to sense of what's, I guess, at least from my point of view, what's happening in the space is that, you know, the, the, the DevOps team, the IT team, they wanna, or the application teams, they wanna do things and they get blocked by security because security in many cases now becoming almost like an internal regulator with the organization to say, oh, no, you can't do this because of security concerns.
The nice thing about solutions like confidential computing is that they become, that they become a neighbors, right? They, they're telling you, oh, yeah, if, if you use this, then yeah, you can go ahead and, and do this. Go ahead and move to the cloud, go ahead and, you know, do this, you know, collaboration of data, uh, that you couldn't do because before we didn't have the right solutions to do so.
Uh, I would think that, you know, that we've kind of seen a very good example of that without what happened with HashiCorp Vault. The vault was a solution that didn't come into the security teams, it actually came into the applications team. They use it to say, oh, we're using, you know, vault, so this means that we can, you know, we can do these things that we couldn't do.
We can, you know, move these to the cloud, we can do things that we couldn't do before because we're doing the right things. And their growth path was mostly to the, you know, the, the, the CTO office and the developers more so than the security team. What's your best advice to organizations about how to go and kind of embrace all this?
Because I'm sure you've seen some organizations do it. What did they do well that other people should copy? The first thing I would say is if you, if you don't know about counter computing, go and just educate yourself about confidential computing.
It, it's a huge shift that's happening in security and infrastructure. You know, I don't see the, you don't see the Apple announcement, but Apple said that everything they're gonna do on top of AI is gotta be everything under, with AI is gotta be on top of confidential computing to maintain the security and the privacy of their, of their customers. Again, this is just a huge shift that's, that's happening.
So one is go, go learn about this. The second step after that, uh, you're gonna essentially have this sort of decision to make whether or not you're going to by building on top of sing yourself or use a platform like, like Jun, which essentially it soft per stack that enables you to use this. And I would, I would argue that every time the fundamental shifts like this happened in our hardware architecture, you needed a software stack on top of it to enable it.
And maybe the best examples is, is what happened with VMware and virtualization, right? Virtualization was part of the silicon, it was part of the operating system. It wasn't invented by VMware, but what VMware did was build a software stack, just make it super simple to virtualize everything.
And that's what virtualization really took off. I would argue if you, if you're convinced confidential computing or you wanna try confidential computing, go and use one of those software stacks to make it very simple to use it. Otherwise, you're gonna go down the, you know, rabbit hole trying to change and rebuild applications for this new hardware environment, which is gonna be a very, very, very difficult task.
So I would argue go and, and look into one of those software stacks. But again, the value is just enormous and it's gonna simplify your security stack, it's gonna simplify processes, and it's gonna enable things that you just couldn't do before because of security and privacy concerns. All right, folks, you heard it here.
Hey, when it comes to security, if you think about it, it's important to distinguish that which is a symptom versus that which is a cure. And I think we're spending too much money on the symptoms. Hey Al, thanks for being on the show.
Yeah, thank you. Thanks for having me. All right.
And back to you guys in the studio.