Decentralized Identity – Eve Maler, ForgeRock
Eve Maler, ForgeRock CTO, discusses why decentralized digital IDs are gaining traction. Eve explores the evolution of decentralized identity, including challenges to adoption, real-world use cases, the evolving regulatory landscape as well as how to design a decentralized digital identity system that is both secure and user-friendly.
Transcript
This is Techstrong tv. The great pleasure being joined by Eve Mailer. Eve is CT O with for Rock.
Welcome Eve. Great to be here. Thanks.
Great to have you here. You know, it's, it's uh, tight for rock and talking about, uh, digital identities. We were both just chatting a little bit earlier about, uh, you know, identity's not a new thing and digital certificates of something.
We both have had our hands in to varying degrees and been around for a long time, but things are kinda changing and evolving. Right. We still, of course have digital certificates and use and Yes.
You know, I don't think they're going away anytime soon. Not anytime soon. Yeah, for sure.
But I think maybe the thinking around identity is starting to evolve. And I know you, one of the things that you are focused on is around this idea of, of, uh, distributed identities. Is that the right term?
Yeah, distributed, decentralized. It's got some other decentralized nicknames, which we can get into. Um, but yeah, I mean, you know, certificates obviously have formed a substrate, a very important substrate for things that have been built up over the last couple of decades.
You know, centralized identity and access management, having a repository and recording people's kind of profiles. And then we entered into the era of federated identity. So thinking about cross domain, single sign-on, which was a major innovation 23 years ago.
I was actually first chair of the SAML group, if you know, who were you, right? Security assertion. Oh yes, yes.
Markup language. Oh my. And I always joke that the funny thing is SAML doesn't have an eye in it cuz we didn't really talk about identity.
We talked about security and directory and certificates and things like that. And, and all that's really important to the ultimate solutions. We've taken things far enough that we can now kind of outsource authentication through this notion of single sign-on and federated identity.
And that's taken us pretty far. It's a very centralized approach. And as people have gotten more and more privacy sensitive, um, and more kind of cottoning onto, oh, I don't know, cryptocurrency, when people say crypto now you have to ask which one they mean.
Mm-hmm. Um, it's, it's brought together some new opportunities for solutions which are able to put identity information. So maybe username, maybe email address, maybe lots more information on the edge, like for example, on a smart mobile device.
Um, and then have it be free attested to by somebody who actually knows real information about you. And then you can kind of be in charge of handing that to services when you go and visit them. Almost putting more power back into the end user or the individual's hands.
It's not just on some, you know, a certificate authority somewhere, said somewhere that this is a valid device, person, server, et cetera. Mm-hmm. More thinking about it from whose data it is and then Attaching.
That's right. Yeah. And I've, we've certainly seen the number of privacy regulations, you know, the world over GDPR and all of its cousins, things like that, that have influenced the thinking.
Um, and, and this really started actually even a little bit before GDPR in the era where people are just sort of fed up with filling in web forms over and over. Mm-hmm. And then people running the services going, you know, what kind of data did I just get?
Is this person really at, you know, 1 23, Mickey Mouse Lane? That sort of thing. Mm-hmm.
So there might be a nice confluence of interest here with services able to get good quality data and people being able to choose when to actually share it and actually when to unshare it as well. Yeah. There, there's also of course the big, um, how do we get away from passwords and Oh yeah.
As well as our, you know, our own identity. And at one point we're all supposed to get a digital certificate for ourself and Mm-hmm. You know, that kinda knew not that far towards solving the problem.
It's, It's easy to hate passwords and it's been easy to hate passwords since pretty much they were invented. Um, and, and there's good reason not to like passwords. Right.
You know, I was just mentioning to you, we, we publish a, an annual identity breach report and, you know, passwords are this huge vector for a lot of these breaches. And unauthorized access writ large is, is the major cause of a lot of these breaches. And so if you can find a way to use the other factors and use things cleverly and use multiple other factors, you can get to a passwordless world that's becoming more and more possible today.
Um, and we actually see this decentralized identity world possibly playing a really big role in getting us to, to next gen passwordless, if you will, because where you put the data when I said you put it on the edge, you know, here's where I wave my phone. Mm-hmm. If you can put it somewhere on the edge, then, um, you have the opportunity to have people unlock their phones, unlock a special app, which is getting to be called a digital identity wallet.
And that wallet is what holds the information. And the wallet can actually be in charge of logging you in with a, with, with a much better experience without compromising security and, and hopefully privacy as well as, as we've started to discuss. Mm-hmm.
You know, I I, I'm still kind of getting over, when you said federated identities, I remember trying to explain that to my lawyer team that, oh no, this is not an antitrust issue. This is like identities totally different kinda federation than No, I mean it's interesting because, you know, federating identity, where you've got, you know, we call it a relying party and that's some service that relies on an identity provider. The big question is, can I actually outsource liability?
What does that look like? Mm-hmm. So, you know, there's the technology which we've had available for a long time, and then there's the business trust questions, which mm-hmm.
You know, have sometimes prevented us from doing more like transferring attributes that the identity provider knows about me. So decentralized identity is actually sort of making another run at it, doing it a different way by using the user as the kind of conduit for that information. Um, I'm really curious, tell me a little bit about the, for direct perspective of what, what brings customers to you?
Usually there's a two or three sets of problems that commonly come to a, you know, a technology provider and, you know, and lot and oftentimes it's a very common one that people run into. Yeah, yeah. Sort of those use cases that you see most often.
So enterprises, um, and, and particularly large enterprises have challenges when they have, um, either consumer populations or they might have their workforce population where they've just collected too many applications for which they've implemented user management. Mm-hmm. And they've got silos.
And it's either preventing business, preventing upsell, preventing engaging with customers better, or it's preventing a really hard look at security for their workforce and for their partners. And so they're trying to get away from that, what I think of as application by application user management and get onto, um, kind of a higher maturity basis for, uh, registering users, onboarding employees, um, authenticating those users strongly and in a way that they can kind of swallow. Mm-hmm.
And we can talk more about passwordless. Mm-hmm. Cause that's something that really is here now.
Um, and looking at the entire cost risk, value equation and, and kind of injecting digital identity into all of it. People think of identity as kind of a login box these days, right. And it's easy when you have a lot of passwords in your life.
I'm starting to think of it as the cardiovascular system for any connected enterprise, for the connected world. Uh, so that, that's the kind of problems that we're solving for customers is, is, um, unifying these silos, making it efficient to get people using their systems and to identify those users to make the experience not just pleasant, but kind of really make it sing. Um, and, and really to, uh, provide the backing.
Uh, for example, there's new standards in authentication like the Fido standards mm-hmm. Fast identity online where you can really start to implement these things in a, in a lot easier way if you have an expert IAM solution behind you. Cuz this's what we do all day long Ex Exactly.
I think as much of as we've gotten digital in all parts of our work, essentially all parts, um mm-hmm. Yes. There's internal systems, so many more external systems and SaaS and single, single signup clearly helps with that.
But one of the big complaints I hear from end users is authe and authenticator apps and texting codes and backup codes and what is all this stuff, right? I I'm just trying Oh gosh. To get my job done in accounting.
Right. That's Yeah, totally. I'm Trying to enable work, but, And, and what we do to workers is really often not very nice.
Like, you know, we, we sort of enable poorer experiences to be shown in front of employees then that we can get away with for, for consumers, right? Mm-hmm. Mm-hmm.
Um, and so that's really why I think the Fido standards have become so important. Um, and this is where they, they leverage something you have and something you are typically, so you can do like a local phone unlocked to start that experience. Um, and it really gives you a multifactor strong authentication and increasingly in a passwordless way and increasingly in a way that doesn't even mind so much if you lose your phone.
Because if you've heard of pass keys, very popular topic these days, that comes from Fido and it's this approach that can really bring multi-device credentials. So for web and mobile, we're starting to get some solutions locked in as long as the implementation sort of can be trusted. Um, now when it comes to employees, they interact with VPNs and remote desktop software and all kinds of environments, legacy mainframes, databases where it's not so easy.
It's not just sort of a web mobile, Hey, let's stick Fido in here. Uh, we actually have a solution, um, that we call enterprise connect passwordless for that as well to kind of like take the pain and the toil out of, um, you can't necessarily eliminate the passwords, but you can give a fully passwordless experience. So these, these things are definitely possible.
Yeah. Almost like a, I'm in my enterprise session now, I can go use the tools and applications mm-hmm. Normally would use without feeling like I'm in living in a world of SaaS applications that are all you Yeah.
Secure. Yeah, exactly. SAS applications that, you know, none of which know about each other.
That's, that's the sad part. So speaking about passkey, do you think, I mean Apple just announced in next version of their os they're gonna be supporting that on both iOS and MAC os, I believe. Um, do, do you see that as being sort of a big thing that if people will be adopting it sounds like a much better User Experience?
I really see people adopting it. In fact, I've had consumer experiences apart from any work conversations or work interactions where they've offered me pass keys. I use a password manager that offers, that is a passkey provider.
So if you think I was talking about identity providers, being a passkey provider is kind of the same level of seriousness. And we know Apple is, we know Google is. Um, and, and we're starting to see these, I'll call them third party, uh, passkey providers.
And I think that's exciting for the, you know, an ecosystem of, um, making passwordless attractive so that people adopt it on their own. Like, can you imagine rolling out a new IT program where you don't have to do any convincing, you don't have to sort of buy off any user groups. They just want it.
This is where I think we're, we're really going. And, um, that's, it's, it's enabled in, I mean, we already do support paske, uh, iOS PAs keys in the ForgeRock platform. Mm-hmm.
So it's, it's, they've made it that easy and, and having Fido support, um, be before you show up, uh, to the passkey conversation definitely helps. I dunno how often security people get standing ovations when they're rolling out new stuff. But maybe passkey is that that event, Right?
I think so. I mean, I, it's, it's been 20 years that I've sat next to people on a plane who are not technical and they say, so what do you do? And I'm like, Hmm.
Yeah. And the conversation always still goes to passwords and just how much people hate them. And I, I, I don't blame them.
I do too. Well Eve, it's been a great pleasure. Uh, tell us a little bit more about the report, um, and then also where we can get ahold of that.
Absolutely. com, forge Rock. Sounds like two words.
The rock in the name is not an accident. I see those guitars on the wall. Um, yeah.
And, uh, it's the Identity Breach Report and it's our 2023 edition, our fifth annual. Very nice. And, uh, we hope that'll help people out.
It's nice. Always nice having some continuity of multiple reports cuz you can see some trends and what's changing, what's what's Exactly, et Cetera, so. Exactly right.
Excited To check that out. So folks, be sure to check out, uh, that report and also if we're rock and the great things, uh, that you have to offer working with enterprises and identity, uh, whether it's centralized or, or it's decentralized Or decentralized, et cetera. All of the above.
Well, thank you so much, Eve. Great. It's a great pleasure talking with you.
Look forward to you coming back again. It was a pleasure, Mitch.