Eliminating the Need for Passwords – Paul Trulove, SecureAuth
SecureAuth CEO Paul Trulove discusses the path toward eliminating the need for passwords to access IT infrastructure.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Paul true love who's the CEO for secure op, and they have a launched our culex, which is a product that enables you to manage access to infrastructure without having to rely on passwords. So it looks like we're moving home ball forward as they say Paul. Welcome the show.
Thank you. Glad to be here appreciate the time. So walk us through how is that we can get past using passwords to access infrastructure because you know, frankly Society has been relying on passwords since the first caveman grunted who goes there.
So what exactly are we doing here? And what's changing? Yeah, it's a it's an interesting Journey that we've been on in some ways.
We've been talking about passwordless, you know for probably 10 years plus I think the key. Change that has to to occur is organizations have to embrace a passwordless authentication framework, you know as a reality and and something that cannot only replace the utilization of passwords, but maybe more importantly do a better job than passwords could ever do at you know, simplifying the user experience of authentication and improving, you know security not just to the core infrastructure but really to any application or data store that a user might try to gain access to so, you know, I think what what is beginning to happen is the bow wave, you know of interest because the technology is advancing to a point where people can have confidence without leveraging passwords is one of the authentication methodologies that they're using and and you know, maybe before I hand it back to you all I'll make one other comment, you know, one of the challenges I think people have with with passwordless is many times the authentic. And journey might start out as a passwordless journey, but revert in an Adaptive authentication mindset to ultimately add a password back in you know, when when another authentication method isn't isn't either working or is it providing a sufficient level of assurance and so in unfortunately, I think a lot of people on the journey to password List have ultimately put passwords back into that adaptive flow and and created the same scenario that we're in today, which is passwords are still, you know, part of the authentication framework, you know and fabric for most organizations.
How hard is it to make this transition what's involved? What do I have to set up? Because I think a lot of people are just intimidated by the whole process.
So they're kind of like well, we have passwords and that's what we know how to use but how do I get from point A to point B? Yeah, I think if you you know think of it in a very simple framework of people process and Technology the technology in this case, I actually think is the easiest part their Solutions like what secure off recently announced GA around archulics that provide the technology piece and and that's a pretty straightforward implementation for most organizations, whether they're implementing it for their their Workforce. They're you know, B2B partners and supply chain or you know, they're consumers and citizens what really has to change in order for us to accelerate this paradigm shift is the people and the process so organizations internally have to get comfortable with an authentication process that does not rely on passwords that replaces password with other authentication mechanisms that are then implemented through the technology and maybe most importantly we have to get people comfortable with this this Evolution on both sides of the equation as a user.
I have to become comfortable. All that when I don't see a prompt for a username and a password. That I'm still securely authenticating and logging into you know, the underlying application or infrastructure, you know, or data storage accounts and on the you know, the the company side I have to get comfortable that while I may not be prompting for those same authentication factors that you know have historically at least serve me, you know to a to a certain point, you know, I'm actually increasing the security of My overall, you know authentication methodology is part of that transition.
So, you know, if you just go back to that that Triad of people process and Technology, I think in in most cases technology isn't really the barrier. We're we now have technology that can serve this need. It's really getting the people in the process aligned so that we can embrace it more holistically.
One of the dirty little secrets of it is that it people create back doors into infrastructure all the time because you know, well, they're just generally lazy and looking for a way to make things a little bit simpler for them. But the bad guys know about this and start hacking into those back doors. So can we eliminate the need for people creating these back doors in the first place if we go passwordless?
I don't want to Salt any of the it professionals that are that are hopefully listening to this today. But you know, I I would acknowledge that continues to be an issue that we see, you know, crop up from time to time and ultimately the goal should be to eliminate, you know, all of those Legacy methodologies, you know, that that users regardless of whether they are a standard user or a privilege user, you know used to gain access into the infrastructure. So if I universally replace that architecture with a password list infrastructure as my you know, primary authentication mechanism, you know, then we can eliminate a lot of those those back doors is as you referenced but it's not it's not again, I you have to go back to people and process more than just technology you have to be willing to say the only approved authentication methodology in this organization for this infrastructure or this application is the passwordless technology and therefore everything else.
Going to be shut off and eliminated. Should we basically assume that usernames and passwords are on the dark web. I mean, it seems like credentials have been stolen left right and Center.
So are we at a point now? We're just doesn't make any sense to keep using username and passwords as our methodology because frankly it's all compromised anyway. I think it's it's a very fair statement and whether it is already compromised or easily compromised, you know is is essentially one in the same.
I think if you look at the account take over a tax, you know that we continue to see I know you know, whether it's it's at a work level or personal level. I get all kinds of emails I get texts I get, you know a variety of different attack mechanisms hitting you know me every day trying to gain access by having me share something that can then be utilized, you know to act on my behalf as a you know, malicious malicious attacker. And so I think as long as that continues to be true and and there's no indication that it will ever go away moving to a methodology where you get Beyond just something I know.
That can easily be captured and shared and then reused to you know to emulate me as a person to something, you know, I either have or an activity based on Biometrics or other types of data. Then that's much harder to emulate and much harder to share, you know on the dark web as a attack takeover paradigm. There doesn't seem to be anything such as perfect security.
So people are working the way around multi-factor authentication, but then guess the goal here is just to raise the bar. I mean, I don't think we're promising people that everything will be innately secure just because they shifted to a passwordless approach. Correct.
I I think anybody that would issue a you know, a unanimous perspective that you know, whatever they're doing is 100% secure and could never be hacked is just asking for trouble. You know, what what we have to think about as we look to you know, protect sensitive data and other assets inside or outside of an organization, you know is is what can we do to reduce the likelihood that someone who should not have access can gain access, you know, either today or take over systems and and in most organizations that requires a layered approach to security and authentication, you know is is one of the first places organizations, you know need to to implement and and I think over the course of the next several years we need to to advance the Paradigm for authentication, you know forward by a couple of generations, but behind that you have to have other other, you know systems as fall back and it's one of the reasons that is we look at Changing the way that authentication works. One of the things that we want to do is we want to bring in other data elements around security that we can leverage in order to get a better understanding of what's really happening.
And so it's one of the reasons that our risk engine is such an important part of how we view this evolution of authentication so that we're not just looking at you know, a simple username and password as an authentication Factor. We're looking at a variety of data, we're pattern matching against, you know normal activities that a user does relative to their peer set relative to themselves. And if we see an anomaly then we can begin to step up authentication or in the context of continuous authentication.
We can actually remove that person, you know from the system temporarily until we can ask them to reauthenticate in a way that they give the proper level of assurance given an increased risk factor that may have entered the system. All right. So if I'm suddenly logging in from Venezuela, and I've never been to Venezuela, you'll recognize that right recognize that and ask for for more information around who you are in order to, you know, bring the level of assurance up to the the appropriate risk level before we let you continue or if all of a sudden we see another login on your same credentials, you know from Halfway Around the World then we can you know, what we want to be able to do eventually is cancel both of those sessions and ask the users to re-authenticate and if we do that at the at the right level only what only the real person should be able to get back in.
How hard is it to set this whole thing up? I mean do I draw a line in the sand and say from here on out? We're going to use this or can I go back into all my legacy infrastructure and switch out the passwords for this approach?
so it it all it really is a you know crawl walk run type of model. You don't have to in order to start taking advantage of a passwordless authentication mindset. You can decide where you want to start and and how why you want that to reach within your organization.
So we see a lot of you know companies start with A specific group of users, you know, for example, we've got we've got an opportunity that we're looking at now where Mac users are the the place that that organization is struggling the most because they, you know, the Mac operating system is just fundamentally different than you know, the majority their environment and so we're going to help them Implement a passwordless authentication framework for those Mac users. And then once that's in place we can step into the other, you know Computing systems whether that is a Windows environment or you know, true virtual Computing environment and you can do the same thing from an application perspective. One of the things that we believe is very important and we've designed our arcules product to support this is not having to replace all of your existing, you know.
Identity IDP infrastructure in order to take advantage of a new authentication mindset and so, you know being able to layer authentication over a variety of idps without having to swap out all of that, you know infrastructure which for most organizations is where the heavy lift would really happen, you know, this allows you to start down a passwordless journey on each authentication provider or each each identity provider, you know on a stepwise basis so you can you can shift a portion of your infrastructure portion of your applications, you know also a portion of your users and kind of you know crawl walk run your way into moving to you know, a true passwordless Journey for the entire Enterprise. Now this platform is based on technology you guys acquired. So where do we go from here?
What's next? It's correct. We made an acquisition last October of a company called accepto and and they were really leading in you know, driving a Next Generation authentication Paradigm based on you know, we're risk engine that that is a heavy, you know, or heavily leverages Ai and ml as part of that process so that the the announcement that we made today is really gaing a rebranded version of that with you know, some important enhancements as as we've come to Market what's next is is continuing to build out that platform.
You know, it's one of those things in in technology especially and I didn't access management, you know, the work is never done. So one of the things that we are prioritizing very high is, you know, the the orchestration capabilities so that you know, we recognize that every organization implementing an authentication platform may want to tune it to be slightly different based on their you know, whether it's Workforce whether it's you know, Partners outside the organization whether it's consumers. And that can be one of the areas that that organizations spend a lot of time and money time and money customizing and so what we want to do is get people out of that customization mindset into a configuration mindset, you know where they're really using it a low code or no code, you know platform to define the the user Journeys that they want their authentication, you know past the follow without having to go in and build and hard code a lot of policies and and other things, you know, in order to implement that that very ability for for each of their user populations each of their infrastructure application targets and you know, you look at that on a company by a company basis.
There's you know, tremendous amount of differences in the way people will Implement so that that's a that's a big area and a big push for us over the course of the next several months. What is the biggest challenge in getting people to make this transition is it simple inertia is that people just assume that everything has a username password or is there a technical challenge? I think it's primarily inertia right now.
The technical challenges are being solved, you know, and and like I said earlier people in process tend to be the things that sometimes are harder to change in in a line of business. And so, you know getting the technical team on board that this is a, you know, a safe and effective approach to securing corporate assets can be done fairly easily getting the business to change the way that a user, you know works and interacts with the system that can be, you know, a little bit longer longer discussion and then get getting people comfortable that you know, the changes that are being rolled out still provide them the Safety and Security that they're looking for, you know in their digital lives is you know, that that third important element. So a lot of this comes back that comes down to you know Education and Training of the popular user populations and the people behind the scenes, you know, that that are supporting the technology Who's taking the lead on this?
Is that the security team or is it more likely to be an internal it team? That's just sick and tired of dealing with password username changes and updates. So I would say all of the above and more.
Historically, you know authentication and access management, you know tended to be a very operational, you know side of of an IT organization. As the digital transformation of most Enterprises has accelerated, you know, that's come squarely into the you know, the siso or head of Securities, you know frame frame of mind and in the way that they think on a day to day basis, but importantly we're also starting to see a shift where business is pushing an agenda here as well. I talked to a client recently that said one of the reasons that they are moving on this today is they are looking at Next Generation authentication as a way to simplify their employee experience.
And ultimately improve retention and recruiting efforts. So if you think about especially a you know, an employee that has high levels of access to a lot of different systems. They may have to reauthenticate dozens and dozens of times a day.
And that that is Weighing on jobsatisfaction. It's Weighing on, you know, employee recruiting efforts, you know to bring new people into the the Enterprise that maybe aren't used to security being forced upon them like older generations of workers, but want to you know, what to feel safe and secure without having that that heavy pressure. You know, that that we I think a lot of us have been in business a long time have become accustomed to so that that line of business Coming into the conversation supporting what security wants to do supporting with the operations team want to do but really helping them think about it a little bit differently is beginning to change the conversation.
I think in a very important way. All right, folks. You heard it here.
The next time somebody wants you to change a username and password. There's just a better way to think about it. Hey Paul.
Thanks for being on the show Absolutely appreciate the time. Thanks and now back to you guys in the studio.