Enterpise Password Manager – Dan Amiga, Island
Dan Amiga, Island co-founder and CTO, discusses the release of Island’s self-protection features and a new password manager natively built into Island’s enterprise browser. The new password manager helps eliminate password abuse, ensures organizational custody of corporate passwords, and embraces passwordless user authentication.
Transcript
This is techstrong tv. Uh, the great pleasure of me joined by Dan Amiga. Dan is co-founder and CTO o with Island.
Welcome, Dan. Thank you, Mitch. Pleasure to, uh, do this.
It's always fun to chat with you. Uh, before we jump into things, I know we've got some new news we wanna share with folks. Um, but tell us about yourself and tell us a little bit about Island.
Sure. So I'm based in Tel Aviv. I'm the C p O and Co-founder, so I do everything, product and engineering.
My team is over a hundred engineers now. Um, been been in this business for 20 years, or or so, started in the, uh, Israeli intelligence, uh, doing cybersecurity stuff. Um, I've been doing enterprise security for the past, uh, 15 years or so, and a lot of my work went, uh, into, um, browsers, building browsers, um, was, uh, the original inventor of, uh, remote browser isolation.
Um, my previous company, Fireglass, was acquired by Symantec, so has been doing a, I've been doing a lot of work around, uh, uh, browsers. Um, and, um, in August, 2020, uh, we, uh, um, officially started Island io together with, uh, Mike Pay, our ceo. Uh, Mike used to be the, uh, president and c o o of Symantec and before that C of McAfee.
And, um, it's been going, uh, great of power. You know, we are with Island are building, uh, the world's first enterprise browser, uh, which is, uh, um, uh, you know, just like you have Chromeo edge or, or brave or, or Safari, now you have a Bower that plays really well with the enterprise. So we baked inside a lot of the controls, like networking stack, A V P N stack, uh, D l P stack, a lot of an anti phishing and security awareness.
Um, and today we'll be talking about two, uh, two new announcements we have around the, our self-protecting browser and, and password managers. But for the, for the viewers, uh, we basically are consolidating, which is something that's required these days, right? Uh, we're consolidating and building inside, uh, two seconds installation, uh, in user mode, the entire security stack, data stack, networking stack, and productivity stack.
So our users have better controls like robotic process automation and advanced clipboard tight integration with, uh, chat G P T and a lot of, uh, AI assistant, uh, uh, tooling, uh, to have a browser that's, uh, that works better in in the enterprise. And, uh, we've been lucky. Our customers, uh, today, many of the largest and most sophisticated financial, healthcare, industrial hospital, hospitality technology pioneers of the world.
Um, and they, they've been using it either in the manage environment or B Y O D for the contractors. Very exciting times, uh, for us. I, I know I've trying to manage browser security and users throwing passwords and browsers and, you know, and then let's say password feature.
And yeah, there, there are some abilities to quote unquote managed, you know, manage your Chrome browser, you know, through the Chrome administration, but it's not really you, you have some, some abilities to kind of lock down or control a few things, but it's not really what an enterprise would require in, in a today's world. Most of our apps coming over a web browser, right? And, and even in web applications, it's coming through web browser and inside of a, a mobile app even.
Uh, talk a little bit about some of the distinct characteristics are of an enterprise browser, and then let's go into what you're announcing around self-protecting and what that means. Absolutely. So for, for Starter, we've built a, an enterprise ready policy level.
So it's easy for organizations to apply, uh, D L P rules or networking rules or security rules. And what that gives you is you can suddenly take away a lot of the investment you made or about to make in things like, uh, upstream proxies in things like, uh, D L P tools, but even a A V D I environment, if you think about that horrible experience of having, we call it the length of the wire, you have to wait for the pixels to be streamed from the cloud. Who wants that, right?
Um, you, you take that away, you take that insane cost, thousands of dollars of a VDI instance, right? Most of the access to VDI is to ss, right? Um, you can just go direct and have the enterprise base or control you.
So we're taking enterprises away from this really complicated architectural proxies and VPNs and extensions that become malicious over time. Cookies that get left on the disc, passwords that are persisted on this. Um, uh, so that's, that's the enterprise browsers is to play better with your existing IT and security stack and give you an opportunity to reduce cost.
Mm-hmm. Now, we've studied, uh, um, and, and we are really trying to, uh, um, it's not a security process. Security is a big part of it.
And one thing that we have done in, in the security world is we've carefully studied the attack landscape against, uh, against parcels, um, the, you know, the phish attacks, info Steelers, those cryptos or ransomware tools that steal your passwords, et cetera. And what we did is we have baked, uh, inside the commun, well, based on commun, which all the modern bases are, and we've worked for three years to build a large set of what we call self-protection. So when you deploy island, and you can deploy island in an environment that is fully managed, where you have security controls, or you can deploy island on an unmanaged device like your home pc or your mobile phone, right?
Or even a contract or device, which you absolutely don't cost, right? And all of a sudden that operating system, that bao becomes the operating system to access the organization, uh, SaaS applications or internal applications, the business, right? And then we've built inside things like protection from memory exploits, uh, protection from a attaching debugger, and stealing data from, uh, uh, from an active process of the browser.
We've built in things like keystroke protection. So if you already have a keystroke logo on your device, we're gonna detect that, and they're not gonna be able to grab your sensitive data. Mm-hmm.
Um, so many, many, many protections that did not exist in the, uh, chromium stack, because the chum stack is meant to be built for 6 billion users all over the world, right? Um, not for your enterprise healthcare, your enterprise financials, right? So we had to build all of that.
And when you deploy island, you don't need to deploy any other tools. And the browser itself has all of the protection mechanisms to make sure that data isn't exfiltrated, um, and, uh, uh, um, and organizations can trust users to do the work on the on, on island. It seems like one of the unique or distinct characteristics to Dan is, you know, in a, in a regular Chrome world, or pick your favorite browser, you're trying to manage all these extensions, right?
Here's my V P N extension for the browser. Here's the one for the password manager, here's one for, or AD or malware or data protection. Or, or, or, or, right?
And so you're, you're trying to manage this collection of add-ons, many of which are not really meant to be, they don't know about each other. They're not really great to try to manage 'em on an enterprise level, and you end up with this kind of Lego, but it doesn't look like a really nice thing that you built, and it's really hard to run. But here, I think what you've done in island is you've kind of taken that all away and say, here is everything in it integrated together, and you can manage it at an enterprise level, um, and, and custom customize it, manage it to, to your security policies and also the technologies that I'm using.
Am I, am I on track? No, absolutely. And, and I have a, I have a story I always like to use.
Uh, the, um, so you know what a very popular extension these days, usually bef, usually before big sport events. So an NBA playoff tracker would be a very popular Mouser extension, right? Mm-hmm.
A World Cup before, uh, the, the World Cup in, in, in Qatar, right? That becomes really, really, really, uh, uh, popular. And then what happens is over time, those extensions inject malicious code inside.
Right? Now, those extensions is a, is a chicken and an egg, uh, story. Uh, the CU opensource sps, they wanna limit the permissions of what extensions can do, right?
But it's such a big marketplace, it's gonna, it's gonna damage the marketplace so they can, they can do it. So what part of our self-protection is we've built what we call an extension guard. So users can use whatever extension they want.
That extension does not have access to your, the, your sales force. It doesn't have access to your Office 365, right? There is no cookie access to cookies or network.
Definitely extensions is a big part of the story. Now, the other thing is it's also an enablement play. So now organizations can be more, more, uh, liberating in, in, in just giving users the ability to install more extensions mm-hmm.
When they know they're being protected, Right? Because I mean, today is sort of wild, wild west who can download any extension you want to the degree of limited that, and we all know every one of those are highly secure with great sarcasm. I say that I Great sarcasm.
And so even if they do that, you've kind of put this walled garden around them to say, okay, download the a, ESPN N N B A, you know, major league baseball, whatever you want to do, or, you know, betting thing or whatever that is that you wanna download for an extension. And if that's kind of in its own kind of protected space, at least protect, protecting everything else et Correct. Would normally be able to get to Correct, correct.
O it has to approve which each one of those, right? Mm-hmm. And then it is, and then, and then it's a nightmare for them.
How do they know? And, and they change over time. They update.
So we take, we take that hurdle away. Exactly. Okay.
Interesting. So, so I mentioned earlier the, one of the banes of my existence is That's okay. I just, I just saved my passwords in the browser.
Well, thank you very much cuz it never asks you to, you know, reauthenticate and, and anybody sits down at your computer now, they've got your browser now that's synced across all your devices and you lose your phone or whatever it is. Like, it's, it's just a big scary mess. So I, I always discourage, or, or you know, disabled, but, you know, saving passwords in the browser, there are password managers that are offered as an extension, but you're launching something different, different.
Tell us about password and password management in, in Ireland. Yes. So, so first let's start with, um, whenever user logs into a website, right?
Those two things that are, uh, uh, critical or an organization. One is to make sure the password isn't being leaked and stolen and then it can be reused. And the second thing is post authentication.
The website issues for years and years. A cookie that proves that you've been authenticated in the previous module that we launch our self-protection browser, right? We have what we call cookie protection.
We make sure the cookies are encrypted in memory, we make sure the cookies are encrypted on disk. We make sure that when they're transferred over the network, it's a secure encrypted connection. There's no men in the middle.
That, that was a big issue for a lot of organizations. It prevented them from, um, you know, allowing users to access their Office 365 email. Cause it doesn't matter what security controls you put in, somebody steals the pa the cookie, it's game open.
Then over the last three years, as I said, we, you know, deployed this browser. Many, many, many different customers. And, and one of the feedbacks that we get is, you know, can you guys build a password manager for us?
But not the built the built-in one that's in chromium. Why would we have to buy another one if you guys can build it inside Ivan? So we took a close look, password managers are really important security tool, but they're only as secure as the bars on the device they're being used on.
Mm-hmm. Right? So most password managers are deployed as a browser or extension.
They do not act in the context of the enterprise. So what we have done is, instead of building an extension that's easy to disable, it's easy to steal the passwords from disk, right? We've built something that's an enterprise grade, and what it means is, uh, we take care of everything for making sure that when you type in your password, the device is in a safe location, the device poster is safe, the connection to the website is secure, the passwords are not being saved locally unencrypted or encrypted with simple encrypt encryption mechanisms.
You think about your, uh, standard browsers, where did they take the key to encrypt the password on this? They took it from the context of the user, but now if you have a malware that's running in that context, it's easy to steal the passwords, right? So what we do is we use, uh, uh, a zero proof knowledge mechanism, uh, where we, we and as island never see the passwords, they're being encrypted on disk.
There's a, there's a very strong public encryption, uh, that happens, uh, uh, uh, on pub public private key encryption that happens on disk. Um, and we make sure the device is in a safe state. Now, when you build it into the core of commun, it's the user experience is better.
It integrates well with, uh, the browser windows. It integrates, uh, better than an extension with filling in your username and password. And we control the entire security, uh, security stack.
We understand where you are when you're typing your password, what wifi you are connecting to when you're typing your password, where is that persisted? Are you allowed to persisted? Right?
And, and, and those capabilities really provide what, what we think is really the first secure, um, uh, password manager for enterprises. And, uh, um, we're really excited. We already have, uh, quite a lot of customers, uh, in beta and today we are releasing it, uh, uh, to the world as, as as a new module on the island platform.
And, and you mentioned context earlier, it sounds, seems to me that's one of the big missing elements through any kind of extension, but particular, particular password managers, they don't know if you're sitting in the tire shop and you know, down the street or you're working from your home office or you're in the, you know, where you should be or maybe a place you shouldn't be. Maybe we don't want you logging into s a p in the middle of, uh, you know, on a subway train somewhere, don't Share or just, I dunno if you could do that, but Oh, oh, no, you can. Or, or sharing your password.
Mm-hmm. You know, password sharing, password sharing is a big thing for, uh, for enterprises. Who do you share your password with, right?
How do you share it on what device are you sharing it with? How do you, how do you, so all of all of do, do you have, do, do you have, uh, uh, did you step away from your computer for five minutes? Who take care, who takes care of blocking it?
Uh, once, once, uh, you do it, do you have a, an already remote access version that is recording the screen or recording your keystrokes? Who protects that password from being clicked, right? Yeah.
So it's kind of like a 360, uh, uh, degrees approach. The other thing is, um, the web is moving to, uh, new standards and is going password list. Mm-hmm.
Right? So we're already supporting the new standards, like, uh, the organization MFA and pesky and biometric authentication. Uh, so think about it as an end-to-end, uh, uh, solution.
You can use it in the enterprise and you and end users can also take it to their B Y O D, right? And then by policy we'll say, Hey, well you can use that password on your B Y O D device, but you cannot use that. You cannot use the organization business password on the B Y O D uh, uh, device.
So context is, is a big, is is definitely a big thing. Yeah. Interesting.
Yeah. Apple just had their announcement of safari and the next iOS, or excuse me, Mac OS and iOS support for that, Google's now promoting that. So certainly the, that's one of the waves of the future to help us not have to use passwords for everything.
Uh, I wanna explore one thing because ultimately there's a lot to security, but one of the most challenging aspects is the user experience. Because anything gets in the way end users will try to bypass it, right? They've got work to do.
And, and so if, if the, um, filling in the password for you in, in logging into something conflicts with the view the password button or the pass password that's saved in the browser, all these things are kind of fighting for that space in the password field. And sometimes it's unusable. I mean, it is just literally, you know, the, the browser's pa popping up, its save passwords, your password's manager popping up.
Yeah. That, that's a terrible experience. Talk about, I'm gonna bypass all that and do something that's like not secure.
How is integrating it the way you have into the browser get past some of those user experience challenges? So first I'd say in Ireland, the, um, um, maybe the first phrase on our first day was the most important thing in our business in cybersecurity in it is the end user experience. The number one thing, and specifically for the, and, and, and it means the buzzer is one faster.
It means the more tools you consolidate, the experience is better. Um, I like to call it, uh, there there is no step two, you install island, you don't need to do anything else. There is no step to, so with password managers, you are absolutely right, Mitch, when the, the, the, there's a, there's an existing password manager that's very consumerish in chromium, then you have another password manager, then sometimes both of them don't detect the right username field.
Cause the website author didn't implement the right style. It's an S right? So what what we have done is we, um, um, we have great respect for the Corum code base and we used all of the, all of the knowledge that goes into the chromium code base.
Um, but we have, we have uh, uh, built the user experience, the detection of capabilities, um, in the heart of the browser. So we took those problems of, uh, mis dependencies and misunderstandings and we worked on them. Uh, and, and actually a little look behind the scenes, the team that has spelled the password manager in Ireland, it was a joint effort between the security team and the user experience team, right?
Mm-hmm. So we definitely, definitely a, a big, a big issue. There's other, there's other issues.
If you think about from an enterprise level, um, users, you know, they would use, they would try to use the uh, um, the easiest password that, that is still complex enough, right? So you gotta take care of that. Then you have users using passwords that are already leaked to the dark web, right?
We gotta, we gotta notify the organization on that, right? Um, uh, so there's, there is, there are, there are definitely a lot of, uh, and, and those phish attacks. I can ask you for your password on something that looks exactly like office, office 365.
Mm-hmm. Right? Um, so, so we take care of the, the management, the administration, the dark web leakage, the user experience, the anti phishing, uh, is, is a very, uh, um, end to end approach.
Well, fantastic. Um, I'd love to dig into this sometime and experience it myself. Uh, where can folks do that?
Is this available today with the announcement? io and say, Hey, sign me up. I want to give this spin or help me with what would be best for my environment?
How does it work if somebody wants to engage with you? Absolutely. So the, the password manager, uh, is being released today.
So customers, uh, that enjoyed it in data, uh, can keep on using it, uh, in uh, release mode. And anybody that's interesting, just ping us on the website. Um, and, uh, we'll be happy to set up a, a demo and, uh, and show you the, uh, um, you know, what I think is, as I said, very appropriate today, the con drive, cost down, consolidate, uh, improve the user experience.
We have quite a lot of other modules we haven't discussed, uh, uh, today. Uh, we're happy to show you, uh, the platform and how you can activate uh, uh, the possible manager module. Fantastic.
Well, Dan, thank you. So always a pleasure talking with you and look forward to more exciting great stuff. We want you can come back and share more about what some of those other modules are.
And Next time is ice cream. Is Ice cream, okay. Alright, sounds very good.
io. There's some great people behind it, Dan and, uh, and the team. And I think I'm making some really great inroads and what we might think is just a common everyday thing.
We all use browsers now. If you're gonna do a secure browser, again, I'm doing an enterprise secure browser, takes a much different approach and, and silent seems to be on a good path for that. io.
Thank you, Mitch. Bye-bye.