JumpCloud Password Manager – Antoine Jebara, JumpCloud
The release of JumpCloud Password Manager relies on a decentralized architecture that is a hybrid between a cloud-based password manager and an offline password manager. This approach minimizes security risk by keeping credentials stored locally on user devices and by syncing vaults between devices through JumpCloud servers in an end-to-end encrypted way.
Transcript
This is texturing TV. Hey everyone, welcome back to techstruck TV. I've got a first-time guest here on Tech strong TV with us.
His name is Antwan. Jabbara. And Antoine is with jumpcloud.
He's gonna tell us about John Cloud. But before we talk about jumpcloud, let's welcome and here a little bit about who is Antoine. How are you and welcome to text drug TV?
Hi Alan. Thank you for having me on. It's a pleasure to have you on here.
We always like to have new people new faces new ideas coming on the show Anton. I mentioned you're a jumpcloud. But before we talk about jean-cloud, let's hear a little bit of your story.
So I'm I co-founded the company called Mikey they used to do password management specifically decentralized password management and over the past year. We sold the business to jumpcloud and I joined jumpcloud as a co-founder and as the GM of our MSP business. excellent So you mentioned decentralized well before we get it called that thought for one second bigger story.
I we've had folks from jumpcloud usually Greg. A chief strategy officer from jumpcloud, but for people who are familiar with jumpcloud. Why don't you give them a little just a quick kind of overview of jumpcloud.
So enjoy jumpcloud is an open directory platform what that means is that we centralized identity access and device management capabilities in one unified admin console for admins to be able to manage all of the different facets of these three pillars regardless of the operating system underlying operating system of the device of the authentication mechanism required to any application. We like to think that with jumpcloud users authenticate into jumpcloud and jumped out takes care of the rest. excellent and then you mentioned you know, the Special Sauce in your password solution was a decentralized password solution.
Why don't you you know for people in our audience, maybe hard not familiar with the term or not. Sure. Why don't you explain what you mean by that?
So traditionally you've had two types of password Management Solutions offline password managers that stored the information locally on one user device and users unlock this Vault with a master password that they created man and remember And on the other side of the spectrum you have cloud-based password managers that did the same but stored that vault in the cloud. The disadvantage of offline password managers is that you can't choose them on multiple devices easily. They're not really fit for Enterprise use cases.
So we'll just drop them in the context of this conversation, which is more enterprise-focused because jumpcloud offers an Enterprise password management solution. Now, if we focus on cloud-based password managers, here's a ton of convenience in there users are able to access passwords across devices Enterprise use cases exists. So centralized management centralized other thing all of the stuff that you expect but we still rely on users to create manage and remember and master password.
And as we all know users tend to be the weak Link in a security strategy and relying on users to be in charge of the keys is not the best idea and that leads to issues in general because passwords if passwords if Master passwords or week or reuse they can easily be guest or root forest and also in the edge case where the service provider or the password manager gets compromised and hackers are able to exfiltrate encrypted. Words then users that had weak Master passwords will see their results be decrypted much faster than the volts of users that have created strong and unique Master passwords. So that's the traditional bucket at jumpcloud.
We've created a hybrid between an offline password manager and a cloud-based password manager and we call it decentralized because the password manager stores passwords locally on users devices, but things these passwords between different users and devices in an end-to-end encrypted way through jumpcloud servers what that allows us to do is get rid of the concept of a master password because the keys used to encrypt these passwords at rest and the passwords that are being transmitted to other devices are now stored on the devices specifically in the Secure Storage units the key chain the windows credential manager or the Android key store. So for user they unlock their computer in the morning use A biometric or a simple PIN to unlock the password manager and that's it. It's the same level of convenience as a cloud-based password manager.
So you have Enterprise use cases centralized management centralized other team a Multi-Device access for end users sharing between different users and departments within or teams within the first organizations. But you get the benefits of getting rid of the password master password and the passwords get being stored across users devices as opposed to all the vaults being managed by jumpcloud. Excellent.
Excellent. Look Antoine is we sit here today. I don't have to remind the audience of you know, what what's going on in this Marketplace in regards to password and password manager and Method strong Master passwords and volts being Compromised and what have you I like this concept.
I guess I got a few questions on it. If you don't mind that you can help with so. You know, one of the concepts of this Enterprise password is that you can sell you can not sell passwords.
You can share passwords, you know with your teammates, right? I'm gonna give you access to our HubSpot or our you know, whatever. was sharing and from what you're telling me if I were going to share a password with you, I would share it with you by sending it in an encrypted.
matter via the jumpcloud servers and then down to you and it would be stored then locally on your devices as well. That's exactly so the worry that works is every device has its own sets of encryption keys that are shared between the different devices and let's say I want to send you a password my password management application the jumpcloud password manager will encrypt and sign this password using your key to encrypt and my key to sign and this encrypted. Event, which we call a sync event is then relayed through jumpcloud servers onto your device.
If your device is currently online. It's almost into instantaneous takes less than a second. If you're offline, then that sync event will be stored on a buffer on jumpcloud servers waiting for your device to come online.
Next time. The device comes online gets being done your device received. This thing receives the signed and encrypted sync message verifies the signature to make sure that it's coming from me and from another.
User and then proceeds to decrypt the sync event using their own private key which remains stored on their device. They then have the clear text password that I shared with you with the incorporate and to their locally encrypted database at any point in time. If I want to stop access to your account, then I go in my password manager the activate the access by clicking a button and that would send a message through jumpcloud servers.
Asking your device to remove that password from your vault. Sorry and Course, it's encrypted and Transit like that that kind of prevents sort of a man in the middle attack because even if they were successful in setting up, you know. Server in the in between the jumpcloud server and my device they would just get the encrypted.
They don't have the key to unencrypt that that transmission anyway now let's say you're going to share a password with me and I may want to put it on my Mac here, but I don't really use this Mac to access a lot of sites. I want it on my other Mac or I want it on my phone. Is it like once it's on one of my devices locally?
It automatically sort of generates it to all of my local devices. So the outcome is correct. You're gonna have the password on all your devices, but the way it's gonna work is I actually will know ahead of time how many devices you have set up because you're gonna have shared all of these keys with me and they'll be associated with one user which is a type to your jumpcloud identity in the open directory platform.
And so when I want to share a password with you, what I'm actually doing is signing an encrypting that message for all of your devices. So we simplified that flow and explaining it before it was a one-to-one flow, but that would be a one to many for users. It's transparent.
You just select the user just goes out you don't even know how many devices are gonna get it Etc. But in the background, you're actually emitting multiple think events that are gonna get received on the other devices. So this is in case you already have the password manager installed on multiple devices, but let's say you've already received some passwords from other users within your organization.
You also had your own password stored in there and you want to start choosing the password manager and your phone the way that works is through a simple pairing mechanism. So you just launched up put in your email address. It'll give you a six digit code.
QR code that you can easily scan or copy on that other device and it'll keep them in safe. Take them up. That's great.
So you can add new devices at any time when they're instantly synced up like that. It's fantastic. So two more questions, I'm sorry that so many questions, but I'm just exploring so there is no cloud-based copy of the Vault the vaults are only on the individuals.
Yes, the cloud our Cloud servers Only Store temporarily sync events, right? It's just it's just a Transit point if you will and it's only a a password being sent not the entire Vault or anything like that. right and case of a device being compromised my phone my computer whatever.
You know, it was compromised. The the information is stored. And encrypted base.
Anyway, correct? It is stored in an encrypted way. But if a device is compromised to the point where a hacker has admin privileges on the device all bets are off.
It's not just about the password manager anything that you have on that device any session cookies any other passwords that you might have to another password manager, even cloud-based password manager cache passwords locally on devices sure would be considered compromise because a hacker with this type of access can either instantaneously gain access to the stuff that they need to have access to or they can put in key loggers screen recorders and then capture information over time until they get the full picture that they're looking for. Got it. Looks when it comes bad like that, it goes bad like that, right?
So It's now last question. I promise. on my local devices passwords are stored not necessarily in the jumpcloud password manager, but whatever you're using to store passwords on your machine, whether as you mentioned keychain for apple and you know iPad, I iPhone or Mac or oh whatever it is, you know, like Google Chrome has passwords does it use it uses that it's not setting up yet another copy of my passwords encrypted or not.
See so everybody the way that it works to make this extensible and scalable across different operating systems because you know different operating systems have different restrictions on what type of information you can store in them your way. That works is as follows. We created database on the device.
It's separate from that Secure Storage unit. This database is then encrypted with the key. That's locally generated on that device.
So now it's an encrypted Vault and that key is put in the Secure Storage unit of that device. So you're getting the same outcome, which is you're keeping the thing that's giving you access to the actual sensitive information where you want it, which is the key chain the storage Etc, but you're keeping also the flexibility of being able to maneuver this database regardless of the operating system that you're on and this is what allows us to be available at launch on Mac Windows Linux, IOS and Android on all of these platforms imperative. Love it.
Great. All right, let's pivot to the business side of things. What does it cost?
How does one get it? Is there is it an individual? Is it a team thing?
How is this packaged if you will so it's an add-on to jumpcloud platform. You could purchase it on its own just with a core directory offering or on top of any package that you currently have. If you're one of our partners imagine service for provider, for example, we do offer packages that include the password manager and it just to make it just easier to adopt internally but also deploy to your customers in general.
I think that the real benefit of our password manager is the fact that it's not a point solution. It's actually part of the jumpcloud open directory platform because even though passwords are still an important part of our lives and I mean that Reliance is going down but it's still slowly decrease for the foreseeable future it's there. 100% the real value is and being able to move to passwordless authentication mechanisms, and I genuinely think that today in the market.
No one does that better than us because the jumpcloud open directory platform has single sign-on MFA password management also authentication to ldap radius. We support certificate-based authentication and that's what you really want. Like passwords are considered a legacy authentication mechanisms that we still have a rely on having a password manager.
That's part of the jumpcloud open directory platform gives you that flexibility to start moving away from these passwords much easier than you would if you had a password manager as a standalone solution a single sign-on solution as Standalone solution and MFA solution as a standalone solution, that would be just so much harder. com. All right.
Hey, it's hard. We're about at a time man, but I got to thank you for coming on here. Actually, this was an X.
I think our audience learned something. I hope they learned something check out. This jumpcloud solution is part of their big or sweet.
Come back. Keep us posted on what's going on, you know, it is is obviously a Hot Topic right now. So keep us posted and best of luck to you.
Thank you. Thanks and have a great rest of you. to Antoine jubera jumpcloud jumpcloud password manager here on Tech strong TV.
We're going to take a break. We'll be right back.