Locking Down AI in the Browser – Dan Amiga, Island
Mike is joined by Dan Amiga, co-founder and CTO of Island, to discuss why the enterprise browser is the best place to enforce content security policies. Mike and Dan delve into the importance of user experience for security products and the historical challenges of DLP before addressing the potential data security issues of generative AI tools like ChatGPT and what Island is doing to protect that data.
Transcript
This is Textron tv. Hi everybody. Mike Rothman here.
Another interview for Textron tv. I am joined by Dan Amiga, who is the co-founder and c t o Dan. You're the c t o, is that, is That ct.
O T o of Island. Island is, uh, an enterprise browser company, but I'll let Dan explain that and certainly don't want me, uh, given the, the intro to, uh, to Dan's company and, and, and island. Uh, we're gonna get in a couple of of interesting things, obviously, just kind of why the browser is an interesting place to, uh, enforce a number of different security policies that have been hard to enforce at scale, uh, for many years.
We'll talk a little bit about that. Uh, and then we'll talk about things like content protection, uh, d l p as a mechanism to do that, uh, and really a new announcement that Island just made, uh, about adding some capabilities to their enterprise browser platform. So, uh, Dan, welcome to, uh, techstrong tv.
How are you today? I am wonderful. Thank you, Mike.
All right. Coming, coming, uh, to us from Tel Aviv. It doesn't, you can't really see it, but Dan, show me a view of the beach.
It's, uh, it's a pretty scenic place that is a fake background behind me. I'm not in Poca water. I'm in a dungeon somewhere that nobody knows, uh, uh, where we are.
So, so today, tell us a little bit about Island. Um, you know, I know you've been on the show a couple times, so, uh, some folks may have a little bit of a background, but I, I never make any assumptions. So you, you know, why the enterprise browser is, is interesting to you and also some of the key capabilities that you're bringing to enterprises with the, uh, with the island browser.
Oh, sure, Mike, and thank you for having me. So, uh, island, um, headquartered in Dallas, Texas, and then our engineering and product teams are based here in, in Tel Aviv. And, um, what we figured out is that probably the most used application in the enterprise is the Basel, uh, but it was not designed for the enterprise.
So when you need to do application delivery, like let employees, contractors, users from home, access those Salesforce, the Office 365, the other business applications, homegrown applications, et essentially do the work, right? You have to, uh, buy, integrate many different solutions. You gotta have a V P N, you gotta use VDI for that.
You gotta use some D L P controls, which we're gonna talk about. How do you do malware scanning? What about a password manager?
How do you measure the digital experience? You probably need to put in 50 tools in line somewhere, and that completely goes against end user experience, right? Uh, so what we've done is based on core, which is the open source code behind Chrome Edge, et cetera, uh, we've built Island and Enterprise BAL distribution that has, think about the, the security, the it, and the end user productivity controls baked inside.
So you launch it like, it looks like Chromo Edge, right? Uh, but the V P N is built inside, the DLP is built inside. Even the privacy, uh, tools to protect the user from all sorts of, uh, privacy invasion cookies, et cetera, are built into the browser.
So you don't have to install these web extensions. And with that, we allow organizations to reduce their V D I usage, uh, consolidate those security and IT tools, uh, better support A B Y O D model, uh, or a contract or model where you don't have to ship laptops. And by the way, it doesn't go against Chrome or Edge in, in any, any manner.
Users can use Chrome and Edge, but when they need to use their business apps, they're being redirected to Island, which is where they do their work. Um, so far, um, you know, we've been blessed to have tremendous success in the market. Um, many large enterprise customers, fortune 10, fortune 100, but also a lot of tech companies, um, uh, medium businesses from really any, any vertical.
So, uh, exciting times for us. Yeah, I mean, ha having struggled working with a number of, of consulting clients, you know, with vdi, right? You know, just the provisioning and getting that up and running, and I gotta have the right client on the device that I'm using in that given time.
I mean, it's a, it's a huge hassle. So I can certainly see y you know, the, the value there, but also, I mean, let's talk a little bit about, you know, kind of the remote context. But, you know, obviously a couple years ago, right around the time where you said you, uh, guys founded, uh, island, we got into a position where we couldn't be in the same place where everybody was remote, by definition.
Uh, and I think that created a lot of both scale issues and manageability problems, uh, in terms of enforcing policies where you don't have kind of that traditional perimeter, and we're both longtime security folks, right? So the perimeter is kind of how we grew up in, it's just like, oh, you know, build the moat deep, make it tough, put some sharks in there, you, you know, and, and everything will be all right. And then, you know, again, H G T P screwed everything up, uh, from that standpoint, and then you, you know, now this whole SaaS thing means I have no idea where my data is.
So it, it's an interesting approach to really kind of look at the user as kind of the center of that universal, uh, turn in Galileo and Copernicus on their ear, uh, a little bit, uh, from that standpoint. But, but again, I mean, I think it's, it, it's an interesting approach. I mean, do you see organizations looking at it as much a management tool as a security tool?
Or is it you, you know, most of the main use case is security. When you, when you get down to it, I'd say, uh, uh, security is one use case. Uh, but, uh, definitely a, an, uh, an access tool, a management tool, um, and really an end user, an end user experience, uh, uh, platform.
So you think about, uh, the journey where, um, you know, companies have to spend thousands of dollars on a VDI session and then what we call the length of the wire. You gotta wait till this pixels from the cloud somewhere, render locally on your endpoint. Nobody wants to do that.
That's not the, uh, um, that's not the, what, what I call the consumer experience, which you buy a laptop and then it's just a perfect experience, right? Uh, with Island it is, right? We bring you the security controls and benefits you get from a VDI session in, uh, a, you know, a much better ROI and cost factor, and a much better user user experience.
And, uh, and I like you, you know, when you said, then HTTP came along. So if you think about, um, think about the SaaS vendors, think about Salesforce, for example. These guys have hundreds of security professionals, right?
Protecting the Salesforce frontend, the Salesforce backend. But the moment you spin your browsers and go to Salesforce and authenticate, where is your cookie? A cookie is local, where is your cash?
Where is the data? What happens if somebody takes screenshots locally from your machine, right? You gotta protect that last mile.
So when you, when you use Island, island compliments that by doing what we call less mile security on the device. And, and that's a super popular use case, uh, uh, for us. The, i, the, the manageability, the end user experience and the security.
Yeah. So I, I don't, I don't wanna understand, I mean, we do wanna talk about dlp, you wanna talk about, uh, Jen Abbott. I have one, one more question on that front.
And, and one of the advantages that a lot of the large, especially heavily regulated organizations looked at and, and really wanted with V d I, was this idea that the content was within their confines, right? You were just sending presentation, uh, out there. There was no cash y you know, all the data was, uh, again, on that central environment when, when you were doing fireglass back in, in, in the day, you know, again, similar type of approach.
Everything was controlled within an environment. How are you guys protecting that cache, that protecting that data that does kind of end up on that local machine since, you know, in a regulated environment that can be pretty problematic? So one of, one of the things that I learned, you write my uh, uh, uh, first company was called Fireglass.
It was pioneering remote browser isolation. We, by the way, have some of these capabilities in Ireland today. Um, one of the things that, uh, um, is required when, uh, uh, um, when you wanna protect data is making sure that it cannot, what we call leak away, uh, in the endpoint, right?
So we make sure there's no many in the middle where you can't intercept the data on the network. You can't, you can't really take a screenshot, you can't use developer tools to, uh, extract elements out. So they use everything on the endpoint is actually encrypted.
Your cash, your session, your cookies. So you really can take the data out, right? In one sense.
But then the other thing is you gotta look at the context. So even if you have a VDI session, somebody can spin a browser and copy things form your business application into payin, right? Island also gives you that contextual layer that says, well, you, you can only really exchange data between your business applications, not with these, with the wild, wild internet, right?
So that combination of those two, um, gives you the solution you want better than a vdi, right? Um, in security and cost. So, so one of the things we, we kind of said when we were just chatting ahead of time is it, it's really more of an operating system than an application.
And I think when you start thinking about, um, enforcing policies between applications, right? I think that's what what you're getting at there. Uh, and again, an important aspect of that because again, an applications application, you can run other applications, you can, y you know, back in the old days we had the green border, I remember Green Boarder company Google bought and then, you know, drove into the ground.
Um, you, you, you know, but it was a similar type of concept where they wanted it to be a very isolated type of experience, uh, within the browser, but ultimately because they didn't control all the other applications you could get around it, uh, like, like everything else. So, so interesting thing. Let, let's talk a little bit about content, right?
Again, coming outta the remote browser, browser isolation, you know, world, obviously the challenges and, and being at Symantec for a while and in a past life, uh, D L P was, was a thing, a big heavy thing, right? That generated thousands of alert that nobody would ever really look at. So, so now you guys are talking about content, you know, kind of security within the, the browser platform within the enterprise, the island enterprise browser.
So when you say that, what do you mean, right? Is it just, Hey, I'm gonna provide some context, I'm gonna look for intellectual property. Cuz d l p can mean a lot of different things to a lot of different people.
Yes. First you gotta, you gotta make it easy, right? You gotta make it easy on, on, on, on customers and it, cuz DLP tools have been, um, so challenging to operate and, and you would meet customers, yeah, at scale you would meet customers that have like a whole team just doing DLP policies and debugging those, those policies.
So I'll give you a few examples. When you build it from the ground up, when you build that operating system that we called island, right? Uh, first what we can do is you can define application boundaries and that makes management and also security much simpler, right?
So you can basically say clipboard operations or files, right? Or drag and doop can only be exchanged between the business applications in mind, right? It's much easier than going and defining DLP tagging, et cetera.
Right? Now we do leverage because a lot of our enterprise customers do have the, the files already tagged. So we do integrate with Microsoft information protection or different tagging solutions.
Uh, but think about application boundaries as one thing that's really, uh, uh, essential. Then, then the next thing is you wanna control p i i data or you want to be able to allow customers to mask data in the page itself. Uh, call centers is a typical use case.
You better call center agent. Uh, we're gonna talk about the G P P soon. You wanna be able to mask data before it goes on the wire or before it's being rendered to the end user.
Then build workflows on top of that island gives you that as well. So, um, we have DLP controls on file, upload and download. We have D L P controls on the network.
We have d DLP controls where you can mask content and you can define application boundaries. And what we did is we took that you can apply it easily on any SaaS application, right? And specifically one of the more popular applications that we are getting a lot of in down interest on is any application that's based on, uh, G P T or all the open AI interfaces, uh, or bar in that sense.
Yep. Yep. So let's, let's go there, right?
Because y you know, again, I think it's, it's one of these things that people don't quite understand yet. I mean, that's model and you know, ask it to write you a short story, you know, in the voice of, oh, about y you know, some something inane, right? You know, a lot of folks ha have fun with that.
But as a business tool, you've got people that are uploading private data, right? You know, you're, you're, you're sending this, hey, you know, put this in the table or hey, format this, uh, in a certain way or draw conclusion, you know, from, from that perspective. Uh, and it does create, you know, clearly not just a regulatory problem, but but a security and, and an intellectual property protection problem.
And again, it's not that these folks are trying to be malicious about, right? They're trying to do their job and they see Chachi VT is a way to maybe do that, uh, a little bit easier, but obviously it creates all sorts of, of different issues. So have you done anything specifically with chat G P T or is this just, you know, kind of the, the basic island stuff that you guys have been doing for the last couple of years applied to this specific problem?
Uh, we, we, we have, uh, built a, a whole, uh, what we call a module around the check G P P to help our customers or maybe large language models, uh, uh, in general. So, you know, the main thing is I don't think these users are trying to be malicious, as you said, Mike, right? It's a business enablement problem right now.
Um, what happens if you block it as an organization? These, you know, your end users will do it on their home computer. They will find a way to take the documents out so it becomes a bigger problem, right?
So it's, it's all about enablement. Uh, and I think one of the most, um, uh, encouraging things for, uh, my product folks and engineering folks and with Passing Island is our customers are sending us their videos they send their end users with, with introducing Island today, and it'll be an easier way to use chat g, pt, uh, et cetera. So what have we done first?
Uh, we have added what we call an AI system where any user of island can go in and interact with the AR system in the backend. That can be based on Chad g pt or that can be based on the organization l lmm model. And then we have our DLP controls where you can say, Hey, you cannot send p i i data to the Chad G PT engine, or you cannot send any organization policy data.
Um, and you can define those l p controls. So that's one, that's our AI assistant tech. Uh, the second thing we did is we actually wrapped it as an application.
So you don't have to use a standalone, uh, you don't have to use a full browser full island browser. You can just launch the chat G P T app. It has all of our D DLP controls, uh, and you can immediately work with it from within other applications.
The standalone app in the operating, uh, in the operating system. And then finally, as I've mentioned, you can define what we call application boundaries. And you can actually say you cannot copy data from business applications into the chat G P T, uh, window into the AI system window, uh, uh, et cetera.
So a full workflow organizations can, you know, in, in it takes us about 15 minutes to roll out and explain to, uh, a, it how to configure. Um, but a very quick way to enable CHE g PT within the organization. And now we're getting, uh, all sorts of interesting, uh, requests from customers.
So they wanna bring their own CHE g PT or Azure AI key, uh, to us for us to use their own, or they wanna plug in their own large language model and APIs instead of the G PT one, but just baking it into either the browser real estate or our own standalone app. And having the D L P controls, again, we go back to a much better end user experience and enablement tool. Yeah, no, that's interesting.
I, I, Dan, I, I, seriously, we, we could sit and chat all day. I mean, I have so many questions about, you know, how do you set the policies at scale and all, I mean, with all those different knobs and, and all that, but we'll, we'll have to leave that, you know, for, for another day. Um, but really interesting stuff.
Again, you know, I have some old friends, uh, that work at Island, uh, as well. So they've been keeping me in the loop, uh, a little bit about what you guys are up to. Very exciting, because again, it, it's a, it's a real problem that we haven't been able to address with the current kind of set of security controls and, and tools that we've been using for, for a long time.
So, good times. Again, very interesting. Keep an eye on, on I, if folks wanna learn about more about the company and, and specifically around the, the chat sheet, PT and, and AI capabilities you have.
Is there a specific area they can go to or should they just go to, uh, your, your general website? io, Dan Amiga. Thanks, uh, a million for your time, uh, and telling us a little bit about what you guys have up to.
And, uh, we will see you next time on Text Strong tv. Now let's send it back to the studio for our next interview.