Teleport 10 Availability – Ev Kontsevoy, Teleport
On July 27, Teleport announced the availability of Teleport 10. With this latest release, Teleport eliminates the need for passwords with a biometric infrastructure access solution, representing the beginning of an industry-wide shift toward biometric-based access management.
Transcript
This is texturing TV. Hi everyone. This is Alan Shimel and welcome to another tech strong TV.
Interview, I'm happy to be joined Again by actually, we usually see him in person at a conference but we've got them on Zoom today. It's F Connor Connor's boy EV is with actually. He's the CEO of teleport.
He's here to tell us about some teleport news. Hey F. How are you?
Hey, good morning, Alan. Thanks for having me on Zoom. I'm just as good on Zoom as I am in person.
Well, no you got that. Nice pretty Kind of Shipyard background there. Yeah looks good.
So have you know what for people who are not familiar with teleport? Why don't we give them a little background? Yeah.
Absolutely teleport is the easiest and most secure way for engineers to access Computing infrastructure. That means SSH servers RDP Windows machines kubernetes clusters databases everything you have inside of your clouds the way you securely access it using your identity is what teleport provides it's an open source solution. com Excellent.
Alrighty, and of course as I mentioned of you're the CEO at teleport and you're here to tell us some recent news actually, very recent news. Yeah, the new version of teleport is out teleport 10. It's it's a very nice round number and it includes capabilities that I'm personally very excited about principal congratulations, you know doing a tense release.
is is impressive and for anyone who's been in the software business whether it's SAS or not, you know when you It's one thing today have when you know every day. We do five different kind of micro releases if you will on some of our phone AppSec and you know, we change a button from red to blue and that makes it a new release right? Yes, but but a true release where we're adding.
You know more than a few even new features and functionality, right? Going back to my pre devops days and waterfall and all of that. It's a big job, you know going oh cycle and everything.
Yeah, it looked particularly. If you are an open source project, which means that people have to actually put an effort into like downloading the new version and getting it installed. And yeah, it's a major release.
So we usually have this kind of minor releases that are minor improvements or some kind of performance improvements something like this. But in this case teleport 10, we truly proud of it because it's finally delivers capability that we wanted to add basically since the early days just to kind of give you a story of where teleport came from which kind of plays nicely with the announcement that we're making with this version. So we originally like the people who started teleport they founding Engineers came from handful of let's just say hyperscaler companies, you know, like the companies that have hundreds and thousands of millions of servers and processing massive amounts of data.
And at these companies like to wait infrastructure is access has always been quite different from the rest of the world simply because of the fear of the kind of the scale. Just how many machines you have how many Engineers are interacting with this infrastructure? Because what happens is like when someone gets hacked there is this pattern that occurs every time there is an attack first the human error is exploited.
That's how attackers initially get in the get a foothold in here infrastructure. It could be a compromised laptop. It could be a compromise like server somewhere and then they pivot they try to go and in fact as many systems on the same network as possible.
So in the response from kind of best tech companies has been a little let's just call it a secret list plus zero trust secretly means secret list means that the access to infrastructure should not be governed by any secret. So private keys are no no passwords. Obviously, it's a bad idea browser cookie is another form of secret.
It's really really bad if you use that so you have to go completely secret list you access your infrastructure to prevent human errors from happening because all human errors is about leaking a secret. So if there are no secrets then humans cannot do something wrong and probability of humans making an error just goes up in time as you hire more and more people as you add more and more infrastructure. That's hypers.
This is why these I keep calling hyperscalers these companies why they moved away from Secret based architecture. So the Legacy approach to access infrastructure is it's something called privileged access management space. So there's a password rotation secret rotation there like password management is a big deal.
So all of this doesn't matter at scale. So if you want if you building a cloud native application, if you're running in the cloud if you're planning to scale you have to move away from secrets. And zero Trust basically means it's that's how you protect from pivoting.
It effectively means that networks don't matter. You don't do security and network level at all in instead you secure each Computing system as if it was running on a public internet. That's really the kinetic combination secretly access and zero trust and that's what teleport is because we realize when we started the project is that in an open source World, there is no equivalent to technology that is used by hyperscalers to deliver secretly zero trust access and teleport has always been like since the day since day one.
It was built with secret lists architecture, but version 10 eliminates the last secret that existed in the system. Can you guess what it is? Not password username Knight.
I don't know God you actually got pretty close. So like today if you if you teleport nine the way you access infrastructure like you go through corporate this you click like login with SSO button, you fill out your username password multi-factor authentication like and we have this kind of in identity based space and then you integrate teleport and teleport gives you access to infrastructure. So that is the step that we replaced with completely passwordless and completely username less access.
So the way it works in this doing that, yeah, so the way it works is but you have to have a laptop with black TPM trusted Community module and biometric authentication on it. Which let me just start right there for those of our audience who maybe aren't you know Security Experts or familiar? The TPM and biometric module was something I think it was Intel built into the Intel chip line.
Jesus it's got to be eight years ago 10 years ago have Holy Spirit through that's not new. Like there's been numerous iterations of the same TPM technology. Apple calls them touch Ada.
I believe that's just a kind of overall system that's combination of our TPM and and the fingerprint reader you could buy it separately. Like if your computer is not equipped with one you could buy like you be bio. I think that's that's a thing that has integrated fingerprint reader and the way it works is that first you have to do you enroll your device into teleport.
So then you teleport knows your laptop. And it's really the TPM chip that you're enrolling. And and then the second thing that happens when you when you authenticate is that you you register your fingerprint with your TPM.
So then your TPM plus combination of your fingerprint. That means that it's truly truly you. And the interesting thing about this architecture is that it's your identity in this case that you're using and when we talk about identity like I would love to popularize the term true identity because true identity just physical attributes of your computer and physical attributes of you combined together and the difference between this identity and they kind of Legacy definition of identity is that true identity is not data.
You cannot steal it. You cannot upload it. You cannot download it.
You cannot sell it on on like Marketplace of credentials simply because they're physical things like your fingerprint. For example, it doesn't travel anywhere like from your TPM. So when you do your fingerprint authentication, it's your TPM validating your finger print like there is no software that can get in the way and still that fingerprint.
So that is the addition of teleport and it's basically using true identity for Access so we're extremely excited about it simply because it eliminates probably the last opportunity for humans to make an error. So completely eliminates the most common way how infrastructure currently is attacked. That's big.
That's really big actually. Yeah. I'm I'm running it myself.
I'm installing it on my home lab. It's gonna run in my home office here. So be a very excited about this.
It's fantastic user experience as well. It's like one of these rear instances where security and productivity don't fight because usually those two things are at odds with each other, but in this case, it's just a match made in heaven. Absolutely.
And again, let me emphasize. For those of you out there the over overwhelming majority of you do not have to go out there and buy some separate piece of Hardware or something your machines. Probably have it already built in absolutely like all available Hardware had this capability for very long time and there are more and more kind of laptops that have this capability.
And again, even if you have old school desktop machine that you assembled yourself, you can add this capability with kind of external. It's it's a USB dongle that you can use Absolutely, great. All right have beyond that.
Let's talk about more teleport 10 features. Well, obviously, I promise you that it was gonna be it is a major new release. So in addition for adding this passwordless secret list access, we've implemented an interesting capability.
It's called basically just in time access request for one particular resource. So here's what it means like imagine you have let's say production infrastructure staging infrastructure and like test infrastructure like all these different environments and you have Engineers that like obviously they shouldn't be accessing production all the time and and historically like the way it would have worked if some engineer for whatever reason needs to access production. Maybe there's some kind of emergency some like some very hard to trouble shoot problem that requires access to production.
So like people would like bump that the access of that engineer to like like a different level like different role would be should so a Teleport supports for this use case is that let's just say you need to access like a specific Journey this cluster or specific server for If a reason teleport can elevate your permissions temporarily just so you could go and access this Resource One Time based on your manager or maybe your peers approving your request. So imagine for example, if you executing Cube cuddle command or SSH command and then that command kind of pauses for a second that happens because it sends in the background access request is lack. So your team is getting notified that you're about to access this one thing for this one time.
So then your team says yeah. Yeah, like we have needs to go and have access to this thing. So they approve and then you get in and then once you get out of it, once you've done whatever you need the access is a revoked again, so you see like the way this the benefit of this feature is that it shrinks the attack surface area in time.
Because most people if you say well does by Alan have access to this kubernetes cluster the answers like for example, yes, Alan should have access to this kubernetes cluster. But are you using that access right now? I actually interacting and if you not then maybe you should take it away because what if your laptop is compromised, right?
So that is just yet. Another capability that is widely used by the industry and another. A very exciting capability of teleport 10.
Is that this? Can a true identity that we talked about it's kind of secret lists a way of accessing things. It's not just for humans.
By the way, it's really important to realize that like our infrastructure is in many ways self-managed like backups are happening automatically, maybe security patching happens automatically deployments are happening on schedule. So like we basically have machines acting on behalf of humans telling other machines what to do. How does that happen your cicg when it does deployment.
How does it actually get access to your production to run the deployment? Well machines also need credentials. So teleport 10 delivers this capability called machine ID and machine ID again it basically very similar capabilities.
So that machine gets a certificate from teleport to go and do certain things. So teleport 10 delivers machine ID for kubernetes for databases and for like other forms of resources that you I might have in production. In addition because again, our goal is to be the easiest and most secure way to access all of your infrastructure.
So we keep adding support for more and more resources. So with this with teleport 10 that includes snowflake that includes elastic search that it looks Cassandra elastic cash and Amazon memory DB. So we keep adding more and more resources because the end game if you're using teleport is that you go through this secret list authentication once and you are connected now you do have access to everything you need to be productive like everything.
Inside of your Cloud if you're supposed to have access to it, you will do it through teleport. Oh, I love it. But let's want to go Don't even download teleport at this time, but just want to get more information on relief stand here.
com and there is a resource center. They can go and learn and watch videos and take tutorials. I do agree with you that downloading is probably not the first thing it should be doing because teleport is an infrastructure product.
com. Absolutely, but you know how a lot of people are we don't need no manual videos Everyone Loves very much ideas. Yeah, no kidding around really, you know, I put a little drone and I couldn't get it to work.
I Googled they had some great videos watch the videos explain to everything was so much better than reading the manual. Anyway, hey congratulations on teleport 10. It's it's a milestone right?
It's an accomplishment. Give our audience a little background. How often do you guys come out with a major release like this?
we So about twice a year, I would say we do a major release about every six months and then we do kind of Point releases that usually contain kind of nice to have improvements. Cool. All right.
Hey. let's hope Right, and we'll see you in person as well and some shower or another but until then be well congratulations and thank you very much. Will do.
Thanks for having me. com. That's right.
com.