Trust Lifecycle Manager – Brian Trzupek, DigiCert
DigiCert recently announced its latest offering, DigiCert Trust Lifecycle Manager. Key benefits include unifying CA-agnostic certificate management, private PKI services and public trust issuance. Alan gets the latest from Brian Trzupek, SVP of product at DigiCert.
Transcript
This is texturing TV. Hey everyone, welcome back here to Tech strong TV. Our next guest is from our friends in digicert.
It's Brian true Peck. Brian is SVP of product there and Brian if I mispronounce your name, I apologize say it correctly. Now you got it right Alan it is true back.
So just pretend that you know, yeah, absolutely and I thought it was but I I don't you know, hey, who am I to mess up your name, but So Brian, you know what before we jump into? I want to talk about today which is digital trust. Why don't we give people a little bit of your background?
Because you have a pretty distinguished cyber. Now, we call it cyber a pretty distinguished, you know security background. Sure.
Yeah, I mean in just real quick. I mean I go back to the days of being a developer still actively developing a software on the side. I wish my day job kind of let me do more of that.
But you know, it kind of pivoted me into the interesting aspects of security, right? And so I did some stuff with defense back in the days and and got into you know Aviation and auto and you know kind of fell in love with this whole pki thing and so for about the last 18 years been doing a lot with kind of pki crypto what's happening with encryption and then how that's applied out into broader ways that it works not a lot of people are familiar with pki but it's everywhere. well It is everywhere and it's funny.
I you know, I so pki for people who aren't familiar as public key infrastructure, right and I man, I first became aware of pki I'm gonna say early 2000s is that it's about right. Well, you know Nets game Navigator, right they started with this SSL thing to secure websites. Absolutely about pki and that's kind of where it got born.
Yeah. Yeah, actually you want to know the truth. com day.
So 2019 ninety nine and that we because we were we were we were what they call an asp application service provider. This is no Cloud T1 lines. We're hosting Lotus Notes people search people soft and and oracles, you know, and so we have Lotus Snowden.
Yeah. I know look at least you remember what it is. You say something.
But you know, but we had to have you did you didn't have virtual machines like you do now you certainly didn't have can you know the kind of containers and Cloud native, but you didn't have Cloud but you had to have some sort of security and and so, you know, and in those days it was kind of roll your own pki. Right it you know, it wasn't an easy it I mean you got you know, it's easy now but back then it wasn't so easy. So yeah it is but you know surprisingly I look back so that was what 23 24 years ago for me, right and it's still the backbone of so much of what we do around trust around.
You know authentication and and so forth. So it certainly has shown it has legs, right? Absolutely.
Yeah, I mean it's at the heart of everything we do at digicert and Powers everything underneath digital trust. So absolutely man. So you would mentioning did you search I think most of our company?
Most of our audiences is has heard of digester. They probably don't realize how many times they interact with digit sir. That's right on a daily basis.
Why don't you give us a little digit start background Brian? Sure. Yeah, I mean digit has been around for quite some time as well.
And you know in that time right we started out with those roots of PK. We just talked about right securing websites and and you know, making that information exchange over the Internet safe and secure preventing man in the middle attacks and keeping credit card safe. That's usually the way people understand that one the easiest right but that core technology which you just talked about earlier pki public key infrastructure.
It's broadly applicable and so our company really rapidly once we all up expertise and that area of helping customers, you know solve that problem. We're able to apply pki much more broadly and that's where this digital trust category kind of comes from is underneath everything we're doing whether it's phone calls, whether it's you know, you're set top box communicating with your provider whether it's a aircraft traveling and communicating information down to the field. You know, I always like to say we we do drills at the bottom of the ocean and information coming off of Those in protecting that to satellites and outer space.
So it's everything from you know under the ocean to the edge of outer space pki is protecting all that information and everything in between then digital search providing the technology that makes it easier like you just said it's easier today and I think it's really that that investment that we've done in that industry of up leveling that technology and continuing to carry it forward and bring it in new places that it can be used to solve all these diverse problems, you know, and now you see this, you know in it and devops and I you know iot area identity access management all kind of underpinned and more with pki providing that security layer. Absolutely, man. Good and just before we jump in did you start calm for people who want to get more information is the right website?
That's right. Thanks, Alan. Yeah.
All right. All right. So Brian, let's talk digital trust a little bit.
So as we look at digital trust, it's it's this interesting dimension for companies. Now, they're pulling us in this direction because As customers interact with businesses online more and more right? We saw through the pandemic everybody went home.
There was workers or people, you know ordering things from Amazon all the stuff that was happening the internet the it was in the middle of all these exchanges. And so this notion of trust really got pushed to its limits and and we see trust happening on the internet and how do you know that the other person is trustworthy the other company that your information is trust is going to be trusted. How do you know that when your car starts in the morning, you know, it has firmware that comes from somewhere and and you know controls that vehicle that that's trustworthy.
And so this whole notion of digital trust kind of wires up under all of that so that as an organization is working with their customers their responsible for trust. They're providing trust out to their customers the infrastructure below that that layer below that that's often transparent is fundamentally and a lot of ways based off of pki and other core security Technologies. That's where digits are really, you know digs in and so we're off we offer customers.
Trust in the area of like identity access management trust in the area of secured devops and operation of workloads and execution of those things iot firmware and communication and Trust in those categories documents exchange of documents and signatures undocuments and Trust in those areas and then authoritative DNS, right so that at the root and core of the internet, how am I resolving things and knowing that I can trust what it is I'm talking to that's NS. And so that's kind of the fabric we've together that is providing our our customers the ability to provide trust to their customers. excellent So just make note of the time of our interview Brian because it took us this long, but it comes up in every interview today.
what do you think Ai and and this kind of I mean we're seeing things you want to call them deep fakes or what have you but you know, what? What effect do you think this has on on? Your business on digit search business on the whole issue of trust.
Yeah, I think it's a great question and we talk about it often here at Digis fair, right? We're involved in a lot of these standards bodies and you know how you sort through those problems and how you communicate trust and I think ultimately it does come down to a larger surface area problem. Right?
It's it's an industry that's going to solve this problem because there's multiple participants right if you take the area of like secure content and think about that a photo, right? How do I know that that photos are real photo and it's not been AI generated by one of the Myriad, you know, that models that will generate photos and you know, there's there's content standards, you know, Adobe pushes a large content standard Consortium, which is multiple vendors, right? So it's a kind of iot connected so cameras and digital photography and videography and how you associate identity for that device the user on that device and then the content actually being created in that device to say those things.
Those three things came. Other created this photo and now through the production chain. I know that information is associated with that photo and further.
I know modifications that have happened to that photo, right? So that's a good example of where the industry's kind of coming together to say, let's provide authoritative source of information or how identity can be associated with some artifacts. So, you know, it's not been generated or if it has been modified, you know that too and guess what at the core of that is pki, right?
So what enables that infrastructure the signature for that photographer to be assigned to that device to be assigned to that photo to be communicated through the chain of wherever that photo goes and it's core is pki and so we look at that as as an organization, you take that that one example and scale that across other types of content, right those standards are still very much in development. It's a very fast moving area of kind of the internet right now, but it's one that we're actively tracking and actively working with Expand on that whole concept so you can see you can't imagine how you can secure other types of content and how you can verify where it came from and when it's been modified Beyond things that are photos. Absolutely.
You know in many ways Brian I I view the whole. trust thing as core to you know, so to me the killer Security app for the cloud is IAM identity access management. Now, what we've seen is identity and access are really two separate things that could be managed independently, right but underlying all that is trust right and and of course the big thing RSA is coming up in next month and last year was all about zero charts and I'm sure zero trust will be out there again, but and zero trust is a great concept.
I'm not saying different. It you got to have you got to be able to trust that some point in order to move up from zero choice, right? It's like saying, hey, we can make things real secure out just unplug everything from the internet, right?
No one gets in or out. you know trust is such a it's so vital, but it's It's elusive. I mean, you know, I think a lot of people take it for granted.
Right because it's such a like pki. It's such a part of the fabric. But you start pulling threads off the edge and that fabric comes apart pretty darn quickly.
That's right. Yeah. You know, so what how does digicert?
Ensure that we don't we don't have loose threats, you know on that on the edge there, right? Yeah, it's it's a constant. Yeah, no, that's a great question.
And I think you know kind of where your your question came from and that identity access management system those changes we've seen whether it's zero trust or any of the things that are happening there. It's one of the core pieces that were were commonly asked about right, you know, the the interesting thing about identity access management is we've kind of seen this shift that's really been ushered in with a lot of the devops thinking in devsecops thinking that went from initially, you know, Alan or Brian needs to access a resource. We need to know it's Alan and Brian to now this workload needs to access the resource and I need to know that that workload is one that I have, you know accounted for authorized and it should do so and then even the kind of third lane that is more granular.
How do I manage those permissions too? Right? So that workload may have access at this time and date and and you know within this context but I had another time date and context it may not and so I think that kind of marriage of all that Nation required rapid change, right you need to be able to support maybe even a femoral types of authentication and workloads in there.
And at the core of that is that you know, like you said identity and then authorization and underneath those even if you look at new technologies like Windows hello for business, right? They've kind of rolled that out and came into that space underneath that is pki right so fundamentally PK has what is powering the access and roles and authorization of what's controlling that environment you expand that out and it's the same thing when I you know, when we talk to Dev a lot of devops customers Mutual authentication between those workloads IE machine identity. They're using pki because it's a trusted way that they can run loads in a cloud that they don't control and then they can as a scribe and identity and make sure that it can access other workloads and other you know Cloud where they don't control the data center, but they can control the cloud itself.
And so, you know, it's at that core that we have been working with customers. And it's weaving in at all those points, you know, not just the adoption of pki to be used for all of that exchange of identity and information but doing it the right way like you said earlier. There's a lot of ways you can mess these things up and you know, we try to enhance standards and and you know work with different software vendors and folks to make sure it's it's going the right way.
So generally people can default into a mode of trust but like you said people can customize things all over the place and that's where they can get into trouble and that's where we kind of come in and help folks. You know. Hey, this is the right lane.
This is the right way whether it's an industry or a customer and this is how trust can actually be communicated in here in a safe way that is repeatable. And it isn't that thread that's being pulled apart because it's somehow weak Link in the exchange of information and identity. Absolutely, you know listening to your talk.
I think you know this whole Cloud native microservices architecture that we've has become sort of the new standard right for compute stack today. It's also based on trust. It's also based because we're using you know.
Containers that have a lifetime of five minutes or less and each container. I wouldn't this containers talking to that container or this service is talking to that service. I got to trust Right, and I want that trust to be easy.
I'm not looking to reinvent the wheel there necessarily right? Let's If you know don't fix what's not broke, so that that's just another huge. You know kind of example of where trust comes in just internally right here because we do have so many third-party dependencies Yeah in our software today and everything else.
Yeah anyway. Good, right. I was just gonna add and I think it's interesting because a customer specific like customer maybe about eight years ago.
They came to us and they maybe nine years ago. They said hey, I need very short lived certificates for these ephemeral workloads because I'm doing this authentication and trusting it for me personally. It was the first time I had heard a customer say I need certificates that are gonna last 10 minutes or four minutes, right?
You authenticate these workloads and it was really yeah because it's like, well it is because why should I pay for a yearly fee for them? ing around from like you're filling up a portal with certificates that are very short-lived and you're having millions of these things as opposed to yesterday. You had thousands of these things.
There's a whole different shift of management that needs to go along with that. There are patient that's needed to manage that right. There's all this other stuff that happens once you shift to that cloud like you said and I think it's interesting.
Yeah, the scalability. It's such an interesting area. It really is it really is Bryant.
You know what I'm gonna talk to them. We should just do it a whole show on these kinds of things because these are real issues like even from making people understand the basics of pki all the way up to. How how certificates work with containers and you know and if ephemeral kind of instances, but we don't have time today.
I'm afraid but hey man, it's great seeing you. Thank you for coming on text strong TV. Say hello to our friends all our friends that did you sir?
Well, hey back on soon. Thanks Alan. It's great to see you again.
I appreciate it. Alrighty. Brian Drew Peck here SVP product the digicert we're going to take a break on Textron TV.
We'll be back in a minute trust us. All right.