Evolution of Digital Trust with Amit Sinha at RSA Conference 2024
Amit Sinha, CEO of DigiCert, discusses the evolution of digital trust from verifying people to machines and now to content. He emphasizes the need to address challenges posed by AI-generated content and prepare for the impact of quantum computing on cryptography. DigiCert has designated Sept. 26 as International Quantum Readiness Day to raise awareness and assist organizations in adapting to the changing security landscape.
Transcript
This is Textron tv. Hey, everyone. We're back here Live in San Francisco for our r continuing RSA coverage.
It's Wednesday. I guess technically it's day three of RSA. The whole lot kind of took place the first two days.
Uh, this is to me always the, this is the Hump day, right? Yeah, this is the work day and, uh, we've got a lot of going on here. We're happy to join us.
I'm joined by a good friend of mine, Amit Sinha. Amit is the CEO of Digi Cert, or Digis Cert. Uh, if you're not familiar with Digis Youer, you're probably a customer and don't even realize it, but Ahmed will explain that to you.
Ahmed, it's a pleasure to have you back here. You, you always visit us at RSA, or actually, I, like, one of my favorite conferences is going to your user conference. Oh, That's awesome.
Thank In Vegas. Uh, when is that? This year?
Is that, um, Yeah, we had, uh, our Digital Trust Summit last September. Right. We're actually doing a Trust Summit Road show.
We're Taking, oh, this year we're doing a road show To six cities. I'll be in London and Munich, uh, next week and then followed by Melbourne and Tokyo. So we have to ask You back world.
If you want to take me to Melbourne. I'm always down for a trip to Melbourne, But One of my favorite cities. I appreciate that, man.
And I've never been to Tokyo, so I mean, we could do that too, but we could talk. Um, anyway, Amit, as I said, if they don't know who DigiCert is, they're probably a customer. Yeah.
Tell them a little bit, if you can, who is DigiCert? What is, what's going on There? Uh, so, so DigiCert's, uh, the global leader of Digital Trust, digital Trust is foundational infrastructure that makes sure all our interactions that we do online, you know, between users and businesses or business to business is secure and trustworthy, right?
Yep. When you connect to a bank, how do you know it's the bank's legitimate website? How do you know your communication is encrypted?
When you download software from an app store, how do you know it's came from Apple or Google? When you sign a document, you know, how does it hold up in a court of law saying, Hey, Alan really signed it. So all of this is based on cryptography, you know, authentication, encryption, and, um, DigiCert's the leading provider of, uh, of solutions and infrastructure that makes it happen.
Absolutely. So, Amit, you know, I, I'm familiar with DigiCert for many years already. I, I've been in this industry for a very long time, and I, I've seen a real evolution around this whole concept of digital trust.
I think when I first became cognizant aware of the whole digital trust issue, digital trust was a people thing, right? Right. Digital Trust was, is this really amid, is this Alan?
Are they really them? Right? And, and it e-commerce, right?
Am I really connecting to the bank that it says it is? Am I, I really, you know, that kind of thing. Then with the rise of Internet of Things and the rise of, uh, you know, the whole machine identity, digital Trust became not just trust of a person, but trust of a machine.
Yep. Was this really, that website, was this really that sensor? Was this Yep.
And, and funny DigiCert remained at the pinnacle of each of these movements, and, and the funny thing is, we went from having, I don't know, 400 million people on the internet. It's a 600 million to literally billions of machine identities, and you guys are securing and allowing us to have trust in all of them. Yep.
Now, for the first time, I think we've entered a third era of digital trust. Yeah. Right.
This third era is trusted content. Absolutely. Yeah.
New ball game. Yeah. No, look, Are we throwing in the cards up?
What do you, how do we do this? Oh, look, you know, you're absolutely right. I mean, dig has been in business for 20 years.
Mm-Hmm. And, um, initially trust was about, is this my banking website? Can I trust it?
Right. Uh, fast forward to, to, to today, there will be 75 billion iot devices, 10 times more than humans. Yeah.
Um, so DigiCert, for example, uh, provides identities to a billion TVs in Europe. Oh My God. We, Uh, uh, you know, we are providing birth certificates to air conditioners in India.
We are, uh, getting into EVs, you know, we are the first neutral certificate authority for North American plugin charge stamp. Really? Okay.
So we connect your ev and you Know how we know it's really you, you can tell me if they're really working. I've had problems. Put that to whole nother story.
It's early age. Yes. But, but you can imagine, you know, you connect your car to a, uh, to a charging network.
How does it know it's Alan's ev I get it. And the what account to Bill? So you're absolutely right.
I mean, the, the number of things that need trust at a foundational layer is just exploding. Now, you know, 80% of Fortune 500 are DigiCert customers, and they originally, you know, interacted with us on websites and securing kind of their public domains. But look within all of these organizations, and it's not uncommon for them to have, you know, hundreds of thousands, if not millions of cryptographic assets from workloads to servers, to machines, to iot, OT devices, and they all need identities.
They all need authentication and encryption. And a huge challenge there becomes how do I manage trust lifecycle across all of these devices? Because, you know, the validity durations and secrets and keys are getting shorter lived, and you want to make sure that you are first issuing, uh, these tokens to the right devices, and then kinda managing the whole life cycle.
Now, you made a very interesting comment. So we've talked about, you know, in a typical enterprise, there might be servers, load balancers, Kubernetes workloads, user devices, uh, for email encryption for wifi authentication. But fast forward to today, the theme at RSA is all about ai, right?
Um, and the same cryptographic mechanisms have been used to secure content. For example, when you sign a document, it is using, you know, the same RSA mechanisms or are signing mechanisms to, to lock down the content so you can edit it and have a signature on it. The question these days now is, you know, we, we live in a world where, you know, AI is generating content, right?
What are some of the new content challenges? Um, and DigiCert's helping in two ways. Uh, the first way, which is very obvious, I mean, you're in the media business, right?
Um, how do I know that this video that we are recording and is released later on, uh, is, is authentic. It's not being edited. Maybe someone deep fake something that I didn't want to say, or maybe, you know, uh, or am I really Allen?
Yeah, you're not really Allen, right? So how do I, uh, so we are working with a lot of, um, uh, content platforms and content creators to be able to certify authenticity, right? Mm-Hmm.
Uh, that, hey, this is really a tech strong video, right? And, uh, you know, here's the timestamp, here's the metadata, here's the list of changes applied. Here's the ownership, right?
So it's called kind of the manifest of content digitally signed, so you can't, you know, tamper with it. Um, so that's one area and, uh, we're working with, uh, you know, the usual suspects and we influence a lot of industry standards in this, uh, area. The second, which is a huge theme around is how do I trust ai?
Right? That's a wild, wild west. And is that a bit of an oxymoron?
You know, look, um, if you look at these large language models, right? Um, I saw a demo where, uh, all these LLMs have been trained on, on kind of the knowledge on the internet, right? So they kind of know everything.
But if you ask an LLM, how do I rob a bank? They'll say, well, politely, we're not allowed to tell you that. Because after that training, they've been trained on values, right?
Okay. Now, um, all of these open source models that are out there, you can go ahead and fine tune them with your data and actually inject back doors. You can override their values training and absolutely inject back doors.
So the question, uh, in a lot of, uh, enterprises minds is, my developers are downloading all these libraries and these cool, you know, uh, ML models, but I don't even know what's inside them, right? Uh, maybe it has a back door, and it goes back to that whole software supply chain integrity with all this AI getting injected into it. So there again, you know, we, we work with a lot of software companies.
We integrate with their DevOps and CICD, uh, we can inspect software. We can tell them these are, uh, these, uh, these libraries or these models are certified and they're good. And if you use these kosher components, right?
What you're shipping out is generally trustworthy, and we sign it, right? So just like you trust an app in the app store more than something that's out in the wild, wild west, you know, you want to get to a place where can the software supply chain with all these AI models is producing trustable software with a bill of materials and all the, uh, associated standards, Everyth, everything talked about. And it, look, it's the biggest thing.
Well, AI is the biggest thing, but software, supply chain security, s bombs, all this is also Yeah. It's Exacerbating the problem with ai. So you're, you're right.
Like now we are talking about, we started with trusting web servers, then we went to trusting servers, workloads, infrastructure components to users, to devices, and now we are getting into the world of like content and software. So speaking now as a content provider, it irks me that my content that I pay good money to produce, right? Right.
Is out there being used by these models Mm-Hmm. For these things, and I, I'm of two minds. One is I'm flattered, but I'd like to get paid for it.
Yeah. Two is I'm really, I'm like cutting my own throat because I'm, I'm giving my advantage to other people. And underlying all that is the, is the, uh, possibility that it could be subverted sort of used against me, if you will.
Yeah, yeah. No, you're right. Right?
Because it won't be real or what have you. Yeah. No, and, and this, this is a problem for me.
Problem. Well, look, I mean, this is a hairy media rights problem in a much bigger scale, right? So, um, look, there are companies working on, uh, training, data governance, and the ability, uh, to ask Alan, Hey, Alan, you know, do you give me permission to use Yes, your, your content to train?
Is it really, Alan giving you permission is a whole threshold question, And that is a big problem, right? So It's like a Russian doll kind of thing. There's problems with problems with problems here, but nevertheless, it's something we need to figure out.
No, it's, it's a, it's a larger problem to solve, uh, digital rights management for training data in this crazy world of ai, right? But you know what, at the end of the day of it, it's a great problem for, er, it sounds like business to me, right? I mean, this is something You guys can really jump into it well behind, behind trusting content certifying it remains the same.
Absolutely. One thing I will mention, there's a lot of talk around quantum computing, and the reason why there is so much discussion is because the availability of cryptographically relevant quantum computers is a extinction level event for all of the trust that I talked about. Right?
Exactly. Because they based, there's No horizon thing, Because all the math, Like, we don't have enough to worry About all the math, all the math that protects all the stuff that we talked about is based on, uh, is based on the fact that, uh, current computers will take tens of thousands of years to, to break those codes. But a quantum computer can do those, those things in minutes.
It's just the availability of stable cryptographically, uh, cryptographically relevant com from computers. But the funny thing now is like there's an arms race going on between Microsoft and IBM and Google and Microsoft and Continuum just announced that they have error correction in quantum computers Yes. That are a thousand x better now.
Um, so I look at this as like a y 2K times 10 problem of our generation without a date, right? Right. Open ended, Open-ended, but nist, for example, as released those four algorithms for which are, uh, quantum safe, right?
Right. One for key encryption and three for signing. I mean, it's basic plumbing, Right?
It is back to like, Hey, give me something better than RSA and Diffy Hellman. Uh, and, uh, that is gonna get released, uh, as FIPs standards. That's what we hear.
So, um, a lot of the conversations that we are having with our customers is, how do I prepare? Uh, and it boils down to basics. Step one, you know, have a inventory of all cryptographic assets within your organization, and our trust lifecycle manager will scan your network, will work with, uh, agents and tools within your environment, and give you a full inventory.
Then you, then you start working on prioritizing and automating. For example, you know, in order to be crypto agile, you can't wait for QD to happen. I agree.
And then say, oh my God, I need a five year plan to replace all of these things. Right? So progressive organizations, Alan, are just, uh, you know, doing the lifecycle management with discovery automation and, and then, uh, when, when p qc standards are available and post quantum certificates and post quantum key encryption is available, you start swapping these things Out.
Don't put it there, but you know what, so not to pat ourselves on the back, right. But the quantum one is one where I feel we, we did see it coming. Yep.
We have done some really foundational things that are making this better. And, and I'm, I don't want to use the word confident. Yeah.
But I'm optimistic that we got the tiger by the tail here, that we are going to make the, this isn't gonna be an extinction level. Yeah. Just like Y 2K didn't shut the world down.
The moves to quantum won't shut us down here. Either way, we're on top of it. Yeah.
I think the, the bigger issue, I think from a lot of people's point of view is like, let's call it the boy cried wolf, which is we've been hearing quantum, quantum, quantum, That's part of the challenge. But I think, look, NSA has been working and NTA has been working on this. The standards are out FIPs standards, you know, I think they're called 2 0 3, 2 0 4 and 2 0 5 for signing, and key encryption will be out this summer, right?
Um, you look at CloudFlare blogs, they'll talk about some close to 20% of traffic to them using quantum encryption, right? Uh, for key for keys, um, Chrome, the latest browser version supports quantum key encryption, right? Um, so yes, you know, quantum computers have always been a 10 year horizon event.
And that's been part of the challenge because, you know, CSOs and security organizations have so many issues and problems, and how do I prioritize my calories? You know, there's zero trust, there's identity, there's ai, and when they hear a, the quantum computer is five years away, they're like, okay, let's wait for, yeah. Got five years.
Yeah, I got five years. Talk to me in four. Yeah, talk to me in four.
But the issue is that this is kind of core infrastructure upgrade, right? Like you, so you need to start preparing for crypto agility and at least look at your crown jewels and, you know, what are my long-lived software libraries? Do I have 20-year-old contracts that need to get, you know, uh, re-keyed and protected?
Um, you know, if I'm launching satellites, I'm not gonna send another rocket behind it to do A-A-P-Q-C upgrade. So it's expensive. It's an expensive pro.
So, you know, to kind of bring more awareness, especially with Chrome and, and, uh, CloudFlare and all of this, uh, we DigiCert announced, uh, September 26th as, uh, the first International Quantum Readiness Day. Right? So Hold on.
September 26th. Yes. Quantum Readiness Day.
Yes. And QRD. QRD.
Okay. I like that acronym, sir. Yeah, everything's an acronym.
Gotta get a marketing team. But, um, so what are we gonna do? Our QRD?
Well, Look, uh, NIST standards will be out there. You know, we are going to talk about, uh, what's, what progressive organizations are doing. What can organizations that are struggling with budgets and priorities start doing to prepare?
What are some of the best practices? I mean, a lot of the challenge that organizations have is it's such a big problem, they don't know where to start. Yep.
So, you know, we have launched A-A-P-Q-C advisor program where our experts talk to organizations and kind of guide them, Hey, step one, let's build an inventory. Step two, let's figure out, you know, what are your crown jewel things and what needs to happen there. And here's kind of a plan.
We've, uh, we've launched a PQC lab where people can play around with, uh, you know, PQC, uh, based digital certificates. Mm-Hmm. You know, measure performance, key sizes, just kind of get their hands dirty in a real sandbox, right?
So, uh, international quantum readiness days to bring more, uh, visibility and kinda raise the industry awareness to all this. How can our audience participate in this? What could we do?
Or, or is it too early yet? Stay tuned. You're Gonna hear, stay tuned, you're gonna hear about a lot of things that are happening.
com/labs and you can play around with our p qc labs. Um, you know, if you are struggling, you know, reach, uh, reach out and we'll be happy to connect you with our, uh, PQC advisors that, you know, will help you with crypto agility even today, by the way, even if quantum computers never happen, which is unlikely, right. Topic.
The crypto agility is such an important thing with all the, you know, Microsoft's gone into problem with key management and, you know, secret durations are getting shorter and shorter. And, uh, CSOs today struggle with outages. Even basic things, you know, a, a critical service has a, has a cert that expired.
Right. Even Elon Musk wasn't immune to it, right? No.
We, he tweeted, tweeted about, uh, uh, the Starling ground stations globally being down because of an expired cert. Right? So the ability to kind of manage, um, uh, your cryptography in a, in an automated way across the lifecycle is a very, uh, core requirement with or without quantum computers.
Absolutely. And it currently helps you with, with quantum. The quantum, you're gonna need it.
Yeah. September 26th, remember that date? Okay, we got that.
What else? Well, look, uh, the future for dig sets, right, Alan? Um, I just hired a new CFOA new CMO and a new CRO.
Really? Yes. Good for you.
I'm glad To hear that. And, uh, you know, we're kind of marching towards, um, a billion dollars in annual recurring revenue. We're a private company.
We don't publicly talk about financials, but we are a very strong Business. But that's, yeah, that's a great, and, uh, That's a big mark and, you know, we really are grateful to our customers and partners for trusting us, uh, because it's trusted, But, but that trust is nerded. com.
com. Dot com. Check it out September 26th.
I mean, it's always a pleasure to see you, man. Thank you, Al. Good luck on the rest of your world tour.
Right. Thank you. And, uh, hopefully we'll catch up again soon.
Always, always. If I'm chatting with you, thank you for Having me. Pleasure, man.
Alright. I, I'm in now CEO of DigiCert here, our Techstrong tv. We're gonna take a break.
We're back on live at RSA all day. Awesome. Stay tuned.
Thank You.