Arculix – Matt Ulery, SecureAuth
Matt Ulery, chief product officer for Arculix by SecureAuth, explains how passwordless technology developed by the FIDO Alliance will be applied to secure infrastructure.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Matt. Ooley. Who's chief product officer for kulik's by secure.
Auth? We're gonna be talking about passwordless access to infrastructure. So we're getting rid of those passwords.
Finally. It's been a long time coming and there's a whole effort called the Fido Alliance and archulex is contributing to that effort on the infrastructure side, but let's jump into it Matt. What exactly is this photo Alliance about we know that Microsoft Google and apple are involved.
But how does it apply an infrastructure? And where are we going? Well, the phyto alliance is a group that's been around for a while now and they started with a mission on moving to a password.
This world the first step. They took was basically making integration with authenticators ubiquitous. So their first version is they they delivered a common protocol that allowed everyone.
To be able to work with almost any authenticator. So the authenticators could support the protocol and then any vendor could support it. So they really opened up the flexibility and options organizations had to just use a wide range of authenticator.
Simply. The next thing the phyto alliance did with was Fido too. Was it became part of w3c.
So it became part of the web standard and enabled passwordless authentication for web applications and websites. What they've done what's happening more recently, which you just referred to is I considered the third major phase. Is that Microsoft Google Apple.
These major players are adopting more of the phyto protocol deeper into their infrastructure, which is really helping the industry gain much further momentum toward a true passwordless environment where it's not just for the web applications, but all the things around the the operating systems and and the systems that make it a little difficult to provide for passwords now, there's still a password. And you have occasionally have to work around things in the operating system. All of these are being phased out.
There's more to this and I'm excited about it. Some of the things are allowing for things like omnichannel. So I'm pairing a device with myself.
I can move to another device. It's also paired with me and I have a streamlined password authentication across both. It's both my identity is recognized on both.
These are these are major shifts forward for usability and balancing security and usability How will that get apply to infrastructure than I mean it people have been using credentials and passwords to access things using certificates. And we all know that there's probably more back doors in the systems than we should probably admit but, you know people like to have quick ways into things. So how will this change the way we think about accessing infrastructure going forward?
There's a number of things there everything from the typical end users and then the admin so I'll go ahead and take both of those on from the it perspective. I've had conversations with ciso's directors of security directors of identity for a while now infrastructures teams, and they're actively moving to put MFA but the MFA burden starts to be intense where people have to do non-stop multi-factor authentications every time they're accessing applications resources doing infrastructure server updates what's happened over the years is adaptive authentication has allowed that to limit the number of authentications passwordless. Let's take it further.
So the password just is no longer part of that MFA Journey. I get to do a more streamlined journey. I might move to I might stay with multi-factor.
I might go with single-factor biometric. So the admins who are accessing the infrastructure the certificate-based approach things like a virtual smart card these types of approaches just become options in that larger scheme and I just get to take password and all the human risk that comes with that all the credential risk that comes with that and just ignore it. I have to go around it and use these other options.
For the end user side not admins. I have security teams and it teams excited about how they're going to be able to provide a much better end-user experience for admins and normal users while the same time not giving up security actually doing moves to improve security at the same time. Does this mean I'm out of the business of managing Secrets or am I just managing them different differently.
It's a very good question and the answer is I'm not out of the business of managing Secrets. I just have different Secrets. Um, the certificate example is there I'm still going to do Secrets management.
I just will be doing fewer password ones and more certificate ones more keys that I'm going to be managing on the password side. We're still not at the point where the passwords are gone. We're still on that Journey with the phyto alliance is doing along with these major vendors is actually moving us along that path.
It's a good and exciting step forward. But yes, the shift is happening to where we're going more to nonpassword Secrets as opposed to password sequence. How long might this journey take and if it's not a password then what does it look like?
Is it biometric? Is it something else or how do I manifest the actual credential? in this case There's a variety of things and some of what you're asking is part of that Journey.
So am I going to get to the point where the operating system has? No password? Today for instance with Windows.
Hello. There is a password under the covers. If you look at what Mac is doing the Vault again, they're Secrets being managed.
Um, there are options for applications and devices where you're using things that the features are called virtual smart cards and under the covers. It's a certificate. So there's going to be some type of certificate or key period because we have to The nature and how we exchange them under the covers deeply we'll probably stay close to the same.
But the idea of having to do a password doing password resets having credential stolen. These will be gone and I'm going to start a tying the Biometrics to certificates and what they're looking to do with phyto alliance with phyto 2 and the operating system is actually being able to use some of these certificates shared across different devices that are bound to me. So I validate I need to that device that Associates with the certificate then that's used to basically as a credential as you described and I'm able to give access so these are major move forwards where I'm removing the human risk from it.
I still have credentials of course because I still have to have an identity. and will we still be in the business of changing and updating passwords though? Because it seems like yeah half of the request for support involves somebody sending an email going.
I forgot my password or I can't remember my password and there's a lot of Automation in that space but there's still a lot of manual efforts. So can we get out of that business? We will be we're definitely on a road where that that effort will be reduced to the point where it eventually goes away.
I look forward to the point where it eventually goes away when I look at this and have conversations with organizations. There's the cost that everybody's familiar with of the F costs of help desk supporting me through this process the cost of automating that process there's the cost of me distracting myself from the work. I'm trying to do to reset passwords.
Getting to the point where I never issue a password to the user will be a step that occurs before we get to the point where they're probably completely out of the operating system. I may be wrong here, but I'm expecting a flow to where the password might be an artifact under these to covers that the user never gets then it will go away the the operating systems might move faster than that, but that's more or less the path. I'm expecting if you look at what Microsoft's done with Windows.
Hello, even before 502 you can log in with a pin you can do these things. They're just keeping the password in the background now if I can sign up and never see my password and I'm just using with my facial recognition and pen. I I it's already a major step forward because I'm not touching managing and messing up my password let alone all of the additional efforts of password complexity software that allows for denied lists and all the other things we use to make customers and end users lives complicated dealing with passwords letting them all go away.
One of the compliance implications for this because a lot of times when you're trying to achieve compliance, you know, you're trying to prove that the passwords were handled properly and so can we skip that too? It will definitely make a change. What's interesting is as passwordless.
Was just starting to come and with phyto 2 and the web-based past with us the most common question. I had from leaders of identity and security was on the side quietly. Hey, do I have to give up MFA to get past with us the answers?
No you do what makes sense for the risk of the situation for the context for the user to get it secure access and deliver the right user Journey but to your question where we're going with this is I need to have the right controls that control is basically going to be maybe it's something around nist. Maybe it's something you're doing a little more specific to your industry and focus where you need to have it and the level of authentication or a little confidence the users who they're claiming to be not just the initial login but over time. If I'm doing that with a certificate a smart card Biometrics, I'm still going through the right hurdle.
I just don't have to do what the password and all of the other controls of the passwords. Go away. Your other point from earlier is still very valid.
I didn't get out of the business of doing Secrets. I just have a different secret. So all the compliance controls around that remain.
Yeah. What's your best advice to folks about how to get started with this? I think a lot of people kind of like the general idea, but I have no idea how to go about actually, you know beginning this journey without trying to boil the ocean.
So what's the simplest thing I can do today to kind of get my organization moving down the path tomorrow the customers that I've seen that are most successful internally. So skipping all the technology for a moment the ones who are rolling it out and having the biggest impact internally are usually starting with a certain population within their organization accessing a certain set of resources and making that past with this getting people excited. Then getting other people to ask for it and then start rolling it out further in the organization.
I'm working with a current customer a large bank that's focusing first on their Mac OS so logging in passwordless to to the Mac OS and then doing non-interactive logins from there. I have other customers that started with all of their admins. I have another group that starting with they actually were trying to drive funding and started with their executive team and it's very working down.
So really it's getting that early success with a key set of applications and users. Showing that to the rest of the organization and expanding but it's it's not difficult with the right Solutions and there's some options out there. All right, folks here to here first we might get to the point where it people are not essentially glorified police officers keeping access to controls the systems and we can move on with our lives and do something a little more rewarding.
Hey, man. Thanks for being on the show. Thanks for having me.
All right back to you guys in the studio.