MFA Integration with Vault – Paul Trulove, SecureAuth
SecureAuth CEO Paul Trulove explains how multi-factor authentication (MFA) will be integrated with Vault from Hashicorp to better secure secrets.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Paul true love who's CEO for secure author. We're talking about how our culex has been integrating with the cloud platform from hashicorp known as Bolt that a lot of people use to keep their secrets and their applications. But the question then becomes how do we kind of make that easier for everybody else Paul walk in the show.
Glad to be here again. Good to see you. So walk us through exactly what you guys are doing with the hashicorp.
And how does this all come together in a way that makes everybody's security situation that much better Yeah sure thing. So how she Corp obviously is is widely deployed, you know from a vaulting perspective and a wide range of cloud devops environments and customers because they utilize that really to store the keys to the kingdom but they're still in administrative capability to get into that product from a password perspective, you know are some what exposed to the the same, you know challenges of username and passwords and any application. So what we're helping hashicorp do by integrating our archulex product is really bring that that next Generation multi-factor authentication but do that in a very frictionless passwordless way.
So by layering on top, you know, we create that that very seamless way to access the hashy court Vault without having to jump through a lot of Hoops and doing that reduces friction, but also improves security You think the bad guys are shipped in their focus a little bit. They were fishing individual developers, but maybe they figured out hey, there's this thing called Vault and if we can fish that we'll get all the secrets. We definitely seen a transition.
I think you know account takeover can take many forms and factors individual, you know fishing to an individual obviously takes a lot of time and if you can get to something where you know, a lot more data is stored especially around something like a cloud system, then you can can move you know, horizontal horizontally and vertically much faster. So yeah, I I think anytime you have a central system. You have to be a little bit more careful with it than you do individual accounts and applications.
everybody and his brother is talking about not only just shifting security left towards developers, but they're also talking about zero trust. What's your sense of the progress? We're making on both those fronts.
You know, I I think look it it's a long term evolution. You know, some organizations are ahead. I know I was was speaking in a conference this week and kind of did a show of hands in the audience and and just said, you know, how many of you have actually rolled out this kind of a technology.
It was maybe you know, 15 20% of the room and I I think that's probably true for you know, both the shift left movement, but more more important zero trust in the zero trust world. One of the things that I have seen happening over the last few years isn't an acknowledgment that zero trust is much larger than I think a lot of people initially imagined it to be started off much more on the network side. And I think as we've rotated back towards identity and I did any security being the center of a zero trust people recognize that they may be a little bit further behind on the maturity curve for that area.
And so it's going to take longer to you know, really get to a long-term, you know point of view on zero trust in their organizations, but people are making progress. So what makes shifting towards an identity based approach to security difficult. I mean, what's the hurdle that people encounter?
I think people understand the general idea and the philosophy but one of the encounter when they go to do it Well, a lot of Legacy complexities, I think I am over the decades that I've been doing. This has been fraught with a lot of complexity and a lot of stagnation in terms of its ability to you know, really help an organization Embrace rapid change in the Enterprise. And so, you know, if you think about a large financial institution on one side, they're trying to boldly embrace the cloud and Sass applications on the other side.
They may still be right, you know running a Mainframe. And so when you're trying to bring a zero trust architecture and approach to all of those very disparate systems, it takes time to be able to go in evolve your identity platform, you know, figure out what the right, you know balances between security and user friction, you know, when you look at it through the lens that we do on the authentication side and it just it just takes time. So sometimes you know, I I think unlike an application when you have an Enterprise platform in place the time it takes to you know retrofit.
Migrate it, you know move to the next generation is typically measured in years and sometimes decades not you know months or quarters. That seems to me in the core of the issue. I mean each platform has its own way of managing identity in each application has its own way of managing identity and somehow or other I want to unify all that.
I'm how much effort is that really required? Because it seems like yeah every time I add a new app or a new platform. I just make the situation worse.
and in a lot of ways that you do I was I was chatting with a old colleague of mine that that works at large Pharma company a couple of days ago and one of the things that he said that they were struggling with is the fact that so much old technology is embedded in their operational processes. That they're running. Platforms that have been decommissioned by the vendor, you know, sometimes five and ten years ago because they can't afford to take those systems offline to do an upgrade.
So when you're battling that on one side and you've got the next sometimes you just have you almost have to split the environment for you know certain period of time which is why Technologies like what we're doing on the arculic side become important because it can become a layer over those Legacy platforms and allow you to start improving things without necessarily having to rip and replace that Legacy infrastructure. I was having a chat with somebody about secrets and the management thereof and It was their position that some of the older developers are worse than the new developers because the older developers have been just going to put in secrets in there and clear text in their applications for years is kind of a a back door work around during the development process and then they forget to take them out and lo and behold they show up in a production environment. So is this somewhat of a generational issue do you think I think it is.
I think I think as more and more of those Legacy applications are decommissioned and you know, you move to much more modern paradigms for whether it's Cloud SAS development. You know, you're going to see removal of some of those bad. Not best practices but old practices and in favor of new technologies and new platforms where you know, the developers don't have to think as much about building that component because they can pull that in from one of the you know, one of the cloud platforms like AWS or azure.
Now there are other ways of managing secrets. So is this the first in a series of things you guys will be doing to make it easier to access these kinds of repositories? Yeah.
No, we see Hashi Corp is you know one area that that you know organizations are using for this there are obviously, you know, a wide range of other other Technologies. So we you know, we'll continue to forge, you know new new industry Partnerships and then support, you know, the technical and integration on the back end but this is something that we're super excited super excited about and I know the hashing Corp team is too. One of the things that people are concerned about these days is that there's all these generative AI platforms that the bad guys might get a hold of and then they'll be able to create a artificial representation of somebody that might fool something in the next thing, you know, they're hacking and everything.
So how do we make sure that those artificial identities don't get access to things that we don't want them to get access to I I think we're going to use artificial intelligence to do that. So one of the things that we we are really excited about is our AI ml-based risk engine and it can look for those biobehavioral patterns, which are very different when you have automation doing something versus a human. and so if we expect a human identity to be authenticating whether it's into something like Hashi or something else, there's a there's a bio behavioral pattern that that transaction should follow And by looking at authentication is a much more continuous process where we're Gathering Data before the actual authentication event and then continuing to gather data post authentication after authorization.
We get to watch and see and we can compare now there are certain systems that may actually be intentionally accessed by automation. Right? I mean that that is a use case today.
And so we just have to be able the engine has to be able to recognize those differences and if it's a human identity and it's starting to act like an automated bot then we can take additional steps and and either do stuff about authentication that only a human would be able to interact with or decommission that that particular session and enforced, you know reauthentication from the very beginning. So in a way, you know, it's like the old adage Fight Fire with Fire I think. You know as AI is starting it starts to be deployed as a threat actor.
We're gonna have to fight that with AI. All right. My model can beat up your AI model.
Um, the next question though is do we think too much about identity as associated with humans, and we're not realizing that applications have identity machines have identity. I mean might identity can get pretty granular. Identity is is very complex and very granular and and I think the entire I am industry has recognized that we're not only trying to deal with human identities, but I think a lot of customers have to also Embrace that same paradigm shift and understand that you know anytime.
I'm letting something access an application data store, you know platform. I have to understand that it is fundamentally and identity and needs to be managed. It has a life cycle it has, you know certain things that it can and can't do and you have to be able to to enforce that and I think it's one of the reasons that we've seen new vendors coming into the landscape that are only focusing on machine identities, you know as their primary, you know purpose for being but at the same time, you know, I also worry a little bit about you know, so many disparate points of view and and you know, my models being created that we don't we don't really centralize them and bring them all back together.
So you get that That one universal view and control point for all identities no matter whether they're human or machine and no matter what they're what the end identity is designed to do in a lot of organizations. They're still struggling with the idea that they have internal identities that are full-time employees. They have contractor identities that you know need a different set of capabilities.
They have Partners or B2B, you know people that need access to internal systems and then you start layering in all the consumers and citizens and everybody else. It begins to be very complex that gets magnified. You know, when you when you look at it through the the non-human identity world.
And what's your best advice to folks about how to get started with all this because it does seem to me that there's a certain amount of inertia in the system. Right people have been using passwords since the first caveman grunted who goes there. So, you know, how do we move from where we are to where we need to go?
Yeah, I I think two things are probably important one is is people ought to spend time really mapping out what that long-term strategy is for their organization. Where are you today? What's the maturity curve for each of the major elements look like and and how do you want to get there?
I think a lot of people sometimes end up being very Tactical. Risk responding to a breach responding to an audit deficiency. And that's fine.
Sometimes you have to do that but really sketching out where you want to be in terms of your kind of zero trust identity, you know Centric security strategy is complex and it takes time to really know where you want to go. But if you don't take the time to know where you want to go it's hard to end up in the right spot, but then behind that I think you have to be willing sometimes to to take a stepwise approach. You're not going to go solve that in one Fell Swoop.
So, you know begin to think about where you can have the biggest impact for your organization today. And then how does that layer into that long term strategy and take those those baby steps towards that that you know longer maturity cycle, but make sure you're having a tangible impact on on the business and and the other thing that I would say and this was a big theme at the conference. I was at this past week is you've got to balance use your experience and Security in a very different way than people have in the past.
I think as security practitioners, especially for Workforce and other other kinds of identities. We felt like we had control over the person and we could just Force Security down their throats. There's a real backlash beginning to happen.
And so I think people have to to decide how do I make this security experience more user-friendly so that people Embrace and are part of security not fighting against it. All right, folks you heard it here. If you're approached to identity is somewhat schizophrenic.
The good news is you're not alone, but you guys should start thinking about how to kind of work your way through that whole process because otherwise you're just going to drive yourself and everybody else even more crazy than we already are. Well, thanks being on the show. Absolutely great talking to you.
All right back to you guys in the studio.