PingOne Neo – Frank Cardello, Ping Identity
Ping recently announced PingOne Neo™, a multi-standards decentralized identity management solution. Many digital services require verified information about people to do business.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Frank Cardello who's executive advisor for paying identity and we're talking about a decentralized approach to managing identity. Hey, Frank, welcome the show. Thanks for having me.
Nice. Great to be here. I definitely of course is at the root of any approach to zero trust these days but there seems to be a lot of different approaches.
What does it mean to have a decentralized approach versus what else we might be seeing out there. We'll decentralize approaches are are you know kind of the opposite of centralized approaches where the identity information about the user is resident with the user on that user's device and in control of that user providing access and consent to their information as opposed to having that information being stored in a centralized repository in traditional models. Are there different use cases where this makes sense for instance?
Is it better suited to I don't know a b2c kind of scenario versus B2B environment where I may know everybody. Well, there are both we see both in the on the consumer side. You're hearing a lot right now about mobile driver's licenses where we're taking what was a physical credential turning it into something digital and putting it on a device of the individual and allowing them to present it for identity purposes.
So we're seeing a lot of those consumer was also plenty of internal use cases in the workforce where You know a contractor has the right to work on a particular piece of equipment at a remote location and they can carry both their identity information and their authorization within that credential and present that credential, you know for access to remote or on-site environments. So we see both right now. How hard is it to set this all up because the perception at least is once you get into something that's decentralized.
It's harder to manage than something in a centralized well. we're not doing this in a vacuum in that there's 20 years of centralized infrastructure that exists that we need to, you know properly transition to however You know a person's identity in their attributes are resident, you know within a database and the actual issuance of that credential to the individual is not terribly complex. The user does need to have say a mobile app or a wallet where that credential can be issued and they need to understand how to present that credential when query by the service provider but it's technically not terribly complicated outside of the the standards work that's in process and needs to be done.
I think a lot of it is how we teach people how to you know how to embrace the new paradigm and why it's a good thing. Is there a way to go after this that's more efficient because at least in the real world per se I have my wallet and I've got a million different cards for a million different things in there. And it seems like the same scenarios playing out in the digital world.
I got different wallets and IDs for different things. Can we centralize this a little bit? Can we bring some maybe order to the chaos or is a good thing to have all these different identities?
um, you know I think we all have one true identity. The question is which identities will be transitional. It will be transitioned and supported digitally and in what order and I think that's why you hear a lot about primary use cases around mobile driver's licenses and starting there because if you don't necessarily have Um, you know a defining credential that represents who I am that's trusted whether you convert a you know, you know, you know any other credential Healthcare card or you know, a diploma or others, you know, the list is endless, but I think where you start matters and and that's why I think you're seeing a lot of States supporting, you know, the the transition or transformation of those physical IDs like a driver's license, that's something digital and that's for the standards have started as well.
Taking the lead on all of this. I mean, is it the security team? Is it a development team or is it someone else in the organization is kind of looking at this and saying we need this more decentralized approach to Identity.
You know coming a lot out of the IAM, you know Architects and security Architects and the traditional IAM space and but that's that's where it tends to be starting because that's after all we're a lot of the attributes, you know are being held it but you're also seeing a lot of the you know, you know business owners who are driving some of the use cases, but we're seeing it come out a lot of the early adopters are coming out of the I am, you know architecture side of the house. We of course have been talking about zero trust forever now, but it's not like something I can go by per se and so do you think people understand the nuances of zero trust and identity and what exactly do we need to do to achieve zero trust? You know, it's a great question.
And I I think people are starting to understand this transition from this transformation of physical identities to digital identities. But I really think the key is going to be the you know, it's one thing if an organization starts issuing the credentials but the other side of this who's accepting those credentials and verifying them is important because that's where usability kind of begins and ends and I think that's one of the reasons why you're seeing at least in in the in the in the government side of things a lot of age verification use cases emerging for for certain types of content or for certain types of sites like social media, I think around 20 States right now are requiring some form of age verification for access to different types of content. So, I think it's the it's the utilization of the credential that's important.
I don't think the average consumer knows what zero trust means. I just think they want a unified, you know experience across platforms that gives them secure access to the services that they want to consume. Now the bad guys have been stealing credentials forever.
So what makes this approach fundamentally different to me won't they just continue to Target people's digital identities? Well, there's two things I think to say about that one. We're changing the attack surface of what's being targeted meaning historically in centralized models the you know, these are databases containing, you know, millions of Records about individuals.
And if you breach that database you gain access to you know, you know a lot of dangerous information. When you issue a credential into the wallet of the user in the user maintains control of that information within their phone now, the attack surface is the actual wallet. It's the actual individual.
So the bad guys are going to have to attack individuals as opposed to databases. So the change in the attack service it is is very important. But there's also quite a bit of Technology around crypto cryptography and public keys that is securing using the secure enclaves, you know on the devices and providing a level of security that hasn't existed in centralized models for the user itself.
So I think we've improved security there's standards that are emerging, you know, that that are that are helping evolve interoperability across product, but we're also changing where people are targeting. How long will it take for this to all play out in am I actually moving towards what people call this passwordless future where I don't have to sit around and remember a 22 passwords that are all variation of the same password that some hacker already has on the dark web. yeah, the reason why I'm smiling was that you my background is that I I was here at I know on Andre Durand and I go pretty far back.
I was with him when when we built. Jabber the instant messaging product and then I was very early here at paying for the first three or four years. And in that time the the Paradigm that we were breaching or developing was a single sign-on after all, you know, paying, you know popularized a term Federation we needed a term to describe what was happening and at that time.
There were many many different protocols that supported the same thing similar things, but whose goal was interoperability? And so Samuel 2. Oh didn't even exist.
We were talking about, you know, Liberty Alliance protocols the Samuel 10 and shibboleth and all the like and the reason why I bring that up is it took quite some time for the industry to consolidate their use cases and have products that were interoperable. And now all we really talk about is Samuel 2, and of course, you know a lot and open ID. Later, but it did take some time.
And the same thing is happening in these use cases that are emerging this Paradigm is Shifting and we're at the beginning of what will be the next 20 years of innovation and awful lot changes when you shift control of identity information about an individual. From a database or centralized control to an individual and I think the early use case is matter. There's there's quite a few standards out there that matter but it will take some time for those standards to mature use cases to develop and consolidate and provide a better user experience.
But this journey has started and and paying has started, you know with our launch of of our Neo product set, which is squarely set on being an early provider of addressing a set of use cases that will be very important over the next 20 years. Do you think that maybe our appetite for digital processes is maybe bigger than our security eyes can handle right now because maybe we're too far down the path and some of these initiatives without really thinking through the identity question of how these things are accessed and safely authenticated. Well, I don't know if I you know.
In these emerging markets in use cases. What's most important is to get started? Take small bites and deliver, you know use cases that bring value that that don't enhance risk.
I don't think you know, I think ultimately Decentralize approaches will present a more secure and more empowered and a more privacy enhanced manner to control identity that said you got to get started and and the centralized models, you know, I want to say they've brought they run their course, but I think over last 20 years. We inherently understand. What makes them weak and what happens when they're breached and that this next generation of protocols Technologies and approaches will ultimately be more secure but we're still going to have to be you know steps ahead of the of the bad guys and but with but you got to get started I think.
If you're in Tech these days you can walk down the street without somebody asking you what you think about AI so here comes that question. I'm does AI have a role to play in all this stuff going forward and what might that look like if it does. Well, we you know, we use AI within the product to gather data to you know, improve experiences, but AI is also a threat and you know.
The way we think about you know AI is that yeah, it's gonna be less and less obvious who the authenticity of an individual we're gonna present very layered and enhanced approaches to first, you know, look in decentralized identity. The first thing you have to do is proof the individual verify the individual you got to know that you're talking to Frank in that Frank is present at the time you're having that conversation. And so these use cases that emerge say talk off selfie for remote onboarding that occurred, you know, during the pandemic to onboard people there's lots of different approaches and ways to attest data about the device there on has a SIM card, you know and changed in that device authenticity a device ownership, but it's going to take a layered approach to both understand and be comfortable with who you're communicating wish before you issue them a credential that they're then going to use to represent the IND.
Visual, you know as opposed to say an assertion from a an identity provider. So they'll be layers of technology that emerge on top of kind of the Baseline capabilities, you know in identity proofing before you're going to issue that credential and trust it. Seamless, you know this again.
I'm asking the question because some people would say any process that you can see is fundamentally broken and security seems to inject itself a lot into a process in ways that some end users at least would you as cumbersome? So yeah, how much better? Can we get it all this?
Well, I think a big part of this is creating an omnichannel. It is improving user experience that the the Federation use cases don't work. Well in Mobile right now, there's a lot of AppSec switching and the like I think a big part of the attraction about my ability to carry aspects of my identity with me and present them for not just authorization, but as a form of identification is Presents a an opportunity to to improve our experience and improve security and and maintain control, you know that you know.
the ability for you know an example, you know, I've got a 21 year old daughter when she goes to a bar and she presents her driver's license you You're handing over everything about her height her weight where she lives, you know everything about her Bowl when the day comes that she can based on her consent just demonstrate that she's over 21. Um, and that that's all that that our restaurant needs to know. They don't need to know anything more than that.
So I think that when you enable users within a mobile environment to maintain control of their information that the experience is going to get better and it's good, but it's going to take some time but I think the opportunities are are worth the investment. On the bad guys watching all this and and sometimes I wonder you know, they'll hear us talk about all these fanciful things that we're gonna do to protect this that and the other when they're like basically just working off the fundamentals and stealing a password and username and calling today and they're not really going to a lot of extra effort to do all these wonderful things that they can do. So and we collectively just need to focus more on the fundamentals.
Well, yes, of course, they're paying attention. Everything we do is is fairly public particularly as a relation standards in emerging use cases and and what we talk about, you know, within state and federal government in terms of this shift toward mobile driver's licenses and we are just going to have to you know, stay one step ahead that said if we if we don't keep moving we're not addressing, you know the problem but you know, that's why there's a long road map of capabilities that we need to be investing in so that you know voice verification which say, you know, a year ago was well understood, you know, they're starting to capture voices and replay them back. So we need to layer voice authentication with some device specific things.
And so we'll you know, we won't stay static. We will stay busy if we're going to stay ahead. All right, folks.
I heard it here the most important thing. We need to take control of our identity before somebody else does. Hey, right.
Thanks for being on the show. There's a pleasure. Thank you very much.
Appreciate it. All right back to you guys in the studio.