Safeguarding Sensitive Data and Securing Infrastructure – Mike Malone, Smallstep
The Smallstep Trust Platform will help IT leaders and their organization address the ever increasing security challenges they are facing when attempting to keep sensitive data safe. Since its early days as an open source project in the DevOps community, Smallstep’s mission continues to be to secure the world’s infrastructure by enabling end-to-end encryption between distributed applications and the people who manage them.
Transcript
This is techstrong tv. Hi everyone. Welcome back to techstrong tv.
I've got a new company to tell you about here today. I want to introduce you to Mike Malone. He's the founder and c e o of a company called Small Step.
Hey Mike, how are you? Hi, Alan. I'm great.
Thanks for having me on. It's a pleasure to have you here, Mike. Um, I guess before we even jump into the small step story, let's start with a little bit of the Mike Malone story, if it's okay.
Yeah. Um, I'm a software engineer. I'm a nerd, uh, Ben, Ben that way, uh, since I was a kid.
0 back when we called it that. Um, I remember that. Yeah.
Yeah. Uh, uh, I like to say, um, I'm a distributed systems architect. That's my happy place.
I like building large software systems and building teams to build large software systems, and I have had the good fortune to be allowed to do that and paid to do that even, um, my entire career. So, yeah, that's me in a nutshell. I get it.
You know what, I often tell people that our whole community, our whole audience here at Techstrong across all of our brands, whether it's DevOps, dot Commerce, security Boulevard, or Cloud native now, tech Strong AI says Digital Cxl. We are a community of nerds, nerds and geeks. And, you know, you may laugh, you may not think we're the coolest people in the world, but hey man, we, we have a good time and, and the things we do shape our world.
And, um, you know, I I relish being part of that, you know, that's who I am and that's who we are. And it's cool. I hear you.
Yeah. Uh, so you're the founder, CEO of Small Step. Tell us, tell us how that came about.
0, I was buddies with, uh, you know, the folks over at, at Flicker who were sort of developing that idea. My first, uh, startup job, we were using AWS when it was just S3 and E C two. So like cloud native DevOps, CI/CD, agile microservices.
This has been like my life. And, um, you know, my, my immediate prior gig gig just before starting small stuff, I was, I was CTO at a company called Embedable. It was a platform for online gambling.
And, um, you know, I had observed this prior to Vettable, but really at Vettable, um, it became more critical, like security really still isn't fully solved in the context of those sort of modern methods and mo modern technologies, and there's some missing core infrastructure. And that was sort of the gap that, uh, that we saw at Small Step that we wanted to fill. So I've been in security, and when I started, it wasn't called cyber right, it was called InfoSec.
And I've been in security since 2000, long time, 23 years. Um, not only was it not solved in modern architecture, it certainly wasn't solved in pre-modern ar it's never been solved, right? That that's the bottom line.
And there's always been gaps, and there's always been, you know, there's more than one reason for this. It, it's hard to say, oh, that's the, you know, that's why No, that's a contributing factor. Here's 12 other contributing factors.
Um, and the funny thing is, Mike, through all, all of this time, every survey I ever read said, well, security's one of the top three priorities for our organization. You know, I used to say it's may be so, but their arms are too short to reach to the bottom of their pockets to actually do something about it. And, um, but that's changed.
I mean, I will tell you, I don't want to be that security grudge and who, you know, rah, we, we all know those security people. They're my friends too. Right, right.
We have made a lot of progress recently. Security really has become a top priority, like job one for more than just security people for entire organizations. So, you know, maybe the time is ripe to do do, to do this.
Right. And, and we've made a lot of progress too. Security today, were much more effective.
It's much harder to break into stuff today than it was 10 years ago. Absolutely. You know, 15 years ago.
Yeah. So, I, I don't wanna be that, you know, that old angry man who's a pessimist saying, you know, go play in front of your own house. But, um, nevertheless, there's a lot of work to be done.
Tell us what, what makes small, you know, this, I think the last, I counted this, 4,000 some odd venture backed security companies. What makes small step different? Well, to start, I'd say like the, we're open core.
So in the foundation, the, the core technology I mentioned earlier that sort of missing technology, um, is an automated certificate management tool chain, and that's open source and it's extremely popular and has sort of a vibrant open source community. We invested a lot in developing that technology and building the community, making sure to address this need of delivering certificates, you know, a variety of credential that's really important, uh, at the pace and scale of the, you know, I love it. Right.
Um, and, uh, so it's written in goling and, you know, it, it, it can scale up to, you know, issuing short-lived certificates that to, to ephemeral services that are coming and going using modern best practices, all that good stuff. Um, and that's really the foundation. And, um, you know, so to some extent we see ourselves as sort of democratizing this really important fundamental infrastructure technology and making it accessible to everybody, which we see as just an important thing that somebody ought to do.
Um, and then sort of, uh, we, our commercial product builds on that. And what we're delivering is a, a unified platform for end-to-end encryption for everything everywhere, devices, people, workloads, machine identity. Um, and, and we really aim to dramatically reduce the time and effort to achieve end-to-end encryption and achieve zero trust, uh, um, which is becoming a security priority, as you said to a lot of people.
And, you know, the curmudgeon in me wants to say like, well, we've known that this is the right way to do things for 25, 30 years, and that's true. Um, but the optimist in me is just happy that we're doing it now and, um, and a Link than never for, right. Yeah.
Yep. So let, let's talk about this, and I'm gonna talk to you afterwards. We, we are just making an announcement in the next week or so actually around, uh, something we're doing in, in this space.
But when we, when you talk about certificates and end-to-end encryption, you're not just talking about certificates for people, like for identity for a person, we're talking about machine identity and machine to machine certificates. And those could be things like containers, right? The ephemeral, they could be, you know, instances, virtual machines, they could be IOT devices.
They, they could be anything that has a quote unquote digital like identity. That's correct. Yep.
And, and the workloads, the Postgres, the ET c d, the Kubernetes control plane itself is all using certificate based authentication for your Absolutely. API server, uh, Microservices. It's a ubiquitous technology.
Yep. Your enterprise IT infrastructure, that new zero trust network access access proxy that you're using. You know, one of the best ways that you can authenticate a machine as your machine accessing that piece of infrastructure is to issue it a certificate based on its unique device identity.
Uh, so absolutely it's a powerful technology that's useful in, uh, you know, uh, it's broadly. I agree with you. So look, I, I, I'll talk to you, I was gonna talk to you off camera, but we're, we're announcing, we're doing a virtual event at the end of August on certificates, p k i in a post quantum AI world.
Right. And it, it's very funny, I pulled my team together to talk about it and you know, most of my exec team, Mike, are people my age that I've known for 20 years or more, and they're security people. And I was like, Hey, I wanna do this because you wanna know the truth, the basic underlying technology with certificates really hasn't changed much since S S L in Netscape in 1998 or 99 or whenever, 97 maybe, whenever that was.
Right. And PKIs been PKIs, I'm in technology over 30 years. I don't think it created The web.
Right. It's a tele, it's a telco standard. Exactly.
And I realize it's not sexy, and a lot of people kind of roll their eyes, but, you know, without, without that stuff, this whole thing grinds to a halt really quickly. Right. But for the first time, Mike, in our work careers, you know yours as well, there are things on the horizon that could break it.
Yeah. Yep. They can break the, the, the backbone here.
Things like quantum, things like ai. Yep. Um, you know, which is, you know, which is why like Google and some of these others are looking to now really limit the, the duration of a certificate.
Right. It's one of the reasons why they're looking to limit it. Um, interested, you know?
Absolutely. We're at a precipice here. We're at kind of a boundary point, And I think I couldn't agree with you more, right.
Like you, and, and there is progress being made there, right? NIST has begun to standardize some new post quantum algorithms. And, and if you look at that, you know, NIST was not tasked with developing post quantum certificate capabilities.
NIST was tasked with how do we continue to secure things in a post quantum world? So they looked at the option of let's get rid of certificates very deeply. You know, like much money was spent, uh, uhhuh to the conclusion that that's not an option, that's not happening.
Mm-hmm. It's just, cuz it's, it's the backbone on which virtually all secure communication and e-commerce is running on. Look, even, even if you look at protocols that avoided certificates because of say the, the perceived complexity, like I worked on, um, OAuth and Open Id Connect, um, which don't use certificates except they absolutely do because they depend on H T T Ps for aspects of, and that's certific good space.
And without that, they're not secure. I, I hear you. That's, you know, I've been security a long time, as I mentioned, I used to love the people who said, oh no, we're agentless.
We're agentless. Right? We just put a little program on your computer, but it's not an agent.
Well, no, I don't give a, I don't care what you call it. It's an agent, agent. You're putting crap on my computer coat on the computer.
Anyway, Matt, we'll talk more about this event that we're doing offline, but let's come back to small step in the small step trust platform. Now tell us more about it, how it works. Yeah, absolutely.
So I mean, that bottom layer is, uh, is the, the certificate management that core infrastructure, but then what we aim to do is sort of uplevel that and the, the, you know, the business objects that we're working with inside of our commercial product are the things that need to be secured. Your Apple laptops, your AW SVMs Postgres running on that A W S V M. And we, we have workflows and monitoring and OB and, and observability capabilities that we're building out, right?
We're a startup. So like, there's a journey here and it's not all done, but here's the vision, uh, to, to make it easy for folks to, uh, leverage the native support for TLS in your infrastructure, in your language libraries. Where it exists is, is, is a ubiquitous, very widely deployed technology and to deliver end-to-end encryption between all of these components for privilege access, for machine identity, for workload identity, to achieve zero trust, um, in a way that's easy to deploy and configure.
That's approachable, uh, for the average software engineer. You know, because this, the, the, these technologies are not as difficult as they appear to be. If, if you're, if you're looking at, uh, uh, you know, tool some of the tools off-the-shelf tools like Open ssl, which is a great tool, but it's just, it's designed for a P K I expert.
Um, so, uh, so you know, the pillars are, you know, we wanna help you, uh, find the things that, uh, need attention, the, the risks in your, in your infrastructure. Uh, so identify those things and then, uh, get them secured using, uh, integrations and workflows that are approachable and understandable by the average software engineer. And then, uh, give you observability visibility and allow you to understand what's going on, um, so that you can make, you know, smart risk-based decisions about your infrastructure and you have more confidence that it, it, you know, you have all of your bases covered.
Um, so, so, yeah. And all of that, or, you know, our approach to that is all asymmetric key based, uh, eliminating passwords, eliminating API tokens as much as possible. Um, end to end, you know, uh, we try to avoid proxy based approaches and really go, you know, from entity to entity that needs to be secured.
And, um, from the silicon up, you know, we're, we wanna identify the device ideally, uh, using, um, uh, a cryptographically secure mechanism like, uh, an attestation from a trusted platform module, or in the case of like an Apple laptop, you know, the, the secure enclave. Uh, and there are, there are new protocols that allow open standard protocols that allow for that. Um, so, uh, uh, that's, that's the, the shape of it, right?
So do the right thing from the silicon up, zero, zero gaps and make it easy for, uh, the, the people who are doing the work and make it seamless and, uh, and easy for the end users who are in these workflows. Love it. Got a little bit of time left, Mike.
How, how, how can people engage with small step for this? It's, it's an open source and a commercial product, so I'm hoping there's, they get their hands on the software right away. Absolutely.
com, we understand that not everyone wants to talk to sales, but if you do, there's a contact sales button right there, and our sales folks would love to talk to you. Um, and from our website, you'll be able to find our open source if that's the direction you wanna head in. Um, you can also go ahead and sign up for our product right there.
Um, uh, if you're watching this and, uh, and it was just published, just know that, uh, we have some big product improvements coming in the next month or so. Uh, so keep an eye out for those. Um, but, uh, but yeah, it's all product led try before you buy, so feel free to, to just sign up and check it out.
Great. There's great documentation. Uh, read our blog, uh, especially if you're interested in learning more about public key infrastructure.
Uh, we, we do a lot of, uh, we have a lot of educational material on there. com is the, is the right place to start to find all of that stuff. Excellent, man.
Hey Mike, I want to thank you first time here on Text Strong tv. Appreciate it. Hopefully we'll see you back on here soon, and best of luck with Small Step.
Thanks so much. Small step do com. All righty Is it's Alan Shimel.
We'll be back in a moment.