In today’s evolving cyber landscape, securing enterprise systems and protecting customer trust demand a comprehensive, identity-centric approach. Identity Threat Detection and Response (ITDR) and Fraud Prevention are two critical disciplines working toward this goal, yet they differ in scope, methodologies, and technological frameworks.
ITDR is focused on preventing, detecting, and responding to cybersecurity events in the enterprise, such as those caused by negligent over-provisioning or malicious insiders. In contrast, fraud prevention mainly addresses use cases involving unauthorized transactions for consumers and B2B customers.
Join Justin Richer, Founder of Bespoke Engineering LLC and Martin Sandren, IAM Product Lead at IKEA, for an insightful discussion on the technologies, processes, and strategies shaping these two fields.
Moderated by John Tolbert, Director of Cybersecurity Research at KuppingerCole.
Hello, everyone. Good morning, good afternoon, good evening, wherever you are. I want to welcome you to our webinar today. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole, and today we're going to be talking about identity-centric security. We're on the road to EIC, our big European Identity Cloud Conference that comes up next month, and today I'm joined by two experts in the identity-centric security field, Justin Richer and Martin Sandren.
Justin, would you like to introduce yourself? Sure.
Hi, everybody, and thanks for having me on today. My name is Justin Richer. I've been a practitioner in the security and identity space for about two decades now. I've done a lot of work with open standards and around the security and identity space, including OAuth2 and OpenID Connect and things surrounding that whole ecosystem, and I'm really excited to get into the discussion that we have today. Great.
Well, welcome. Martin? My name is Martin Sandren, and I've been in the identity space for a bit more than 20 years now. I'm the Product Lead for Identity and Access with InterIKEA, which is the mother company in the IKEA group, and I mostly do raw meatballs and flat packages across the world. Welcome to you, too. Thanks to everyone who could join us. We're looking at identity-centric security in a couple of different ways. Let's say it's use case driven. On the first side, maybe we'll look at consumer, customer. What does identity-centric security mean for those kinds of systems?
Then we'll switch midway and talk about what does it mean for enterprise systems. First up, I thought we'd just take a few questions or talk a little bit about the consumer side. We all know, probably through personal experience, that fraud has just really taken off in the last few years, lots of different kinds of fraud.
Of course, it's mostly, almost entirely about trying to make money off of victims, but the techniques that the fraudsters have used have evolved a lot over the last five or 10 years. You think back during the pandemic, we saw a huge surge in different kinds of fraud, ATOs, account takeovers, trying to take over any an account where you could steal money or steal something of value. Fast forward to today, obviously ATOs are still a big problem, but there are other fraud trends that have evolved.
I just wondered what, if any, trends you might have seen in your daily work related to consumer or customer fraud that you might want to mention. Go ahead, Martin. I think the biggest trend is, if you can look at the consumer side, it's basically that attackers are starting to leverage AI, which means that certain protection layers, like for example, you have the Icelandic banks, who didn't have any problems with phishing emails because no one were able to write an understandable email. There wasn't a huge market for Icelandic fraudsters. That is not possible as an attack.
You do also see as the authentication mechanism is becoming stronger, of course, than people are attacking the more vulnerable victims. I can see that from Sweden, for example, I'm originally from Sweden. There's a huge fraud market of basically trying to convince especially elderly, frail people to give up their bank ID, their strong authentication mechanism, using all kinds of strategies, like, for example, pretending that you are a part of a...
that your children or an elderly person, that your children has been in an accident and therefore that they have to identify and solve their bank ID to be able to get information about which hospital the children are, similar things. Yeah, the trend that I've been seeing along those lines is that, you know, it's the people that are being attacked more than the technology. I think the technology has gotten a lot stronger in the last few years.
We've seen the rise of pass keys and multi-factor authentication and various things like that that have, you know, we as technologists, I think, have really pushed a lot of things to make sure that we are, you know, properly protecting the systems from attackers bypassing the login system or compromising the login system itself. But there's this adage going around in the security industry right now that attackers don't break in, they log in. Because if you think about it, an attacker is always going to go for the weakest part of the system.
And if you build up all the technology, you know, real people still need to log in. So those real people now become the weakest part of the system. And with the rise of language-based AI, I think Martin is spot on that we're seeing an increase of targeted attacks that can go scrape a whole bunch of social information and try to, you know, try to buddy-buddy somebody. I actually got a, it wasn't a scam attack, it was a marketing email that somebody had very clearly pointed their AI summary bot at my LinkedIn page and sent me a targeted marketing email.
And, you know, I could tell because they had called out things that I specifically had placed in the same post on LinkedIn. And I was, you know, me reading that with a skeptical mind, I recognize that. Somebody who's not looking for that kind of thing might think like, oh, this person's really impressed by me.
They, you know, they obviously, they must be legit because they know all of this stuff about me. Where really what's happening is that all of that's being sort of summarized and regurgitated in order to create this compelling story and this sort of camaraderie with the person in order to get you to, in a scam case, give up something to log in. Because it doesn't matter how strong your password is if somebody else has a copy of it. It doesn't matter how good your two-factor is if somebody gets you to bypass it.
Yeah, excellent points. Or if they can convince you to transfer money on your own, you know, I think you both made good points about, you know, let's say social engineering and the use of AI.
You know, these attacks are far more targeted. They're collecting information about an intended victim up front. They're weaponizing that information. They're using LLMs to write, you know, much better phishing emails than ever before. So they certainly sound plausible.
Yeah, and I think we all probably experience this every day. You know, a different attempt at fraud on us individually.
You know, we've seen an increase in things like authorized push payment. You know, maybe you try to get somebody, there's still the old tech support trick. There's purchasing tricks. And I got one, you know, saying I'm from a, you know, a large e-tailer and you need to click here to authorize this payment.
So, you know, and again, they're very plausible things that they're saying that you need to authorize. So just the volume of these kinds of fraud attempts has increased greatly and they're much, much more targeted.
You know, they have pertinent information about the victims that they intend to reach, which does make it harder to guard against, I think. Yeah, because a lot of the same techniques that we use to recognize legitimate uses of the system, those are now being the things that, those are now the things that are being targeted by these attackers. And I think John makes a really good point here is that they might not even need to log into my account as themselves if they can just convince me to do something for them. So there is a well-established scam. So I live in Massachusetts in the U.S.
and there's a well-established scam in our state that because of state, because the regulations of how electricity is provided in the state, there's this whole thing about how your power is generated and how it's delivered are basically two separate accounts. And so there are these scammers that come in and they try to get you to switch to their power production, which is usually 10 to 20 times more expensive than any like legitimate one. And it's one of these, like, it's technically legal, but no person would willingly actually do this.
So what they do though, in order to get people is that they call up and they will ask you for a bit of information, like, hey, let's compare your electric bill. And just let me know these couple of numbers and look, I can save you all this money, which is of course a lie. And this is one of these things that, like, this is a relatively small geographical region. It's a very targeted scam. But these language based AI systems allow targeted scams like that to scale to unprecedented levels.
And that to me is kind of the crazy part of where we are right now, is that you could take a scam like this and target somebody with, you know, in some other jurisdiction with some other weird utility regulation thing with the same type of scam. And the thing is, like, people that fall for this here in Mass, they don't know it until like four months later when they get $1,000 electric bill and have like no idea what's going on. And then the power company is like, look, you authorized this, you know, this change over on this particular date, and it's a mess to untangle.
Yeah, another thing we've seen a lot of recently, too, are all these fake toll messages. You know, you've signed up, you know, in your state for, you know, the automated toll, you know, paying your tolls for road usage or trade usage or whatever.
You know, we're getting lots and lots of those. And I think that's happening all across the country, too, is another way for scammers to know that, well, most people probably have an account like this, so let's try to take over that account.
Yep, yep, exactly. And then there's the bank, you know, people pretending to be from a bank saying, oh, and they'll call.
And so, I mean, this kind of demonstrates the whole multimodal way of operation. You know, they'll send you a text, they'll call you. It's not just phishing emails anymore.
I mean, maybe there's some level of awareness in the general population that, you know, you can get a phishing email that you should watch out for. Well, now they're texting, now they're calling, and they're saying, look, you know, we perceive a threat to your account, you know, your bank account, and we need you to move your money into this other account, and there it will be safe.
You know, and it sounds legit, maybe, but, you know, they're just trying to get you to move your money, the entirety of your money, into another account, which they control, and you don't. So, again, this is, you know, many channels they use to try to steal money.
Yep, absolutely. And it's all attacking things that would seem like legitimate user behavior, and that's what makes it especially difficult for us as practitioners to protect real users, because, you know, we've sort of stumbled into one of my favorite topics, and that is if you make it so hard for the attackers that it starts making it hard for regular users, then regular users are going to find clever workarounds that are way worse than if you hadn't locked it down in the first place.
Like, we all talk about the, you know, the sticky note full of passwords sitting on top of somebody's desk, just that doesn't actually have passwords on it, in case anybody's wondering. It's my notes of what I'm supposed to be doing later. But in any case, you know, we talk about the sticky note full of passwords that's on somebody's desk, and those come about because we have all of these, you know, draconian password complexity requirements, and we've made passwords non-memorable, and so people have decided, like, I'm going to externalize this.
So now it's a, it's a, it's now a physical proximity attack that we have enabled on somebody's workstation, because all somebody needs to log in is to be able to get to the computer. Previously, they had to have knowledge and access to the computer, or access to something on the network.
Now it's, it's, it's, it's, it's pure physical location. So this is what I like to call a complicated unlocked door, because you think about how doors work. You walk up to them, you turn the handle, and you go through, right? This is how we sort of model our login process. If you have, if the door is locked, you have to have the key, or you have to have the combination, or you have to have some means of getting through. But if you post, this is how you unlock this door on the door, then it's not a locked door anymore.
You, you walk up to it, you follow the instructions, and you go through the door. It's just a really complicated door handle that makes it annoying for regular users, and doesn't stop any attackers. And I think that as an industry, we're really quick to jump onto technological solutions that raise the security bar, but also start to sacrifice the usability, and the, and sort of the, the day-to-day experience that regular users use.
And this, I know we're going to get into this a little bit later, but this is something that I think we're particularly bad about in the enterprise world. I think that on the customer-facing identity world, there's less of an appetite to, to take off your customers, because they might take their money and go somewhere else. But your employees don't have a choice. They just kind of have to accept it. They just kind of have to deal with it. And so I think we're, we're more quick to throw these kinds of well-intended, but usually poorly, poorly deployed systems out against enterprises.
Martin, your thoughts? Yeah, the, that is, of course, always the, the difference between the enterprise and the CM world is that in the enterprise, the end user has very little choice.
They, they have to use your systems. So you spend a lot less time and energy on looking at things like churn, and A-B testing, and improvements on these things, because at the end of the day, they, the employee or the contractors, they, they have to use the systems. But that said, a lot of it, I think that the CM side for a few years have been a lot more advanced than the, the enterprise side. And there's lots of things that the enterprise side can learn from the CM.
Yeah, I agree. Sorry, go ahead. Didn't mean to talk over you. I was just going to ask what you the best, the best things that could be learned?
Well, I think one important thing is that if you look, especially if you're talking about financial services, that they have already for a long time been quite good at looking at all the signals. So are you using an unknown, your normal device, or using another device? Are you coming from a different IP? Are you doing this in a normal pattern for you?
And many of these concepts have just recently entered the world of, of what you do in a, in an enterprise, like ITDR is relatively new in enterprise, while fraud discovery and fraud reduction has been something that has been used actively for at least three or four years in the especially financial industry in the CM space. Yeah, I think that's a great point. I think that's what, you know, maybe we more broadly call the consumerization of IT.
I think we saw that over the last five or 10 years with authentication mechanisms to, you know, internally, a lot of organizations have been using stronger forms of authentication, but, you know, they're not always user friendly. You know, carrying around second factors and, you know, forward thinking consumer facing businesses, I think, have really begun to adapt, or adopt, you know, multifactor authentication with passwordless, or, you know, FIDO2, phishing resistant sorts of authentication methods.
And, and we, you know, in our lives as consumers see, hey, there's a better way to do it. There's that plus like the risk based authentication, where the, the authentication system will look at a variety of factors in the authentication context and decide, you know, whether to elevate the risk level and require some sort of additional factor for authentication or authorization.
And I think now we know that we could bring that kind of technology into the enterprise and apply that to enterprise use cases so that you can make passwordless possible, you can do risk based authentication, internally, increase your security posture while not aggravating users quite as much. Yeah, there are there occasionally comes along technology, technological advancements that raise both security and usability.
You know, very often these two things fight, you know, an unlocked door is easier to walk through than a locked door. That's just, that's just how it works.
But if, you know, to to completely overstretch this metaphor, if the door recognize you, recognizes you, without you doing anything, and the door knows that you're supposed to be there, then it's it might as well be an unlocked door. And that's what really this, you know, risk detection and, and, you know, fraud mitigation type of technology kind of does the system starts to be with potentially multiple, you know, multiple factors or multiple presentations that you have to take make an effort to do.
And so you can save those for the exceptional cases, when you're like, okay, this, you're, you're logging in at 2am on a Tuesday night, that's weird, give me something extra to prove that it's you. Right?
That's, that's when things not start to make sense. Or I just recently swapped out my laptop. And so all of my accounts were like, hey, I've never seen this thing before.
And so, you know, over over the course of a week or so, I've been slowly convincing Google and Apple and all of these other consumer facing services that no, really, it's me, I can, I can prove it, I can go through this. And now everything's like, yep, this is you.
And, and that old laptop that you saw before that that's not active anymore. If you see that that's an error, that's somebody trying to break in. Which is which is a step I don't think that that the average consumer is going to do. Right? I remember the first time I dug into I think it was my Yeah, it was my my Google account. I saw Android phones from like eight years ago, that are like, you know, have long since gone to the recyclers. And but they were still they were still in my Google account. And Google was ready to ready to accept those should they should they wake up?
Well, it's nice to those kinds of platforms give you the opportunity to remove old accounts and old devices so that it reduces your personal attack surface. Mm hmm.
It's, it's nice to have the opportunity. I think that most people are not going to think about that. It's not something that I immediately thought of, even as a professional in this space. And I think sort of hidden in your comment there, john is the truth that there's a lot of places that don't give you that opportunity to do that type of that type of proactive cleanup, even when you want to. We've got a question here. Don't these basic capabilities of zero trust incorporate all the fraud reduction methods listed on the slide?
I just put up a slide in the background of what I see is, you know, the six major categories of fraud reduction. I think Yeah, I think zero trust to me, we don't commonly apply it in consumer use cases, but I think that's a good observation.
You know, I think that's also kind of can lead to a problem that I wanted to talk about, though, specifically around things like behavioral biometrics and user behavioral analysis. So in order to do fraud reduction, you need to know something about the consumer. How does that affect compliance with regulations like GDPR?
So, you know, if you really, really want to do very granular fraud detection, you know, ideally, you would have transaction history to know which transactions which payees that a person normally sends money to are normal for them. And then like you were mentioning, you know, times of day, days of week, to know when people are up and doing things that, you know, fall into their normal baseline of activities. But then there's also location information, you know, what networks you're on. And then with biometrics or behavioral biometrics, you know, how you actually interact with devices.
A lot of this would be considered PII. How do we, you know, use this kind of information in a way to help reduce fraud, making it a better world for the consumer, and also adhere to privacy regulations?
Martin, would you like to go first on that one? Yeah, I think this is a big problem. Like what is a reasonable amount of information to keep about the consumer? And of course, it depends a little bit of what kind of services you're offering. If your financial services, for example, are reasonable to keep more than if you sell furniture. And of course, there's also the fact that this data is not 100% reliable.
So I, for example, got a bit of a shock about six months ago when I discovered that my LinkedIn account had logins from Jerusalem. And I was thinking, has Mossad and or Hamas hacked my LinkedIn account? And after a bit of investigation, it turned out, of course, that the VPN or the provider for didn't, they didn't really keep good track of their IP pools. So somehow the information about where these IPs belong to had gotten mangled somewhere in the So I was spending the last six months in sunny Jerusalem, and then I moved to San Diego for a while. I think I'm still in San Diego.
So at least that speaks very nice places for me. But yeah, so both from a fidelity standpoint, and also from a what is ethically reasonable to keep, this is a big, big challenge.
Yeah, I think, I think that there's the two prongs here are so, so important, and they interact with each other very well. The first is when does collecting this type of information and processing this information to lead to the type of recognition that I was talking about before? When does that into surveillance, right? Because that's really what the whole privacy type of thing, whether it's a, you know, a targeted surveillance or sort of a blanket population surveillance, when does it cross into that? One could argue intent is a big part of that. But I think it's not quite that simple.
The other is the accuracy of the information itself. If you have you have information that is affecting you, and it's wrong, like, what is what's your recourse? How can you? How can you get redress for things like that? How can you prove that?
No, actually, I was I was here and not here. And, you know, I think that, again, going back to the sort of, you know, the the fuzzy processing that, you know, language based AI's and things like that, really start to give us, they give us a great way to do some sensemaking on fuzzy information. But they're not always right.
You know, either the information can be wrong, like in, like in Martin's case, or the information can just confuse the model, because it ends up going down some, some detection path that it had where I had a firewall not let me in, because my IPv4 sex, my IPv4 address was coming from the United States, but my IPv6 address was coming from Southeast Asia, for some reason, it was it was an IP pool, VPN related kind of thing. And the thing is, the the system saw that and was like, okay, this is weird. And I agree coming from two geographical places at the same time is definitely weird.
But I really didn't have a good opportunity to say no, really, I'm I'm here. How How can I prove to you that I'm here? What information can I give you? I didn't have any information that I ended up for for that particular system, I ended up having to turn off IPv6 on my laptop for for a few minutes to be able to get to the system that I needed to and then back that back off. And you know, that's, that's the kind of thing it took me maybe an hour to debug what was actually going on, like what was triggering.
And then, and then it was a really just bizarre circumstance that I don't blame the risk detection model for for flagging that. But how could I correct that? I'm I don't have control over where the IP addresses show up from. So you know, what can I do? And you do, of course, have when you start walking into really bad territory, for example, you have in the US, you have your protected categories, which you don't necessarily have in Europe. I'm a US citizen, I'm Swedish citizens, I used to live in the US. And that is a very big difference in behavior. But what do you do?
And when you kind of started to that some part of your AI discover things that it really shouldn't be doing, and start concluding that, that, you know, everyone that based on something you are, for example, a specific ethical group, and based on the fact that this specific ethical group, then this higher, let's say that it results in a higher default rate or something like that, and then stops, you know, stops giving out loans, etc, to this ethical group. That is, of course, not really something you can have in a civilized society, at least in my opinion.
And it becomes really complex to how do you detect those kind of things and avoid it. I think this speaks to a sort of an overarching problem of how society and technology kind of run into each other. And this is, again, been one of my one of my favorite topics throughout my career, is where people sort of run into the technology and make just a beautiful mess of things.
You know, that's, that's, that's why that's why I'm in the space that I'm in. And this is a case where the types of resolution, the types of processing, the types of societal things that we do are designed around things being a little fuzzy and a little ambiguous and somebody having to kind of sit down and look at things and think about it and make sense of it and then make a decision. And we have things built into many of our societal systems to allow for that type of ambiguity and allow for processing that type of ambiguity and allow for redress of things when things go wrong.
We've got, you know, the entire court system. If I've been denied service or something, I can, I can sue.
I can, you know, publish information about, like, this is what happened to me in, you know, the court of public opinion. There, there are things that I can do that are very sort of fuzzy human things that a risk detection algorithm isn't going to care about. It absolutely isn't going to care about. It's going to, you know, take its inputs in the context, make its decision, and then that's that.
And this is becoming, I think, more and more important for us in the industry to consider because we're relying more and more on fuzzy information and sort of these fuzzy conditionals that decide whether or not something can happen. You know, it was almost easier when everything was just, you have an authentication event and then a session, and then it times out, and then you're either in or out. But that doesn't model very well how we interact with the world.
So we're getting better about doing things that are risk-based, doing things that are recognition-based, doing things that are, you know, your, your privileges, the whole zero standing privileges model, I think is fabulous because it's like, in the context of what I'm doing, like, what is it that I, that I need to do to be able to do this one particular action kind of thing, right? If I go into my bank and I ask to withdraw all of my money and close my account, they're going to look at me a little funny and ask me, like, okay, why, what's going on?
And that's, that's a very human conversation kind of thing. How we used to model digital accounts and still do in a lot of, a lot of the world is, if I'm logged in, I'm allowed to do that, right? And it's the same as if I'm just checking my balance. We're moving into a space where we're doing these fuzzier things, but I don't think our systems are really coping with the types of errors that happen in these fuzzy spaces as well as we need to.
Yeah, that's a good observation. And it's, I think, related to the latest question that we've gotten here. I'll just try to summarize that as, you know, AI is making all these things harder. How do you trust the veracity of the data that we're talking about to make these kinds of informed decisions about access? And I think this can apply on both the consumer or the enterprise side. But I mean, the questioner here specifically points out deep fakes.
And I know from the round of research I'm doing right now on fraud detection, that deep fakes are a big problem, especially in the identity verification stage. We are hearing more and more about the use of deep fakes for trying to get accounts in the first place. So how do we trust the information that we're using to make, you know, authentication and access control decisions?
I think what I've learned, and then I'll turn it over to you all, is that a lot of, some of the vendors in this space are now so concerned about this, they're building in things like detection for virtual cameras, adding additional methods of liveness detection, trying to really fully exploit all the different sensors that are on mobile devices to do things that they had not been doing before, like with behavioral biometrics. You know, we've seen things like touchscreen pressure and typing patterns and whatnot forever.
But, you know, many of them are looking at not only that plus accelerometer, but ambient light, ambient sound. But again, that gets us back to the privacy thing. Because if you're checking ambient light and checking ambient sound, you've got the camera and the microphone on. And have you authorized that? Are there any safeguards on what that information is going to be used for? I don't know. I think it gets more and more complicated. What do you all think?
So to me, this actually harkens back to the first question of, well, doesn't zero trust solve all of this? Because it's right in the name. It's like we have zero trust. But you always have to ask, what do you have zero trust in? If you look at the original writings on zero trust, it's about zero trust in the network, in the network fabric. It's about, you don't trust something just because it's coming across a particular network fabric. You trust it at the end point. You do additional verification and stuff like that.
We've now expanded the definition of zero trust to mean sort of a larger set of things, for sure. But it always needs to be contextual.
Like, you can't have zero trust in anything. Because ultimately, you do have to trust that your processing of this is going to give you the right information with enough accuracy for you to be okay with it. It's just what you put that trust in and when you put that trust in it, that's what can change. Those are the levers that we really have to pull. So to John, to the question, I don't think that there's a really easy solution to this. Unfortunately, I think that it's a really fuzzy kind of space where a lot of, you know, a lot of work is being done to figure out what it means.
So you look at, you know, a lot of the deep fake systems, they're actually not targeting the technology, they're targeting humans. You know, they're targeting humans that are making an authorization decision or making an onboarding decision or something like that. That's like, so the, oh, person calls and they, from your bank, they sound like your local regional accent or, you know, an indeterministic call center type of accent and, you know, a nice soothing voice and all of these other things that don't give away what's actually going on.
I've had, I've gotten calls with fake voices, like very clearly fake voices that had fake call center noise in the background to make it sound like a call center. It is phenomenal. I got to give them credit for the cleverness there, but it's really frightening that this is where, this is where things are going.
So yeah, it's, you always have to verify, you always have to have the context, and I think it's going to be an arms race. And I think if you look at what AI can do for you, it can, of course, help the attacker. So it can figure out that, yeah, where in a cost efficient manner, because of course you can, you can figure out a lot of things about Justin if you spend enough time looking at where he is, what the very posts, and, you know, you're in all the organizations where Justin is a member and do all of these things manually.
AI, of course, means that you can can clean a lot of this information much more efficient, but a lot of things are not so easy. It's easy, for example, to say, yeah, this person lives in Massachusetts, so let's give me a Massachusetts IP through a VPN, so that's easy to do. Other things might be harder, like device copying.
Sure, you could, like, AI won't really help you very much with that, but you do see the AI attacks also against primarily the kind of the service desk. So the switch where you have a device, for example, that's a very nice attack surface for an AI-based attack, and that they convince the service desk that this is actually the right person. So it's definitely going to be a need once your startup start to get the phishing resistant MFA in place, then it comes to the next part, okay, attack against the service desk to be able to replace the MFA.
Yeah, it's definitely going to be our part. And then there's going to be the attacks against the humans as well, that, you know, you convince the human to actually do the transaction for you, and then, hey, you don't need to crack the account if you can get the human to do the thing you want to do, you want to have done. Great. Let's segue over to the enterprise side, but we do have another question from the audience. Following on to the prior question, do you see self-sovereign identity enabling more fraud as identities can be artificially created and verified? That's a good question.
I was also going to ask, is there a way in which something like decentralized identity might help prevent fraud? But I think like any technology, and, Justin, I think you were pointing this out earlier, it can kind of go both ways. It can be an enabler or it can be a hindrance.
Yeah, so I have some very strong and public opinions about self-sovereign identity in that I actually at EIC, I think it was two years ago, John, gave a talk entitled Your Identity Is Not Self-Sovereign. And I got to go into math. It was great. But fundamentally, all of these things are only as valuable as much as they are accepted by systems.
So if self-sovereign identities and sort of these self-asserted but verifiable attributes and VC presentations and things like that, as those become more accepted, and I think that in niches, we're going to start seeing this with MDLs and various state-based licensures and things like that, that's going to become more of a target, both for capture and replay, which I think we're doing a decent job at protecting that, baking that into the technology, but also for faking it, for faking it and for getting it to be presented in a fraudulent context, like we were talking about before.
I might not need to steal your information if I can talk you into giving it up. And so I don't think it actually helps move the needle, but I don't think it specifically makes it worse. I think it shifts where the conversation is going to happen about what we do about it.
But yeah, overall, I think it's almost even set with a very, very slight better, and I'll give you the one space where I think it is better. To do identity proofing in the excuse me, in the United States, it's very, very common to accept a utility bill with the person's name and address on it of a locally recognized utility company kind of thing. I don't get paper bills in the mail anymore. I haven't for over a decade, at the very, very least. So I don't really have a lot of well-established mail, except for junk mail that comes to me at this address.
What I do have is the ability to log into the accounts of my utility providers, like that electric company we were talking about before. And I could actually prove that, yes, I am the owner of this account. This is the address of delivery. So that is a relatively strong indicator that this name and this account and this person are all kind of tied, this address are all tied together. Here's the funny thing though, for acceptance of this type of thing, they don't accept me logging into the account. What they accept is me printing out the PDF version of my bill and bringing that into the desk.
That wasn't sent through the mail. That wasn't printed by the provider at all. It's something that I am printing in my house and carrying with me that happens to have the right information on it. This is trivial to fake, and there's no checks that happen on it. In cases like this, things like, you know, Verifiable Credentials and Identity Federation and stuff like that, they are made to be able to solve this kind of thing. Because I can do a verifiable document presentation that can be digitally asserted across systems. That's one place.
So this document verification, I would love to see more adoption in that space. Where I think it makes less sense is the, this is my identity and I'm carrying it with me and I can prove that I'm me and nobody has to say anything about who I am. That doesn't make sense. Like sort of the ethos of self-sovereign identity and, you know, what pushed a lot of this technology originally. Because these systems don't care who I think that I am. They care who somebody else thinks that I am and how I can prove that association.
I had a really fun experience of this because I was trying to re-take control of one of my bank accounts that I had in the UK. I created when I lived in the UK a long, long time ago. And they required a copy of a recent utility bill. Now I can get a PDF from my electricity provider.
I then, but of course it's very easy to fake it. So I had to get a certified translation of my PDF to send over physically to their location.
So, and of course I could get a very strong, because in here in the Netherlands, there is the ability to get, go to your local municipality. You have to register and then they can give you a nice, nice, what's called an outroxel that shows that you are registered on this address. And this is something of course that will really help when you can have this kind of database data can become in a digital form that can actually be verified. Because today it's pure theater, like sending PDFs back and forth, et cetera.
And of course also the, this is really going to help with avoiding storing, for example, copies of passports, because you really don't want to do that as an enterprise, because this is one of the things that the attackers go after. Once they break in, they go after HR parts because there they can get a lot of information, which they can then sell to do further fraud on the fraud markets. Yeah.
I think you touched on something really, really interesting here is that for sort of the audit and verifiability of a lot of these systems, especially on the enterprise side, we don't actually really want to store the evidence. We want to store some type of proof that the evidence was verified, right?
That's, we want to say like at some point of time, you know, it was verified in this way, it was presented by this like, and tie all of that together in a way that it can be looked up and checked again.
The problem with all of that, of course, is that unless I can go look at that record and check it again, somehow, and figure out like, hey, this is, this is a way to like, this gives me enough hooks that I could actually validate again, that this, this really did happen, and that this really is the case, then, then it's really hard for us to kind of reason about it, which is, I think, why we do things like store a photocopy of a passport, because if I can go look at that, and I can say, oh, this is the passport that was presented, show me your passport now, and look, they're completely different, and this wasn't reissued, and like all of those other red flags that I can actually, as a human, figure out what's going on there.
So we've got a couple other questions that have come in about using TPMs, confidential computing, blockchain. Do you have any quick comments on that before we take a look at the enterprise side?
Yeah, the answer to blockchain is no. It's a distributed database, and this is a hill I will 100% die on, and it's got, it's got some interesting characteristics to it, but it is a technology, not a solution. As far as the, the TPM stuff, I think it's going to really help us with device identification, and sort of all of that, but it needs to be coupled with things like attestations, and, and, you know, certifications of device during onboarding, and auditability of those things, without tracking necessarily the specific device itself.
So we're making progress there, we've got a little ways to go. I think we're, once again, a little too quick to say, hey, I can get private keys into place, and then that's going to solve my problems. I think passkeys showed us that the ecosystem has, has forces in it that are prepared to break all of our assumptions about, for example, the exportability of private keys to a hardware authenticator with, with syncable passkeys. So thinking about enterprise use cases in ITDR, what is it good for?
You know, maybe applying, you know, broadly speaking, fraud prevention techniques on enterprise accounts. What are some of the top kinds of threats that you see enterprises facing on their identity systems today? So I would say that one of the top attack vectors, unless you have completely a phishing resistant MFA in place everywhere, which most don't, it is possible with AI to craft beautiful phishing emails. And then in many systems, it is relatively, EvilGNX, for example, I recommend strongly to just watch one of these sessions to an attacker.
So the attackers today, the kind of the balance of power is in the, in the favors of the attackers. They build most likely, if they have some money to spend, they will be able to crack at least one of your enterprise users and in cases more. So you need to have the defense in depth. So you discover that, hmm, this user is behaving strangely, be it that they have a new device, be it that they come from a new IP, be it that they're behaving differently, they are accessing new applications. So you can kind of find them and then react to them.
And also, of course, you have the ability to bring in the, for example, accounts that are being sold on the dark web. That is another defense mechanism that you have in place. And then of course, once you know that the user might be fishy. And the thing, of course, if you have a well-tuned ITDR system, you might be as good as 0.1% of the events that you get in are actual real compromises and the rest are false positives. So you need to put in the systems to be able to handle this. You can ask in a reasonable way.
So for example, if you have a privileged user in tier zero, tier one, it's not unreasonable if you see that they are becoming a risky user that you say, okay, but then please log in again with MFA. And then you can have the user, the attacker gets kicked out of that. So having an effective way to identify this and also the next step of ITDR that we're seeing is that, okay, we are now able to identify it within kind of a platform.
So if you are a, for example, a Microsoft customer, if you have installed, we've got, if you're advanced and have all the things in place and have tuned it nicely, you might be able to find that you have compromised identities, thereby you can protect your Microsoft ecosystem, your Microsoft IDP from this. But how do I take that and make sure that I can start spreading the news across your ecosystem? Because unless you're a hundred percent Microsoft, you might have AWS stuff.
How do you make sure that that is also kind of put on risky footing for this user or GCP or Oracle or whatever, or for that matter, Salesforce. So that is the next part where we see the rise of the shared signal framework and similar to what's in the CAPE. And that's, I think, is still kind of being, it's still in development. We're a lot better now than we were just a year ago. Yeah. I think that a really important point that Martin just brought up is that of detection.
If you have a very secure system or something that you believe is very secure, but you can't detect when you've been compromised, how secure actually are you? You could have like absolutely everything locked down and enforced and all of this other stuff. But if an attacker manages to slip in through some crack somewhere or manages to beat somebody with a pipe wrench and steal their YubiKey, if you can't detect that, then I would argue that you're missing one of the most fundamental aspects of security of your what zero trust was really getting about.
It's like, just because you see something coming from a place that you trust doesn't mean that it's okay. You need to check it again. You need to check it in a different way in order to figure out what's going on. So that detection is hugely, hugely important. And I think that with things like shared signals, we are seeing the growth of stuff like that. And that's really awesome to see where it still falls short today, in my opinion, is getting people, getting organizations, getting vendors to actually share the signals.
We've defined the signals, we have CAPE, we have the whole risk framework from OIDF and all of these other things, but getting them to actually tell other people that something bad happened or something notable happened is tricky because there has to be a deep trust relationship between those entities for that to actually kick off. Or at least it seems that that's the case.
Go ahead, John. So this, we're coming up on the top of the hour, so this might be our last question, but so ITDR, Identity Threat Detection and Response, we've talked about the willing to do in terms of automated responses, because I look at the EPDR side, the XDR side, you know, and R is cool, I think, but what are people really doing with that? Are you willing to disable accounts based on, you know, signals that say it's been compromised? Are you willing to disable an executive's account because it looks like it's been compromised?
I mean, I look at, you know, another real quick point I wanted to make about like the ISPM, all of our security posture management tools that are kind of detection, you know, really just about detection versus something like ITDR that should have response capabilities. But again, what do you think organizations are willing to allow to be automated? I think there's two important things to this.
So they, it depends on what type of operations you're doing. I think if you roll out something to everyone, you will very quickly have the problem that your support is going to get overwhelmed. While you might say that, well, we can do this for tier zero and tier one admins, they do very important things, have perhaps zero standing privileges, if their account actually do get flagged as compromised, they're mostly ready to do another login, et cetera. So I think it's about making sure that you target the ones that really matters the most, who crowned you as the access to those.
So there you have ability to do response while, of course, at the end of the day, you know, once you locked out your CFO or your CEO a couple of times, then your automated response would probably be brought back a bit. So that's important part of this. And it's also just a mentioned part is that it's all about when we come to the response part, it's also about giving the SOC and the teams enough time and signal.
Like if you make sure that you don't have hygiene, for example, that you don't have extra more access than you need to broad groups of people, that does mean that there are fewer people that can be phished that can actually bring the attacker closer to the crown jewels. Those things make a lot of difference. It's all about putting little speed bumps in front of the attacker and slow them down enough so that the response has the time to react. Justin?
So I think that one of the most interesting things that comes from all of this, especially automated response, is that you need to manage the trust in the system, the trust of the end users, and particularly the end users that get to make the decisions about whether or not the system can continue. And you may be doing something really good and keeping out a lot of, you know, a lot of fraudulent accounts and things like that.
But if it gets in the way of people doing the things that they want to do in a way that they don't understand in a way that they don't accept, then the rejection and the rollback and even the, you know, even the workarounds, like the sticky notes with the passwords, are going to compromise your overall system much more. So it needs to be trusted. It needs to make sense. And it needs to ultimately be accepted. And that's something that especially in the enterprise case, I think, that we're really quick to say, like, well, this is the system. You have to use it. And you just have to deal with it.
Like, to end with a quick story, I was once on a system, and I told this on another talk, there was once a system that required rotation of passwords every six months. And it couldn't be any of the previous 24 passwords. And so some unnamed enterprising young security engineer, I couldn't possibly tell you who it was, wrote a script that connected to the domain controller and cycled the password through 25 times and set it back to the original password in order to just get along with the day.
Technically compliant with all of the regulations, absolutely bypassing everything that they were trying to do with this. And this is the kind of thing that is going to exist in these systems when when the policies get in the way of people doing what it is that they feel that they need to do. And aren't actually helping the people. Ultimately, systems are there to be functional, to provide something. And security too often gets in the way of that instead of helping it. And we as an industry can and need to do better.
Well, great. Well, thanks to both of you for joining me today. I think it's been a really interesting discussion. And we are sure to have more discussions like this at EIC next month. So look forward to seeing you both there and hopefully many of you in the audience today as well. All right. Thank you so much for having me today. Thank you very much, everyone. Have a good day.
See All Locations
See All Locations