Good morning. So we are at the last day from a nice conference. We have heard a lot of talks, at least I did. Very interesting and I want to take the time to step back a moment and just have a more broader view on security and in the identity space, security in a more general sense and what that means and what the impact of AI is to that topic and how we deal with that. And more specifically, it's about the arms race where one is half a step behind or half a step ahead of the other or as opposed to having a leapfrog where we really change the rules of that game.
And my background is I'm one of the authors of the FIDO specification and looked into that and tried to find a way to make authentication more secure and so much more secure that we are not only half a step ahead of the attackers but really changing the rules of the attacking game, changing the rules of the security game and let's see what we can see in similarities in other spaces as well when it comes to that topic.
So the background in my opinion here really is if you look at the cyber fraud, we see this is exploding, it's growing at a much higher pace than the global GDP is and so the question is if we are spending so much money, why is the cost of cyber crime still growing at this high pace, right? And what can we do differently because apparently all of our existing efforts which we have taken are not good enough, right? We have done a lot of things, tried a lot of different approaches but it seems to be not good enough to keep cyber crime under control.
And there are many factors that fuel the rapid growth of cyber crime. The first is I think anonymity in the internet is a good reason to encourage people to malicious behavior. There's interesting studies around that but that's a general theme that we are seeing here and the increasing digital transformation we have seen in the past is also one of the driving factors, right? We are now transferring real money and doing real business processes in the internet.
Yeah sure, if we attack those, the impact of crime is much more different than it was 30-40 years ago. We have interestingly simplified access to sophisticated hacking tools, right? So phishing toolkits now are easily available to anyone and AI is fueling that simplicity, that growth in that area as well, right? The AI for bad is very easy to do, right? So I can create deep fakes and we have heard about that, videos, images, everything I want, a voice even, right? So it's changing rules, right? And in my opinion this last one is the most important topic here.
It's the lack of robust security, cyber security measures that leave organizations really vulnerable here and I will want to explain what I mean with robust here and give some examples how we change that. And to start with that, first if you look at the defenders game in some way, we see there is an asymmetry, right? There's a lot of different factors, right? Attackers need to hack only one door but you have to protect all the doors and that asymmetry goes on, right? You as a defender, you need a 100% success rate where you as an attacker, if you have 3% success, right?
That's typically good enough, right? Look at the phishing emails you get, right? There's an open rate, maybe that is between 3% depending, right? Up to 30% or so, the click rate in that range. That is good enough for attackers to make money and justify their attack, right? From their perspective. But if your protection technology is only as good as reducing the number of attacks by 3% to 30%, it's not good enough, right? You are looking at the wrong thing, right? You have to do something much better than that.
And this is an asymmetry we have and we have to think about that really hard, what we can do to make that better. We have to, as a defender, have to cover all the users at all times, right? As an attacker, I find one user which might be violating rules, who knows, right? And now we are in, right? And this continues. We must avoid false rejects as well, right? It doesn't help if you close all doors and now no one can do any business, right? That's not good for us. As an attacker, I don't care, right? Someone gets the wrong email, right? Nothing happens to me as an attacker, right?
So false rejects are not a problem for me as an attacker, they are a problem for me as a defender. So collateral damage as well. And the last one is, as a defender, you have to follow rules, right? We are good citizens, we want to follow rules, we have to follow rules. As an attacker, you don't care, right? And that's interesting, the thing about AI, AI for bad and AI for good, right? Why is one always faster than the other? Maybe there is some reason here, right? So we really have to think about that. So why do traditional defenses struggle?
And this really goes back to what is the core challenge we have to find good solutions for defending. And security often is an arms race, right? So if you have a virus pattern, you need a new rule, right? And that means the update, meaning in the virus protection business, you are kind of half a step ahead or half a step behind the attacker, right? This is really what I really consider that this is the arms race, right? It's very tight, you are constantly in a race.
And I just attended a conference of a meeting of CISOs and they told me many of us are burned out because we have so many things to do, right? It's never ending, not enough people and always the next step on our plate. So what can we do here? Phishing email is exactly the same, right? New phishing email, now you have to configure, reconfigure the rules and maybe you have tools which try to automate it and they sometimes work, but sometimes they don't. So sometimes you have false rejects, meaning they log out the wrong emails. Different thing, but always it is the arms race.
It is not a leapfrog that we want to have, right? This asymmetry makes it hard for us as defenders.
So AI, what is the role here, right? We need AI to defend, but attackers like AI because it's so much easier, right? It automates all the processes, it can help me creating deep fakes, it can help me to translate the phishing emails to languages I don't even know, right? So I'm an attacker in whatever country and all the countries of the world, I have automatic tools and translate the languages and they sound convincing to those users, which makes it even harder. Hallucination, another interesting topic in that AI space, right? And there's always a slight percentage which is still there, right?
Maybe three to zero dot four percent or so, but if I'm defending that is bad because this opens up doors for attacking. As an attacker I don't care, right?
It works, sometimes it's the wrong email, who cares? Or maybe I attack people in the other country, right? So we need solutions to get that. And now I said, I promised I will show some examples here, right? Look at the secure remote interaction, right? Online access to cloud service, if you want, think about that, right? There are two things here. The first is users sign up. Who is the user that signs up? And the second question I have as a service is the next day who is the user that signs in, right? To that server. And let me give the first example.
What we did in the past, we were using bearer tokens, right? And what's wrong with bearer tokens? And by the way, we are still using bearer tokens as cookies, right? They are still there. And so what's wrong here? They mostly work, yeah? They mostly work unless you are under attack. Because if you are under attack and someone extracts that bearer token, and that is not so difficult to do, right? They are in. Meaning extracting the bearer token could be as good as asking the user for the password. If you are doing that in a nice way, the user will tell you the password, right?
And there's no way for the user to know it. The user shouldn't tell you the password, but tell someone else the password. Meaning distinguish the real from the wrong application here. AI makes it easier for attackers to run those attacks. And that leads to an arms race. And this is exactly the arms race we have been in in the authentication space for years.
That's, by the way, the reason why FIDO was founded. To replace that with something much better. And if you look at how Parskeys do that, you see we are using cryptography, which is not most of the time correct, right? That most of the time it's practically always, right? Meaning there's no false rejects, there's no false accepts, right? We really changed the rules of that game. That doesn't mean it's 100% secure. You will always find implementations that might be a little flaky, right? But it's provably secure on a protocol level, right? And that's what people have done and shown.
Implementations could be different, and people will find ways around that. And they will just refocus, right? On something different. That's always what happens. But at least we have changed the rules here, so I don't have to add more band-aids, right? To augment passwords in some way, right?
For me, this is a good example where we, as an industry, were able to change the rules to get out of the arms race and leapfrog the attackers at least in one space. It's not the only one, that's true. It also meant that now the attackers focus more, and I think if you look at the statistic, it really shows that it was kind of, yeah, correlating with COVID times. But the attackers were focusing on the onboarding, right? At the sign-up, they could impersonate users, because at the sign-in, right?
That was, at least when using PaaSkies, that's almost not practical to attack anymore. Now, we see a lot of selfie and picture ID kind of approaches, right? Show me your, unless you are in the, verify your email address, right? Let's keep those out, because that's in a different space.
But this, whatever, a few percent of the banking services, right, which do selfie and picture ID, which have a need for more secure remote ID proofing, right? Take a selfie, take a picture ID, and how do I verify it's correct, right?
Now, I can create deepfakes. Now, people tell me, yeah, we have new AI technology, which can tell you whether this was a deepfake or not. Sure enough, yes, but sometimes that technology fails, right? There's always a residual rate of maybe three percent where it's wrong. And for attackers, those three percent don't hurt. For the defenders, the three percent hurt. They really hurt, right?
Bad press, there's real fraud there, which always fuels the cyber crime. So, we have to get out of that. And for me, that's the other interesting observation here. And this is why we are talking about wallets, right?
Always, right? So, why do we have to scan something and convert it from the analog world, right? The non-digital world into the digital world, where we can use digital right away with cryptography, right? Which really gives us the security that we need to make that viable, right? And make it secure all the time, right? Unless someone attacks a different space.
So, it's really leapfrogging, right? As opposed to the arms race. Get out of that, change the game.
So, we are doing that here as well. Meaning, we can change the game on many levels. Reliance on user, right? To only enter password into legitimate applications.
Fido, leapfrog that, right? Selfie and picture ID, where you don't know whether it's a real camera or just a video stream, a fake video stream, right? Leapfrog that with digital wallets, right? This is what we can do. But that doesn't solve it all, right? There are more problems remaining. And those problems are what is confirmed, right? Just anything. The user wants to log in, that's an easy piece, right? The user wants to delete all emails, might already be different, right? The user wants to transfer ten thousand dollars, yet another question, right?
And how do we know what the user wants to do? And how do we know the user really, really wants to do that, right? This is the question which, in my opinion, already gets us out of pure digital space, right? If someone calls me and says, oh, you have to really transfer money to this account because your kids are in immediate problems, right? And to help them, you need that money now, right? Those scams. And we are seeing those already.
So, what can we do regarding those, right? How do we, as a user, verify the incoming information that might be even a phone call, right? Where the traditional authentication methods do not work.
So, the world gets more complex and we have to think about how to get out of the arms race and get into a leapfrog even harder. I, and that's my personal opinion, don't think that AI will easily give us that answer, right? We need the real biological intelligence here, in my opinion, to find more examples than the ones I've shown already, where we can really get out of the arms race, get into a leapfrog, right? Find things which are giving us robust security, meaning security that is robust even if it's attacked, right? Under scalable attacks, right?
There might be someone standing with a gun behind you, right? Sure, you would do anything, and maybe technology is not a solution to that. I would agree with that, right? But at least we can find many other things, right? Look into that to help the CISOs, right? To not get burned out, but help the CISOs have a reduced and more relaxed work environment where we can slow down, significantly slow down the attacks, because now the attackers cannot easily scale the attacks. They have to think really hard on how to crack the system, how to find another entry point, right?
To get into the system, refocus, because the current protection method, like we've seen with PASCIs on authentication, with wallets in the identity approving world, right? They are so secure that they cannot practically be attacked directly. You have to work around those, which is possible in many cases, but that needs more time from the attackers and will slow down the rate of attack and hopefully get us out of that arms race which leads to increased cyber security fraud on a global scale. Thank you very much for your attention, and I think we have some minutes left for questions.
Thank you very much. Any questions from the audience, please raise your hand. Thank you for that.
Just, I mean, more a philosophical question, maybe, is that instead of sort of going identifying and authenticating point to point, I sometimes read that the missing layer in the internet is sort of a more identity. In your opinion, in your view, do you see a possibility where you would have sort of split internet, one that's anonymous, and then one that's where authentication identity is much more built in, where you don't have to individually authenticate to each service, but somehow the browser or what carries that information, they always know who you are. Do you have any view on that?
Very good question. So, I think there's always a balance between we want more security and more protection and stop the growth of cyber crime on one hand side, but we do not want to lose all the privacy we have.
I've just seen this morning that in Switzerland there was a new rule being agreed upon that they say, now whenever you are providing digital services to more than, I think, 5 000 users or so, you have to do ID proofing, you have to really know who the user is, meaning there is no onboarding with email addresses just to use Facebook, but that would apply to Swiss companies only, like Streamr and those companies. And there's, of course, this creates another debate right now, it doesn't apply to non-Swiss companies. How would you regulate a company in the US to do the same?
For me, this is, I don't have an easy answer to say. We have to find a balance and with we I really mean the society and the answer might be different in different geographies, different countries, but it needs to be a balance and adding more accountability to the internet, in my opinion, is a good thing. There's a hole in the internet which is a missing security and identity layer. We have to see what is possible and practical to add there and that's not an easy thing, right? I can't ask chat GPT and this will just give me the answer.
So from that perspective, if you ask me, will AI help us with that? I'm not so sure, right? AI could be helping the attackers more than it helps the defenders and where we have to use our BI, the biological intelligence, to really get out of that arms race into a leapfrog system on even more layers and even more different areas. But for me, there are some things, you might go back to maybe that slide, right? So what is confirmed, right? We could easily add that, right? Like the transaction confirmation, what you see is what you sign.
I think there are things which are being discussed, whether that is the wallet or the browser, right? I see good reasons why it should be the browser as opposed to the wallet. Whatever I think, we will get to that. The real intention is a different thing, right? This gets into the how are people influenced, the psychology and that's a different discussion, much more difficult. Speaking of that, this is actually a great question to smoothly transition to our last session of today.