Now, we would like to talk about passwords, to be more specific about passwordless. Today, we have Dietmar Wyhs right here, and he'd like to tell us something about revolutionizing PAM in a zero-trust era. Please help me to give a welcome to Dietmar. Thank you.
So, my name is not Bond, and nobody calls me James either. My name is Dietmar Wyhs, and on behalf of SSH, I welcome you to this short presentation.
SSH, the name is not coincidence. We are the founder of SSH.
So, 30 years ago, the founder of the company, Tato Ullinen, a guy from Helsinki, invented the SSH protocol, made it open source, but also started a company with that topic. Of course, in 30 years, we developed a little bit more than just open SSH and the like.
So now, today, we are in the access management, and we do it a little bit different than other companies. We do it passwordless and keyless, and I think all of you know these kind of cumbersome processes at the very beginning of any kind of sessions, and it's just a nightmare.
I mean, I'm fairly senior regarding IT age, and I've been doing that more than 40 years now, and it didn't change at all, and it's just a nightmare. And I don't know why, but it seems like it's very hard to move away from this. It's maybe not compliance, but we say give these kind of credentials entering the finger.
So, I would like to invite you to talk a little bit how you can make access management password and keyless, so you have not to remember any kind of passwords or have to put in any SSH keys or any other kind of standing credentials. And, of course, it needs to be just in time with just enough access, and still, I know I'm also talking more than, let's say, 20 years now, data anywhere, anytime, still on-premise versus cloud is still a topic. Sorry to say, but critical infrastructure, as well as public departments, as well as large companies, it must be both options possible.
It should be a solution where you can decide you have on-premise instances or in the cloud or even in a hybrid environment. We do have customers who really have a hybrid installation because, therefore, they reach the highest availability they can get.
So, they have some instances on-premise, some instances in their private cloud or even public cloud. And then, of course, you need to have security, and, therefore, you need to have MFA, and that should not be entering any more pins you get with Microsoft or Google Authenticator, but it should be enough just to scan your fingerprint or your face recognition, pass key feed or whatever.
Of course, if you insist, you can still continue the old classical way. We support also that, but we advocate our customers to move away from that.
So, why are we still using that? Well, in our MBA, it's still our classical perimeter wall building thinking.
However, IT is very different. Since a few years, everything is connected, even in the OT space.
So, still nowadays, sometimes you come to OT environments and people say, yeah, we are air-gapped. Most of the time, that's not true. That's simply not true. Even in the OT space.
So, everything is connected, and, therefore, you have to think a little bit different. Because one of the biggest issues is once you are in the walls, you can move there around, and you can do anything you'd like.
And so, once you've broken the perimeter, then you're in the systems. And especially those accounts who then can do administrative things. SSH is not a general identity management system. You have heard about that, I think, the last three days ten times or even more. We take care of the specialized accounts, the administrative accounts. Because when you are attacked, when someone tries to get into your systems, they are always looking for the administrative accounts because then they can do much more.
And so, you have to protect these accounts in a special way, but not in the classical way with additional MFA or passwords or keys. You have to try to become password-less and key-less.
So, how can you do that? Well, you first start the classical thing. Password vault. You obfuscate, you encrypt the passwords. You have the shared accounts. You rotate the passwords. But the next step, that's the key step, is to get rid of them. And how we do that, I'll explain in a second. Very different story. And I've seen many, many enterprises where they had already a PAM system in place. But most of these PAM systems are not very good in handling SSH keys. Okay? We are in the venture of SSH keys. I think we know how to handle SSH keys.
Because there, it's much more difficult to find out what SSH keys are in your environment, who is using them for where and when and what. At least in 99% of my experience with enterprises, they don't dare to delete the SSH keys because they don't know who is using it for what. So I personally experienced one case where we found 400,000 SSH keys and we could delete 300,000.
Of course, that's a significant reducing of the attack surface. And also the transit trust with SSH keys is a big issue. Because once you can jump to a host with an SSH key, you can look what other SSH keys are and where are they leading to. So transitive trust is a killer topic in large environments. And we can take care of that. So we can discover the keys, we can eliminate the unused keys, and we can start to manage the keys. And then again, the last step is how to get rid of the keys. Likewise with the username and passwords.
So we advocate our customers to use, instead of the standing credentials, so-called ephemeral certificates. Anybody heard about ephemeral certificates? Thank you. It's short-lived certificates. Which means it's issued when the user wants to have access. And if he's allowed to do it, of course. Once the session is up and running, the certificate is already made invalid. So it's even less than a one-time password. And therefore, what's the advantage of that?
Therefore, you don't have to store it somewhere and do key or password rotation. In very large environments, that's a very, very big topic. We do have customers which are global. They have only, I'm talking now only about SSH keys, but there are other standing credentials. They have more than 1.5 million valid needed SSH keys. Can you think about an automatic rotation of that amount of keys? Every IT system will have some failures.
Therefore, they try to move away from that. The good thing is they don't have to do it in a big bang. They can do it piece by piece, group by group, role by role. And then there's a little add-on on that, and we do that even in a little bit different way than any other vendor I know. We do that already quantum safe, with quantum safe encryption. And I'll come to that back in a minute. So how does it work?
Yeah, okay, we are something like a proxy. So we are, of course, getting information from the classical world out there, all the I, G, M, A systems and so forth. So we can integrate in single sign-on systems, in LDAP, SIEM systems, whatever. So you don't have to start from scratch to define your groups and roles.
Because, of course, we are a role-based system. And then you can define even more granularly what this human or machine account can do to reach the targets. The targets can be physical devices, databases, can be cloud stuff, can be, of course, located in different network segments, or even different global continents and so forth. And therefore, we added a little extra microservice architecture software, Privix Extender and Router, which is a reverse proxy. Because between the segments, you have the central instances, maybe several because of availability.
And then you have the segment, let's say, in the US. And you don't want to open the ports in between.
Therefore, you install the microservice architecture extender from us. And this is a reverse proxy. Fetching the tasks from the central instances, executing it in the local network. And then this traffic is already quantum-safe encrypted. So the highest encryption you can get today. Even quantum computers will not be able to break them in five-ish years. And that also works with OT stuff. So the difference, for example, is not very big, but it is for IT systems. It's the classical SSH, RDP, HTTPS, VNC, whatever. You know that.
But then you have this large area of OT stuff with very specialized protocols, like Siemens S7, like Modbus, like stuff from Honeywell Schneider, etc. And these systems used to be air-gapped a few years ago, but nowadays they are reachable. And therefore, you have to take care also of that. And we can handle these specialized protocols to control the access even for the OT environment. And of course, any kind of applications. We also have, of course, still the user password vault, where you can do the old stuff.
But again, we advocate where possible to get rid of those and use the ephemeral certificates. So for the user, for the human user, all he needs mainly is an HTML5 browser. He connects to our system.
It can be, of course, integrated with workflow systems. We have our own workflow system, but you can integrate with existing workflow tickets like ServiceNow, etc., with a REST API.
And then, of course, you want to, according to his role, allow him to access whatever device target system. But you want to control and manage it, so you want to do session recording. You want to maybe even look in parallel. You want to monitor the session. And at least you want to have audit logs. And these logs, of course, can be also exported in other systems like SIEM systems or whatever with REST API. If there are questions to that, please do it immediately. What is OT? The manufacturing environment.
So if you think about the automotive sector, there you find a lot of PLC stuff or other kinds of machineries. Or we do have a lot of customers in the pipe and paper production. Or we have a customer called Kone Cranes.
Kone, you might know from the elevators, from the lifts, but they have actually a larger business, which is the big container cranes in harbors. And they have more than 50 harbors worldwide. And they operate from Finland and manage and control and update and configure the cranes with our system. And of course, they are very specialized protocols for this kind of machinery. Thanks for the question. Last but not least, remember this guy. I'm not Bond, as I said.
It's very, very important in large environments. This is an agent-less system. In order to do all of that, you don't have to install anything on the targets. Especially in large environments, it's of course critical, because if you have thousands of devices or servers or databases or whatever, you don't want to maintain an agent on any of these devices. So this is a key, minor topic, but it's very important for the usability. Have I said already that SSH keys can bypass pumps? So that's what I said before.
We've seen a lot of large customers coming to us saying, yeah, we have PAM already, but SSH keys, we are not very sure if we are really controlling them. And I make a bet with you. We give you a free risk analysis, and if you don't find unmanaged SSH keys, it will be for free. Take me by the word. I'm very sure I won't have to pay a dime. So of course, what they normally do is they start up the PAM, deploy their public-private keys, and then they go around to PAM. That's admins, how they work. And therefore, we have a tool called Sherlock, or SSH, or we can even do the service for you.
You can do a risk analysis and see if you might find some SSH keys which are not controlled, which you don't know who is using it for where and when and what. And I'm very sure. Until today, I never had an experience where we didn't find something. So please come and talk to me if you're interested in getting such a kind of a risk analysis. Which brings me to a few topics which I just wanted you to remember. Our system, our solution, that's the hard fact, is based on the Linux environment. So it cannot be installed on Windows Server. That's the only hard fact.
But we support any kind of Kubernetes environment, so very easy to scale and maintain. We support, as I said, multi-protocols, the standard protocols as well as even the specialized protocols for OT. You can install a solution on-premise, in the cloud, or hybrid. And therefore, our customers, they really like our solution because also it's agentless. And therefore, we have an extremely high network promoter score. I've been working for other companies, and I don't know if all of you know the network promoter score. It's from minus 100 to plus 100. And you are good if you reach 30.
And I remember a company I worked for, we reached finally 30, and we were cheering and making a huge party out of it. At this age, we have an NPS of 71. I was too lazy, actually.
I said, I need to check how many companies reached that point. Unfortunately, I was too lazy to do it, or not enough time. And therefore, we have happy customers, and we can name a few of them. Unfortunately, not too many, honestly, because we are also in critical infrastructure. And most of the time, those customers say, now you cannot name us. And so that's the chicken-and-egg problem. When you might come to me, can you name me, give me some use cases?
Yeah, well, I can give you, but I cannot give you a company name. That's not possible. Then I ask you, will you be my customer reference I can name? Most of the time, they say, I cannot. I cannot be a customer reference.
So anyway, we do have a lot of customers, which are very happy customers, and I'm happy to talk about the use cases, but most of the time, I might be not able to tell you the name. Anyway, one more thing. I stole it from this old guy, old guy. One more thing. Quantum safety. I don't know how many of you are interested or have even looked at it. I can only recommend start doing it. It is key. Unfortunately, even the U.S. are ahead of us.
Joe Biden signed a bill, an act, in December 2022 that any public authority and enterprise who is implementing new stuff or even having stuff needs to start working on the topic. The topic is that quantum computers will break legacy encryption in, okay, let's take Gartner in 2029, which is roughly for almost five years from now. You might say, okay, let's do that in two, three years. Unfortunately, I would say it's not good enough because I think there's a lot of data which needs to be saved more than three, four years.
The issue is that since Snowden, we know, all of the traffic is stored and it will be decrypted then in a few years from now. So you have to take care of that topic today. And we are working on the topic since more than seven years. We have implemented the first customer in 2020 already. We have now implemented more than 10 customers with that technology. And you should start thinking about it. It is now and not tomorrow to start working on the topic. And we have that as a standalone version.
So if you have, let's say, different sites, if you have a site in Berlin and a site in Peking, for example, and you want to have really safe data exchange, you can get an appliance from us. And all the traffic in between is quantum-safe encrypted. And it doesn't matter what kind of connection it is. We are working on layer two and layer three for the technical guys here. And it is a hybrid encryption, which means it's using the new algorithms. And it's also on top still having the old Ecliptic Curve Diffie-Hoffmann because the hybrid is seen as the best encryption today.
We are part of the NIST Consortium for that. So the NIST Consortium also recommends a hybrid encryption for that. And in that space, it's important why SSH. In this kind of topics, it's important to know where is the development, where is everything done. In our case, it's in Finland, in Helsinki only. No nearshore, no offshoring. We are tested, the classical one, like ISO 2701. But we are also even NATO certified. And therefore, I can only recommend, especially in these days because of geopolitical topics, we are in the EU. And therefore, of course, in the EU, it's very easy.
The only thing is, if you might be outside of the EU, there might be some UK guys here. Sorry to warm that Brexit topic up. We need to get some approval to export out of the EU. But that's a matter of time only. And that's it from my perspective in 20 minutes. I'm on the second. And who knows this sound? Who remembers this kind of sound? What is it? Sorry?
No, it's Morse code. It's the Morse code for SSH. And therefore, thank you for your attention. And I hope you have a good lunch. If there are questions, for every question, I have one of those bottles. Anyone? Let me just give you a microphone. Yes. Very good question. Thank you for that. We do have a so-called UEBA, user entity behavior analytics. And I didn't want to use another password. It's with artificial intelligence. Sorry for the password again. We do have that. Yes. You can define regarding the top, the severance of the top, or the severance of the issue.
You can say that it terminates the connection, or it sends an audit trail to the SIEM system, or whatever. That's how you set it up. You're welcome. Thanks for the question.
All right, then. Thank you for your presentation. Thank you. Thank you.