My name is Mike Kiser. I'm Director of Strategy and Standards at SailPoint. I have been orbiting AI for a while, even before it was really, really AI, especially in terms of philosophy around it and ethics around it. I would say that things largely haven't changed in the last five to six to seven years. I think that we've made some strides in terms of documenting that intersection in terms of transparency and accountability and those types of things. I think people have ideas that they should be ethical.
I think some of those concepts, especially in the States, are slipping away slowly but surely, given the current winds. But I have hopes. That's my general, non-specific answer. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole. Opening thoughts on AI.
Well, you know, we listen to a lot of vendor pitches on AI inclusion into products, and they all seem a little bit rosier than what is probably going to be the case. You know, you talk to customers. I think there's, depending on the customer type, there's a bit of ambivalence about AI.
You know, it's just another tool. But then I also cover the fraud prevention space, and I see that, well, if there's one area that AI is getting used, it's to help create more and more fraud. So I think the jury is still out on the overall usefulness of AI and identity.
I mean, I think there's plenty of opportunity to use it for good, but the opportunity to use it for bad is equal, if not greater. Hey, everyone. I'm Tim. I'm Head of Solution Engineer at Unosecure. It's a company founded during this new era of AI. In my perspective, when I look back at AI, the best is to look at the history. And I think we dealt a lot about machine learning, and now we have this new wave of Gen-AI.
And what we see is that with Gen-AIs, the number of attacks are growing, and the threat of identity being the number one attack vector, which is like 80%, will grow even more with that. Yeah, and then they are getting even more sophisticated with time, with the use of AI. So we collected a couple of interesting questions, to begin with one. As a matter of fact, fraudsters are using LLM for new account and synthetic identity fraud, specifically to create plausible PII, like in supporting documents, like utility bills, to get in illegitimate accounts.
Do you think that it is possible to defend ourselves against this? I can start with you, Tim.
Yeah, I think it comes down to what kind of application we have, because there is nowadays technology to prevent this deepfake stuff very good. However, it's a trade-off between the cost and the effort, that you want to add this extra layer of friction for someone to maybe register, sign into those services, versus providing a good user experience. And I think if you have a not-so-critical service, then you can use some extra loops and steps of maybe email verification or something like that, which helps in the first place. And I think from the technology, there is some really good stuff.
I mean, when I was walking around here at EIC, and I'm not sure if you talked to some of those guys, but there's really good things on the market, on the technology, where you can prevent it. Did, for instance, any one of you travel to the UK over the last, like, two or three weeks, and you had to go through this new process, where they don't have a visa, but you need, like, an extra document to, like, to enter in the UK? No one?
Yeah, so what they did is a very smart thing. And I think this is something where also companies can adopt it. And that is basically, when you have to sign up, register yourself, they use the passport. And there's some new technology out there. There's different banners which support that. But within our passport is a chip, and you can use your smartphone to scan that chip. So if you download that app, and you sign in, you have to scan the chip.
Now, everyone might be worried about, like, yeah, I mean, Forrester can basically walk by and scan the thing. Actually, when you go to airports, and you have to automatically, like, sign in, then you basically put your ID card on top of a scanner. And on the first page, there is an ID number. And that ID number is used to actually unlock access to the chip.
And, I mean, I don't want to go into all the details, but it's, like, cryptographically signed, and so on. This is something where, like, if a Forrester wants to create an account with my identity, they actually have to steal my actual passport. This is something where you can have a high, like, entry point.
Yeah, I think in cases where you're trying to get a really high assurance level for identity, there are ways to do that. But I think, you know, in the spirit of the question, some of the cases where you're not demanding high identity assurance, how do you tell a deepfake document gets a lot harder?
I mean, you're right, because there are ways to, like, use NFC, reading against the chip. But, you know, a lot of the fraud prevention solutions out there now either don't do that, or you have to look for the really high-end ones that do.
And, like, a fake utility bill, how are you going to tell? I mean, you're taking a picture of a picture.
Yeah, I mean, maybe you can use some logic and figure out if there's... Yeah, I don't think I need AI to create a fake utility bill. No. I just need a sample, and I'll change the dates or change the, you know what I mean?
Like, I hear you. But, like, if I bootstrap my way up from that, that's a lot easier than trying to get past the British Border Patrol. So I don't see how we're going to do that without massive investment, and I just don't think it's going to come. I think what's going to happen is the forms of proof that you currently have are just going to be yeeted into the void. In other words, they're just going to just... That's not going to count anymore. Just like video of someone saying something is not going to count anymore. If I'm a politician, that was AI, right?
And so I think there's just an eroding of trust is really what's happening, because not only can you do it, but I can do it on my MacBook or my Windows PC in, like, 45 seconds to a couple minutes. Think about how many people at this conference put their slides together or wrote the abstract or wrote the script with ChatGPT. I bet a lot of them did, right? As I yell into the void like an old man.
Well, you know, thinking about the erosion of trust, which is an interesting topic. I mean, how many people, if you see a number on your phone and you don't recognize it, does anybody answer a number they don't recognize? Does anybody... I'll keep that in mind.
I mean, you don't respond to texts you don't know. I mean, some people do, but I mean, my 80-year-old aunts even know, don't answer the phone if you don't recognize the number.
So yeah, we're kind of in a spot where we don't trust governments in many cases, we don't trust businesses, and we don't trust random numbers that pop up on our phone. Yeah, I can absolutely agree on that. And I think for organization, it becomes a really, really big challenge because there's no technology that can provide us this extra layer. I think it comes down for the education, the people, the way we behave. To give an example, with our organization, there is a lot of phishing emails that we are getting, and it all looks like it's coming from our CEO and founder.
And what we have introduced is some things like, you will never get like a one-on-one message from me. It's always like with some other guys in the group. And if you get the message and even it's in a group and you're not sure, write directly to me to verify if the thing is from me. I think it really starts with the culture, but it has to stop at the top. Like the top, like the founder, CEO, those guys have to show the culture, bring the culture into a company.
And especially for us as we work in security, it's important that we are the ones that are the role model and are the ones that define the culture of the company. To argue against myself and everybody else as well, there are movements though afoot, CDPA and some others that are using AI and they're introducing watermarking into the products, right? Cryptographically signed watermarks. So I could see that route being headed down in potentially productive ways that anything I produce with Adobe would be digitally signed by whatever.
And if they're already producing those documents in those applications, I think that's key, right? I don't expect any of these organizations to create an artifact and then run AI on top of it.
And then, no, it's got to be part of the default process, right? But then you have the other issue, right? The receiver of that has to be able to validate it and verify it. And that's a whole different... As soon as you involve a consumer, then you have some potential issues. Anything to add from our audience? All right. So I can maybe switch the topic to some phishing emails.
Enough, I think, talking about the fake IDs. And actually, I was actually going to ask you maybe a small question. This could be a small question. Do you think that is there a way to train our data sets to distinguish between the real and fake IDs? And do we need to do that?
I mean, what's your thought on this? Maybe we can briefly discuss this as well. I think if we have some really smart algorithm that can detect that this was generated by AI, the attackers start to manually craft those emails.
Yeah, I think some of the identity verification vendors are doing exactly that. They're training their algorithms to be able to recognize legitimate IDs. And therefore, anything that sort of falls outside of that would probably not be legitimate. Yeah.
I mean, if what you're doing is looking for something that will fool a person into clicking, that's a much lower standard, I suppose, right? Like, yes, your AI could be used to detect other AI. But if I'm a malicious actor, what I'd like to do is run my AI through your AI to learn what your AI is doing. I just want to say AI five times in a sentence. But you get the idea, right? That the whole idea of GANs is that they threshold and learn against a standard anyway. So I'm not sure.
Like, other than domain routing and actually looking at the headers and those types of things. I think a solution would be that an AI can support us in defining a risk level. Imagine you would get an email or you get an image, and you can get an additional risk level from an AI that tells you, like, this is maybe high risk, this is low risk, just as an extra thing. What do you think about that? Say it again. Sorry. So when you get a phishing email, or maybe you generate an image.
And for us human beings, I mean, even when we use AI and we can detect some stuff, there will be no way to 400% detect everything. But I think where AI can support us as the person that is being targeted is by providing us more context, more risk signals. Do you think that would help us to differentiate between something which could be real versus something generated by AI? If you could detect the risk signals, then why wouldn't you just go ahead and block it with the AI system rather than advising the human? Would be my...
Yeah, because you don't have like 100% way to tell if something is like generated by AI or if it's real. There's always the false positive or those edge cases.
Well, and legitimate emails can be generated by AI. Just to muddle the picture further.
Yeah, that's true. How many times have you said, yeah, I'll take that reply, just reply for me and writes the email for you and... But then it's again culture. If you just like use those tools, generate an answer, you don't even go over that. Isn't that like a cultural problem?
I mean, I think that ship has sailed. Right? I really think that people are long-term are not going to write and read emails. They might read emails, but they're probably not going to write emails. They're just going to let AI respond for them. And I mean, with prompting, right? Not like just respond whatever you want. But I think that from what I've seen, you basically, you seed things to technology because it's easier. The classic example I used to give before it became a really old example is how many phone numbers you may have had memorized in your head before you had a mobile phone.
I probably had 20 or 30 numbers that I could, oh, that's my friend, so-and-so. Now I have like two, because why would I memorize that? My phone does it for me, right? I think math is the same way. People don't do sums in their head. They don't maths in their head. They let their device do it. And I think writing is another thing that's going to be seeded.
Okay, Calma, thanks. Hey, I think that's another concern. I think everyone is also concerned here about the better crafted phishing emails. This begs the question, is there any way that we can train our employee to get to a point where we can be at least more feeling more secure about how we do our daily businesses and not to be afraid of what an employee will do? And I think there's a lot of things that an employee will do and cause maybe damage and so on. And maybe you can also share us what are your thoughts on this and the alternatives we can actually think about already.
I'm kind of torn on that one because, yeah, you want users to be well-educated and to make the right decisions on their own, but with the constant one-upsmanship, I mean, that's a lot of training, you know, and how useful is that to your business to put that kind of time into it? I mean, obviously, it's useful if they don't cause some sort of massive cyber breach, but with the constantly evolving tactics, I mean, yesterday I was talking about voice deep fakes.
And, you know, right now there are certain things you can listen for, but six months from now, the bad guys will have figured out what those are and then they will quit doing that so that what you tell somebody now will not be valid six months from now. I mean, if you're, well, a couple thoughts. One is you can inspire them on one level by saying, if you don't identify or pay attention to a potential phishing email, then you have to take more training. That will incentivize people to not miss that because no one wants to take training, right?
I think the long-term answer, if you think about AI and the intersection of identity, there are sessions after sessions this week full of people saying, here's the new way I can communicate to you that I am me and prove it to you cryptographically and you can prove it to me that you are who you are cryptographically. I know your identity, my identity, it's all verified, it's all secure. We've tested this, et cetera, et cetera, but we don't do that with things like email.
So at the risk of sounding like someone from 2001 saying we should all just switch to PGP, which is horrible in usability sense, at some point it feels like the answer is just to cryptographically sign everything if you can make it easy. And I think that may be your ultimate identity intersection with AI, at least in this space.
I don't, I'm not saying it's easy, by the way. Yeah, I would actually go one step back because why do the attackers send that email or phishing thing in the first place? And I think it's not possible, I mean, there is a way where you can protect the front door. We have MFA, we have like different things in place.
However, what I think what organizations also need is the visibility behind it. So if the attackers are successful, because we cannot protect it in the first place, how do we get the visibility of like the evil is happening?
All right, I think the time is up, but maybe we can have one last question. I was going to say, so at SoSafe, we did phishing training and employee awareness as a product. We were competing with Nobby4 and Hawksund and whatnot. What I learned from there is, you know, you can have endless training as much as possible. It's a never-ending story. All the employees come through this, you know, every year they get a training. If they are in healthcare, they get training and whatnot.
But from a security leader's perspective, it's important that you build a comprehensive system around it, that people are going to make mistakes. And you assume that, you assume breach, you assume certain emails or phishing emails are going to get through your email security gateway, whether that is your Microsoft, if you're a Microsoft shop or a Google shop, or even if you have Proofpoint or Mimecast or abnormal security or in a material or whatever, sitting in front of your email server with the admin API integration.
So it's important that you train your users and also to not entertain a blame culture. It's okay for you to click on an email. Not everyone is on the same security education as all of us. So how do you reward? How do you not blame? And how do you integrate multi-layered security systems with native email servers capabilities and add an email security gateway? And let's assume everything went through. The email security gateway fails to explore the email in a sandbox, analyze that hash values and whatnot, and the executable get downloaded into a system and got attacked. So how do we get there?
We get an EDR and all of that. So it's important to assume people are going to make mistakes and build a security systems all around it. So we give a sense of security to the employees that we are working with.
Okay, we're over time. So thanks guys.
Thank you, Tom.