Hi, I'm, hello, hello. I'm Darrell Geusz, I'm product lead for NEO at Ping Identity, covering identity verification and digital credentialing in wallets. 25 years in the biz, first job, first product manager for Touch ID, helped invent it. It's very old technology. And most recently did all the mobile driver's license work with Apple and the TSA in the United States. Howdy. I'm Jon Lehtinen, I'm presently at a boutique consulting and product firm called UberEther.
I've been working in the industry for a little over 20 years and my perspective is informed of someone who's a little bit more pragmatic and approaches identity and sees identity through the lens of the people who have to accomplish an outcome for it. So less hyper-visionary, more, all right, well, what does that mean now? I'm Samir Nigam, director at Trevonix, which is, I am consultancy and service implementation partner. And I have been in IAM space for like 20 plus years, predominantly working in financial industry.
But I have the perspective of being a consultant as well as running the IAM, so I understand the pain on both sides. And yeah.
Awesome, well, we clearly have a lot of experience here. I was intrigued by the title of the panel that we were given. Instead of fabric, it's mesh. And now we're going all the way out to the edge to consider all the implications there. And a lot of us have contributed to standards work, have implemented standards, where the whole point is independently invented and implemented systems have to work together. So in the modern world, you expect to see a lot of heterogeneous systems having to interact together.
So why don't you each tell me a little bit about your perspective on how loosely coupled systems really are out there in the enterprise and where things go wrong? Go ahead, sure, Darrell.
Yeah, I mean, I'm coming from a perspective of a very large identity and access management company. We have IDPs all over the world, 500 banks, something like that. So we obviously, one of the biggest concerns when decentralized identity thinking came into it as a new integration approach was that were we gonna cannibalize our own business? And the answer is absolutely yes. And so we've planned for that in the business model. We know that eventually MFA is gonna be replaced in a lot of use cases with the verifiable credentials and wallets.
So we have cannibalization built into our model, including in our pricing and all that stuff. And so, but you're right that we're gonna have hybrid for a long time.
In fact, for many use cases, it may not make any sense to use the wallet at all. And we're gonna talk about this, but this concept that you have to move the identity data to the edge and take it out of the central stores, that's not necessary, that's optional. So it will be hybrid. There'll be data in both places, depending on the use case. What it really is is a new channel to interact with the user and the customer. And it's a new way to move data and move information instead of in the sky.
So it is an extension all the way outward and you don't have to necessarily disconnect from the central servers. So you guys both, I bet, have a lot of experience with a lot of hybrid circumstances and some legacy technologies and having to connect those in. So tell me a little bit about that.
Sameer, why don't you go ahead? Yeah, sure. Thank you. So if you look at the enterprises and the ones which have been doing like identity in the financial services, let's say, they already have some very, very tightly coupled models because that's what they started with. And let's not kid that everything is now loosely coupled in SaaS and cloud, like half and half. It's the environment that they operate in. So if it is a new startup, yes, they have the ability to be just, say, completely SaaS, completely cloud, very much all new protocol based.
Yes, they are a bit loosely coupled, but the enterprises and the organizations, the reality is there is still a lot of tight coupling there. So till the time that is there, as I already said, it's going to continue. The advantage or the excitement about the decentralized identity is that it adds another kind of method to it.
And yes, it has its advantages, but that doesn't mean that it's a choice of one or the other. It's the way in which, where it makes sense, do the decentralized and provide that, and maybe even reduce the cost by not having to maintain some of that data. But the other point, yes, you still need some amount of that data still to be there. So at least for the time being, and for a considerable period, probably it's going to remain a hybrid approach.
So, you know, you're reminding me that there was an awful lot more conversation, kind of in the old days, about how client server was going to go away, APIs were going to go away, and it was all going to be peer-to-peer. But you're reminding us that there's actually an even sort of prior step, which is very tightly coupled, not REST APIs, no API shim on top of things. So the hybrid extends all the way back, as well as all the way forward.
John, what's your take? It's going to be hybrid till we're dead. Because I've had the benefit of working in lots of different industries, from like, you know, really big R and G style, to a SAS provider, which was purely cloud. Notwithstanding, there's, you know, unless you're building a business purely with the intention of avoiding some old patterns, most things tend to develop organically.
Hence, you can't necessarily cut off your foot because your foot offends you. You need to actually incorporate additional feet to your foot, so that way you can run to the cloud and also still support the footpaths you're walking on. So yeah. Block that metaphor. Is this sneaker net we're talking about?
Yeah, I like to say nothing deployed ever dies, and you've just made a really good case for why we should have, I don't know, millipedes worth of feet in the picture. So, all right. Now let's run all the way out to the edge and explore that a little bit more.
Darrell, tell us a little bit more about what are the design patterns that you're seeing around, if somebody's running to the edge, what they're able to do to change that backend picture? Yeah, and a lot of people will say, well, retail's never going to use wallets and DCI.
Well, actually, because you can use the exact same account credential, or KYC credential, or entitlement, whatever it is, it could even be for workforce, supply chain, with a work order in the wallet, because you can use it in person, as well as online, the exact same credential, that's extremely attractive to organizations that are consumer-facing and also contractor workforce-facing. So, that's one of the biggest changes that DCI brings about, is you've got a new channel being supported with the exact, could be the exact same user experience, in person, as it is online, so that's a big one.
The second one is, I don't know if you saw the letter from the CISO at JPMC, like three days ago or something, but the APIs and federation is under severe, severe attack, especially now with adversarial AI gaming these systems. And he came out and said, we can't just keep doing the same business, OAuth and OIDC in line, authorization, authentication, in the same channel, it cannot continue.
So, you have to do something out of band. And what we're learning is that DCI and wallets is a really good way to frustrate the fraudsters and the hackers, because with the double cryptography, you're snipping the wire in the sky, you're rerouting it through the wallet, it makes it an extremely expensive hacking to get to it and to compromise it.
So, if you require the wallet in the workflow, it can be very frustrating to the hackers, right? And so CISOs are starting to get this, their eyes are lighting up, and so we're actually seeing for security reasons, it can be very powerful, even for online interactions. Does that make sense, what I'm saying?
Yeah, absolutely. I wonder, have you guys run into these use cases and how's it going?
Yeah, we are doing an implementation where we are trying to work with a financial service organization on how they can leverage this, both internally and externally. And as Daryl said, the interesting thing about this is with the IDAS, with other things, it's becoming much more mainstream. And the consumers are going to demand, why can't I have that kind of an experience, even within the organization and across?
Plus, there are new use cases that are coming up. Doing all this age verification and everything, or doing the KYC and everything has been so manual and it's still not fully, fully in an automated manner. This can simplify the process that much. In addition to this, so the user convenience and the adaptability, in addition to the security, things that Daryl highlighted, I think it's definitely going to happen. It's not that it's not happening. It's just that the organizations need to understand where these are best used and how to adopt them.
In that case, I sort of have an impertinent question at this juncture, because we have had the conversation in the FIDO world about, okay, well, if device-bound pass keys are hard to recover, now we go to what I think of as insidious re-centralization with synced pass keys, and that's a challenge that we face. Recovery is a challenge that we face when everything is really that decentralized.
So, I don't know, John, you're nodding. I wanna know what your thoughts are about this. Go for it.
So, from a practical perspective, yes, I think it'll be an additional channel for information. It could greatly simplify certain processes, namely, let's say, employee onboarding identification, I-9 processes, and stuff like that.
So, I think that has the potential to be cool, but I am worried that in a world where we start pushing increasing responsibilities onto individual consumers, as we've done more or less for the last 40 years, it's gonna be an explosion of more like the homo economicus, where you have to be an expert in every single field in order to navigate anything. So, now, were we gonna have everybody be an expert in decentralized credentials and setting those up? Will there be, like, do you introduce a centralized capability to help people onboard into a decentralized ecosystem? Does that under?
Cough, custodial wallets. Okay, like, does that undercut the thesis of it?
No, you'll have personal AI assistant. It'll take care of it for you.
Oh, God, that's so cool. It'll help you.
No, I'm serious. I see a gauntlet thrown here.
Okay, let's talk about this. It'll help you figure out what creds, what attributes I should or should not share with this verifier. And by the way, these are already being built. Really? Personal AI assistants for wallets. I have no problem meeting Crow and being proven wrong, because God knows I am a simple man.
But, you know, it's like, I just see it's like, from the challenges I see today, decentralized identifiers, decentralized credentials, decentralized identity, the works, I see where there could be incredibly value. The problem is we still need a central authoritative source of some species for that initial attestation in every single workflow I've ever seen inside of an enterprise. And perhaps it is a limit of my imagination right now, which I'm willing to change and be proven wrong about to see how that will change and then value will be added.
No, totally. I mean, there has to be an initial proofing event. And generally that'll be a centralized authority involved. Even for a retailer, you know, that's, for example, we have a chicken chain, very big chicken chain, and they're gonna do DCI and they're gonna keep only the email address. They want everything else on the edge. They're a fast food server, who cares? They don't need all that crap, the data, and be liable for all that. But if you're a bank, you're regulated. Of course you're gonna have everything in the sky, right?
I mean, usually the reason to have all that data is, you know, not because you're taking on liability, but because you really wanna monetize the data. And that's some of the source, I would say, of that insidious re-centralization. You're all suggesting that the experience for the poor individuals involved is gonna really matter. And so I wanna turn, before we go to any audience questions, I just wanna ask a little bit about the state of orchestration of these journeys and workflows. What's kind of the state of the art? What are you guys doing and seeing there?
Yeah, I mean, if you come by the booth, I'll show you the video, but we have a bank that's doing app switching. And it's an investment brokerage app that's legacy, heritage.
So YDC, it doesn't even know what a wallet is. But because of a standard called PsyOp V2, the wallet becomes an OP and looks just like a federated event to that application. You guys are all the tech-savvy folks who knows what an OP is, right? Yeah. Open ID provider, identity provider of the OP sort. And so we've got a lot of legacy apps, of course, in single sign-on even, that can have a wallet single sign-on into these applications. And in their case, the customer doesn't even know they have a wallet. They've instantiated it through iconography and checkboxes.
You don't need to show a card like Apple Wallet does or Google Wallet does. Is it a web wallet? Are we talking about a web wallet? No. It's in the phone. It's on the device, okay.
Yeah, but you don't need to instantiate the visualization the same way. The user doesn't even know they have a wallet, but they're exploiting the technology and the better experience. So it's a walletized app, I guess?
Yes, exactly. Okay, Samir, I can see you.
Yeah, you've had some experience with this. So if we just look at the orchestration across the identity journey, I think the benefits of that is being able to bring in a new factor at much ease. I was speaking with someone yesterday who was talking about taking a long time trying to implement another way of MFA, for example. And if you have a proper orchestration, you should be able to bring it to life very, very quickly. So that is the advantage. And decentralized, again, can be just another factor that can be added to it.
That's the way we see it, and that's the way we are seeing some of the customers. Yeah, we have one bank that gets a request for 350 new API or OIDC connections every month because of fintech, business partners, whatever. Their IT department can't even build 15. And their legal department can't even handle 10, right? The federation model is not scalable. And it doesn't scale fast, so you have to do a security assessment and a privacy assessment and all that garbage.
With DCI, you can light up use cases without any backend integration. And so now you can light up use cases very rapidly, even with a lightweight MOU. So you're suggesting, this is a more disruptive claim, no pun intended, that the better, more scalable way to make the mesh happen to actually integrate systems is through the edge. I believe so, including in person, not just online. So we're back to key signing parties then.
No, just kidding. If there are any questions, we'd love to take them now before we got just a couple minutes, I think. Any questions? Any answers?
Yes, Patrick. I always have a question. If you're on me, I always have questions, yeah? Story of my life. So the thing is, I'm very curious about what they're all talking about and so on. But do you have an idea, just from your gut feeling, to which extent the user needs to understand what is happening here, yeah?
To really, it's not like it is done today, like give you a credit card and a CVC number to like everyone, yeah? To which extent do we need to have digital competency in the society to make maximum use of it? I can start.
Right now, we're actually working with banks to converge payment and identity. You'll never have to type the credit card number ever again.
No CVV, no expiration date, no billing address. All that automatically happens in the interaction. And this was shown like four weeks ago with one of the pilot programs for EIDAS. It was a Greek ferry ticket that was purchased, a Romanian credit card, and an identity from Sweden, in a Swedish wallet, and it was gorgeous user experience. That is the future, and it actually helps, not hinders, from that perspective, right? And I believe, again, you don't have to show cards or Rolodex of 1,000 cards to make it happen. And I really believe AI assistants are gonna be part of this wallet experience.
And again, major banks are already building this today. If I can just add to it, like in two examples.
One, in India, when there is something called unified payment interface, and it's like, you even go to get like a grocery or anything from even a roadside shops that are there, they all no longer, I feel outdated if I go there and I say I'll give cash or I'll give credit card. Because they say, okay, just do UPI. And they will show that on their phone, you scan and the money gets transferred. Now the good thing is, the government has enabled a framework in which it can operate and people have that trust. And that is what is needed.
And speaking with the Department of Technology in UK, we had a presentation and I was speaking with him. He also had the same thing that, the government needs to bring in that trust. Once that trust is there, there are private players will get involved and make it usable, even beyond what it has originally been thought of. And that's what we need. So user guidance will come in time, but it should be about like, don't give out your CVV out there, right? But those are like some very simple messages that can be easily understood.
But there's still people who don't use mobile banking because they don't trust it. So it's not, everyone will do it. Generational. Generational. Yeah. I know we have to wrap up now. Yes. Thank you so much. Everybody. Thank you.