Good morning, everyone. Where do I put this? Make sure it doesn't fall. Thank you.
So, as Warwick said, my name is Jason Keenaghan. I'm the Head of Product Management for IAM at Thales.
So, I know that this is early in the morning, so thank you for those of you who were able to get up out of bed after the happy hour yesterday and join us. Just to make sure that you are awake, though, this is going to be the audience participation part of the presentation.
So, I want you to tell me. Who recognizes this music? Somebody shout it out. What is it? Mission Impossible. That's correct.
So, Mission Impossible was a TV show in the 1960s when it ran in the U.S. from 1966 to 1973. 20 years later, they actually made a movie out of it in 1996 starring Tom Cruise. It became so popular, actually, that there are now seven movies in the Mission Impossible series at this point, with the eighth one just around the corner coming out in a couple of weeks, May 23rd. I'm not trying to promote it, necessarily.
So, now, show of hands. Who's actually familiar with the premise of Mission Impossible? A couple people in general.
So, just so we're all aware, so kind of level the playing field. So, Mission Impossible surrounds... Mission Impossible is focused on this group of elite secret agents that are really like the best of the best. They are part of what's called the IMF, or the Impossible Missions Force. They're called in when some mission needs to be completed that's too complicated, too complex, too difficult for anyone else. And the IMF team are masters of disguise, masters of combat, masters of hacking, you name it. They've got all kinds of skills to get the mission done.
Now, one of the other key things in Mission Impossible was whenever a mission was about to start, they would get their mission assignment and what was kind of the catchphrase that was used? Anybody know?
Yeah, that's right. Your mission, should you choose to accept it. And then the team would go off and fight their mission.
Now, one of the secret agents of the signature tools that the IMF had at their disposal was realistic mask-making technology, voice mimicry that enabled them to go and create these super realistic and perfect disguises that would help enable them to get their missions done. So now the agents in the IMF could impersonate basically anyone, even fooling their own colleagues. Their disguises were so good. So in many ways, the disguises of the IMF were like deepfake technology that we are seeing in place today.
Now, deepfakes have gone from kind of the experimental technology or something that you would only see in the Mission Impossible movies to something that we see in everyday life. So staying with the Tom Cruise theme as an example, on TikTok, deepfakes of Tom Cruise have run rampant, getting millions of views and fooling viewers and making them question whether or not these are actually the actor themselves that are giving these messages. We see other celebrities and public figures on social media often being impersonated and using deepfake technologies.
So a movie director, Jordan Peele, in the US, a couple of years back, put out a deepfake of Barack Obama really as a cautionary tale that in the wrong hands, this technology could be very dangerous, using trusted figures with trusted voices to push false messages. Similarly, we'd see deepfakes of Mark Zuckerberg on Instagram or more recently, Tom Hanks, deepfakes being used of him to promote different products.
Now, unlike Mission Impossible, where there was all of this state-of-the-art technology and you had to have all kinds of money and resources to be able to build these disguises, today there are a wide range of tools that are available for almost anybody to be able to go out and start building deepfakes. So there are free tools out there like DeepFace Labs, FaceSwap, Avatarify, that if you've got the right technical skill set, you can go and you can build your own very convincing deepfakes.
However, there's also more user-friendly options. There are mobile apps like Zao and Reface that make it available for anybody to be able to go and drag and drop and very easily create these deepfakes, either deepfake photographs or pictures or videos as well. So the process of building these deepfakes, I just want to take you through how simple it actually is. So the first step in the process that you need is to actually get your source material. So you need, say, a still photograph, like that handsome devil up there. Who is the target that you are going to want to impersonate?
The second thing you need is a comparative, either a photo or a video, if you want to make it more realistic. So let's say you take a 10 to 15 second video of yourself, a selfie, and you move your head around, you twist it from side to side, maybe you speak on top of it. Now you've got your source material. Second step is actually creating that deepfake. So use one of the tools that was on the previous page that I showed. Here what I'm showing on the screen example is the Reface app. This is the web version of it, not the mobile one.
But once you've got your two source materials, you simply upload them to the app, you click a button that says Swap Faces, and it will take the still photo, put it over either the other photograph or the video image, does some churning in the background, out you've got is your deepfake video. Now you can go and post that on social media, send it to your friends, do whatever you want. But if you have more nefarious aims in mind, you could be using that now to try to defraud an identity system.
So the third step in the process is if you want to use deepfakes to be able to combat what we think of as traditional identity-proofing solutions, this becomes a little bit more technical, but still, if you follow the instructions, it's pretty easy to do.
So here you take your video, you upload it into a tool like OBS Studio, which is a totally legitimate tool, you go into your settings on your device, like on your laptop, you disable the embedded camera, you enable the virtual camera of OBS Studio, and now at this point, whenever the system, an application, tries to access the camera, instead it will get the virtual camera. You've uploaded your deepfake video, maybe run it on loop, and now that is what is going to be presented.
Now, from an identity standpoint, why are we concerned about deepfakes? I mean, likely it's obvious. We're in the business of security. We're also in the business of building trust with our end users. And so how do we ultimately build that trust? One of the key things we need to do is bind a digital identity to a real identity, right? And that becomes really the root of trust of our entire identity and access management systems.
The way that we do that binding of a digital identity to a real identity in today's world, and this is evolving, but this is still going to be a key part of our systems, is through a process that we call identity proofing, identity verification, or IDV for short. Now, identity verification gets used in a few different places within the identity lifecycle. So think of during customer or employee onboarding, during an account recovery process, either self-service or via help desk, or maybe as an extra form of authentication to validate a high-risk transaction.
Or even during an age verification or some kind of other access control process. So that's where IDV systems come in, and they are at the root of our trust that we build.
Now, the method of IDV that gets used today depends on the types of interactions that we have. So, for example, I walk into my local bank to make a cash withdrawal. The teller on the other side is going to ask to see my driver's license or some form of ID, and they're going to validate that, you know, my picture, that I look like my picture. This is probably the weakest form of identity verification that you can have, but it's something that we're probably all familiar with.
A more automated and more secure form of this, maybe many of us saw as we were traveling to come to this conference today, right? So either going into the airports or crossing borders where you do passport verification, where you have some kind of a document scanner that validates the authenticity of the document. Maybe comparing that with a photograph or a biometric to compare to make sure that you are the individual.
So now these are all kind of in-person types of identity verification, and on the Mission Impossible side, with their disguises, these are the types of things that they were trying to thwart or overcome, right? Here what we're talking more about is more on the digital interactions themselves. So how do we validate or verify an identity in a purely digital exchange? The pattern is still very similar. We want to authenticate a document, make sure that it hasn't been altered in any way, and we want to validate the human on the other side of this.
Now, IDV vendors like Thales and others have been working now to continually evolve and protect against the different attacks that fraudsters have on our identity verification systems, and it's no different with deepfakes. In the past, we were worried about fraudsters holding up a photograph to the camera and taking a picture of a picture rather than taking a selfie themselves, and so we put in protections like liveness detection and passive liveness detection to be able to make sure that there's actually a human on the other side of this.
Now, with the deepfake technology that I showed you before, with those virtual cameras, traditional IDV systems can actually be fooled still because, you know, there's motion, there's things happening on there that make it look like it actually is a real human. So the technologies needed to be able to detect and stop these deepfakes has needed to continue to evolve as well. So AI models on the back end are continuing to evolve to be able to detect anomalies in the video stream, as an example.
But even more so, the front end, the device itself, whether it's your mobile phone or your laptop, needs to become an active participant in the fraud detection capabilities as well. So it needs to be able to look for certain risks inside the device. Is there a virtual camera present, as an example?
You know, is the device jailbroken or rooted? Is there some other malicious software that is running on the device that elevates the risk level? So now all of these factors must come together to be able to determine, you know, is this a legitimate user and to protect against the threat of deepfakes. So even if you're using one of these technologies today, you know, I don't want you to become complacent because all types of fraud, cyber attacks, it's a continuous game of cat and mouse, right?
Vendors, organizations, we're working together to try to, you know, close up holes and reduce vulnerabilities. At the same time, adversaries are working diligently to try to find new vulnerabilities that they can exploit. And so the protection mechanisms are going to continue to evolve.
And, you know, you need to be diligent and be ready to be able to adapt to those changes as well. Now... If we look into the future and what's coming, and I'm not even sure I can really say it's the future because, honestly, it's here today, we're really entering into what I call the post-fake era. Hard to believe, given we just started trying to tackle this threat of deepfakes now, but now there's already other threats that we see kind of on the landscape. The next big challenge for IAM systems is going to be agents.
Not gate agents at the airport, not insurance agents like Jake from State Farm, not even the IMF secret agents, right? We're talking about AI agents or agentic AI. I'm not going to stand up here and claim to be an expert in the area of agentic AI. Far from it.
I mean, there's a lot more knowledgeable people than me that are going to be speaking in the streams on this topic. But when we talk about agentic AI, we're talking about AI systems that are designed to autonomously perform actions or perform various tasks, make decisions, and ultimately interact with environments or interact with individuals and mimic human behavior, right? So you can see how this would start to become a threat now to our IAM systems.
Earlier this year, the Imperva Application Security Team, which is a division of our Talus cybersecurity products, put out their annual bad bots report. Now, one of the statistics that stood out to me in this bad bots report was that in 2024, it was the first time that non-human activity outnumbered human activity on the web. So 51% of all traffic on the web last year was from non-human activity.
Now, this is being powered by AI and LLM that is making it much easier, much more accessible, much more scalable to create bots. Now, not all bots are bad, right? But 37% of all internet traffic last year was from malicious bots. So let me say that again. More than one-third of all internet traffic last year was from malicious bots. So that is a risk that we have.
Now, I'm not telling you this to try to scare you away from AI or AI agents. Well, maybe a little bit. Kind of a cautionary tale, at least. With any kind of transformational technology that has positive implications, you have to be aware of the potential negative side or the risks involved with that as well. And with AI agents, they are something different. They are not human, they are not devices, they are not APIs. The way that we secure those agents needs to be different than how we deal with humans and how we deal with devices today. And there's a lot of open questions in this space.
So for example, how do you actually verify the identity of an agent? What are going to be the credentials for those agents? How are agents going to communicate? Either how do we communicate with them? How do they communicate together? These are open questions still. How do you monitor the behavior of agents? Is there some kind of policing that has to happen to make sure that they're behaving correctly? Technologically, can we implement some kind of a reward system that encourages the agents to behave correctly?
Lastly, and this is maybe more of an ethical or even a legal question, who is accountable for the actions and the outcomes that agents take? Is it the instructor? Is it the person who's using the agents that's asking it to do something on its behalf? Or is it the builder? Is it the individual developer, the organization, who actually created those agents? So there are lots of open questions still in this space, and it is moving very rapidly. The technology, the industry, the usage is moving at a much faster pace than anything we've seen in the industry.
Now, as AI grows in adoption, it is going to be forever intertwined with identity. I didn't talk about this today, but you will see AI being used within IAM itself to be able to deliver better outcomes, rest assured. All of us vendors are looking at ways to embed AI into our products. The second area, though, about protecting our identity systems from malicious AI, that's what I talked about on the deepfake side. And then the third area is around IAM being used as a key part to actually secure AI itself, and here's where I referred to the agentic AI.
So now, in closing, I just want to leave you with a couple of calls to action. So the threat of deepfakes is real, right? And it is there to undermine the root of trust of our identity systems. So if you're not using an IDV technology today, well, you should be. But if you are, don't become complacent. Know that this technology is going to continue to evolve, and you need to be on the forefront trying to stay ahead of the attackers in this space, too. On the second side, prepare for the next step, right? For non-human types of interactions with AI agents.
Be an advocate inside of your organizations and make sure that identity is taking a key role in securing the usage of these agents. And then lastly, this is an evolving space. It's moving rapidly. We need all of the industry to be working together to help come up with solutions. So collaborate with your colleagues, with your peers, with your vendors. Get involved in standards. Make your voice and your thoughts heard so that we can continue to evolve in this space. So with that, I know it's early in the morning. Once again, my name is Jason Keenahan from Thales.
I want to thank you for your time and wish you enjoy the rest of the conference. Good luck. APPLAUSE Jason, you seem to have attracted more people into the room, which is a good sign. Thanks for your good start. I love the Mission Impossible series, so I really enjoyed that. Thank you. We just have one question. I don't know whether there's a quick answer to this, but it says, what are the best ways to take down multiple deepfake videos for, say, CEOs or political persons which just pop up every day?
Yeah, that's tough because ultimately, there we're talking about kind of policing the Internet at that point, right, and how do you take down social media and stuff. I don't think I have a quick answer to it. I think that's something that, you know, the technologies that we talked about here with IDV aren't going to prevent, but it is something I think a lot that we have to do is educate users, whoever, especially, you know, our children on social media. I know I have two young daughters.
I worry about this very much, about their influence and making sure that they are, you know, well aware of the sources of the information that they're consuming. Okay, thank you very much.
Thanks, Jason. Thank you.