[
  {
    "start": 0.06,
    "end": 13.54,
    "text": "This is now a world where AI agents are starting to log in for us as well doing our work, yet our security systems still rely on the nineteen seventies era thinking about passwords and factors."
  },
  {
    "start": 14.54,
    "end": 23.66,
    "text": "When identity can be faked forged or hijacked at machine speed The real question becomes terrifyingly simple How do we know who what?"
  },
  {
    "start": 26.34,
    "end": 30.7,
    "text": "To deal with such frightening prospects you really need to have ice in your veins."
  },
  {
    "start": 31.44,
    "end": 36.42,
    "text": "But then again, maybe it's your veins themselves that hold the key to your security."
  },
  {
    "start": 37.48,
    "end": 41.28,
    "text": "I'm Steve Prentice and this is The Talas Security Sessions podcast."
  },
  {
    "start": 54.16,
    "end": 66.04,
    "text": "To help us understand what the future of authentication looks like And where biometrics behavior and continuous signals collide With deepfakes AI agents, and the end of logins as we know it."
  },
  {
    "start": 66.56,
    "end": 79.66,
    "text": "I sat down recently with Ant Allen, former VPN analyst at Gartner for a truly in-depth and fascinating conversation And welcome to The Talas Security Sessions podcast."
  },
  {
    "start": 80.54,
    "end": 81.9,
    "text": "Thanks for inviting me Steve!"
  },
  {
    "start": 82.2,
    "end": 83.78,
    "text": "Hope i can provide some value"
  },
  {
    "start": 84.54,
    "end": 88.44,
    "text": "Before we get into the mechanics of authentication...I want zoom out."
  },
  {
    "start": 89.74,
    "end": 95.52,
    "text": "We are watching AI agents begin to take actions on our behalf, sometimes without us even touching a keyboard."
  },
  {
    "start": 96.16,
    "end": 99.04,
    "text": "And that feels both exciting and a little unnerving."
  },
  {
    "start": 99.76,
    "end": 105.26,
    "text": "so when machines start logging in for us the whole idea of identity and trust seems to shift."
  },
  {
    "start": 106.24,
    "end": 109.7,
    "text": "So from your vantage point what's the biggest thing changing right now?"
  },
  {
    "start": 110.32,
    "end": 111.7,
    "text": "What should we be paying attention too?"
  },
  {
    "start": 112.22,
    "end": 121.36,
    "text": "The things I highlight is That you know if we aren't appeared at rapid change The way we interact with computer systems is changing."
  },
  {
    "start": 122.06,
    "end": 126.52,
    "text": "And what can do with computers, it's changing the way that we interact."
  },
  {
    "start": 127.12,
    "end": 135.4,
    "text": "We have things like artificial intelligence nobody logging in anymore because artificial intelligence agents would do everything for them."
  },
  {
    "start": 135.48,
    "end": 138.16,
    "text": "I think that raises all kinds of questions around."
  },
  {
    "start": 138.74,
    "end": 143.78,
    "text": "well how to know who this person is and first place has got some kind login?"
  },
  {
    "start": 144.56,
    "end": 149.64,
    "text": "How you trust a particular agent is acting on somebody's behalf."
  },
  {
    "start": 150.06,
    "end": 159.54,
    "text": "I think there's kind of bootstrapping problem, we're doing all these wonderful things with new technologies but you know how do we get back to the basis of trust?"
  },
  {
    "start": 159.92,
    "end": 177.44,
    "text": "To know that The human actor at the beginning of the chain Is who they claim to be and That authenticated identity is propagated through agents Of some kind whether it's other shantyans or others that are trustworthy."
  },
  {
    "start": 177.58,
    "end": 196.28,
    "text": "We need to understand how identity can propagate and we've had problems since we started doing federation between systems decades ago, but it becomes new again in discussions around AI agents such like using technologies like OpenID to propagate those things."
  },
  {
    "start": 196.58,
    "end": 201.1,
    "text": "Is this up the task or is it mired into a test?"
  },
  {
    "start": 201.24,
    "end": 208.54,
    "text": "A key topic of yours that really resonates with me is the idea, so much our security thinking has anchored in models from the seventies and eighties."
  },
  {
    "start": 209.26,
    "end": 214.34,
    "text": "We're still counting factors like it's a checklist even though attackers have evolved far beyond them."
  },
  {
    "start": 215.34,
    "end": 219.74,
    "text": "Can you walk us through why this factor-counting mindset no longer enough?"
  },
  {
    "start": 219.98,
    "end": 224.56,
    "text": "And what fundamentally flawed about how we've been framing authentication for decades?"
  },
  {
    "start": 225.3,
    "end": 231.16,
    "text": "It was one issue which came up recently on LinkedIn about how we probably get trust down the chain."
  },
  {
    "start": 231.58,
    "end": 241.04,
    "text": "And it comes back to is this good enough and say, well if you look at the specification what you see is something that he's kind of trying to do the right things."
  },
  {
    "start": 241.98,
    "end": 261.839,
    "text": "but like a lot of thinking about user authentication It goes back to A very coarse grained model That is fixed on ideas like specific assurance levels or specific authentication technologies."
  },
  {
    "start": 262.78,
    "end": 280.6,
    "text": "And a lot of the thinking around user authentication is still framed in this nineteen seventies model, having three authentication factors you've got This notion that counting factors and two factor authentication are better than single factor."
  },
  {
    "start": 281.3,
    "end": 283.66,
    "text": "Having three factor is essentially better."
  },
  {
    "start": 284.76,
    "end": 291.48,
    "text": "It's counting factors seen as a good thing, and there are so many regulations that say you must have two factors."
  },
  {
    "start": 291.74,
    "end": 294.74,
    "text": "Two of the three factors... And it is getting back to this nineteen seventies model."
  },
  {
    "start": 295.48,
    "end": 297.2,
    "text": "Is this still relevant?"
  },
  {
    "start": 297.24,
    "end": 299.0,
    "text": "This is still the best way of doing things."
  },
  {
    "start": 299.46,
    "end": 308.34,
    "text": "We know in practice That different authentication vectors Different kinds of authentication methods Have different strengths & weaknesses."
  },
  {
    "start": 309.48,
    "end": 319.0,
    "text": "Now we're seeing some regulations really pity on that, specifically asking for fishing resistant authentication methods."
  },
  {
    "start": 319.54,
    "end": 334.02,
    "text": "Some regulations are being more specific about the robustness of the methods they're looking for but it's still framed in this decades old way and The mainstream example is still based on a nineteen eighties model."
  },
  {
    "start": 334.28,
    "end": 346.6,
    "text": "within this seventies formalism In the eighties we saw the first one-time password tokens emerge and this idea of adding a one-time password token to an existing password, giving multi-factor authentication."
  },
  {
    "start": 347.16,
    "end": 354.58,
    "text": "It defined multi-factual authentication for generation is still broadly the way most organizations are looking at things."
  },
  {
    "start": 354.88,
    "end": 363.32,
    "text": "when we know passwords are flawed with throwing this extra authentication factor on top of passwords create multifactorials indication together as more trust."
  },
  {
    "start": 363.56,
    "end": 378.48,
    "text": "it's that actually best way doing things in passwords so mired a variety of flaws and then different exploits that the value they bring to the multi-factor authentication is minimal."
  },
  {
    "start": 379.2,
    "end": 381.18,
    "text": "so you're really relying on that second factor."
  },
  {
    "start": 382.02,
    "end": 387.66,
    "text": "And, well if we started from scratch and said Is there single factor authentication method?"
  },
  {
    "start": 388.5,
    "end": 390.68,
    "text": "There would actually be far better than the password."
  },
  {
    "start": 390.72,
    "end": 395.24,
    "text": "who wouldn't need a second factor for some lower levels risk?"
  },
  {
    "start": 398.26,
    "end": 401.7,
    "text": "And there are some issues around attacks with deep fakes and so on."
  },
  {
    "start": 401.78,
    "end": 406.52,
    "text": "But biometric authentication is a potential candidate, maybe not face which."
  },
  {
    "start": 407.12,
    "end": 413.1,
    "text": "where the fake attacks have become notorious There's ways of dealing that minimising risk."
  },
  {
    "start": 413.2,
    "end": 418.9,
    "text": "but other kinds of biometric methods were in certain circumstances That might work better."
  },
  {
    "start": 419.0,
    "end": 429.78,
    "text": "we've got vein technologies in hand or finger Which don't seem to lend themselves deep fake type attacks, they're more specialized."
  },
  {
    "start": 429.88,
    "end": 434.6,
    "text": "But in some circumstances that might be an appropriate authentication method."
  },
  {
    "start": 435.26,
    "end": 452.92,
    "text": "and I would say i would intuitively trust a method based on infrared sensing of veins in the hand as a single factor mechanism More than I would trust A method that combines legacy password with out-of-band SMS for example."
  },
  {
    "start": 453.58,
    "end": 457.82,
    "text": "So saying two factories stronger then one factor isn't necessarily always the case."
  },
  {
    "start": 458.04,
    "end": 463.56,
    "text": "It depends on the particular methods you're using, but that's still ingrained."
  },
  {
    "start": 463.98,
    "end": 472.22,
    "text": "and the idea of using a token plus a password is still so ingrained that a lot organizations are reluctant to move away from"
  },
  {
    "start": 472.36,
    "end": 472.48,
    "text": "it.\"."
  },
  {
    "start": 473.2,
    "end": 484.68,
    "text": "I've noticed when organisations talk about going passwordlessly often mean we're removing the password without really understanding what fills our gap... ...it does become kind like marketing term rather than strategy."
  },
  {
    "start": 485.54,
    "end": 490.06,
    "text": "So from your experience, what do people get wrong about passwordless authentication?"
  },
  {
    "start": 490.42,
    "end": 493.88,
    "text": "And what should they actually be thinking about when they say they want to move in that direction."
  },
  {
    "start": 494.86,
    "end": 515.28,
    "text": "One of the things I used to come across talking with clients was this idea you were just doing without a password and there wasn't an understanding hook, if you like."
  },
  {
    "start": 516.2,
    "end": 527.2,
    "text": "But If You're saying I want to implement passwordless authentication that it wasn't really telling you what she were going to do didn't say anything about What you are actually using."
  },
  {
    "start": 527.42,
    "end": 530.12,
    "text": "so i think passwordless is good as an introductory idea."
  },
  {
    "start": 530.72,
    "end": 534.64,
    "text": "but when you thinking About how Do we achieve passwordless Authentication?"
  },
  {
    "start": 535.42,
    "end": 537.0,
    "text": "What Is taking the place?"
  },
  {
    "start": 537.42,
    "end": 541.22,
    "text": "quote unquote of passwords in our authentication methods."
  },
  {
    "start": 541.78,
    "end": 547.66,
    "text": "It's important And that leads into a much broader discussion because there are many ways you can do without passwords."
  },
  {
    "start": 548.26,
    "end": 560.4,
    "text": "In fact, the thing I used to present was if we take that traditional categorization... There were these varieties of knowledge-based methods or these types of tokens and these varieties by metric methods."
  },
  {
    "start": 561.06,
    "end": 563.5,
    "text": "everything except password is passwordless."
  },
  {
    "start": 564.04,
    "end": 565.22,
    "text": "it's getting away from."
  },
  {
    "start": 567.24,
    "end": 568.58,
    "text": "what do we use instead?"
  },
  {
    "start": 569.72,
    "end": 573.62,
    "text": "Then you've got an idea a decision about identity on."
  },
  {
    "start": 574.44,
    "end": 586.22,
    "text": "The way technology has moved is given as tools where we can actually fold far more pieces of evidence, if you like into the decision-about"
  },
  {
    "start": 586.36,
    "end": 586.74,
    "text": "identity.\"."
  },
  {
    "start": 587.68,
    "end": 592.4,
    "text": "You mentioned biometrics like vein recognition and continuous ECG monitoring."
  },
  {
    "start": 592.68,
    "end": 598.08,
    "text": "I have to admit that sounds like something out of science fiction kind of Isaac Asimov or Blade Runner type stuff."
  },
  {
    "start": 598.9,
    "end": 602.28,
    "text": "At the same time, it's incredibly compelling from a usability standpoint."
  },
  {
    "start": 603.04,
    "end": 608.14,
    "text": "But people always worry about privacy of course and their bodies becoming even like corporate credentials."
  },
  {
    "start": 609.04,
    "end": 612.16,
    "text": "So how do you see biometrics fitting into future authentication?"
  },
  {
    "start": 612.84,
    "end": 617.52,
    "text": "Where they genuinely offer advantages over old password plus token models?"
  },
  {
    "start": 618.0,
    "end": 618.46,
    "text": "It is real."
  },
  {
    "start": 619.5,
    "end": 621.7,
    "text": "And there are things very specialised things."
  },
  {
    "start": 622.18,
    "end": 636.44,
    "text": "Many people in industry will have come across Canadian company NIMI NYMI, and they have a wristband wearable that monitors your ECG."
  },
  {
    "start": 637.28,
    "end": 639.92,
    "text": "And I think now it's actually fingerprints labeled."
  },
  {
    "start": 640.44,
    "end": 656.82,
    "text": "so when you put it on in the first place You've got to activate with your fingerprint But then as long as its on your wrist is continuously monocling your ETG and say yes i'm still on Steve's wrist or Ants wrist And then it enables a PKI-based mechanism."
  },
  {
    "start": 656.92,
    "end": 658.64,
    "text": "So essentially functions like the smart card."
  },
  {
    "start": 659.16,
    "end": 664.86,
    "text": "in terms of interfaces with computer systems, there's nothing inherently novel required on the back end."
  },
  {
    "start": 665.08,
    "end": 668.24,
    "text": "It works just through standard Smart Card Interfaces."
  },
  {
    "start": 668.34,
    "end": 671.18,
    "text": "as far I understand that The key is...it's On your wrist!"
  },
  {
    "start": 671.66,
    "end": 678.76,
    "text": "It Just needs to be in Proximity With the Computer To Be able to log you In Once You've Activated at the beginning Of the day Until you take it off."
  },
  {
    "start": 679.2,
    "end": 681.52,
    "text": "Its always active and its not cheap technology."
  },
  {
    "start": 682.08,
    "end": 690.44,
    "text": "But there are some use cases where that is very effective, not just for a matter of user convenience but also in terms of environments."
  },
  {
    "start": 691.14,
    "end": 702.48,
    "text": "Where people unable to handle conventional types authentication tokens or we're interacting with computers inserting a smart card whatever would be problematic."
  },
  {
    "start": 702.6,
    "end": 709.62,
    "text": "so thinking technology clean rooms and pharmaceutical companies that kind of environment's were people wearing protective equipment."
  },
  {
    "start": 709.92,
    "end": 713.26,
    "text": "That works very well But it's not a generalizable solution."
  },
  {
    "start": 713.62,
    "end": 723.5,
    "text": "You know, the rain technologies is something we've seen in healthcare for several years and A number of manufacturers including Hitachi and Fujitsu have solutions here."
  },
  {
    "start": 724.08,
    "end": 740.9,
    "text": "It's a technology which runs expensive compared to some of the mainstream solutions but this has seen adoption In clinical environments in health care And they're like where The sensors are able To work through medical gloves using infrared."
  },
  {
    "start": 741.2,
    "end": 744.78,
    "text": "There's no touch involved and it has advantages there."
  },
  {
    "start": 745.34,
    "end": 756.62,
    "text": "So I think that are some interesting possibilities for biometrics technologies, not just the user experience point of view but the practicalities in environment where they're more expensive."
  },
  {
    "start": 756.66,
    "end": 759.4,
    "text": "so really scale in a specialist areas."
  },
  {
    "start": 759.66,
    "end": 769.82,
    "text": "The idea using biometrics at all is an interesting challenge because two parts this one Privacy regulations."
  },
  {
    "start": 770.46,
    "end": 774.72,
    "text": "What do organizations have to do to justify using biometric methods?"
  },
  {
    "start": 775.2,
    "end": 784.22,
    "text": "what they have to protect the data, which I always thought was a bit of non-problem or it wasn't a problem specific to the privacy regulation?"
  },
  {
    "start": 784.42,
    "end": 796.0,
    "text": "because if you had any kind of data that is used as credentials You want to protect them at best and meeting that part of the privacy regulations shouldn't be a challenge Because you should be protecting now."
  },
  {
    "start": 797.86,
    "end": 805.78,
    "text": "I think a lot of people are wary about where the legislation applies, they're wary running foul and that's been an inhibitor."
  },
  {
    "start": 806.36,
    "end": 812.44,
    "text": "But practically it is something very advantageous from user experience point-of view."
  },
  {
    "start": 813.36,
    "end": 822.6,
    "text": "Nowadays vast majority with any kind phone or tablet use biometrics to unlock devices."
  },
  {
    "start": 822.72,
    "end": 827.32,
    "text": "perfectly happily If you say, okay well it's not just the device now."
  },
  {
    "start": 827.94,
    "end": 833.54,
    "text": "My organization is going to be using this then that might raise more issues about oh am I comfortable with this anymore?"
  },
  {
    "start": 833.6,
    "end": 835.7,
    "text": "because who looking after the data?"
  },
  {
    "start": 836.3,
    "end": 837.58,
    "text": "What are they gonna use for?"
  },
  {
    "start": 837.96,
    "end": 850.16,
    "text": "people might be more averse but i think Just having experience of using biometric methods on personal devices has changed lot of attitudes too The broad adoption of biometrics."
  },
  {
    "start": 850.36,
    "end": 852.06,
    "text": "anyway People are more comfortable."
  },
  {
    "start": 852.1,
    "end": 863.24,
    "text": "you know, there are those that still might have privacy concerns which we've got to be wary of but I think that's significantly shifted people's attitudes towards it."
  },
  {
    "start": 863.28,
    "end": 891.92,
    "text": "The other thing because we're seeing now and it goes back to discussion about different options for passwordless authentication and what FIDO Alliance has been doing if people are happy using the biometrics on their device then that can be part where it's still just the biometric method on the device, and all that data is stored in a device rather than in the organization essentially."
  },
  {
    "start": 892.0,
    "end": 910.4,
    "text": "Where you can use that biometric methods as user gesture to unlock the pass keys of the device whether thats the pass key implemented into the operating systems or if your have some proprietary solution which has device bound pass keys on mobile devices."
  },
  {
    "start": 910.46,
    "end": 913.24,
    "text": "we've seen, I think from Microsoft RSA now at least."
  },
  {
    "start": 913.58,
    "end": 931.44,
    "text": "And i think that is a potential strong model for the future in leveraging FIDO within enterprises without the need to issue hardware devices to everyone which has always been a barrier in terms of costs and logistics and so on."
  },
  {
    "start": 932.0,
    "end": 938.4,
    "text": "So I think biometrics may not be something we always use as a primary authentication method."
  },
  {
    "start": 939.56,
    "end": 959.68,
    "text": "being able to exploit the device-native biometrics on the device with its privacy preserving features as part of a broader authentication solution, I think is probably where we're going see most use of biometrix in enterprise workforce and consumer use tests."
  },
  {
    "start": 960.38,
    "end": 990.84,
    "text": "I see a split amongst the population between those who recognize seemingly positive stuff."
  },
  {
    "start": 991.34,
    "end": 1001.0,
    "text": "Do you anticipate, however because this is the continual cat and mouse game we have in security with The Other Side being incredibly fiendishly brilliant at knocking down anything that we build?"
  },
  {
    "start": 1001.68,
    "end": 1002.76,
    "text": "do You anticipate?"
  },
  {
    "start": 1003.1,
    "end": 1012.4,
    "text": "That This could also be prone to fraud or again deep fake reconstruction of veins Or other kinds Of physical characteristics?"
  },
  {
    "start": 1012.84,
    "end": 1014.82,
    "text": "are there weaknesses To this particular argument?"
  },
  {
    "start": 1015.74,
    "end": 1026.839,
    "text": "I've told everyone that I've dealt with over the years, particularly vendors who come up with new authentication methods."
  },
  {
    "start": 1027.319,
    "end": 1028.52,
    "text": "Don't say it's bulletproof!"
  },
  {
    "start": 1030.06,
    "end": 1035.099,
    "text": "So many people have and they're saying no you cannot anticipate every potential attack?"
  },
  {
    "start": 1035.92,
    "end": 1046.96,
    "text": "The question is understanding the threat model with all of these methods... to understand the potential difficulty."
  },
  {
    "start": 1047.2,
    "end": 1055.88,
    "text": "So yes, we've got a theoretical attack against this method but given the way it's implemented what are the potential attack vectors?"
  },
  {
    "start": 1056.26,
    "end": 1059.76,
    "text": "What is the technical challenge for an attacker?"
  },
  {
    "start": 1060.56,
    "end": 1062.12,
    "text": "What are the logistics around this?"
  },
  {
    "start": 1062.62,
    "end": 1066.32,
    "text": "so It's like... For example The difference between passwords and PINs."
  },
  {
    "start": 1067.52,
    "end": 1069.02,
    "text": "We know passwords are flawed!"
  },
  {
    "start": 1069.6,
    "end": 1079.9,
    "text": "We know there in multiple ways that passwords can be compromised They really stem from the way passwords are used, that there's a centralized store which can be compromised."
  },
  {
    "start": 1080.36,
    "end": 1085.78,
    "text": "Passwords are transmitted, passwords are entered online... There're various ways of capturing them."
  },
  {
    "start": 1086.64,
    "end": 1093.46,
    "text": "so we say all our passwords about idea and then go okay We've got five out two security keys Which are pin protected?"
  },
  {
    "start": 1093.84,
    "end": 1095.62,
    "text": "Which looks very much like your password to me."
  },
  {
    "start": 1096.02,
    "end": 1101.8,
    "text": "but The kernel here is That the PIN Is completely local To the device."
  },
  {
    "start": 1102.52,
    "end": 1105.7,
    "text": "So it's still possible to use shoulder surfing."
  },
  {
    "start": 1106.14,
    "end": 1113.32,
    "text": "You can see what pin somebody is typing in, but you're reducing the potential pathways available to an attacker."
  },
  {
    "start": 1113.96,
    "end": 1123.26,
    "text": "so with biometric methods if your using something which relies on a camera-on-a device and you are capturing some thing how could that be compromised?"
  },
  {
    "start": 1123.36,
    "end": 1125.78,
    "text": "How people insert deepfake?"
  },
  {
    "start": 1126.1,
    "end": 1128.4,
    "text": "How they do injection attack...and so forth."
  },
  {
    "start": 1128.7,
    "end": 1130.54,
    "text": "Think about the complexities of that."
  },
  {
    "start": 1130.96,
    "end": 1134.84,
    "text": "if you implement something in a particular instance, for example."
  },
  {
    "start": 1134.96,
    "end": 1145.14,
    "text": "In that clinical environment using vein recognition, patent recognition software then that's much more complicated technical environments."
  },
  {
    "start": 1145.68,
    "end": 1149.3,
    "text": "attackers have secretly present in that environment to be able to compromise that etc."
  },
  {
    "start": 1149.94,
    "end": 1151.34,
    "text": "so the risks are different."
  },
  {
    "start": 1152.3,
    "end": 1169.22,
    "text": "More broadly and from most organizations Using authentication generally workforce or customers, then the key has always been that we don't rely on a single thing."
  },
  {
    "start": 1169.7,
    "end": 1170.68,
    "text": "I'm walking back little."
  },
  {
    "start": 1171.02,
    "end": 1174.2,
    "text": "what i said before about Single Factory Authentication might be good enough."
  },
  {
    "start": 1174.26,
    "end": 1184.58,
    "text": "in some circumstances it still might but more broadly The More Things That You Can Evaluate The Less Dependent you Are On Any Single Thing."
  },
  {
    "start": 1185.06,
    "end": 1189.92,
    "text": "So If One Thing Is Trompromised You Still Got Other Things To Rely On."
  },
  {
    "start": 1190.8,
    "end": 1193.3,
    "text": "I love the way you frame authentication as a truth claim."
  },
  {
    "start": 1194.04,
    "end": 1198.32,
    "text": "Essentially someone saying, ''I am who i say I am'' and this system weighing evidence."
  },
  {
    "start": 1198.38,
    "end": 1202.54,
    "text": "it's that much richer of a way to think about identity than just passwords or tokens."
  },
  {
    "start": 1203.76,
    "end": 1211.02,
    "text": "Can you expand on how behavioural signals device identity in contextual clues like that can help build that evidence?"
  },
  {
    "start": 1211.14,
    "end": 1212.56,
    "text": "And why are they becoming essential?"
  },
  {
    "start": 1212.78,
    "end": 1213.8,
    "text": "modern authentication?"
  },
  {
    "start": 1215.16,
    "end": 1224.76,
    "text": "This is probably a good segue into the idea that there's more to user authentication nowadays than those traditional three factors."
  },
  {
    "start": 1225.56,
    "end": 1241.2,
    "text": "There are many systems which have, over the past ten or twenty years incorporated other kinds of signals... ...into the authentication process and one of the challenges is Is this still authentication?"
  },
  {
    "start": 1241.9,
    "end": 1243.12,
    "text": "Or is it something else?"
  },
  {
    "start": 1243.92,
    "end": 1261.16,
    "text": "And a lot of organizations, I think are looking at this through the lens that it's something else and not bringing back to... ...the question is giving me confidence in identity claim which is core idea for user authentication."
  },
  {
    "start": 1261.94,
    "end": 1275.72,
    "text": "This gets philosophical because my physics background led down path thinking because one of the things that happened during lockdown was a physicist from Johns Hopkins University called Sean Carroll."
  },
  {
    "start": 1276.18,
    "end": 1283.04,
    "text": "The series of podcasts about the basic ideas in physics and what are the things he said is, you know how do we know what's true?"
  },
  {
    "start": 1283.08,
    "end": 1293.92,
    "text": "I think it was talking about Bayesian approaches and quotation form a principle about being able to put your trust in something only as far as the evidence you have."
  },
  {
    "start": 1294.56,
    "end": 1295.8,
    "text": "And kind of suddenly hit me."
  },
  {
    "start": 1296.04,
    "end": 1298.0,
    "text": "this is the basis of user authentication."
  },
  {
    "start": 1298.7,
    "end": 1301.94,
    "text": "Use authentication is basically addressing a truth claim."
  },
  {
    "start": 1302.92,
    "end": 1305.02,
    "text": "I am and how do i demonstrate that?"
  },
  {
    "start": 1305.18,
    "end": 1315.8,
    "text": "And we've got to evaluate all the evidence, and How can we quantify The level of trust We can put in That identity claim based on the evidence we have?"
  },
  {
    "start": 1316.24,
    "end": 1322.5,
    "text": "and the evidence were usually using Is having provided the right password Have I generated an OTP from the token?"
  },
  {
    "start": 1322.64,
    "end": 1326.04,
    "text": "I have you know Am I presenting the rights biometric trait?"
  },
  {
    "start": 1326.6,
    "end": 1327.84,
    "text": "But we can look at other things."
  },
  {
    "start": 1338.6,
    "end": 1347.4,
    "text": "We've got more gross behaviors in terms of how you broadly interact with systems, how you navigate pages... Things like this which are kind characteristic to the individual."
  },
  {
    "start": 1347.44,
    "end": 1350.86,
    "text": "and certainly there are differences between a human."
  },
  {
    "start": 1356.32,
    "end": 1365.86,
    "text": "There are even differences between a legitimate user and human attacker because the human attacker will generally be more precise about what they do."
  },
  {
    "start": 1366.52,
    "end": 1367.74,
    "text": "An attack, well know what to do!"
  },
  {
    "start": 1367.88,
    "end": 1377.28,
    "text": "They're following this script... ...they don't exactly where to move on page to perform their attack whereas a genuine user is vaguer than thinking about it or making mistakes."
  },
  {
    "start": 1377.54,
    "end": 1378.76,
    "text": "so there's difference in patterns."
  },
  {
    "start": 1379.14,
    "end": 1388.9,
    "text": "not necessarily that this is Ant rather then anybody else but we can say This person who claims their ant is behaving like a genuine user rather than behaving like an attacker."
  },
  {
    "start": 1389.42,
    "end": 1401.24,
    "text": "So there are lots of signals that we can bring in, and there's lots of things which historically have been part what was used to be called one broadly fraud detection account takeover prevention."
  },
  {
    "start": 1401.68,
    "end": 1402.72,
    "text": "so they're various things."
  },
  {
    "start": 1402.8,
    "end": 1421.78,
    "text": "then behavioral biometrics were kind of part but the other thing as well is location device behaviors patterns over time different which are taken into account there and think, well they were basically designed to say oh if I see something anomalous that's probably an attack."
  },
  {
    "start": 1422.04,
    "end": 1423.14,
    "text": "Probably fraudulent."
  },
  {
    "start": 1423.48,
    "end": 1424.3,
    "text": "so i should do some"
  },
  {
    "start": 1424.36,
    "end": 1424.5,
    "text": "thing.\"."
  },
  {
    "start": 1425.58,
    "end": 1435.6,
    "text": "It's interesting that so many organizations treat fraud detection in IDTR as separate domains even though they're looking at the same signals that could strengthen authentication decisions."
  },
  {
    "start": 1436.34,
    "end": 1440.16,
    "text": "it feels like we've artificially siloed things that should be working together."
  },
  {
    "start": 1440.88,
    "end": 1442.68,
    "text": "Why is that separation a problem?"
  },
  {
    "start": 1442.78,
    "end": 1449.42,
    "text": "And how should organizations rethink the relationship between authentication, fraud detection and identity threat response."
  },
  {
    "start": 1450.04,
    "end": 1473.68,
    "text": "In more recent years we've seen interest in Identity Threat Detection & Response which again is evaluating a lot of signals about behaviors as users traverse computer systems... ...and that's kind of carved off because it part this ITDR idea, it's been lots of companies focus on this and lots of acquisitions here."
  },
  {
    "start": 1473.98,
    "end": 1475.64,
    "text": "And say oh is all ITDR?"
  },
  {
    "start": 1475.94,
    "end": 1478.24,
    "text": "It's something which is its own thing."
  },
  {
    "start": 1478.76,
    "end": 1485.88,
    "text": "but these signals are exactly what we need to fold into those decisions about that claim of identity."
  },
  {
    "start": 1486.46,
    "end": 1494.82,
    "text": "carving them out as a separate saying I think is a challenge and We need to pull these together so they're kind of the same symbols."
  },
  {
    "start": 1494.86,
    "end": 1497.74,
    "text": "you can look at this in the light if These other ideas."
  },
  {
    "start": 1498.06,
    "end": 1502.24,
    "text": "So it's like we're looking through different lenses at the same core data and events."
  },
  {
    "start": 1502.64,
    "end": 1509.48,
    "text": "But my feeling is because I was the authentication specialist, I kind of greedy on that everything to do about user authentication."
  },
  {
    "start": 1509.56,
    "end": 1524.68,
    "text": "but genuinely if you have all these signals thinking about them as ITDR or fraud separately from user authentication he's just going to diminish the value can leverage from there."
  },
  {
    "start": 1525.26,
    "end": 1535.84,
    "text": "You've got a think about this in terms which of these signals supports the identity claim, and which of them detracts from that."
  },
  {
    "start": 1536.34,
    "end": 1541.9,
    "text": "Does this look more like a genuine user or does it looks like an attacker?"
  },
  {
    "start": 1542.5,
    "end": 1563.52,
    "text": "This goes back to Sean Carroll's ideas about weighing in evidence saying what set of signals including legacy credentials but also all those things about device behavior so on... What set of signal supports the contention that this is the genuine user, and which support the contention of it."
  },
  {
    "start": 1564.34,
    "end": 1569.18,
    "text": "And I think you can make a decision about authentication."
  },
  {
    "start": 1569.64,
    "end": 1581.02,
    "text": "so even if he's saying oh i've got these strong credentials... I have my passwordless fishing resistance FIDO-II deviceband pass keys that are relying on."
  },
  {
    "start": 1581.8,
    "end": 1584.62,
    "text": "That gives me a lot of evidence in the first instance."
  },
  {
    "start": 1585.08,
    "end": 1589.02,
    "text": "but Other things which say there's something you miss here."
  },
  {
    "start": 1589.76,
    "end": 1596.26,
    "text": "Other aspects of this login, Which make it look more like an attacker that's compromised at some hair."
  },
  {
    "start": 1597.3,
    "end": 1601.52,
    "text": "Traditionally as I understand authentication has been a front door event."
  },
  {
    "start": 1601.78,
    "end": 1608.16,
    "text": "You log in and your trusted enough to go But the way you describe continuous authentication flips out on its head."
  },
  {
    "start": 1608.68,
    "end": 1612.38,
    "text": "Trust can increase or decrease As the session unfolds."
  },
  {
    "start": 1613.08,
    "end": 1619.64,
    "text": "So how does this continuous model change the way we think about security and what is it enabled that older models simply could not do?"
  },
  {
    "start": 1620.68,
    "end": 1634.74,
    "text": "When you take this approach of weighing up all these additional signals, We're also enabling something that can't be done with legacy authentication methods MFA in a classical sense."
  },
  {
    "start": 1635.26,
    "end": 1638.64,
    "text": "We were able to do this continuously use."
  },
  {
    "start": 1638.68,
    "end": 1642.74,
    "text": "authentication traditionally has been a gateway event."
  },
  {
    "start": 1643.5,
    "end": 1655.04,
    "text": "When somebody logs in, we're making an evaluation of the degree to which they trust them and with demanding a level authentication based on what is the highest risk thing that could do."
  },
  {
    "start": 1655.54,
    "end": 1656.1,
    "text": "as that put?"
  },
  {
    "start": 1656.76,
    "end": 1660.6,
    "text": "If you say it's just our starting point then this gives us a stake in ground."
  },
  {
    "start": 1661.12,
    "end": 1672.64,
    "text": "if we are evaluating everything else than can understand about context how people behave throughout session Then we have something which is much more robust."
  },
  {
    "start": 1673.26,
    "end": 1683.82,
    "text": "And, if you have a defense against for example session hijacking attacks but it's also something that can get back to how could enable passwordless authentication?"
  },
  {
    "start": 1684.36,
    "end": 1690.72,
    "text": "I've heard people claim they'd done this and used signals based approaches going about many years."
  },
  {
    "start": 1691.1,
    "end": 1696.86,
    "text": "They had through Evender one of their clients use the signal space approach."
  },
  {
    "start": 1697.38,
    "end": 1699.4,
    "text": "That was all there were doing in initial login."
  },
  {
    "start": 1700.3,
    "end": 1705.58,
    "text": "They weren't asking people to even enter a password initially, they were saying I recognize the device you're coming from."
  },
  {
    "start": 1706.12,
    "end": 1710.74,
    "text": "So we are saying yes You get access to this system once you start do something."
  },
  {
    "start": 1711.62,
    "end": 1713.3,
    "text": "We re-evaluating risk of that."
  },
  {
    "start": 1713.9,
    "end": 1720.86,
    "text": "That's a separate evaluation and say oh now if it is in level of risk Now we gonna prompt you to do some thing."
  },
  {
    "start": 1721.44,
    "end": 1738.1,
    "text": "This idea of tailoring friction To the Level Of Risk Allows you make things simpler for users in the first place, and only force them to do something when their level of risk is higher."
  },
  {
    "start": 1738.48,
    "end": 1740.36,
    "text": "So you need to elevate trust accordingly."
  },
  {
    "start": 1741.04,
    "end": 1754.58,
    "text": "but at the same time if your using right quote-to-quote signals particularly if you're using behavioural biometrics You can start doing that continuously throughout a session so you lock it with low levels."
  },
  {
    "start": 1755.66,
    "end": 1758.5,
    "text": "This is often characterizes that trust decays."
  },
  {
    "start": 1759.1,
    "end": 1766.34,
    "text": "Yes, we have a whole level of confidence at the beginning of this section but later on well maybe somebody's hijacked our session or may be someone else has logged in to an open."
  },
  {
    "start": 1766.62,
    "end": 1769.96,
    "text": "it comes across as your computer whatever it is."
  },
  {
    "start": 1770.04,
    "end": 1771.86,
    "text": "so you can't really trust too much."
  },
  {
    "start": 1772.76,
    "end": 1777.88,
    "text": "and when thinking about if using signals then we can maintain that level of trust."
  },
  {
    "start": 1778.66,
    "end": 1780.18,
    "text": "But I think there are even stronger arguments."
  },
  {
    "start": 1780.22,
    "end": 1782.6,
    "text": "If you're using behavioural biometrics how do type?"
  },
  {
    "start": 1782.66,
    "end": 1783.64,
    "text": "How gesture etc."
  },
  {
    "start": 1785.04,
    "end": 1799.1,
    "text": "If you start doing that at a relatively low trust login with whatever factors, if you want to use those behavioral biometrics continuously throughout the session then it can actually increase trust."
  },
  {
    "start": 1799.76,
    "end": 1807.76,
    "text": "It's now thirty seven minutes into this session and we have all of these data that Steve has been typing continuously."
  },
  {
    "start": 1807.82,
    "end": 1812.1,
    "text": "they've be moving their mouse so things fall within loans for users."
  },
  {
    "start": 1812.6,
    "end": 1817.86,
    "text": "You know, we have a high level of confidence that this is an uninterrupted activity by this particular person."
  },
  {
    "start": 1818.6,
    "end": 1821.2,
    "text": "So by the time it comes to doing oh I want now wants make?"
  },
  {
    "start": 1821.64,
    "end": 1823.26,
    "text": "uh i want to access some sensitive data."
  },
  {
    "start": 1823.34,
    "end": 1826.3,
    "text": "or what's making high value financial transaction?"
  },
  {
    "start": 1827.06,
    "end": 1830.62,
    "text": "We have High Level of Trust which is likely sufficient."
  },
  {
    "start": 1830.7,
    "end": 1836.36,
    "text": "so The idea having to do Trust Elevation or Transaction Verification at That point?"
  },
  {
    "start": 1836.88,
    "end": 1837.86,
    "text": "We've already satisfied!"
  },
  {
    "start": 1838.54,
    "end": 1854.64,
    "text": "We might still Do that in certain circumstances but The idea of using these signals on top of traditional credentials allows us to maintain high levels of trust but actually provide much better user experience."
  },
  {
    "start": 1855.14,
    "end": 1877.76,
    "text": "There's also the notion of being able to evolve things continuously over multiple sessions, you know I was talking about looking at things continuously throughout a session continuity across multiple sessions, that you're building up a stronger and stronger picture of that user's behavior."
  },
  {
    "start": 1878.54,
    "end": 1882.98,
    "text": "And able to analyze anomalies with higher confidence."
  },
  {
    "start": 1883.52,
    "end": 1890.84,
    "text": "if you have that continuity cross multiple sessions it's not just increasing the confidence in their density."
  },
  {
    "start": 1890.92,
    "end": 1906.8,
    "text": "claim is increasing this approach where you're evaluating signals, particularly behavioral biometrics throughout a session so that you don't need to ping the user."
  },
  {
    "start": 1906.86,
    "end": 1912.04,
    "text": "Don't prompt your user to elevate trust explicitly when risk is"
  },
  {
    "start": 1912.16,
    "end": 1912.48,
    "text": "high.\"."
  },
  {
    "start": 1913.18,
    "end": 1915.06,
    "text": "I find the psychology of security fascinating."
  },
  {
    "start": 1915.14,
    "end": 1921.42,
    "text": "it's part of my background and especially the idea that too little friction can actually make people uneasy."
  },
  {
    "start": 1922.14,
    "end": 1927.04,
    "text": "sometimes we want to prompt or challenge because it reassures us at system is paying attention."
  },
  {
    "start": 1927.9,
    "end": 1935.32,
    "text": "How do you see friction as being used intelligently, not as a burden but as a way to reinforce trust and intentionality in high-risk moments?"
  },
  {
    "start": 1936.68,
    "end": 1940.72,
    "text": "There are still reasons why you might want to... ...do things."
  },
  {
    "start": 1941.36,
    "end": 1963.64,
    "text": "One is that absence of friction isn't necessarily always a positive user experience because if somebody's doing something they know is risky like a high value transaction They want to feel that something is going on, That would stop a potential attacker."
  },
  {
    "start": 1964.28,
    "end": 1968.54,
    "text": "If they could do something without being challenged... ...they might then worry."
  },
  {
    "start": 1969.3,
    "end": 1970.4,
    "text": "somebody else could as well!"
  },
  {
    "start": 1971.04,
    "end": 1983.56,
    "text": "So it's bit of security theatre but the idea you have to reassure people there IS security behind what their doing in part of psychology of security."
  },
  {
    "start": 1984.02,
    "end": 2000.16,
    "text": "And there's also the notion which I think the NIST digital identity guidelines play lighted, of intentionality that if somebody can slip into doing something without any additional friction where is your assurance they meant to do that?"
  },
  {
    "start": 2000.68,
    "end": 2003.78,
    "text": "So having a challenge say you know it's kind of are-you sure?"
  },
  {
    "start": 2003.88,
    "end": 2006.32,
    "text": "thing and he could have explicit Are You Sure?"
  },
  {
    "start": 2006.42,
    "end": 2007.06,
    "text": "statement before."
  },
  {
    "start": 2012.14,
    "end": 2018.96,
    "text": "This is something that somebody had really sought about and committed to by passing the kind of challenge."
  },
  {
    "start": 2019.42,
    "end": 2026.4,
    "text": "So there are reasons why a totally frictionless approach may not be desirable even if technology enables"
  },
  {
    "start": 2026.46,
    "end": 2026.52,
    "text": "it.\"."
  },
  {
    "start": 2027.28,
    "end": 2030.42,
    "text": "And Alan, former VP and analyst at Gartner."
  },
  {
    "start": 2030.72,
    "end": 2038.32,
    "text": "let me just say what an absolute pleasure has been talking with someone who literally has their finger on the pulse for future security."
  },
  {
    "start": 2039.34,
    "end": 2042.54,
    "text": "Thank you so much for joining us today on the TALIS Security Sessions"
  },
  {
    "start": 2042.7,
    "end": 2043.16,
    "text": "podcast."
  },
  {
    "start": 2043.76,
    "end": 2045.64,
    "text": "No, it's been an absolute pleasure."
  },
  {
    "start": 2045.88,
    "end": 2048.739,
    "text": "As you can imagine I could go on about this at a much greater length."
  },
  {
    "start": 2049.06,
    "end": 2052.239,
    "text": "So thank you for giving me some time to share my thoughts."
  },
  {
    "start": 2053.04,
    "end": 2061.38,
    "text": "Remember if you like what you hear be sure To subscribe and tell your friend or colleague Or client And your favourite AI agent About The TALAS security sessions"
  },
  {
    "start": 2061.46,
    "end": 2061.86,
    "text": "podcast"
  },
  {
    "start": 2062.78,
    "end": 2068.78,
    "text": "Not just for the next one, but our collection of highly useful and very relevant past conversations."
  },
  {
    "start": 2069.96,
    "end": 2078.02,
    "text": "We will be back again soon with another episode or discussion on topics you need to know about to successfully carry out in the business of information security."
  },
  {
    "start": 2078.84,
    "end": 2080.76,
    "text": "Until then I'm Steve Pretis."
  },
  {
    "start": 2081.9,
    "end": 2083.159,
    "text": "Thanks For Listening."
  }
]