Hear from an expert cybersecurity panel on how new generative AI techniques have overrun the biometrics revolution by making voice and video deepfakes commonplace. The panel discusses how we can pull ahead and win the race against online fraud. Loren Russon of Ping Identity, Kevin Lee of Sift, and Eve Maler of Venn Factory lead this panel on the new security landscape and how digital identity will evolve.

Watch the On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:00
Welcome everyone. Thank you for joining today’s panel discussion about winning
0:04
the race against AIdriven fraud. Now you know it seems AIdriven everything is
0:10
just about everywhere in our world and it’s causing massive change to so many
0:14
different parts of the world and it’s doing it at a rapid pace. And just one
0:18
example of many voice and video deep fakes seem to be everywhere and they’re
0:22
causing all kinds of trouble. Here’s just a few examples ripped from the
0:25
headlines. A finance worker paid $25 million to a deep fake CFO following a
0:31
video meeting. A telecom was fined $1 million after transmitting false Joe
0:36
Biden robocalls without verifying the source. A new face swap tool just popped
0:42
up that layers a live feed of a celebrity over a static photo of someone
0:46
else. And that piece of code briefly went to number one on GitHub. All this
0:52
leads me to ask, are your authentication and fraud detection systems and your
0:57
people for that matter prepared to deal with these types of attacks? To help
1:01
find out, we’re going to talk to a great panel today as part of our discussion.
1:05
So, let’s get started with introducing our panelists. First up, he’s a renowned
1:09
expert in fraud prevention and leveraging AI to protect some of the
1:13
largest online platforms. With nearly two decades of experience at companies
1:17
like Meta, Square, Google, and Syft, he has developed strategies, tools, and
1:23
teams responsible for protecting and growing billions of users and dollars in
1:28
revenue. Please welcome VP of trust and safety at Sift, Heaven Lee.
1:34
Next up, she’s a globally recognized strategist, innovator, and communicator
1:38
on digital identity, security, privacy, and consent. She has 20 years of
1:43
experience innovating standards such as SAML and user manage access and
1:48
publishing research and has served as Forester research security and risk
1:52
analyst. Please welcome the president and founder of Venactory, Eve Mailor.
1:58
Finally, he brings two decades of experience in identity and access
2:01
management, driving innovation and security solutions that protect millions
2:06
of identities worldwide. Please welcome our VP of product management here at
2:09
Ping, Lauren Russen, and I’ll be your host and moderator for today. My name is
2:15
Ashley Stevenson, also with Ping Identity. Now, let’s get started. No.
2:20
So, then let’s introduce the other part that we obviously are here to talk
2:23
about, which is AI. So, AI and AIdriven threats, how is AI disrupted the
2:29
adoption of this biometric authentication that we’re talking about?
2:32
And what are the main security concerns related to these threats that are
2:36
AIdriven like we talked about in the beginning? Deep fakes for as one
2:40
example.
2:41
>> Yeah, I can take that on. Um, so AI and biometric authentication, it’s certainly
2:47
a I’ll call it a disruptive duo here where AI has significantly disrupted the
2:52
landscape of authentication both in a positive way and in a negative way. So
2:57
on the positive side, AI algorithms have enhanced the accuracy and the speed of
3:04
biometric like recognition systems. So for instance, instance, AI powered
3:09
facial recognition can now identify individuals with super high precision
3:14
even in challenging uh conditions like low lighting. Let’s say there’s
3:18
different makeup or different hair, uh facial hair, all those things um can now
3:22
be anticipated and accounted for. However, AI has also introduced some new
3:28
security concerns. One of the most prominent ones as you mentioned is
3:32
around deep fakes and these are of course can be highly realistic synthetic
3:36
media uh such as videos, audio recordings uh created using by more and
3:42
more off-the-shelf AI techniques uh and they can use be used to impersonate
3:48
individuals, spread misinformation, and of course commit fraud. And so I think
3:52
there’s three main concerns that I have related to this area. So number one, the
3:58
impersonation fraud. Like at this point, deep fakes can be used to impersonate
4:03
individuals uh leading to financial fraud, identity theft, social
4:07
engineering. I think by now we’ve all received either those broad emails or
4:12
spear fishing email. Uh but now it’s moving to things like voicemail or
4:17
videos that are more doctorred up that look more and more realistic. Um, the
4:21
second piece I worry about or think about is around disinformation and
4:26
propaganda. So, we’re now in, at least in the US, in an election cycle for our
4:31
next president. And there is a ton unfortunately of misinformation and
4:35
disinformation that’s being posted out there in various forms. And I had to
4:40
deal with this firsthand prior to joining Sift. Um, I worked at Meta and
4:44
our one of our chief concerns was around election integrity and misinformation
4:49
propagating on the platform. Well, a lot of that was essentially uh deep fake
4:56
technology uh used to persuade people or try to change the sentiment on of one
5:02
candidate or another. Um, and the third area I think about is around blackmail
5:07
and extortion. So deep fakes can be used uh against individuals or organizations
5:12
by threatening to release this kind of damaging or embarrassing content and
5:17
nobody wants to be the target of such things. And so as a result um if they
5:22
were duped whether it’s sending money to they thought the CFO or someone else um
5:27
those are all areas that become harder and harder to identify and essentially
5:33
easier to fall for. You know, Kevin, earlier this year, we
5:37
did a customer road show and as part of it, we had found this this deep fake
5:41
video that was a a short stretch of Morgan Freeman just saying some things
5:45
to the camera, a little a little mini speech. I don’t know, maybe it was 30
5:49
seconds. And it was just it was so uncanny at how if you weren’t looking
5:53
for it, you really weren’t going to notice that it wasn’t him. And then I’ve
5:57
heard some of these other ones where within 15 seconds an AI can learn a
6:02
voice good enough to to sound like that person on the phone where you’re not
6:06
even seeing the visual part to try to detect it. You’re you’re hearing a voice
6:10
that sounds like it’s it’s in distress. And you know, with with those types of
6:14
things and here we are, those of us in on the panel and those of us listening
6:18
are probably people who think about this a lot more every day than the average
6:22
person out there who, you know, is probably not up to speed on on the
6:26
latest of what’s happening and could who could easily see a deep fake of a
6:30
celebrity or of a leader of someone and and and take that as fact and then and
6:34
then act on it or believe it and and propagate it. So, it’s just it’s it’s
6:38
really fascinating and kind of scary of how quickly the the bad side of this has
6:45
has taken hold.
6:47
>> And don’t get me wrong, there’s Oh, sorry. Go ahead.
6:49
>> Well, just to say, you know, sort of in the popular culture, there’s starting to
6:53
be a a folk index of just how good it’s all getting and how scary it’s all
6:58
getting. Um, a year ago, there was a a Will Smith eating spaghetti video that
7:02
everybody thought was funny. Um, and now it’s getting scary accurate. So there’s
7:07
kind of a Will Smith eating skddy spa spaghetti index um where you know if it
7:13
gets to be that it’s indistinguishable to anybody uh on on the planet then
7:17
we’ve we’ve entered new territory and we we need to battle it.
7:21
>> Yeah. And we have a we have an audience interaction here that’s added something
7:25
that’s a good point call out as well in our um at Identiverse our ping identity
7:31
CEO Andre Duran and and has done a couple of different examples but know
7:35
most recently at Identiverse you could see the video out there on on YouTube or
7:38
on the Identiverse site showing a video recording of himself and then a deep
7:43
fake of himself and you trying to figure out who who is the real is the real
7:47
Andre and so it’s there’s plenty of examples out there but that’s a really
7:51
interesting one,
7:53
>> good call out from the audience. Thank you.
7:55
>> Yeah, thank you for that one. And we see it, I mean, certainly you can have
7:58
founders and CEOs doing this stuff, but on a more personal side, like you can
8:02
see this on Tik Tok and Instagram where celebrities are trolling or there’s, you
8:08
know, creating a meme for something else, whether it’s spaghetti or
8:11
something else. Uh, and the creators in a positive way are using it to, uh,
8:16
create a lot of virality. Unfortunately, that same tool can be used to spread
8:21
misinformation or other things that uh may not uh garner the same sentiment um
8:27
when that content is created.
8:29
>> Yeah,
8:30
>> that’s exactly right. Go ahead, Lauren.
8:33
>> I was going to add though, I mean, it’s interesting how these are good tools for
8:37
verility. So, you could virality
8:42
>> like that was feeling weird. Um but also you consider you know what it’s doing is
8:47
creating a lot of distrust out there because um there was this big wave of
8:51
everyone thought we could solve a lot of the problems through biometrics and now
8:54
we see a slowing of that adoption and I think it is because the fakes are so
8:58
good and um I think that trust is end up you know ultimately being kind of a
9:03
problem with it. We don’t trust them anymore. So someone comes in with their
9:08
face you do a facial scan we again we question it is it really them or not?
9:11
And I think the trust element is also a big part of it. Not necessarily a
9:15
technology piece, but a social piece.
9:18
>> Yeah. I think on the opposite side of like somebody is using AI technologies
9:22
to do a deep fake to take over someone’s account. The other end of it, people of
9:27
knowing what’s real and what’s not anymore. People are creating their own
9:30
avatars essentially for social media and you and using them as influencers to
9:35
monetize an influencer of a person with pictures and photos that was created
9:40
from out of thin air with a with a prompt that are then out there
9:44
monetizing. Um, so it’s just it’s it’s all over the place. So that that’s a
9:47
good establishment of the disruption that’s happening here. So let’s talk
9:51
about how we combat the threats that arise from this. Right. So um AI is
9:57
rapidly evolving. how can we stay ahead of this curve panel and battling these
10:02
new threats um particularly those related to biometrics as we’ve been
10:06
talking about um and things like synthetic identities.
10:10
>> Yeah, I can take a crack at that one first. Um essentially what’s going on is
10:14
we’re in an arms race and in order to succeed we’ve got to fight fire with
10:19
fire. It’s frankly no longer acceptable just to have a static rules engine to to
10:25
handle authentication. When I look at the industry now and where it was, let’s
10:30
say three years ago, five years ago, even longer, really the speed, scale,
10:35
and sophistication of these bad actors has grown by leaps and bounds. And so
10:41
really, there’s two areas that I think of when it comes to kind of staying
10:46
ahead of the curve here. Number one is of course continuing to invest in
10:51
advanced technology. So adaptive biometric systems that incorporate um
10:57
different algorithms that are capable of really learning in real time and
11:00
evolving based on different user behavior to recognize I’ll say new uh
11:06
kind of novel techniques uh to spot these synthetic identities is is key.
11:11
And the second one I’d point to is around continuous improvement and
11:15
updates. So live learning is very very crucial where again we can’t rely on the
11:20
static rules anymore. the algorithms that we do push out must be able to
11:24
respond quickly in real time just because the attacks that we face in
11:28
these digital environments can happen in relatively large waves. Um, so that’s
11:34
one area and really there’s some others around kind of maybe we’ll talk a little
11:38
bit more later around shared global networks. Um, and really having I’ll
11:43
call it a layered solution where that’s why I think ping plus sift can be so
11:46
powerful here where with ping you have a noode orchestration, you have built-in
11:51
MFA, with sift you have AI powered risk decisioning, really powerful automation
11:56
and so having that layer in place can be very beneficial for any company that’s
12:01
looking to kind of stay ahead of these more AIdriven attacks that are hitting
12:06
themselves or or their consumers. Hey Kevin, I was going to add or at
12:10
least agree with you. I think the more we can do to share patterns, we can do
12:15
quick updating, it’s really leaning into, you know, what cloud platforms
12:19
give us because it does bring kind of a community effect to it. I also was I’m
12:24
heartened by the fact that there are like phyto Alliance and standards bodies
12:28
that are now doing testing. So consider phyto alliance has a face biometric
12:33
identity verification test and they’re certifying companies over 10,000
12:38
different tests to see if they certify and then they are measuring you know
12:42
what’s the acceptance rate from an attack presentation and then what’s the
12:46
false reject rate um for those and so I think understanding that there are
12:51
bodies out there that are helping the whole industry to test to ensure that we
12:55
stay ahead of of what some of these bad actors are doing
12:58
>> I think that’s one of the biggest powers that the security community has is
13:02
actually being a community and doing data sharing both humanto human and also
13:07
through kind of te technological means. Um there’s there’s a new standard called
13:12
shared signals that I think might be part of the solution here so that you
13:16
can asynchronously learn when something has been compromised and feed that into
13:21
your contextual risk engine and and be much more adaptive thereby.
13:27
>> Yeah, definitely. There’s definitely a better together story here. So, actually
13:31
right now I’m at a conference in Orlando. It’s a bunch of fraud and
13:34
payment folks getting together and really we can compete on so many
13:40
different levels like in whatever industry or vertical we’re in. But here,
13:44
at least at this conference, there is a known kind of we’re all here to fight
13:48
different types of abuse and fraud. And and to that it’s not necessarily meant
13:52
to be a competitive advantage because we know at the end of the day we want
13:58
everyone to trust the internet or the products that we have. And if we do
14:01
something to poison that well it’s just bad business for everybody involved. And
14:06
so there is a innate desire for us to legally kind of share information uh and
14:12
maybe it’s anonymous as well uh so we can be better at detecting this bad
14:15
behavior where it doesn’t have to be like eve.com that gets exploited and
14:20
lauren.com that gets exploited. not a benefit to me. like it’s better for all
14:24
of us if we can kind of share information and keep these bad actors at
14:28
bay because I mean guess what those bad actors are all collaborating they’re all
14:33
working together to exploit our systems and so what is the channel for us to
14:37
kind of fight back
14:39
>> in fact Kevin they even have given themselves a name at sometimes the fraud
14:43
as a service or fifs talk about that you know um talk about
14:49
the security community better together and coming together it’s important
14:52
because uh the other folks are getting together and creating this a growing
14:56
threat offering, you know, malware and AI tools, bad AI tools, training,
15:01
manpower, and even moneyaundering services in some cases. And so, you
15:06
know, as that goes on, a strong community of of security practitioners
15:10
and companies coming together to help combat that, I think I think can uh
15:15
achieve that. But that just goes to the point that, you know, we’re fighting
15:18
fire with fire and the fire is definitely strong um on the on the
15:23
attack side, right? Uh there there’s another point that you brought up, Kev,
15:27
uh Kevin, that I just want to uh accentuate before we move on. And that
15:30
that is about the importance of uh it’s not the importance, but to say it’s just
15:36
no longer enough to have static rules-based. You said that earlier as
15:40
part of this conversation. I think that’s really a thing to highlight and
15:43
it reminds me of, you know, back in the time um not so long ago in a galaxy not
15:48
so far away when computers were new and people were still doing their books on
15:53
paper and they were still managing inventory manually. And as the computer
15:56
came along and got out of the raised floor where one computer was this, you
16:00
know, the size of a conference room and got down to to where it was really
16:04
making an influence, it became that ubiquitous. um if you had it, you you
16:09
needed it. And if you didn’t, you were just going to fall further and further
16:11
behind. And I think that’s exactly what we’re faced with here in in the case of,
16:16
you know, static rules trying to combat an AI that’s constantly learning. So, um
16:20
just to make that point, we’ve got to fight fire with fire and we need to use
16:24
all that we can on the positive side of AI to combat that fire. Okay. So, let’s
16:31
move on and let’s talk about um pairing biometrics. How can we effectively pair
16:36
biometrics with some of these other authentication methods? We talked about
16:40
um you know MFA is one that’s obvious. We’ve talked about the three different
16:43
factors when we started off here. Um but there’s also things like pass keys, even
16:48
verifiable credentials in the context of decentralized identity. How how can we
16:52
pair these things together to help enhance security to fight back um as
16:56
part of this um better together security community?
17:00
>> Yeah. Well, Kevin said it earlier and it really is just bringing an ex we call it
17:05
experience orchestration or user journeys to be able to tie all these
17:09
together because it’s one thing to be able to detect what’s going on and it’s
17:12
another to be able to make a decision based on that policy you talked about
17:16
and then direct. It’s not just allow deny but I need to direct them to go do
17:20
something. And
17:21
>> I think having that experience orchestration as part of it is key to
17:26
tie this all together. And then that um almost ceremony of where you start. It’s
17:31
like start with a verification um of the user maybe based on some
17:36
verified credentials and bring them in to pair the phone with the identity and
17:40
then start to progressively give them greater and greater access as we get to
17:44
know them better.
17:46
>> You know, and NIST has some things very specific things to say about this that
17:50
I, you know, I recommend reading. It’s it’s not a hard read when it comes to
17:54
their requirement. actually biometrics shall be used only as part of
17:59
multiffactor authentication with a physical authenticator something you
18:03
have. So when you need that kind of assurance, you know, it’s laying out
18:07
some pretty specific ways that you can achieve that assurance. And we’re seeing
18:11
more and more that this is like an ondevice
18:14
uh biometric check, face ID, touch ID, that sort of thing. And um that that’s
18:20
actually quite protective for it to be on device and that can sort of start a
18:24
chain that you can then find more trustworthy as a service.
18:28
>> Yeah, I think it’s good. Have you like I have a question for you Eve like from a
18:33
device standpoint I think you talk about you know the new modern biometric world
18:37
is very device ccentric are you finding some that are more sensor driven where
18:40
you don’t need a a device per se
18:44
>> um you know some things are aggregations of sensors I mean you know your your
18:48
connected car can authenticate you right um it can certainly detect um based on
18:53
the way you take corners going by the sensors and the tires that they know
18:58
it’s you that your insurance company knows it’s you, by the way. Um, so, so I
19:03
think that, you know, there’s room for more, uh, silent risk-based methods of
19:09
just observing you. And I know Kevin, you’re a big believer in this kind of
19:13
behavioral biometrics. Um, so maybe you can just describe some of what you’ve
19:17
seen. Yeah, certainly on the behavioral side
19:20
where I look at it as uh really understanding the entire digital user
19:26
journey here and yes the user may pass through the first gate. They will get
19:32
authenticated um but that doesn’t necessarily mean that you should give
19:35
them the keys to the kingdom and and let them do whatever they want. So the
19:39
example I give is personally speaking um on my Android phone I am a swipe typer.
19:44
So, I use my thumb and I swipe around. Um, and that’s generally how I respond
19:48
to to folks. Um, so, uh, on the other hand though, if my, uh, let’s say I log
19:54
into my Chase account and I’m conducting whatever transaction, um, typically I’ll
19:58
I’ll swipe type to make it make it go. Um, but if it notices that I’m suddenly
20:03
touchyping, which a lot of people do as well, that from a behavior standpoint is
20:07
maybe more unique to me. So, I may have put in my password. I may have
20:10
authenticated um properly, but if the system notices that I’m acting a little
20:15
bit differently when I’m interacting on that platform, does it have the right
20:19
systems in place to not allow let’s say a $10,000 transaction or or something
20:24
along that effect just by my behavior? And so, the systems that we work with,
20:29
especially now where a lot of the companies that I work with, they have
20:34
their own app. And so it is a very more native experience. And so they have a
20:40
lot more curation power, a lot more ability to really refine where they want
20:45
a user to go. And all those are data points that can be used to make better
20:49
decisions on how far do you want this user to go or what do you want to want
20:53
to enable them to do simply by understanding the behavior after they
20:58
kind of pass through that first authentication check.
21:02
>> Kevin, it’s kind of like the digital get to know you over time, right? which is
21:05
something that if there’s a if there’s a targeted AI attack, unless it’s it’s a
21:10
major spear fishing where they do study someone over time and and in most cases
21:14
it’s it’s you know all kinds of attacks all over the place and in that case
21:18
they’re not going to have the advantage of knowing those types of behaviors and
21:23
those types of things that are part of someone’s pattern. So, you know what I’m
21:26
hearing is this combination of many different signals that are in context in
21:31
the moment that can add up and be orchestrated to say in this moment this
21:36
transaction from this digital signal is trusted to be some level of assurance
21:41
this person because of all these different things are are lining up or
21:45
some of them are not. So, we have to go back and do additional validation. But
21:48
being able to put those together and look at different things in the moment
21:52
of given the context where where someone is whether they’re using mobile device
21:56
whether they’re using their computer I think is is an important part of that
22:00
layered defense frankly right and then I think the other thing and I’ll bring
22:05
this back to some audience engagement that just came in um around how do we
22:09
know the person on the device is the actual owner of the account right so I
22:13
think there’s two parts of that um the first part is is I want to come back to
22:17
what we talked about in in the question on verification, right? So, if we’re
22:22
going to bind um a set of things about a person or a device that we say is true
22:28
and then put all these factors behind it, whether it’s a pass key or some
22:32
other kind of multiffactor, how how sure are we in the beginning of that process
22:36
that we’re starting off with the right person or the right identity, right? And
22:40
it I I I spent 5 years at at DHS and got familiar with another NIST um standard
22:46
FIPS 2011 personal identity verification where you have these you know
22:51
certificates encoded on a smart card. And the interesting thing about that is
22:55
just how stringent those standards are in the process of issuing that smart
22:59
card to the person of like the two different people have to be at the
23:02
workstation. there is a background check that was run and then you’re standing
23:06
there and you’re presenting your passport and it’s being scanned and the
23:09
one person is doing that and the person right next to them is verifying that and
23:12
so that there’s a physical chain of trust of verifiable documents and all
23:18
the things that go into the certificate being created on the card. Now, that’s
23:21
an extreme example, but then you know that that certificate that that
23:26
connection between me and that smart card that I’m carrying around for my
23:29
government ID um is is true and trusted. And then that leads us to the question
23:34
from the audience. So, after that, how do they know that I didn’t put in my
23:38
smart card and my PIN and did super strong authentication then walked away
23:42
and somebody else came up and was and it was it wasn’t wasn’t me at the time or
23:46
with the mobile phone. And so, you know, there’s that that I think could bring us
23:51
back to some of the behavioral things. Um, and then it can bring us back to at
23:55
certain points in a transaction. Again, context based on what it is you’re
23:59
trying to do. We might want to double check and do something that would be
24:03
really simple and pretty easy if it actually is you, but pretty hard if
24:06
you’re not there anymore and someone else is using your phone or has walked
24:09
away. But in that context with that question from the audience, I’ll just
24:13
open it up and see if any of you have additional comments.
24:16
>> Maybe Yeah, maybe I’ll just weigh in briefly.
24:20
It’s it’s um it’s a really good point. I think if you’re working with a workforce
24:24
population, you have some additional tools um around mobile device management
24:29
potentially around your operational policies around what you’ve deployed,
24:33
what you’re willing to accept. in the phto world they’re you know getting I
24:37
would say more and more mature maybe not all the way to maturity around how
24:41
enterprises can feel safe that only acceptable authenticators are being used
24:48
um and that you can constrain the ability to register more biometrics um
24:54
in the general population it does become quite challenging because that’s a
24:58
prized part of the flexibility of being a consumer right and so that’s where I’m
25:04
going to lean on those contextual checks some more. If you really, you know, want
25:07
to know, then you can um detect over time some of those signals. There’s
25:13
actually a a nice old word for this technique called tofu, which is trust on
25:17
first use. It comes from like the SSH world. And it kind of means you just
25:22
need one little outofband piece of information initially to kind of onboard
25:26
your understanding that this is the right person. And then over time you
25:30
build trust through what it is that’s been shared and you basically have a
25:34
shared context together. It’s kind of a relationship approach.
25:37
>> That makes sense. But if I was going to add, you know, you speak of kind of that
25:42
verified credential approach and then, you know, if you can associate that to
25:46
decentralized identity where now it’s the user actually is determining what to
25:50
share and when to share it and can even verify, you know, as an individual
25:54
before I do share that that is a verified credential that I want to to
25:58
push. So I think those things help and I did want to add one more thing which was
26:03
I think we are starting to see a very strong trend of adding biometrics in
26:08
more of a server side context. So, it’s, you know, I’m in a kiosk and I remember
26:13
we have one customer that still uses grid cards and they’re really just
26:16
trying to um resolve the I’ve got a kiosk kind of a scenario and I need to
26:21
authenticate those users and I need the biometrics to be server side and so how
26:25
do I create that chain of command and connect them all the way through is
26:29
standard identity proofing. Then also to be able to you know leverage not only
26:33
just phone base but server side biometrics is becoming critical as well
26:37
I think and then just to add on one more point
26:41
in terms of as we talk more and more about decentralized identity I think in
26:46
a positive way that it can alleviate a lot of privacy concerns where a lot of
26:50
this biometric data is really sensitive highly personal um the way that this
26:56
information is collected used um can raise a lot of questions and So um if
27:02
it’s used improperly can certainly erode public trust in institutions, different
27:06
governments, different companies. Um so really having a good understanding of
27:10
who owns this data. Maybe it’s me. Um who has the rights to it? How long do
27:14
they have the rights to it and for how long? And so I’d say digital’s got a
27:19
very long memory. Um but if I have more control of it as a consumer, um
27:23
certainly that alleviates a lot of the privacy concerns on my end. And then I
27:28
can tweak that dial as high as high or low as I go. Um, and then depending on
27:32
how I trust the the business I’m doing uh business with or potentially even a
27:38
government agency I’m doing business with um that really empowers me to kind
27:43
of tailor make how much I want to disclose and not and that’s can be
27:47
reassuring to many many folks. You know there’s an interesting trend thinking
27:51
about the server side biometrics which otherwise have been you know somewhat
27:55
more challenged than client side edge biometrics by this AI era. Um there’s
28:02
there’s the example the newish example of privacy preserving face uh it looks
28:08
like facial recognition but it’s age estimation. Mhm.
28:11
>> And that’s typically done server side because you’ve got some sort of um self
28:17
uh checkout system, say at a grocery store with age restricted products being
28:22
sold, things like that. It’d be really interesting to combine that with the
28:25
credential view. Like if you’ve gone through the trouble of that, it could be
28:29
issuing you a credential that doesn’t have to be zero knowledge proofed or
28:34
anything uh anything like that. It just says you’re in a certain age range and
28:39
then you can have kind of a time limitation on that credential. It’ be a
28:42
neat way to have issuers, decentralized issuers checking people’s ages and their
28:47
age ranges and and you know that that could be useful in a consumer context.
28:51
>> So great. I’m actually creating a Jura ticket right now.
28:56
>> Product innovationing happening live. So I think we’ve established that um
29:04
we’re we’re definitely living in a low trust time in the digital world. And so
29:09
let’s talk about strategies that you all would recommend for individuals or and
29:13
organizations to adopt low trust uh digital environments and how these
29:19
strategies can be particularly implemented.
29:23
>> Who wants to go?
29:26
>> Start. I’ll I’ll say something then. Uh just, you know, one of the the
29:30
techniques I’ve seen spread throughout all kinds of populations, not just sort
29:35
of techy people, is families setting up expectations for if somebody reaches out
29:41
to you in the middle of the night crying. I my car broke down. I need
29:45
money. one of those things that just seems these days like a scam to be able
29:50
to set up pre-register a challenge word um to see if that person really is the
29:56
family member that they’re portraying themselves as. And so that’s a really
30:00
useful technique and it’s kind of a specialized case of what you might call
30:04
dynamic knowledge-based authentication. you know, something that in the moment
30:09
um can be tested. That person can be tested and it’s a it’s a great way as as
30:14
we’ve actually learned speaking of ripped from the headlines from the
30:18
Ferrari executive who nearly was the victim of a deep fake scam except that
30:23
he sent something off and he asked the the other party who claimed to be
30:28
another executive, um, hey, what was that book that you recommended that I
30:33
read a few days ago? Click. Guy hangs up. So the these can be useful
30:38
techniques for pretty much everybody and I think everybody in the workforce as
30:41
well to be that sensitive to to the contextual realities.
30:46
>> If only that could have applied to that $25 million headline that we talked
30:49
about earlier. It’s such a it’s such a it sounds so simple because it is. this
30:54
is part of the solution that is not the technical piece but you know kind of our
30:59
our humanity outsmarting or or knowing the the limitations of of these AIdriven
31:04
threats even though you know there’s a lot of limitations that they don’t have
31:07
anymore there there can be these simple things that can that could just be used
31:13
um to thwart them right so I think that’s I think that’s a really good
31:17
point
31:18
>> actually I was going to say I I had a chance to attend it was an analyst’s
31:22
final presentation to an audience and it was in the UK and so it was kind of you
31:27
know a little bit formal and stuffy but he wanted to leave one message to
31:30
everyone in the group and he said that if we can start to create security
31:34
frameworks consistent with how our families and our communities operate
31:38
will actually achieve and so Eve I really like that comment that
31:42
>> consider how do we get to know people we interact with them and that high
31:46
interaction gives us that sense of I think almost intuition of who they are
31:50
and so you know intuition I think comes from this repeat interaction. We’ve got
31:54
to continue to interact with people and then then it almost seems the reverse at
31:58
times where, you know, when we don’t trust someone, we don’t communicate and
32:01
we’re not transparent. But I think it’s the reverse of that. We need to start
32:05
being more transparent. We need to communicate very aggressively because
32:08
when we communicate and we interact, um trust starts to develop. And I think we
32:12
start to get that reputation of a company that will lead with trust versus
32:17
um always take a suspicious kind of a mode. you know that it I really like
32:21
that and I think it’s something we can really hang our hat on like humanity is
32:24
going to triumph somehow and thinking about Andre’s um uh his keynote his
32:30
opening keynote at Identiverse last year that you you mentioned Ashley it was
32:34
very consequential for people to see that I think it was a real wakeup call
32:38
and I came out of it thinking all right my prediction is face-to-face
32:43
person-toperson meetings are going to become a lot more valuable like maybe
32:47
we’ll even see key signing parties kind come back. Um because it’s a way of
32:53
establishing that high bandwidth exchange of context uh to set you up for
32:57
success in the future.
32:59
>> Great.
33:00
>> Yeah. I think I was really in some communities I pushed towards zero trust
33:05
and I understand why but to me that’s quite a sad thing because I think as
33:10
humanity like from a human perspective we’re social beings. We want to connect.
33:14
We want to trust people. We want to bring folks into our tribe and grow
33:18
them. Um but so I’ll be more of the optimist here where we should absolutely
33:24
encourage more trust and to do that we we do need to interact. Um but to make
33:28
that happen with regards to different strategies to me things like again
33:33
prioritizing privacy like if I’m building a system we need to make sure
33:37
that we have very clear and um kind of transparent decision-making processes.
33:43
We know that from a regulation standpoint that regulation is coming
33:46
down where you must be able to explain how AI or how these things are making
33:51
their decisions. Easier said than done, I know. Um but having that clear box
33:56
decision-m practice really makes um for a better outcome. The second one is
34:02
really promoting diversity in data sets where when it comes to especially
34:06
biometric data, we need to make sure that we are getting an absolute holistic
34:10
view of how the system is operating, what data that we’re collecting and make
34:16
sure that we’re training on a diverse data set on that front. And the final
34:20
thing I’ll mention is just around I’ll call it addressing the the digital
34:24
divide. like there’s always going to be divisions in people. Um, and when I
34:29
think about let’s say the smartphone revolution where uh it started off at
34:32
the the top 1%, right? And now more and more people have access to smartphones
34:37
as opposed to traditional kind of flip phones. But um that divide will continue
34:42
to exist in other means and so being mindful of that and taking steps to
34:47
bridge that digital divide will also be I think a focus area for any business
34:51
that really wants to succeed kind of on this front. It’s a good point.
34:55
>> We have a an interaction from the audience that’ll bring us back just a
34:59
step or two. We were talking about the knowledge based kind of proofing between
35:02
people are setting up setting up something um either ahead of time like
35:07
we know that the the the code word or in this case um uh the audience member says
35:12
we we also need the inverse where I can challenge the other party with my own
35:16
generated onetime password. That way I can look into my app and see that Bob
35:20
from fraud is calling me as the phone system is part of the context and the
35:24
call is linked to the identity of the caller. So it’s kind of the the two-way
35:28
basically example of that
35:30
>> that that’s a use case that I have seen mooded in the digital wallet verifiable
35:35
credentials setting and I think that kind of peer-to-peer interaction would
35:39
be super valuable actually to people. Um, and to me, if I squint, it looks a
35:45
little bit like SIBA, client initiated back channel authentication, only with
35:50
credentials that you can rely on as the result as the thing being delivered. So,
35:54
you know, maybe there’s a cool idea there. And you know the other thing
35:58
that’s interesting on credentials we were talking about I gave that whole PIV
36:01
example and it definitely was a a workforce example but the idea of of
36:06
three parties involved right and and with the with the verifiable credentials
36:11
to be able to start off with a credential that has um a high level of
36:15
of trust or verification upfront that then you’re presenting that can
36:19
continuously be validated by whoever is is asserting that that piece of
36:24
information is true. whether it comes from a security camera that could kind
36:27
of detect your age and nobody needed to assert it or whether it’s coming from a
36:31
government authority. That’s that’s a it’s a pretty cool idea, but it’s a
36:34
great way to carry over I think some of the DNA from what we saw in in those
36:38
technologies that that are similar to the technologies in uh verifiable
36:42
credentials. So, good stuff there. Um let’s um let’s step into um culture and
36:48
politics just for a minute. Um so what are the broader culture and political
36:52
implications uh panel of relying heavily on biometrics for identity proofing and
36:56
how should these factors influence our approach to security?
37:02
>> Kevin you want to go first or
37:04
>> Yeah I can take that on. on really I think some of the points I covered
37:08
earlier one is around just privacy concerns like from a cultural
37:11
perspective um some cultures value privacy more than others and so that’s
37:17
something as as you’re building a product um that’s something to be
37:20
mindful of um and also the kind of discrimination bias I mentioned earlier
37:24
from a political impact like again I know we’re in a a US presidential cycle
37:30
at the moment and that becomes a lot trickier here uh when it comes to using
37:37
biometrics and it’s unfortunate but like I think a lot
37:41
of people in the US they have some mistrust of the government um whether
37:46
right or wrong but to we need to understand that and kind of dig a little
37:50
bit deeper there on what is the root cause of this mistrust and especially if
37:56
you’re handing over biometric information like I’m dreaming of a world
37:59
where when it comes to voter registration like we can collect these
38:02
biometrics uh upfront or more easily so it becomes less of a barrier for folks
38:07
to vote out there. Um, but really to make that work at a political level um
38:14
requires a baseline level of trust and there’s some things and this is actually
38:18
maybe gets beyond the digital side and gets more human where we really need to
38:22
do some kind of repair and and some hard looks at each other. uh whatever kind of
38:27
political affiliation you are to make sure that we’re meeting
38:31
voters, we’re meeting uh people where they’re at and understand that they
38:36
might have not they might not have access to all those things. Maybe they
38:39
don’t want to give up access to all those things. And that gets into the
38:42
more privacy concerns. Um but that one is I’ll call it a sticky wicket when it
38:47
comes to kind of unpacking those types of that that type of behavior. you know,
38:52
you you used this word I love uh previously, clear box, like not, you
38:57
know, really opening up full transparency. And I think that that
39:01
would really help, you know, it helps with trustworthiness in in all kinds of
39:05
endeavors. So, I think that would really really be helpful in thinking about some
39:09
of the just larger cultural implications. You know, we’ve seen
39:14
Ashley, you mentioned that that robocall uh Joe Biden robocall fine on the
39:20
telecom. You know, politicians are are a species, if you will, of celebrity. You
39:26
know, they’re famous people and they tend to be they tend to attract these
39:30
these kinds of attacks. Um but ordinary people are living with these kinds of
39:37
bombarded with these kinds of attacks all the time. Um, one of the the things
39:41
that I found when I was poking around Reddit, uh, when I was preparing some
39:47
authentication and AI remarks a few months ago was somebody who made this
39:51
observation that I, you know, I completely resonated for me. They said,
39:55
“Seeing AI pictures, reading AI generated text, I’m starting to feel
39:59
like Rick Deckard, if you remember your Bladeunner. Yeah.
40:02
>> Uh, I’m no longer able to trust anything I see or even people. I’m making air
40:07
quotes that I talk to through chat or voice. I’m giving everyone and
40:10
everything around me the touring test without even realizing it. And I think
40:14
it would be so sad if we if we really let happen what Andre Duran was
40:19
predicting would happen last year through these unauthenticated channels.
40:24
It’s so important for us to find these ways to sort of claw our way to trust to
40:29
the the other party on that line. you know, if it’s if it’s digitally
40:32
mediated, you know, we we here who are responsible for this kind of technology
40:37
that can battle fraud, that can that can authenticate, that can verify
40:41
identities, you know, we owe it to folks to get that right.
40:45
>> I think so. I was going to say I had a chance to go
40:48
to Australia and I was in Canberra and I was talking to a provider to the
40:52
government there and we were talking about identities and how do you
40:55
centralize you know all the identities and then who do you who do you trust and
40:59
at the time we all thought there’s got to be just one credential provider and I
41:03
remember the response back was no one trusts the government no one trusts the
41:07
bank and I’m like well then who do you trust he says well I trust the bank for
41:11
this information and I trust the government for this information and I
41:14
thought you know that’s a compelling ing pattern. It actually tells that story of
41:19
multiple trust providers. And so I think that’s where the verified trust comes in
41:22
is the more of those that we have that we can use in more implicit flows just
41:28
to validate without having to be you know friction um really helps because
41:32
then we can trust many versus just one. And I think that you know falls in line
41:36
with a lot of what you said.
41:37
>> You’re reminding me of something that I saw very recently. There is an
41:41
interesting research paper that came out on personhood credentials. So just
41:46
proving that you’re a human being essentially and not really having to
41:50
reveal anything else. And one of the things they recommend is what they call
41:54
bounded credentials. So you’d have a verifiable credential that can be issued
41:58
um by by an issuer. There would be only so many of those credentials, maybe a
42:04
limited number, maybe one by any one issuer. So that uh helps with kind of
42:09
fraud, but there need to be many issuers so that people have choice. And I
42:15
thought that that was, you know, a really you because lots of lots of
42:17
issuers can test whether you’re a bag of protoplasm, so to speak. Um and it would
42:23
be useful to have a multiplicity of issuers. Um and I think that would go a
42:28
long way towards building trust.
42:30
>> And it seems like the wallet technologies that are out there, I mean,
42:33
we’ve got that proven in our pocket already just with different issuers. I
42:36
mean, if you’ve got an Apple wallet, you can have, you know, credentials from
42:40
different credit card um issuers. You can have your your your airplane your
42:44
your tickets, you know, in there for for seeing a show or for flying on an
42:49
airplane. And so, you know, then you have one digital wallet where you can
42:54
select which thing you want to use. In this case, the paradigm would be
42:56
selecting which bit of information you want to use and which credential that
42:59
you have you want to pull it from and how much you want to share. But that is
43:02
something that is doable.
43:04
>> Absolutely. And that gets into the the ability for the individuals to select
43:08
which their privacy settings. Like I mean I feel like maybe every day we get
43:13
spammed by it for every new website we go to. Like do you want to share these
43:17
cookies or not? That’s a bit annoying to be honest, but well intentioned. Um but
43:21
that’s just another example where you get consumers to uh choose who they want
43:27
to share with and then there’s pros and cons to that sharing. If you share a bit
43:30
more, maybe you get it a little bit more, but at least it’s a choice of each
43:33
individual consumer.
43:36
>> Absolutely. Okay, so we’ve got uh just over 10
43:39
minutes left into our session. So, let’s move in and talk for a few minutes about
43:43
innovation and given the challenges of keeping up with these AIdriven threats
43:47
that we’ve talked about. What innovative approaches or technology should we
43:52
explore to move beyond the traditional security arms race that we’re kind of
43:56
seeing as being amplified here with these AIdriven threats?
44:02
>> Sure, I can I can kick that off. Um, really the thing I think about is of
44:06
course we’re all in the security space and we oftent times think about friction
44:11
as the answer. Um, but it can’t just be friction like especially from a
44:15
consumer-based standpoint. There’s got to be a balance between both friction
44:19
and flow. And to make that happen, I know AI is a topic of this discussion.
44:24
That’s absolutely a mechanical advantage that we can deploy to make it better.
44:28
Where realistically speaking, like 99 plus% of the consumers on our platform
44:35
are good. They’re legit. Yes, of course, you have that sub 1% that is actively
44:40
trying to do some damage on the platform. And it’s on us as stewards of
44:45
this data or the at these companies to make sure that that that damage is kind
44:50
of controlled within a certain radius here and limited. But don’t lose sight
44:55
kind of for the audience out there that really our jobs is at the end of the day
45:00
to run a successful business. We need to enable the 99% to do what they want to
45:04
do to engage on our platforms um and to to know kind of make those experiences
45:09
more delightful. And I think to do that, transparency is very key. Like we’ve got
45:13
to operate in that clear box mode. Like black boxes are not going to work. Um
45:18
from a regulatory standpoint, from consumer standpoint, that’s just not
45:21
going to fly as much anymore. Um and finally, from a technology standpoint,
45:26
we talk about AI, there’s obviously different flavors of it. But when I
45:30
think about the different algorithms and models are at play to me at the top
45:35
level, there is this global model. There’s a shared concept where we have
45:39
that better together scenario where we can share data anonymously uh in a
45:43
trusted way between bodies so we can verify folks where hey if I’m on let’s
45:49
say Lauren’s platform and I’m a great consumer of his platform and I want to
45:53
switch over to Eve’s platform maybe it’s my first time first time on Eve’s
45:57
platform but if I’m a trusted user kind of reputationally speaking um can I
46:02
engage on on her platform with minimal with minimal friction Um, and then you
46:07
get into like verticalbased models where kind of uh whether it’s for food
46:11
delivery or or just other things, you can have models there. Then finally, you
46:15
can have custom NL or AI models that really tailor to what your business is
46:20
is going for and you can yes of course have some rules in there too, but in
46:25
real time your algorithms can be tuned to exactly what your business needs are,
46:29
what you think you want for your consumer. So there’s a lot of room to
46:32
play there.
46:34
>> Great. I was gonna even add just to kind of take it one step further is you know
46:39
we often talk about that detection side of it and so there’s a lot of signals
46:43
that we can bring in and then if I choose to orchestrate what that signal
46:47
means to me then I’ve got to make a decision and that decision needs more
46:51
signals it needs more decision data to help shape that and then you get into
46:55
the now I need to direct I need to either block them deny access and maybe
47:00
you know deprovision them or I can use orchestration again to take additional
47:05
information um to be able to make um a new path. And I remember one case was,
47:10
you know, somebody was just even trying to access an application they weren’t
47:13
trained for. Um knowing that they weren’t trained and having that a bit of
47:16
information meant I could take them down a better journey and a better path than
47:20
taking them some other way. So I think just information gathering the whole way
47:24
along and then making sure you’re actively detecting, deciding and
47:28
directing um to create that good user experience. I think so.
47:33
>> I’m gonna add an idea maybe out of left field, but you know, going back to edge
47:39
detection of whether some entity is a human being, sort of like testing for
47:44
personhood. Um, that’s kind of the biggest challenge we face with AI bad
47:50
actors.
47:51
>> Um, and the devices and OSS and browsers that we’re using are in a really good
48:00
position to answer that question simply and there are a couple technologies out
48:05
there that do this and I don’t think that they’re very well used and I’d love
48:09
to see more attention focused on them. I’m thinking about there’s a sort of a
48:13
nent standard called privacy pass and Apple has private access token which
48:18
seems to be a sort of version of that. Google has a little bit newer uh private
48:23
state token which kind of convey you know a real person was doing something
48:28
on this device and I’d love to know what it looks like to be able to convey that
48:33
information more widely throughout a service ecosystem and you know it seems
48:39
almost personhood credential like in what they’re doing now. Um, and maybe
48:44
that’s the maybe that’s the right answer for quite a lot of mitigating this this
48:48
very um strong threat that we’re facing.
48:52
>> I agree. Well, I was even going to say what technology I saw recently was um
48:56
voice verification. I thought, okay, they’re just detecting my voice, but
49:00
then they knew my age, they knew my gender, and they knew my height. And it
49:03
was um they said, there’s about a hundred other factors that we know about
49:07
you. We’re just going to use those right now to determine who you are. And I just
49:11
thought there is innovation everywhere um to know those things and compound and
49:16
aggregate the different attributes about the person. So it’s all good stuff.
49:21
>> Yeah. I think one of the things that’s coming out of out of this particular
49:24
topic that I like just to highlight is the idea of the end user who is as we
49:30
said it’s 99% it or however whatever percentage of time it is is them and the
49:35
ex their experience and and having them have the right experience and the right
49:40
the right amount of friction right and and and so when we look at this
49:44
ultimately with all of these different threats out there and everything that
49:48
we’ve talked about today if we are able to put these controls in place and we
49:52
are able to do it in a way where we have the clear box. I love that term um to
49:56
have explainability of why things are happening. Ultimately the end user can
50:00
have an experience where they don’t know the battle that is raging behind the
50:04
scenes and if everything is in fact good then they can just go on about their
50:09
business and maybe even just stay logged in to what they’re doing and just keep
50:14
going. and only when if and when something happens that could be trying
50:18
to compromise their account then then a piece of necessary friction is
50:22
introduced and maybe it is them and we learn that right on the good side of the
50:26
AI ledger um but ultimately the the people who are who they say they are and
50:31
who are just trying to live their digital life it’s easier for them um
50:35
meanwhile it’s much harder for for any of the fraudulent uh AI attacks out
50:40
there right so I think that’s a that’s a a positive note as we as we get closer
50:45
to the close here. So, um, any other any any final thoughts from the panelists as
50:49
we are in our final four minutes before we head to close,
50:54
>> I have one thing just, you know, in working with SIFT, it’s been, you know,
50:59
fun to build out solutions around that full journey. And so, you imagine
51:03
there’s a whole lot of that detection up front that we do, but where it starts to
51:06
get unique is the granularity around the transaction. the very specific thing I’m
51:11
trying to get done at the end and those end up being kind of those highv value
51:14
interactions at at at the boot and so I think there is a lot of innovation
51:18
happening just getting to granularity and I think a lot of interaction in this
51:23
better together thing that Kevin talked about earlier on so yeah just very
51:26
pleased that you know our partner was able to join us on this call
51:32
>> awesome anyone else
51:35
>> well great I think we’re we’re right about we’re getting close to time so
51:38
I’ll just um draw a couple of conclusions here from from things that I
51:42
heard today. Uh number one, the race is definitely on. It’s not just a sprint,
51:47
it’s a marathon. It’s both of them together at the same time at a fast
51:50
pace. Um we know that that bots battling bots and just little incremental wins is
51:55
is not going to cut it here. We know that um static policies and static rules
52:00
are not no longer enough. We need AI on the good side uh to combat these things.
52:06
And we also know that there’s areas where the machines have the advantage,
52:09
but there’s areas, plenty of areas where we can innovate and outsmart the
52:13
intelligence that we’ve created that’s that has scaled up. And so I I like how
52:17
we ended talking about um human innovation. And so I want to end on just
52:22
an example of this. It’s it’s adjacent, but I’m actually going to see if I can
52:26
just share this image here. Um you guys seeing that image?
52:31
>> Yeah. Okay. So a picture is a picture is worth a thousand words, right? When we
52:35
think about autonomous self-driving cars and all the technology and the learning
52:39
and the AI that goes into that, um, speaking of, you know, human-based
52:42
solutions, about a year ago or so, um, there was, uh, some folks who weren’t
52:47
happy with some of the self-driving cars that were going around San Francisco and
52:51
for all of their autonomous nature and everything that they could do, they
52:55
realized that if they just put an orange traffic cone on the hood of the car, it
52:59
would stop and it would go into shut down or panic mode, put on some
53:03
emergency flashers, and wait for a human to come and help it. So, a a a $40
53:09
traffic cone just totally thwarted all of that um brilliance of the machine
53:14
that could drive itself around town. So, I’ll leave you with that thought with
53:17
the optimism that um we can we can fight back and and fight fire with fire and
53:22
and win this this um ongoing battle against the bad AI and and there are
53:28
plenty of ways that we can do that. So, keep that in mind. panelists. Um, Eve,
53:33
Kevin, Lauren, thank you so much. And, uh, thank you audience for listening in
53:37
today. That was great to have you here. We’ll talk to you all again very soon.
53:41
Bye-bye.
53:42
>> Thank you.
53:42
>> Thank you.