Albert David Lewandowski: Managing Trust Between Multiple Clouds and Non-human Identities Without...
About this talk
This talk focuses on managing non-human identities in cloud environments and the challenges associated with them. The speaker identifies service accounts, API keys, and certificates as critical components that need proper management, especially in multi-cloud and hybrid infrastructures. They discuss the evolution of security practices, highlighting the need for continuous monitoring and best practices around access control. The session also dives into the importance of passwordless authentication for applications, addressing the risks posed by misconfigured service accounts. The talk emphasizes the balance between maintaining security and ensuring operational efficiency while introducing new technologies and processes within organizations.
Full transcript
[Music] ladies and Gentlemen please welcome our next speaker Albert David lowski presenting the topic managing trust between multiple clouds and nonhuman identities without passwords hello and welcome today I would like to talk about one subject which in most cases is forgotten so it's about non-human identities so all kind kind of applications service accounts API key certificates which we use in our applications and it's also directly connected
to how we manage it in the cloud how we manage in hybrid infrastructure and also in multicloud environment my background is directly like in uh Big Data cloud and cyber security I spent many years on like migrating systems from one environment to another one and I also spend a lot of time on investigating how we can protect specifically service accounts and in the beginning we need to
start with some definitions because when we talk about applications in most cases even from cyber security perspective it's not so widely known or in fact it's not uh there is not enough like taking care about the applications as when you join the company you need to set up multiactor Authentication you need to pass through multiple different like tutorials uh and also you need to read a lot
of like internal uh articles about like security but when we go to the applications like do we really care about security and what kind of access all applications in our environment have because that's also very interesting shift which is happening at this moment in the market in the past all cyber Security Solutions very directly focus on your Mis configuration providing static and dynamic code analysis and like
immediately I would say about it's not like but it's like the continuous process but like two or three years ago we started to think okay we have very specific application which is responsible for making backup of our database and this specific application has full read write access to our production database think about any Bank Insurance Company government uh if you would be the attacker you wouldn't attack
like someone who has like the basic R privileges you would attack someone to have all of these admin privileges and that's like the very nice sweet spot for in in for for in fact discovering threats and that's like the subject which was forgotten for many years because the identity is not only about the people in the company but it's also about each single application server and nowadays
it when we talk about Cloud on premies we cannot take a look only into Cloud environments we rely on multiple software as a service simple example marketing or accounting teams in many cases they rely on the data which we directly in the it digital team depending on the on the naming convention we provide to them and they may use some third party tools for which we do
may not have like this observability so we do not know what's happening in this data another part is also uh related directly to this approach of serverless because that was like the promise of cloud in which many people believed that is like in 100% true that we go to the cloud we do not need to care about anything everything is you know like use as you go
pay as you go and later a lot of companies discovered that cloud is cloud is great but it's still some on servers and it it directly it's directly connected to managing all secrets credentials we use for many years Solutions like for example Hashi Corb vault in Cloud we have secret managers but later we go to some operational challenges one case is about how we distribute Secrets how
we manage Dot and files for our web applications or how we guarantee that all secrets which are delivered for example to the application and deployed on kubernetes how we can ensure that these credentials will not be used by anyone who has read access and who is able just to run the command go to the uh go to the uh container directly and just make PR print n
another challenge is related to this configuration management we have automation tool it's great but when we go how we manage and how we can ensure that on all systems across the company it will work and as uh as today we already have a lot of technical talks a lot of like this engineering site and during my work I discovered one thing that we as Engineers we can
do absolutely everything we can deliver any kind of the tool which we can imagine and we also do not have in in many cases any kind of you know like limitations that we do not look into many things even like from legal perspective or like business risk because we we have like this point of view as Engineers right so we analyze in most cases Based on data
based on the things which we perceive as they the best when we talk about security the biggest challenge is in combining Legacy and modern applications when we have this uni capability to build product you like from scratch it's great because we can Implement all the best practices from day one but what will happen when we have Legacy system here we can go one more time to the
banking industry which is a great case especially when they may uh when some of the internal system May rely on Old applications from 80s 90s which may not support multiactor authentication or which may just have vulnerability but no one will touch it because any modification can provide the outage of the system so here we go to the continuity and like this I would say the most fascinating
part uh of of engineering daily work so like in fact balancing and finding the right solution for very difficult challenges next part is also about approaching to the team when we talk about embedding security especially when we talk about applications developer would developers would like to deliver all the features as fast as it's possible and one of the challenge which I observed is in fact that uh
some Solutions may impact their daily work it may just make everything longer so in this case when there is like this no involvement in fact of the people who are offers of the most vulnerable or the most critical part they are not on board well it will fail of course you can like fill in Exel yes it's done but it will fail and it's also about developing
like this value proposition Security in many cases is nice to have and and in in in many companies there's just not enough awareness what is the impact and how in fact it can optimize costs you can think about any case in which you had to request access from someone you had to call to your internal uh and like the IT department on you or you had to
request that's the reason why currently there is like a huge shift to all kind of tools which are about providing just in time access it connects directly to implementing the single pane of glass organization we have active directory which is a great example of this like single pan of glass across organization as everyone as most organizations rely on active directory we have like the tool which is
used across all the systems starting from engineering uh through business analyst and indirectly accounting and now it's time I think for the report which is mentioned in any presentation which is about uh nonhuman tities here you have like the data from 2023 report from Microsoft uh not long time ago where is presented like the updated version for 20124 so that we have like the ratio of service
accounts to human accounts 10 to one and ba based on the uh based on the research made by Microsoft only one 1% of all of these permissions are used and another interesting point is like over 50% of all accounts are perceived as high risk so that they have administrative privileges in the environment and that's like the like the spot in which no one took care because it
like it wasn't important but then when we like already like built this fundament fundaments so that we provided multiactor authentication for users also additional uh protection G fishing we discover that okay but guys we have also applications which just work and well we do not care that's also the uh thing about any kind of iot or o or OT devices in hybrid environments we have this additional
challenge but we need to combine different systems responsible for identity and access management in the on premise in most cases we can rely like on active directory or when we are in single cloud we can rely on IM am and that's the solution which is enough for many organizations but when we go to use any kind of software as a service when we start to use additional
third party one case which is related like to gen AI is that we need also to ensure how our employees uh will take advantage of any kind of AI Solutions as like the case that Samsung employees provided some of confidential data over semi conductors products directly to CH GPT and these data have been used directly by uh chat GPT so it's it's like the major problem to
know what kind of accounts our users our applications use internally as in some cases you know like as always there is the case that very someone in the team must do a PC very quickly and that's especially like popular you in startups or in some scal UPS or some like software houses in which the most important part is to deliver a product as fast as it's possible
and in in in such case we can find that people may use a lot of like shortcomings or for example instead of waiting for someone to create the account in third party service they would use their private Google account and in fact we as organization will lose the visibility of this account because it's not managed uh it's not connected to anything what is internal and here we
go to the point that we need to have like this single enforcement and one more time like active directory is great example as each one of us like know uh active directory and that's also the thing which is like the huge challenge when we talk especially about applications and about more complex than single cloud or single on premise in single data center ecosystem here we also go
to another like challenges related like should it be the client installed on the device and then someone will need to Main need update or should it be a proxy to which everyone will be connected to and will use it as single point of enforcement single point uh of trust and about like high level ideas because you can find a lot of solutions and and it's like still
the market which is like in early development stage as we still do not have like the single standard for everything we can see that Microsoft uh with anra so former asan your active directory wants to do it so they want to become the single uh identity provider for absolutely everything and everyone anywhere we'll see how it will go uh but well we can be sure that Microsoft
has this power and in fact almost unlimited resources to promote a specific uh specific setup for environments so uh one idea which is like uh interesting from the site directly of applications imagine that we have like multiple virtual machines kubernetes deployed across uh across different Cloud providers so one idea is that we may rout the whole traffic to a single Gateway which will be responsible to injecting
Secrets or to verifying if the request from a specific application which is deployed uh on the virtual machine which is signed and we have like the information fa it's like an immutable state it wasn't n Modified by anyone who is uh who was like outside the organization or by someone who wasn't authorized then okay you can pass the request another case is uh that we may have
like the set of uh of gateways so instead of enabling like the even internal communication everything would go through the process so like the one case which we have uh on kubernetes is uh is uh ISO another one which would requ require additional development work is about providing like the additional API integration so that we have the client which is responsible for issuing its own certificate its
own token and then we can use something that uh like uh some companies call that is kind of like multiactor authentication or multiactor validation for our service account applications because uh the the the main challenge is in fact to create and to implement something that can be used by all applications out of the box as any kind of the change or new Integrations means a lot of
cost and it may cost the one thing which no one would like to see so the outage of the system in production and uh when we uh when we talk about like this uh authentication is really important to understand also the part of the secrets as whenever we talk about you post Quantum encryption Quantum key distribution all of these nice buzzwords we go to a simple question
how do we know that the new Joiner in our ecosystem can be trusted so in currently we may rely on certificates and with certificates we have one main uh disadvantage which is about the maintenance aspects and how it can be achieved how can it how can it be done who will be responsible for rotating all of them and well in theory like certificates is great but later
when we go uh deeply like into integration it's it's not so nice and when we have like the integration over API key we need to deliver this API key directly to the application and uh that's also like the part in which Cloud becomes great tool because we can simply integrate with the cloud provided secret manager we can configure a specific Plugin or we can uh provide that
VAR will be like the sync or that the application will get the secret uh by issuing it directly from Secret manager as it has assigned like the specific role in the specific uh Cloud environment but the thing is and that's like our end goal that there will be also passwordless for applications now we talk about password L for people right that we can be verified B based
on these that we have our own laptop we have our unique Behavior it's like in Mobile Banking application but like one of the factor of authentication is that we we are detected that uh that we are like the trusted people because we use our phone in the exactly same way as always if there is any discrepancy then we'll be requested for example to provide uh the SMS
code and the main challenge is about like issuing the Zero Secret case it's not like the problem when we are in single Cloud but when we like in multiple environments when it becomes the the problem it's also about uh it's it's also about like removing this vendor lock which is like especially a big challenge for big organizations so the idea is main like to issue these short
lft credentials so it's like in AWS we have I roles which are valid for a short period of time and that's like the goal which we would like to implement also for any kind of machine to machine communication but very will be the way that each single actor in our system will be able to be detected and here we have also like some solutions that we can
inject Secrets directly into runtime and it's it's also like related that uh from security perspective you would like to avoid providing any kind kind of secrets to the applications as we would like also to have a centralized governance of any kind of the credentials usage across the system so that's the place in which in fact that's like a great domain and I'm very curious how it will
look within next five or 10 years as uh as it's directly related to any kind of like the incident response so uh in case of incident respond that's also like very nice place in which AI uh will will join the game right so that AI will support us in any kind of the logs analytics and AI will be also very useful to detect and any kind of
the malicious change modification directly in in our system about the cloud uh I would like to say that it's always like the the best possible environment for small and medium Enterprises because it provides everything out of the box building team from scratch it's it's a it's extremely difficult expensive and time consuming and that's also like you know like like this perfect environment but it becomes not so
beautiful when we start to use anything externally or even when we try you like to connect with some additional data providers as we may just lose the visibility over what's going on across the whole ecosystem and the good part is that we can like autom most of the stuff and we can also like use the single way to deploy our things and that's that's the spot in
which containerization is absolutely like one of the most beautiful thing because in fact to protect what we have maybe even enough to provide you know digital signatures of our binaries of our image and that we can verify this signature and that's also like the uh uh one one thought which which came to my mind like several months ago that well in in cyber sec security it's not
about protecting 100% of the system it's just about creating so many different checkpoints that we'll be able uh detect on a specific one that something is not right as like providing this like you full 360 solution is just not doable in it it's just not possible to deploy everything and configure like in in perfect secure way because later we go like to any kind of the like
business requirement that where need to be done a specific exception for specific applications because of the following one two three for business reason it's it's also I think nowadays we live like in like in very interesting Years also that we started to think that okay we have our company data that's like a kind of uh you know like the like the internal gold and how and why
do we share some of this information with other companies and that will be like the another important shift going from this some of these software as service to go directly to the internal tools as as always it's about like risks and cost balancing as first of all we need to remember like about the cost about our budget and what kind of risks we can mitigate and what
what is like the possible uh impact of them uh one thing with which is always like important when we talk about the the security and managing any kind of the applications is to implement like the policy into development into Cloud that absolutely everything is code it's like the step-by-step process as I have never seen the project in which someone was able to deploy uh you know like
the everything as code and to pushing everything overd with all like the test cases from day one it's like the process in which everyone one must be involved and it's also about delivering the tools to people because in many cases you know for example like development team may gain some changes because it will take more time for them you like to build run test and then waiting
uh for their pool request to be approved but when we see the value and we can also like automate their work then they will uh join directly all of these efforts and as always it's about like the finding right strategy as uh we can observe in end domains related to it that we like doing trendy stuff currently it's you like about gen AI about large or small
small uh language models and it's also like about you know like some passwords right that now we are doing like API security now we are doing some identity security now we are doing some just in time access it's it's like about building the strategy and defining what are the goals for our organization as it will also differ based on the industry in which you work as in
some cases you know like it's exactly like with kubernetes a lot of companies move to the kubernetes because it's trendy and they were like okay we can Autos scale you like we can scale up scale down and I was like I think in in two projects in which someone like promised you like that it will be scaled up scaled down but the application itself wasn't prepared for
it and it's it's like connected about like this uh providing the protection for applications it's it's always like about this impact and defining whether it's important or not as as in some cases just following you know like the basic best practices which you can find anywhere in the internet it will be enough as any kind of the impact for the company will be negligible and what is
also important to understand what kind of the resources we have already in the company it goes directly questions about future so what will happen in the market and how it will work so the first and I I would say the most important Trend will be about implementing the password less as currently one of the most uh men most frequently mentioned issue is about like the credentials lickage
it's also related to this one that people in many teams May manage uh passwords in not secure way and even companies you know with very like extended cyber security teams with multiple factor of authentications they can become like the victim directly and that's what we saw for example with Uber bridge when one guy from The Uber also like provided the multiactor authentication code directly to the attacker
so of course like one of the biggest Vector of an attack is directly in us directly uh in in in human but one part is about like educ ation and second is about reducing this risk because if user you know they do not have in fact password or they are requested to provide like multiple different factors which are like outside the the password or outside something that
they need to type in like manually secure uh and it's also like the another part which is about like learning the behavior analytics so understanding how users behave and also how applications behave as it's not like the rocket science it's not a very Advanced artificial intelligence to see that okay we have a specific application which has like a specific schedule job to make uh for example a
dump of database and this job is done only once at 12 hours so we can Define also like the rule and start building just in time access for applications because if we started to do it directly for for developers directly for engineering team directly for business analysts why don't we do it for applications and it's also connected in fact to the in many cases lack of the
solutions which are you know like like uh uh bulletproof and which have been already proved in the market as is like quite quite new domain and it's also about providing the secure way to manage access as the best permissions for the users in fact is to get rid of any permissions so they just need to ask for the permissions only for a specific period of time and
then someone or something so for example like for example you like the AI agent can decide if someone is allowed or not another challenge which will happen is about building the single system to control access currently we have multiple different open- Source Solutions uh and also ideas how we can tackle this aspect as we have in some cases R base Access Control control attributes attributes based access
control and it's like very complex across different environments just think about the kubernetes and the default Ro based Access Control in most cases it just left as default because it just you know like not straight forward to set it up and in many cases just not some it's not mentioned as something important because uh that's that's also how even you like the leakage like in the American
Army happened right but one one young guy had full access to all the data which was delivered to the to the president of the United States so that's like the very interesting operational change about which you can uh you can think about which is still like not solved and that's also like the goal because currently we have multiple systems and we operate but at one point of
time there will be the time that we'll have like this everything centralized and that's also what we can observe in cyber security Market that everyone is every all the companies are moving to to be like centralized right so we can see that another company acquired like another startup or another player in the market it connect it's connected directly to unifying like the access policies as it's it's
very interesting that currently uh with Focus specification we talk about unifying of uh billing and costs for cloud providers currently it's still Laing beta but I think that well in a short period of time there should be like this final specification so that we'll be able to get information about allb Link in single format and that's also the thing initiative which I believe some of the like
links Foundation or Cloud native uh will take care so to develop the standardized access policy languages and also to standardize identity data of course we have like the solution and we have like the like standard which is like the for example spify which is like implemented or some of the spify uh specifications that that have been already like implemented in the into Cloud providers but still it's
not aligned and it's also about uh like the market Buttle between major identity providers and also like the cloud because From perspective but from perspective of each single cloud provider is always the problem when you go to multic Cloud because you may leave them or when you have like this you like uh environment to which you can move more of the workload next part uh is about
in fact providing like this security development kit as that's that's what I observed in many projects that there were you like some added requirements but there was not in not provided enough specific tools to be implemented or that developers were a kind of like left alone and it's also like connected to how simply we can implement the security framework into our infrastructure and it's also about like
providing to a access control that we can verify everything anytime that's like the idea of zero trust but with zero trust there is like uh like this challenge but business can say yeah we would like to have zero trust but when when it's implemented then it only generates you like more issues and questions uh how is it how is it going going uh it's it's also uh
when we talk about uh artificial intelligence and when we talk about anything like in 2023 2024 it's about data security as like one side is about like you like the applications and second which is in fact the full separate domain of data engineering is about understanding what kind of data sets what kind kind of data set uh in in the in the employees computers you know like
one is like directly about databases as in some cases we may not be able to connect uh the database with IM IM system of the cloud or in many companies you know we have like the full protection of the cloud system but users generate you CSV file which later they process directly on their local computer and I wish that there will be you like the day when
the python will be like General available in the Excel and then there will be like the right time for also like pushing for more plugins and more advanced Solutions also to analyze and to to make like the proper data security including J in time access for the data which uh sits directly uh in the Excel uh and uh when we talk about like the applications and service
accounts itself uh the most important part will be about like using different multiple different trust factors currently we may use like the account uh we can also have the information about like the state so we can have a kind of like fingerprint signature of a specific machine of a specific server adding to this one that this machine should work in a specific subnet it will be you
know like the complex ID unique secure ID of the application of our server which will enable which which which will grant this specific application to have access for database or to any kind of internal service and that's all what I prepared for you so I think that now it may be time for questions and well like I think the last thought is but well it's like the
domain which is still not solved so if you have any good ideas you like very we waiting a lot of money from American investors thank you for your talk and as you mentioned do we have questions in hall or maybe slider yes uh question is uh maybe it's some tools who can scan the whole system and find this all permission denies and can you say again what
uh is any tool who can scan the system and uh manage this permissions can yeah so about like the scanning misconfigurations currently we have like multiple Solutions especially in in fact we have one group of like open source Solutions and second is like the cloud security posture management which are strictly focused on detecting misconfiguration and also providing you a recommendation that if you have the specific a
am role then you should for example remove the asterisk from the policy so we have the tools which are like the support for making the review and then implementing uh and then like implementing but I would say it's like this it's similar State like to the devops industry but many years ago we didn't have like all of this like automat tool nowadays like for example when we
have anible we have like everything automated and we do not only rely on this like more static approach thank you more questions then I'll go um in infrastructure there is something called chaos engineering where they run test to basically break things rather randomly and see how robust the system still stays is there something in a security domain that can either try to exploit like automatically exploit the
system and see how it goes yeah so in fact like the one part is about even like the dynamic application security testing and it's also like in fact uh the whole domain of even like the thread modeling and also like you like trying to break things because like the most common is still like the pentesting as in many cases I would say it's still like the people
are the best Engineers to break the system I think it will be very interesting case like for Gen AI uh I know that is like overused but in fact when we would be able uh you know like to get all information about all C cves to the system and then it would it would may try you like to Infiltrate The System or like trying to make like
The Insider attack right so in fact like impersonate someone from it Administration team who has like quite administrative privileges okay and a little bit off topic question maybe do you know what is the most prevalent type of um security risk if it's actually getting the access to the system or some zero day exploits uh honestly like in most case it's still about human so it's still like
about you know like stealing credentials and of course like when we go to the internet right it's also about like advertisement and marketing companies would present but see like the in fact the weakest point of the system are directly humans and still I can tell you like Cas from uh from like one company just like in the critical infrastructure domain that uh like the internal cyber security
make simple check as simple test because VB domain which is you know quite similar to the official one they even put a huge yellow Banner in the mail that take a look if the domain is valid and see like 15% of all the recipents well they clicked on the link so unfortunately uh it's also like quite difficult to automate it because we can have you know like
Advanced like P anti pishing system a lot of education but still like how could we like prevent users in many cases from doing action as it's not always about you clicking link it's someone sometimes even about like downloading the file and then providing this data well somewhere else okay thank you and last question from my side would be what is your take on role of Open Source
in uh security well I'm I'm big fan of Open Source I may not be like the uh fully objective but I believe that like the open source code is also like the great way to increase the level of security as we have like more people who are involved in checking and it's also like in in fact much easier to understand what are like the vulnerabilities because we
have the visibility into all packages and in many cases also like the open source uh Community V take care of this shift left approach and also like providing you like like the scanning and additional testing so I would say is like the the way of everyone to provide like this joint uh Joint Forces to well make everything more secure and do you see open source as a
source of threat actually uh I would say that it's like the mitigation of risk for many cases as well in it everyone and as in any uh domain of life well we can make uh some mistakes and they may appear like the additional but the thing is whether well we are prepared to mitigate it and whether we have like the in fact Disaster Recovery plan gotcha thank
you we got uh first question on slid though what is that you would like us to take away from your talk H I would say one thing just take a look into your service accounts and applications and how you manage access sometimes just about like understanding what's going on in your infrastructure and then you take action as in many cases it's just you know like about like
leaving some components you know like in the dark and we do not care because we try not to look into them thank you questions from the hall maybe okay I take it as a no you can always uh find our great speaker outside of the booth and at the corner for ask me anything there are like two small couches where you can sit down and people will
find you otherwise thank you for your presentation thank you for being here and yeah