Transcript
Patrick Gray (0:05)
Hey everyone, and welcome to this soapbox edition of the Risky Business podcast. My name's Patrick Gray. These soapbox podcasts are wholly sponsored and that means everyone you hear in one of them paid to be here. And today's soapbox is with Jared Chong, who is the chief operating officer and president of Yubico, which of course make the Yubikey hardware authentication devices. I own one, I use one, I recommend you do the same. I'm guessing most people listening to this and watching this already know about Yubikeys, but trying to deploy them at like enterprise wide scale is not always the easiest thing. And you know, in these soapboxes we often talk about like big picture view, how the sponsor sees the world and sometimes we talk product. More often than not with Yubico though, because they're stuff I just find really interesting. And today the first thing we're going to talk about with Jared is the Yubico enrollment suite because really getting a user enrolled, like previously you've had to rely on people self enrolling and there can be problems there. So now they've done a deal with Okta and with Microsoft so that they can help you to like pre register, pre enroll your users. So they can just get their Yubikey mailed to their home address and it's already enrolled, it's already ready to go. So that's a very cool new thing. So we'll be talking to him about that in just a moment and then we're going to talk about Jared's reflections on cybersecurity in critical infrastructure. He recently was part of a delegation to Singapore where a lot of people were talking about critical infrastructure and cybersecurity sort of was a, was not really a main topic. Right. In a way that was somewhat concerning to Jared. But he also explains that, you know, governments are in a bit of a bind here because if they start, if they start putting onerous cybersecurity requirements on large infrastructure and you know, energy projects, they won't get funded by the private sector, by the VC firms and by the banks, which is where the money comes from to deliver all of that good new infrastructure. So that is the second part of this conversation. But I'll drop you in here where I ask Jared to explain Yubico's enrollment suite and what it actually does. So here's Jared Chong.
Jared Chong (2:18)
So what we wanted to do was let's rethink about how do we enable out of the box experience, which is when you get the authenticator, it just works, right? It's really Provisioned for you, we call it pre register for you and specifically for the service you want. And so we've been working specifically with the Octifox for a while. We GA'd the product two weeks ago and now we work with Microsoft because if you think about it as an enterprise, if you have an IDP that you want to work with and you said you want highest assurance and you want these authenticators to exist for all your users because you really treat this as a high bar that you want to solve, then the last thing you need is to deal with two things, like logistically you got to get it to all these users and secondly, you've got to tell these users what to do to start the journey. And so we want to completely eliminate the first part of this journey, which is you want a user to be onboarded with the best authenticator. We get the authenticators to where it needs to go and we do the provisioning for you, for the users. So think of a new employee, for example. You start with a company, your company has chosen either Okta or Microsoft and you set. I want the users to start working day one. I don't want to have them wait around and, you know, don't have strong authentication and wait for it to enable them. The goal is when you get your laptop or you bring your own device, the day you start, the authenticator shows up with you on the same day and you're in business. All you have to do is log in with the Yubikey and a pid, which is most important.
