Ping Identity’s Patrick Harding on Preventing Identity Fraud

Transcription

hi I'm James Maguire here at the RSA conference with Patrick Hardin Chief product architect at Ping Identity Patrick thanks for talking to us today thank you very much for having me all right I know we're going to talk about identity fraud and what companies can do to protect against identity fraud but first please tell us about what Ping Identity does how does Ping Identity serve its clients so briefly ping is a identity and access management vendor uh we focus on providing ing authentication verification authorization Technologies to Enterprises for both their Workforce as well as their customers and consumers all right so so Ping Identity has a new report it's about identity fraud especially with the rise of artificial intelligence what are some key takeaways from the report so I I think it's uh there's recognition that when you're talking about identity verification um which is the ability to verify users identities sort of online that organizations aren't doing enough of that the demand for it has gone up significantly U mostly because either businesses have gone digital and are now interacting with their customers you know basically online or their Workforce is gone remote so they're now dealing with their employees and workers from a remote standpoint to the point where listen you could actually hire an employee and they actually never you know they might not show up to an office or meet any other employee es for 6 months 12 months 18 months something like that so that opens the door to Identity FY perhaps yes exactly in both cases so in light of the the report's findings what can companies do to prevent identity fraud I think that's a real issue for companies identity fraud sort of manifests in a couple of ways we tend to break it down into sort of two areas one is protecting you from synthetic and fake account accounts new account fraud like what what people do when they're setting up an account for the first time and then there's protecting uh you know helping organizations protect against something called account takeover which is whether fraudster can actually take over a existing user account again whether that's a consumer account or a um Workforce account another one that a little outside of that that we see a lot of though is also the notion of um scams where people are being um defrauded uh out of different things by being made to believe that the person they're interacting with is someone they know and they they then sort of do things um you know to basically move money or you know do stuff essentially against their will a little a sort of form of social engineering actually in that way you mean using a dpck or not necessarily uh well traditionally um you know scams might have involved um you know phone calls or emails to basically make you believe something okay deep fakes and geni has actually just made those scams even uh harder to Det de and EAS easier to implement so that now rather than getting an email uh you might get a phone call uh or a voicemail with a deep fake voice that you recognize or you might see a video with a deep fake video that you recognize right or even fishing emails um where these fishing emails are now so targeted and are written sort of in the flavor of the person writing it say take my you Andre Durand our CEO I sort of know his writing style you know a gen can now generate you know fake emails that sort of feel like he wrote it basically yeah so well did the survey say anything about deep fects it did uh it said that um you know generally you know everybody recognizes what they are they're a risk um and you know sort of 50 you know approximately 50% of organizations are sort of recognizing we we we probably couldn't you know detect de fakes essentially and we'd be vulnerable I don't know what the other % is doing or saying maybe a little naive perhaps I think they got their head in the sand actually yeah so basically I think you know I'd be very surprised if they actually had solutions to this because there aren't many out there right now those would be the companies that are like we got fooled by the Deep F yes exactly yes how how confident our companies in thinking that they really can protect against the Fred identity tag it's it's again about from the survey probably you know half the companies feel like they're doing that okay I think it's a continuous Shades of Gray here I mean people relying on you know Technologies like you know multiactor authentication stuff like that which is a great way to um to basically you know sort of deal with certain things but when it gets to deep fakes again we're basically now talking about communication channels that we've tended to just rely on sort of implicit trust if I get a phone call I recognize the voice I'm okay with it if I see a zoom call and I recognize the face I'm okay with it if I get an email and that email basically sounds like it's from the person cuz the email address says it's from them sure trust it so the the tech you know these things are only going to get better more used stuff like that and it's going to become a cat and mouse game I think to basically sort of deal with that a little bit to be honest we're going to have to do a lot to educate and train users to say look you are going you're not going to recognize and understand these defects you need to be aware of them you're not going to recognize them you now need to think all right if that message that I got that voicemail that I got is asking me to do something um of a sort of a higher risk type of transaction move money reset a password something like that um I likely need to verify sure and basically establish explicit trust that that actually this is occurring this is necessary and stuff like that so there's a lot of Education that's going to have to occur unfortun so what what's your major recommendation what do you want to leave companies with in terms of protecting themselves against deep fa in Ai and in particular how can Ping Identity help with this well I mean there there's all the the the the Baseline stuff we've been doing for a number of years I mean there's you know every everybody should be using strong authentication now um you know whether that's you know onetime passwords whether that's um uh MFA things like that there are things you can now do around ident you know to identify the user initially around identity verification you can start to basically establish who they are by basically it's a matching a selfie photo with a driver's license like a real driver's license or a government credential very hard for a gen to reproduce a driver's license oh good I'm glad to hear that all right so but again those things tend to have um sort of friction like you know there you're not going to basically take a photo of your driver's license every time you want to in sure all right or every time you need to interact with a service and stuff like that basically so what what this is sort of Shifting towards and this is the other part of the report is the notion of decentralized identity which is where my identity information is actually stored in my um smartphone and can only be unlocked by me and with with a B magc biometric yeah it could be a local biometric like like a face ID type of thing okay and and that information is secured with a private key like a cryptographic private key that is extremely extremely difficult to reproduce so no gen is going to reproduce that and now my identity can be shared um from my decentralized identity wallet on my smartphone with different Services could be with you know services or it also could be peer-to-peer so if I'm talking to you on the phone and I'm not sure it's you all right I I might ask you hey send me a you know ping me a a notification through your through your wallet that this is really you basically so you can do that sort of thing out of band so we we actually think that decentralized identity is really going to help deal with a number of these issues we're seeing right now um because it's essentially taking things sort of more out of band and we're eliminating the implicit trust that we've had on some of these channels where deep fakes are being used and replacing it with sort of an outof band explicit trust essentially um using using d identity how close are or far away are we from that world of decentralized identity so it's it's early but it's growing and again I think uh like any technology um its adoption you know is can be accelerated by external factors effectively so we're definitely seeing the adoption of decentralized identity at a completely different place now than it was maybe two years ago oh it's come that far that fast yeah organizations are starting to adopt this you know an interesting case is not really it's not really gen AI fraud per se but we we're seeing examples of companies where during the hiring process they're interviewing um people for jobs they basically then you know say Hey you know give them a job offer and it turns out the person that comes in on day one is a different person okay okay all right all right and there's like a number of examples of that that occur really so we're now talking about you know basically um using identity verification and a decentralized identity wallet and a credential in that wallet all the way back at the start of the interview process where basically we establish it's Patrick and he's interviewing and we give you a credential and every time you do an interview you show the credential to prove it's you such that when we give you the job and you come in to HR on the first day you have to show that credential that it was you and then we actually badge you and we actually give you a employee credential from there and stuff like that so there's you know there's no break in the chain so to speak right because Fraud's occuring in that situation too Patrick I think you said it a a lot of good stuff I thank you very much for sharing your expertise today okay appreciate it thank you for having me

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: May 29, 2024
Updated: Sep 26, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with Patrick Harding, Chief Product Architect at Ping Identity, about how companies can prevent identity fraud in today’s AI-driven enterprise environment.

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.