1
00:00:00,020 --> 00:00:01,720
If you're a bank, you want to know what's happening.

2
00:00:01,870 --> 00:00:03,260
When you're on the end user side,

3
00:00:03,470 --> 00:00:05,500
you want to have a guarantee that your password manager

4
00:00:05,740 --> 00:00:06,480
doesn't know what you're doing.

5
00:00:06,590 --> 00:00:07,640
So you can see already that.

6
00:00:08,980 --> 00:00:11,000
Hello, everybody, and welcome to Techlore Talks.

7
00:00:11,120 --> 00:00:14,240
Today, I have the privilege of having Remy on from Passbolt.

8
00:00:14,370 --> 00:00:16,180
That is an open source password manager

9
00:00:16,480 --> 00:00:19,600
that has a quite similar philosophy to KeePass in many ways.

10
00:00:19,900 --> 00:00:22,440
And we talk a lot about unsophisticated phishing attacks

11
00:00:22,570 --> 00:00:24,660
that target individuals through deceptive emails.

12
00:00:24,950 --> 00:00:27,440
We also touch on the implications of credential theft.

13
00:00:27,490 --> 00:00:29,580
We talk pretty much everything about password managers,

14
00:00:30,060 --> 00:00:32,720
What makes them more secure for most people than regular things?

15
00:00:33,070 --> 00:00:38,100
And also very commonly asked questions like, should you use TOTP or 2FA along with your

16
00:00:38,200 --> 00:00:40,340
password manager and many other things?

17
00:00:40,580 --> 00:00:41,860
So now let's dive into the interview.

18
00:00:42,140 --> 00:00:43,880
Thanks for coming on Techlore Talks, Remy.

19
00:00:44,160 --> 00:00:47,140
Do you want to start by just introducing yourself and what you work on?

20
00:00:48,180 --> 00:00:48,400
Sure.

21
00:00:49,000 --> 00:00:50,220
Thanks for having me today.

22
00:00:50,460 --> 00:00:51,220
I'm Remy Berto.

23
00:00:51,310 --> 00:00:52,460
I'm co-founder of Passbolt.

24
00:00:53,519 --> 00:00:57,340
So I'm a software engineer by trade and training.

25
00:00:58,300 --> 00:01:07,260
And I've been working on basically Passbolt, which is an open source password manager designed for collaboration for about 10 years.

26
00:01:08,440 --> 00:01:14,860
So this is actually all 10 years in 2016 since launch.

27
00:01:16,140 --> 00:01:20,640
Very nice. And when I first learned about Passbolt, first off, it's really cool you guys are open source.

28
00:01:20,920 --> 00:01:25,500
What's kind of the target demo historically? And is that still the target demo you're chasing today with Passbolt?

29
00:01:25,580 --> 00:01:28,900
Like what are kind of the unique things about Passport for someone who hasn't heard of it before?

30
00:01:30,200 --> 00:01:35,720
So when we started a long time back, there were no like web-based password manager.

31
00:01:36,000 --> 00:01:43,880
And like actually there was this infamous article like JavaScript cryptography considered harmful and, you know, all these things.

32
00:01:43,880 --> 00:01:48,960
It was very nascent, like the idea of having a password manager in the browser.

33
00:01:49,900 --> 00:01:56,460
And what was available at that time was really solutions like KeePass that was already around.

34
00:01:56,470 --> 00:02:01,440
So it was like client is basically one file that you have and you decrypt locally.

35
00:02:01,690 --> 00:02:03,260
And it's very safe that way.

36
00:02:03,480 --> 00:02:08,580
What was missing for us, because we were basically making software, we were a software house.

37
00:02:09,360 --> 00:02:17,220
And we were having these needs of sharing credentials and being able to track and audit credentials.

38
00:02:17,440 --> 00:02:22,980
So that, for example, when somebody is leaving the company, we can see who had access to what and rotate the credentials.

39
00:02:23,400 --> 00:02:25,620
So it started from that need that we had.

40
00:02:26,320 --> 00:02:32,080
And my co-founder, Kevin, created a very early version that we use internally.

41
00:02:32,260 --> 00:02:35,220
And then from them, we started onboarding some clients.

42
00:02:35,380 --> 00:02:40,200
And then eventually, we were convinced that this solution was interesting.

43
00:02:40,600 --> 00:02:44,180
So we didn't want to build another personal password manager.

44
00:02:44,400 --> 00:02:45,300
We skipped that step.

45
00:02:45,800 --> 00:02:49,780
we went directly into like, okay, let's build a password manager for businesses

46
00:02:50,520 --> 00:02:52,000
that would meet our requirements.

47
00:02:52,460 --> 00:02:56,260
So there are some security requirements that were important for us.

48
00:02:56,320 --> 00:02:59,380
And there were also some functionalities that were important for us

49
00:02:59,780 --> 00:03:03,280
that basically became the DNA of Fastbolt.

50
00:03:03,860 --> 00:03:07,660
So things like sharing items on the 101 basis.

51
00:03:08,400 --> 00:03:13,100
So as opposed to KeePass, for example, you have all your credentials in one file

52
00:03:13,140 --> 00:03:15,440
or like some other personal password manager

53
00:03:15,700 --> 00:03:17,380
where you have like collections of credentials.

54
00:03:17,840 --> 00:03:19,340
So every time you share,

55
00:03:19,510 --> 00:03:20,960
you basically share a collection.

56
00:03:21,240 --> 00:03:23,340
So you share all the credentials

57
00:03:23,560 --> 00:03:24,240
that are in that collection.

58
00:03:24,780 --> 00:03:26,540
There is no granular, fine-grained,

59
00:03:27,000 --> 00:03:28,760
okay, this person can read this password

60
00:03:29,000 --> 00:03:29,900
but cannot change it.

61
00:03:30,080 --> 00:03:31,820
Or the same goes for audit log.

62
00:03:31,870 --> 00:03:33,720
Every time you basically access credentials,

63
00:03:33,830 --> 00:03:35,140
you download the entire collection

64
00:03:35,450 --> 00:03:37,720
and then there's no fine-grained tracking

65
00:03:37,880 --> 00:03:39,120
of who has access to what.

66
00:03:39,520 --> 00:03:40,620
So you can report back,

67
00:03:40,620 --> 00:03:41,400
the client can say,

68
00:03:41,440 --> 00:03:44,680
hey, you know, I have access to that credential and that's fine for most usage.

69
00:03:45,300 --> 00:03:51,280
But you don't really know if that credential was actually leaked from the client.

70
00:03:52,040 --> 00:03:58,040
And the way we did it for PassVault is that we only download the secret when you use it.

71
00:03:58,140 --> 00:04:01,960
So this way, even if a secret, let's say, is shared with you, if you don't use it,

72
00:04:02,440 --> 00:04:08,580
meaning like you never fill it in the form, we have the proof that you never actually downloaded it.

73
00:04:09,460 --> 00:04:11,860
So yeah, that's so easy.

74
00:04:12,100 --> 00:04:12,960
There are some collaboration.

75
00:04:13,290 --> 00:04:16,280
There are some security requirements that were important for us.

76
00:04:16,519 --> 00:04:19,239
Another one is a lot of credentials managers,

77
00:04:19,680 --> 00:04:23,580
they use a user-generated passphrase or password

78
00:04:24,460 --> 00:04:26,640
as the main encryption key.

79
00:04:27,260 --> 00:04:31,340
And we know that letting people select the basis

80
00:04:31,640 --> 00:04:35,000
for their cryptographic keys is generally not a good idea.

81
00:04:35,140 --> 00:04:37,299
What you want is something that is truly random

82
00:04:37,840 --> 00:04:39,920
and something that people cannot remember.

83
00:04:40,530 --> 00:04:43,920
And so that's why we introduced that concept of having like a private key

84
00:04:44,380 --> 00:04:47,960
that is used to basically decrypt secret.

85
00:04:48,580 --> 00:04:55,340
So other password managers would generate that key by doing iteration,

86
00:04:55,550 --> 00:05:01,780
like a private key derivation function.

87
00:05:02,640 --> 00:05:05,900
And they will apply some rounds so that it's hard to brute force.

88
00:05:06,320 --> 00:05:08,640
But it's still something that is user generated.

89
00:05:09,150 --> 00:05:10,760
So it can still be phished.

90
00:05:10,830 --> 00:05:14,560
It can still be brute force, for example, on the login form.

91
00:05:15,240 --> 00:05:16,700
And that's what we wanted to avoid.

92
00:05:17,040 --> 00:05:20,420
So obviously, it creates some friction with usability.

93
00:05:21,800 --> 00:05:25,760
So it's not ideal that people have to have this private key.

94
00:05:25,810 --> 00:05:31,760
And if they lose this private key, then if they remember the passphrase to unlock the private key,

95
00:05:32,140 --> 00:05:37,500
basically they cannot access the solution unless they have shared that private key with a trusted

96
00:05:37,670 --> 00:05:42,260
party. There are different types of security requirements. So yeah, that's really like the

97
00:05:42,480 --> 00:05:45,420
DNA of the solution. I don't know if I'm talking like, like if it's clear or not.

98
00:05:46,300 --> 00:05:50,160
Yeah. So, I mean, there's definitely a lot there and I've been taking notes so we can

99
00:05:50,440 --> 00:05:55,200
kind of deep dive into some of these things. So I want to start by just maybe covering the basics

100
00:05:55,330 --> 00:06:01,439
of a password manager. And it's so to this day, would you say you're still more enterprise focused

101
00:06:01,460 --> 00:06:02,520
than end users?

102
00:06:03,380 --> 00:06:03,840
Yes, definitely.

103
00:06:04,180 --> 00:06:05,600
Because of these security requirements,

104
00:06:05,980 --> 00:06:08,900
it's like when you're on the end user side,

105
00:06:09,240 --> 00:06:10,480
like for personal usage,

106
00:06:10,720 --> 00:06:12,100
you want less friction

107
00:06:12,340 --> 00:06:13,580
and it's okay to have trade-off

108
00:06:13,620 --> 00:06:14,640
when it comes to security.

109
00:06:15,060 --> 00:06:17,100
You would want to have like maybe more privacy

110
00:06:17,940 --> 00:06:19,980
than say if you're in an enterprise space.

111
00:06:20,280 --> 00:06:21,180
Because if you're a bank,

112
00:06:21,280 --> 00:06:22,260
you want to know what's happening

113
00:06:22,420 --> 00:06:23,060
with the credential.

114
00:06:23,380 --> 00:06:25,380
When you're like a credential manager

115
00:06:25,580 --> 00:06:26,900
and you're serving like individuals,

116
00:06:27,240 --> 00:06:28,860
you want to have a guarantee as an individual

117
00:06:29,000 --> 00:06:30,339
that your password manager

118
00:06:30,360 --> 00:06:31,580
doesn't know what you're doing.

119
00:06:31,680 --> 00:06:32,780
So you can see already that

120
00:06:33,120 --> 00:06:34,320
even though it's password manager,

121
00:06:34,460 --> 00:06:36,460
there are very conflicting requirements,

122
00:06:36,660 --> 00:06:37,680
whether you're coming from business

123
00:06:37,960 --> 00:06:40,380
or whether you're coming from the personal space.

124
00:06:40,920 --> 00:06:43,140
And so we choose to go that side

125
00:06:43,640 --> 00:06:44,900
instead of trying to do everything,

126
00:06:45,040 --> 00:06:46,920
you know, because it's really hard to do everything.

127
00:06:47,760 --> 00:06:49,560
And so what are the kind of the,

128
00:06:50,560 --> 00:06:52,340
you know, what's a typical customer

129
00:06:52,620 --> 00:06:54,880
before we deep dive into some more of this stuff?

130
00:06:55,000 --> 00:06:57,700
Is it small businesses, big businesses, governments?

131
00:06:58,380 --> 00:07:01,060
Who do you see getting the most value out of something like this?

132
00:07:01,700 --> 00:07:22,880
It applies to a lot of businesses, but the sweet spot for us is people that are, I would say, interested in the security posture that we are proposing, as well as things like the ability to self-host or that have a need to organize credential at a very granular level with fine-grained permissions.

133
00:07:23,680 --> 00:07:37,980
And so this tends to be organizations that are small or large, but that are privacy conscious or like that have certain appetite for fixing some of this risk or fixing some of the issues that I talked about.

134
00:07:38,800 --> 00:07:41,540
Yeah. And so, you know, let's say I'm a business owner, right?

135
00:07:41,720 --> 00:07:43,760
Like I have various options to choose from.

136
00:07:43,920 --> 00:07:47,880
There's just not using a password manager and kind of just hoping for the best in the world.

137
00:07:48,500 --> 00:07:52,820
I think most of our audience might know the issues with that, but maybe we can still touch on that a little bit.

138
00:07:52,900 --> 00:07:57,860
Then there's maybe going with a more mainstream enterprise solution.

139
00:07:58,540 --> 00:08:09,140
I'm thinking, I believe like Nord, who has NordVPN, is run by NordSec, who has been moving into more enterprise direction, and they have more of those tools now.

140
00:08:09,700 --> 00:08:13,920
Then we have like probably 1Password, Bitwarden, et cetera.

141
00:08:15,360 --> 00:08:19,620
And then we have kind of you guys who also allow the ability to self-host and all these things.

142
00:08:19,700 --> 00:08:22,260
So what are kind of the general pros and cons of these different approaches?

143
00:08:22,560 --> 00:08:29,200
If you were to kind of break down why someone might go for a specific one and how you guys position yourself in kind of that space.

144
00:08:30,200 --> 00:08:30,400
Yes.

145
00:08:30,900 --> 00:08:39,560
So it's and also we are not the end all of, you know, so if your organization is super mature and very advanced, we might not be a right fit for you.

146
00:08:39,680 --> 00:08:43,539
So I was not trying to present us as, OK, we are the most, you know, secure, most mature.

147
00:08:44,080 --> 00:08:46,920
It's just like to explain like a little bit where we position ourselves.

148
00:08:47,640 --> 00:08:53,760
Like you have personal credential manager, like typically the one built in in your OS or your browser.

149
00:08:54,370 --> 00:08:58,860
And if you're a small business owner, this is perfectly acceptable way of handling your credential.

150
00:08:59,100 --> 00:09:00,040
It's better than nothing.

151
00:09:00,800 --> 00:09:03,000
And it's actually way better than nothing.

152
00:09:03,240 --> 00:09:04,720
It's a proper solution.

153
00:09:05,520 --> 00:09:12,500
And then you have like, if you want to start having like a little bit of collaboration, but your team is small and you don't have like very complex requirements.

154
00:09:13,000 --> 00:09:22,680
And you also want to be more on the, I want a low friction, low barrier of entry, and I'm okay to accept this risk that come with that low friction.

155
00:09:23,060 --> 00:09:28,660
Then you can go for solutions that have came from that personal space and that have developed business solutions.

156
00:09:28,920 --> 00:09:35,960
And then if you evolve and you want to use it as a beginning of doing access privilege management,

157
00:09:36,360 --> 00:09:40,620
and you want to have like more fine-grained tuning

158
00:09:40,760 --> 00:09:41,900
of who can access what,

159
00:09:41,920 --> 00:09:44,500
make sure that there's a least privilege enforced

160
00:09:44,800 --> 00:09:46,080
at your organization,

161
00:09:46,840 --> 00:09:49,620
then you can start like going for a solution like PassBolt.

162
00:09:49,680 --> 00:09:51,600
And then after that, you will, you know,

163
00:09:51,900 --> 00:09:54,580
go into more complex spam solutions and all that,

164
00:09:54,600 --> 00:09:56,580
that if you like really large enterprise

165
00:09:58,100 --> 00:09:59,080
with a lot of use cases.

166
00:09:59,680 --> 00:10:02,160
- And why, you know, 'cause I feel like

167
00:10:02,520 --> 00:10:04,660
if someone's starting a business, you know,

168
00:10:04,760 --> 00:10:08,260
you get like a how to start a business book, you go to business school. Business school is

169
00:10:08,420 --> 00:10:13,100
interesting because I feel like part of the point of business is to be, is to, you know, insert

170
00:10:13,300 --> 00:10:17,600
something new into the market. And it's kind of hard to get that from something like school. It's

171
00:10:17,680 --> 00:10:23,620
a whole side tangent. And it's weird. But my point is, there's no like right way to do business. And

172
00:10:23,940 --> 00:10:29,959
if you try to go through traditional resources, password management and security isn't really a

173
00:10:29,980 --> 00:10:36,140
part of that discussion for a company. So what are kind of the attacks that you guys see and how

174
00:10:36,840 --> 00:10:41,180
might, yes, a password manager help in these attacks, but why should someone even care in the

175
00:10:41,200 --> 00:10:45,100
first place if they're just trying to get their business done? They want to get a product out

176
00:10:45,220 --> 00:10:51,820
there. Why should they put any attention to the security stuff? Most of the attacks and like the

177
00:10:51,920 --> 00:10:57,759
scenarios that are covered by a password manager are like unsophisticated attacks. So typically it

178
00:10:57,780 --> 00:10:59,760
would be like things like phishing.

179
00:11:00,310 --> 00:11:02,700
Like, so basically you receive a link

180
00:11:03,000 --> 00:11:04,240
that looks like a legitimate email.

181
00:11:04,410 --> 00:11:06,740
You go to an app that looks like the login app

182
00:11:06,860 --> 00:11:08,520
and you just log in in that because you're tired

183
00:11:08,740 --> 00:11:10,740
and you're like you have 10,000 things to do.

184
00:11:10,750 --> 00:11:13,420
You don't really check the emails, the URL,

185
00:11:13,930 --> 00:11:16,780
the URL lookalike, but you don't pay attention

186
00:11:16,910 --> 00:11:18,660
and boom, basically like you got phished

187
00:11:19,200 --> 00:11:22,420
and that person have access to the credential for that site.

188
00:11:23,020 --> 00:11:25,099
So let's say you don't have to have a in place

189
00:11:25,120 --> 00:11:30,740
that service then it starts becoming complicated and you'll have to to deal with that breach that's

190
00:11:30,980 --> 00:11:36,740
one issue another issue is that if people don't use anything they will tend to reuse predictable

191
00:11:37,260 --> 00:11:43,160
passwords or like reuse the same everywhere so typically uh you know the name of the service at

192
00:11:43,880 --> 00:11:49,999
the the year but they sign up for the service or like come up with this like what they think are

193
00:11:50,020 --> 00:11:56,480
like very clever combinations but that you know i've been analyzed for years by by attackers

194
00:11:57,300 --> 00:12:02,580
using like breached uh breached data what you want is to protect yourself from these basic

195
00:12:03,180 --> 00:12:08,460
sort of attack you know like it's it's it's it's just normal hygiene the same way like you

196
00:12:09,100 --> 00:12:12,560
clean your hand you know so that you don't get disease this is kind of like

197
00:12:13,540 --> 00:12:19,980
automated thing that you should be doing at that stage because if you don't do it it's it's gonna

198
00:12:20,000 --> 00:12:24,760
to you for sure. And so password managers, they really help you with this. So for example, you go

199
00:12:24,800 --> 00:12:29,840
on a site, it will suggest, hey, do you want to feel that credential for that site? With Passable,

200
00:12:29,960 --> 00:12:35,080
for example, if that URL do not match the entry that you have in the Passable database,

201
00:12:35,540 --> 00:12:39,800
it will not suggest it. So you will already feel that there's something fishy because like you'll

202
00:12:39,800 --> 00:12:44,100
be like, how come Passable is not suggesting the credential for that site? And they will give you

203
00:12:44,200 --> 00:12:47,899
like some hints and then it will generate passwords for you. So it will generate like

204
00:12:47,920 --> 00:12:53,040
truly random and strong passwords that you don't even have to type anymore. If you are a business

205
00:12:53,180 --> 00:12:57,620
owner, like you should definitely do this. And like, for example, even you're in your family,

206
00:12:57,830 --> 00:13:02,120
if you have maybe like people that are a little bit older, they are not doing that yet. It's very

207
00:13:02,460 --> 00:13:07,560
easy now to like hold them out, even just like if they are using an iPhone, then, you know,

208
00:13:07,740 --> 00:13:12,200
just set them up with the basic password manager on an iPhone. It's really important that people

209
00:13:12,680 --> 00:13:16,720
get up to speed with this because it just makes their life easier as well, you know?

210
00:13:17,220 --> 00:13:23,880
Yeah. I want to ask about your guys' business model because you're open source. And always

211
00:13:24,060 --> 00:13:27,980
important to ask how open source projects make money. My understanding is that you offer to,

212
00:13:28,340 --> 00:13:32,600
like if I'm an organization and I want to get going on a password manager that's got good

213
00:13:32,800 --> 00:13:37,400
security, has good permissioning, gives me the stuff. I can roll that over in-house and I can

214
00:13:37,460 --> 00:13:41,120
self-host it. And then you guys theoretically get nothing from that, from what I understand,

215
00:13:41,420 --> 00:13:46,320
but maybe I'm wrong because that's just my idea. And then you probably offer a managed solution.

216
00:13:46,420 --> 00:13:48,420
So do you want to kind of break this down for me?

217
00:13:48,560 --> 00:13:48,720
Yeah.

218
00:13:49,400 --> 00:13:50,840
So we have three versions of Passbolt.

219
00:13:51,160 --> 00:13:54,920
We have the community edition, which is free as in freedom and free beer.

220
00:13:55,460 --> 00:13:58,020
So basically you can get started.

221
00:13:58,170 --> 00:14:02,080
We have packages for all major Linux distribution and you self-host.

222
00:14:02,420 --> 00:14:09,420
And then you have Passbolt Pro edition, which is the same similar code base than Passbolt

223
00:14:09,470 --> 00:14:11,200
Community Edition with some additional plugins.

224
00:14:11,370 --> 00:14:13,540
And that requires a subscription.

225
00:14:13,960 --> 00:14:19,440
like so you will be prompted to enter a subscription key when you use it so the software is free as in

226
00:14:19,580 --> 00:14:24,960
freedom but not as in free beer so it's it's uh it's an important distinction so there is a price

227
00:14:25,200 --> 00:14:31,740
attached to it and then we finally we have the the latest uh which option which is uh cloud so it's

228
00:14:31,980 --> 00:14:37,300
we host it for you so it's basically passable pro but hosted by us and we have some other options

229
00:14:37,420 --> 00:14:41,719
so for example if you are a bank and you work in like regulated environment we also work with

230
00:14:42,060 --> 00:14:48,680
with other partners to provide you with a fully managed solution that match your legal requirements.

231
00:14:49,280 --> 00:14:55,880
So for example, if you want like bank approved hosting environment of Passport Managed with like 24-7 support,

232
00:14:56,020 --> 00:14:57,940
then we do that through partners.

233
00:14:58,540 --> 00:15:03,520
So what's someone missing if they just download the free community edition and they just start using that?

234
00:15:04,320 --> 00:15:08,280
So they will have access to most of the functionality, so sharing groups.

235
00:15:09,700 --> 00:15:34,720
So what would be missing is the productivity features such as policies, like I want to enforce certain policy on the application, like my password needs to be like this, or users are required to sign up for MFA, or I want to have them place their private key in escrow with me so that I can decrypt their content in case they leave the organization or they lose access to their stuff.

236
00:15:35,160 --> 00:15:46,540
So, for example, these kind of requirements, they come from more larger organizations that have requirements that come from their local law or the way they operate.

237
00:15:47,200 --> 00:15:56,680
And so, they will have access to things like LDAP sync or these kind of features that if you're like 20 users, it's okay to invite everybody manually.

238
00:15:56,790 --> 00:16:00,740
But if you have like 500 users, you're not going to want to do that manually.

239
00:16:01,200 --> 00:16:06,560
So these are the functionalities like productivity for the administrator that are part of the paid version.

240
00:16:06,740 --> 00:16:12,720
So this is pretty much how we make the distinction between what goes into the community edition and the pro edition.

241
00:16:13,840 --> 00:16:16,320
Got it. And so this is obviously for larger companies.

242
00:16:16,560 --> 00:16:23,520
And, you know, for us internally, we're just going to use something simple, like you were saying earlier, because we're very small.

243
00:16:24,240 --> 00:16:30,980
But what kind of organizations are going to be self-hosting this on their own versus just paying you guys to host it for them?

244
00:16:31,410 --> 00:16:36,580
Do you find that like really big companies want to self-host it or do the really big companies want to outsource it?

245
00:16:37,000 --> 00:16:39,580
Or is it the inverse or is it kind of just depending on the company?

246
00:16:41,160 --> 00:16:49,040
This is where it gets interesting is like 75% of our customers are using the self-hosted version,

247
00:16:49,500 --> 00:16:54,180
which is not what you would see in other businesses.

248
00:16:54,920 --> 00:16:58,440
And I know that there have been a big move for people to go to the cloud,

249
00:16:58,940 --> 00:17:01,460
but we, like, basically someone else's computer,

250
00:17:01,920 --> 00:17:04,620
and we are seeing now this reverse trend.

251
00:17:06,620 --> 00:17:09,920
Do you think it's because of global politics and digital sovereignty?

252
00:17:10,740 --> 00:17:15,260
Partly because of that, but even before world leaders

253
00:17:15,430 --> 00:17:17,060
starting being a little bit more erratic,

254
00:17:17,360 --> 00:17:24,760
there was already some concern around trusting cloud providers with the crown jewels.

255
00:17:25,420 --> 00:17:27,819
So let's say you're a government.

256
00:17:28,390 --> 00:17:30,780
Do you trust an American company?

257
00:17:30,810 --> 00:17:36,660
Or do you trust even a Luxembourg company to host your most important secret?

258
00:17:37,130 --> 00:17:38,839
And so for a solution like Passport,

259
00:17:39,890 --> 00:17:43,400
it makes sense that this is one of the few things you want to self-host.

260
00:17:44,120 --> 00:17:49,540
like your encryption key, your passwords, like they become like really like something people value.

261
00:17:49,780 --> 00:17:57,180
And now this trend we've seen have accelerated. So we see like even like medium sized company are also interested in this.

262
00:17:57,180 --> 00:18:03,860
And we have a lot of small businesses that start with self-hosted and then they realize that it's too much work for them.

263
00:18:03,940 --> 00:18:09,980
And then they want to move to Passbook Cloud, for example. So this we've seen like all sorts of trends there.

264
00:18:10,120 --> 00:18:26,860
And governments, for sure, they want to self-host, but also like large organization industries that work in, you know, sensitive things like energy sector also is like, you know, they use solutions that are not connected to the Internet because it's critical infrastructure.

265
00:18:27,060 --> 00:18:27,880
They have their own network.

266
00:18:28,660 --> 00:18:30,640
Their network is not connected to the Internet.

267
00:18:31,040 --> 00:18:34,880
So then it makes sense that, you know, a solution like PassBolt is something that you want to use.

268
00:18:35,100 --> 00:18:37,040
We also have like small businesses.

269
00:18:37,180 --> 00:18:39,940
I don't know, like it becomes like a cultural thing.

270
00:18:40,000 --> 00:18:45,280
Like in, for example, in Germany, people are more privacy conscious than, say, other places.

271
00:18:45,620 --> 00:18:51,240
And so they would prefer if they have the choice, if they have the option and the option is good, they will choose that option.

272
00:18:52,940 --> 00:18:58,520
Got it. And a pattern I've noticed, and maybe this is changing and maybe it's a generalization that's not accurate,

273
00:18:58,760 --> 00:19:03,740
but I hear a lot about how the execs in the boardrooms,

274
00:19:04,160 --> 00:19:15,840
They're more likely almost a lot of times to go for a technology that is being sold to them as some proprietary, flashy, black box technology.

275
00:19:16,020 --> 00:19:22,680
Only we have the ability to do this and we keep it, you know, we offer you this exclusive service, proprietary.

276
00:19:22,940 --> 00:19:27,740
I feel like proprietary technology for end users is seen as almost a negative thing.

277
00:19:28,020 --> 00:19:31,420
But for some businesses, it's seen as a positive thing or at least more neutral.

278
00:19:33,260 --> 00:19:36,600
So how do you kind of approach that as an open source organization?

279
00:19:36,850 --> 00:19:38,220
Do you think that's a positive?

280
00:19:38,890 --> 00:19:41,560
Do you think some businesses see it as a negative almost?

281
00:19:41,730 --> 00:19:44,020
Are they like, well, does that mean it's less secure?

282
00:19:45,040 --> 00:19:46,860
Does that mean that this isn't as good as it could be?

283
00:19:47,000 --> 00:19:48,220
Is this kind of a friction point?

284
00:19:48,230 --> 00:19:50,740
Because I could see it potentially being a friction point,

285
00:19:50,750 --> 00:19:52,580
or maybe I'm just making things up.

286
00:19:54,120 --> 00:19:56,580
I think there's a cultural component to it.

287
00:19:57,120 --> 00:20:00,240
So some organizations may not have this culture and it's complicated,

288
00:20:00,340 --> 00:20:03,160
and we have a fit with organizations

289
00:20:04,200 --> 00:20:07,580
that believe that openness is required for security.

290
00:20:08,120 --> 00:20:10,080
So if they believe the opposite,

291
00:20:10,130 --> 00:20:11,800
I don't see them because they don't come to us.

292
00:20:12,280 --> 00:20:14,340
So I see people that are enthusiastic

293
00:20:14,640 --> 00:20:15,640
about the thing being open.

294
00:20:16,140 --> 00:20:17,460
And I think on the long term,

295
00:20:17,680 --> 00:20:20,160
people see the advantages of it.

296
00:20:20,380 --> 00:20:23,240
For example, when we do audits

297
00:20:23,470 --> 00:20:25,260
and we do audits several times per year,

298
00:20:25,760 --> 00:20:26,860
then people can see the fixes.

299
00:20:27,140 --> 00:20:29,219
They can see if we do the fixes or not

300
00:20:29,260 --> 00:20:30,960
or how much time it takes to do the fixes.

301
00:20:31,740 --> 00:20:36,500
And we published our audits and our reports unchanged,

302
00:20:36,960 --> 00:20:41,400
so people can actually see what we are prioritizing.

303
00:20:41,780 --> 00:20:46,920
And this transparency goes beyond the code itself.

304
00:20:47,520 --> 00:20:50,439
Because if I give you the code and the code is just mangled

305
00:20:51,020 --> 00:20:52,840
in a way that it's not human digestible,

306
00:20:54,020 --> 00:20:58,480
or if nobody's looking at it, then what's the point of it being open?

307
00:20:58,600 --> 00:21:06,700
you know so there is also the the component of making it this accessible to people so that they

308
00:21:06,840 --> 00:21:12,200
can make the right choices and understand okay this security risk is covered this security is

309
00:21:12,300 --> 00:21:16,700
risk is not covered and they don't have so much this option with with closed source software

310
00:21:16,900 --> 00:21:23,459
because they don't know like okay what were the arbitration done you know like uh did they choose

311
00:21:23,480 --> 00:21:26,800
to place the cursor more on usability or more on security?

312
00:21:27,180 --> 00:21:30,880
Or did they manage to find a new technique that solve it for both?

313
00:21:31,060 --> 00:21:31,940
And you don't see that.

314
00:21:32,320 --> 00:21:34,260
So you just have to take their word for it.

315
00:21:34,420 --> 00:21:37,660
Now I can see more and more people doing their homework and they want to see,

316
00:21:37,820 --> 00:21:40,840
like, okay, explain to me how it works and tell me about the risk.

317
00:21:41,040 --> 00:21:43,920
And tell me about the risk that you are not covering.

318
00:21:44,380 --> 00:21:44,720
All right.

319
00:21:44,820 --> 00:21:49,620
So I'm going to pivot now a bit more into kind of features and overall the usability

320
00:21:49,820 --> 00:21:50,700
and what that looks like.

321
00:21:50,840 --> 00:21:53,040
And then we can do a quick security deep dive.

322
00:21:53,240 --> 00:21:55,640
and I have a few personal questions for you.

323
00:21:55,960 --> 00:21:57,740
I wanted to start by asking,

324
00:21:58,180 --> 00:22:01,000
because you guys seem to be like a very dedicated solution.

325
00:22:01,340 --> 00:22:03,720
You are offering password management

326
00:22:04,700 --> 00:22:05,860
to predominantly organizations,

327
00:22:06,360 --> 00:22:07,620
but also to the community as well.

328
00:22:09,580 --> 00:22:11,460
There's this trend that I see a lot,

329
00:22:11,520 --> 00:22:14,660
especially with more proprietary-oriented companies.

330
00:22:15,800 --> 00:22:16,860
I don't mind using it,

331
00:22:16,860 --> 00:22:19,120
because there's not necessarily a negative aspect

332
00:22:19,220 --> 00:22:19,940
to this necessarily.

333
00:22:20,140 --> 00:22:22,220
I think NordSec is a good example of this,

334
00:22:22,320 --> 00:22:23,480
where they're trying to build a whole suite.

335
00:22:23,680 --> 00:22:26,980
Like there's the password manager, there's the VPN,

336
00:22:27,780 --> 00:22:30,400
there's, I think they have data removal at this point.

337
00:22:30,540 --> 00:22:31,540
This is for their end user,

338
00:22:31,680 --> 00:22:33,260
but then their enterprise product,

339
00:22:33,380 --> 00:22:34,840
I think also has a lot in it.

340
00:22:35,680 --> 00:22:37,760
Do you see this as a disadvantage for you guys?

341
00:22:37,960 --> 00:22:40,680
Like, are you looking to expand, you know,

342
00:22:40,820 --> 00:22:43,060
Passbuilt to be a bit more than just a password manager?

343
00:22:43,240 --> 00:22:45,360
Or do you think that just a narrow focus

344
00:22:45,980 --> 00:22:47,020
to just do that one thing

345
00:22:47,060 --> 00:22:49,340
is kind of the right approach for you guys?

346
00:22:50,000 --> 00:22:51,960
I think it depends on how much resources you have.

347
00:22:52,240 --> 00:22:55,700
So like, I'll be, I'll be frank, like we are like 50 people.

348
00:22:55,960 --> 00:23:00,180
So, and we have not raised like in hundreds of millions in capital.

349
00:23:00,460 --> 00:23:02,960
So obviously we cannot compete everywhere.

350
00:23:03,410 --> 00:23:05,720
So we have to choose like where we want to be good at.

351
00:23:06,340 --> 00:23:08,200
And it's a very competitive landscape.

352
00:23:08,440 --> 00:23:12,880
So like you, if you want to stay competitive, you cannot just do 20 things poorly.

353
00:23:12,930 --> 00:23:14,360
You need to be good at something.

354
00:23:15,180 --> 00:23:17,140
So that's the way we are approaching it.

355
00:23:17,680 --> 00:23:22,100
So we are still working on like improving the product to the point where like we,

356
00:23:22,200 --> 00:23:31,020
are satisfied with like where we are and but we still plan to support like more use cases that are

357
00:23:31,120 --> 00:23:37,040
like related to credential management and there's there's quite a bit so like our goal is to keep

358
00:23:37,200 --> 00:23:43,860
doing what the users are requesting and um i don't think they will stop asking for things

359
00:23:44,560 --> 00:23:49,039
at any point but we try to have this feedback loop of like building what people are asking for

360
00:23:49,640 --> 00:23:57,880
and since we are not you know building extremely fast then we we we get to to see on the long term

361
00:23:58,080 --> 00:24:02,640
what are the trends and like what's you know what's important for people what is recurring

362
00:24:03,240 --> 00:24:07,920
what is coming from the customer what is coming from the the community what is coming internally

363
00:24:08,200 --> 00:24:15,119
on what people want to work on and like yeah and so what are some of like the requested features

364
00:24:15,140 --> 00:24:17,400
that you guys get that are the most frequent?

365
00:24:17,900 --> 00:24:19,820
A lot of the things that we just delivered.

366
00:24:21,299 --> 00:24:30,000
So recently, we did a major revamp of the architecture with Passable v5,

367
00:24:30,210 --> 00:24:33,040
and now we are able to add some new resource types.

368
00:24:33,040 --> 00:24:37,520
So our goal is for people to be able to create multiple resource types

369
00:24:37,880 --> 00:24:41,360
and be able to compose different types of credentials.

370
00:24:41,540 --> 00:24:47,700
So, for example, a password with a TOTP or a secure note with a list of custom fields.

371
00:24:48,450 --> 00:24:56,900
And so we try to continue going in that direction, like having secure notes, having all sorts of properties that people can add to credential and compose them.

372
00:24:57,540 --> 00:25:01,320
And so we will continue going in that direction for some time.

373
00:25:01,600 --> 00:25:04,160
People are asking a lot, for example, about file attachment.

374
00:25:04,900 --> 00:25:07,820
But, you know, you don't want to become like a drive.

375
00:25:08,090 --> 00:25:09,860
So it's kind of like a fine line.

376
00:25:10,140 --> 00:25:11,940
They are like...

377
00:25:12,240 --> 00:25:13,460
That's a whole other ballgame.

378
00:25:13,880 --> 00:25:16,880
Yes, it's a very different storage of credentials

379
00:25:17,080 --> 00:25:17,940
and storage of files,

380
00:25:18,200 --> 00:25:19,960
like totally different beast.

381
00:25:20,400 --> 00:25:21,820
So we have to be careful

382
00:25:21,940 --> 00:25:23,020
on how we approach these things

383
00:25:23,140 --> 00:25:25,180
so that they have the right expectations

384
00:25:25,460 --> 00:25:25,880
and so on.

385
00:25:26,000 --> 00:25:28,720
Like, okay, you want to attach a certificate?

386
00:25:29,000 --> 00:25:29,420
Yeah, that's fine.

387
00:25:29,420 --> 00:25:30,460
You want to attach a movie?

388
00:25:30,640 --> 00:25:31,280
Maybe not.

389
00:25:33,520 --> 00:25:37,480
So do you guys support integrations?

390
00:25:37,820 --> 00:25:39,179
I know this is more of...

391
00:25:39,940 --> 00:25:46,680
it's funny this is definitely more of an end user regular consumer feature but i actually think it's

392
00:25:46,720 --> 00:25:50,200
very useful for business and maybe i think it's going to catch up to the business world eventually

393
00:25:50,440 --> 00:25:56,360
but aliasing services for emails um so that way yeah is that something you guys support or so

394
00:25:56,840 --> 00:26:01,320
typically this is this is something like which i believe falls in the realm of personal password

395
00:26:01,480 --> 00:26:06,359
management it's what i was saying at the beginning like you want full privacy and you you don't want

396
00:26:06,380 --> 00:26:09,040
the service to know about what is your username.

397
00:26:09,480 --> 00:26:13,840
In the enterprise world, you want to know which username people are using.

398
00:26:13,900 --> 00:26:20,060
I don't want to see the logs in my security operation center of random emails and not being

399
00:26:20,200 --> 00:26:22,160
able to link them to actual users.

400
00:26:22,540 --> 00:26:26,700
So it doesn't like these two things are like maybe there are some scenario in enterprise

401
00:26:26,800 --> 00:26:30,060
where you would want that, but like most of the time, not so much.

402
00:26:30,660 --> 00:26:35,000
Like people are more interested in like having integration with CM, for example.

403
00:26:35,580 --> 00:26:46,420
Can you send me alerts in real time so that I can analyze behaviors and link them to other behaviors that are happening on other services?

404
00:26:46,510 --> 00:26:52,480
They are more interested in these kind of scenarios than, okay, can you make my users anonymous?

405
00:26:52,780 --> 00:26:54,220
It's more like the other way around.

406
00:26:54,220 --> 00:27:02,240
They want to praise them to understand behavior and see if there are patterns that don't make sense.

407
00:27:03,620 --> 00:27:08,460
Got it. And how have you seen adoption for things like passkeys in the enterprise world?

408
00:27:08,500 --> 00:27:11,280
Are they embraced? Are they seen as not good?

409
00:27:13,180 --> 00:27:16,400
So the passkey is pretty vast subject.

410
00:27:16,580 --> 00:27:23,460
And it's one credential that I believe like have a lot of like this is basically the future and like this will happen.

411
00:27:24,080 --> 00:27:28,720
The speed at which it will happen is like it will be like IPv6 or I don't know.

412
00:27:30,580 --> 00:27:32,140
They might take a while.

413
00:27:32,740 --> 00:27:36,320
But I can see people are intrigued.

414
00:27:36,960 --> 00:27:40,460
And this is one of the top things that people have requested for Passport.

415
00:27:40,600 --> 00:27:43,460
And this is one of the things we are committed on working on.

416
00:27:43,640 --> 00:27:45,360
We are actually part of the feed-o-a-land.

417
00:27:45,530 --> 00:27:54,960
So we are seeing how is the RFC evolving and how does it integrate in the browser, for example.

418
00:27:55,460 --> 00:27:58,720
How can we exchange passkeys between credential managers.

419
00:27:59,600 --> 00:28:10,120
And our strategy had been to wait a little bit until the dust settled when it comes to specification, because there is the specification and there is the implementation by Google, Microsoft and all that.

420
00:28:10,120 --> 00:28:11,200
And that becomes the standard.

421
00:28:11,950 --> 00:28:17,620
So it's like you want to see like, OK, of the whole standard, like which part is actually the standard.

422
00:28:18,400 --> 00:28:24,240
So we are kind of like waiting a little bit to see like, OK, what's where are we like on that front?

423
00:28:24,940 --> 00:28:29,820
And now we are like, for example, the mobile experience, I think is pretty much there.

424
00:28:30,440 --> 00:28:35,740
The browser experience is still a bit like, depends on the browser and depend on the OS.

425
00:28:35,880 --> 00:28:44,640
And so for me, it's not ideal that you have like an experience that shifts so much that if you use Edge or Chrome, then you're going to have a different experience.

426
00:28:44,760 --> 00:28:48,380
I don't think that's good for the end user, especially with new technology.

427
00:28:48,900 --> 00:28:53,819
But I think it's going to go there at some point that, you know, there would be like a more unified perception.

428
00:28:54,180 --> 00:28:57,460
Is that because of Manifest V3 by any chance?

429
00:28:58,240 --> 00:29:00,040
Manifest V3, no, it's a separate topic.

430
00:29:00,760 --> 00:29:06,520
Manifest V3 is more like the underlying format for Chrome extensions.

431
00:29:07,280 --> 00:29:07,540
Got it.

432
00:29:07,660 --> 00:29:10,620
So that doesn't influence your ability to develop.

433
00:29:11,060 --> 00:29:11,640
Okay, cool.

434
00:29:11,740 --> 00:29:17,180
So the way the browser works at the moment when you do like passkeys,

435
00:29:17,460 --> 00:29:20,800
it uses some API like the credential API.

436
00:29:21,820 --> 00:29:23,760
And that then talks to your browser.

437
00:29:24,260 --> 00:29:32,560
And so if your browser extension, you can basically replace that JavaScript API with your own stuff that will talk to the extension.

438
00:29:32,680 --> 00:29:41,560
But if there are several providers and they are all doing that, then it becomes not clear who's adjacking the most the credential API.

439
00:29:41,560 --> 00:29:50,120
And you would want to have some form of agreement that if several people want to do that, then this is how you do it so that for the user it's clear.

440
00:29:50,600 --> 00:29:53,380
Let's say I'm using Dashlane and Passbolt.

441
00:29:53,510 --> 00:29:56,380
So Dashlane for personal use and Passbolt in my company.

442
00:29:57,080 --> 00:30:02,220
And I have passkeys for Gmail, like my personal one in Dashlane,

443
00:30:02,630 --> 00:30:04,620
my professional one in Passbolt.

444
00:30:04,730 --> 00:30:07,040
You want us to play nice with each other.

445
00:30:07,520 --> 00:30:09,680
Basically, we're like, okay, do you want to use which one?

446
00:30:10,180 --> 00:30:15,240
And not like, okay, I nuke Dashlane out of existence and you only use mine.

447
00:30:15,860 --> 00:30:20,280
And the OS level, sometimes they are a bit brutal like that.

448
00:30:20,420 --> 00:30:21,340
They're like, okay, we're Google.

449
00:30:22,840 --> 00:30:25,160
It's a Chrome browser, so you want to use our stuff.

450
00:30:26,560 --> 00:30:34,220
I think there needs to inevitably be some way to select and disable passkey options on devices.

451
00:30:34,330 --> 00:30:36,160
Because right now it happens with me.

452
00:30:37,500 --> 00:30:43,220
I figured out some workarounds, but if I'm going into a website, I use ProtonPass as the extension, right?

453
00:30:43,250 --> 00:30:44,940
And then it's like, oh, login.

454
00:30:45,240 --> 00:30:47,540
I accidentally, I don't use passkeys too often, actually.

455
00:30:47,630 --> 00:30:49,680
I normally use passwords and I use my YubiKey.

456
00:30:50,580 --> 00:30:52,260
but I don't use proper passkeys

457
00:30:52,860 --> 00:30:54,280
and it'll be like, oh, log in

458
00:30:54,530 --> 00:30:56,280
but I'll accidentally click the passkey button

459
00:30:56,390 --> 00:30:58,520
this time around and then ProtonPass

460
00:30:58,680 --> 00:31:00,360
comes out and it's like, oh, no passkey

461
00:31:00,510 --> 00:31:01,460
found and I say, oh, ignore.

462
00:31:02,260 --> 00:31:04,240
And then the Brave browser automatically comes up

463
00:31:04,400 --> 00:31:06,240
next and it says, oh,

464
00:31:06,420 --> 00:31:08,160
no passkey found and I click, ah, shoot

465
00:31:08,300 --> 00:31:10,380
and I click cancel and then like the OS

466
00:31:10,680 --> 00:31:12,520
comes up and it goes, oh, no passkey

467
00:31:12,690 --> 00:31:14,400
found and I click cancel. So there's like three

468
00:31:14,660 --> 00:31:16,780
people who get pinged

469
00:31:17,000 --> 00:31:18,439
to see if they have a passkey

470
00:31:18,960 --> 00:31:24,800
and I think that that's kind of like demonstrating exactly so it's it's frustrating um and I think

471
00:31:24,920 --> 00:31:28,940
that'll be figured out over time so it's good you guys thinking about that like in field alliance

472
00:31:29,160 --> 00:31:33,920
this is I think it's a big topic and like um like the thing is like people would have different views

473
00:31:33,970 --> 00:31:37,740
on that so you need to find consensus and all that but I think it would get it would definitely

474
00:31:37,890 --> 00:31:43,339
get better it's already getting better since like last three years you know like at the beginning

475
00:31:43,360 --> 00:31:49,860
there was like the the ux was uh changing also a lot because they were learning and so it's it's

476
00:31:49,920 --> 00:31:54,740
also complicated for users like if every time you log in with a passkey the the experience changes

477
00:31:54,900 --> 00:32:02,740
because you're fixing it at the same time it's also like uh you know confusing so and so with the

478
00:32:02,980 --> 00:32:11,019
passkeys do you think that's a good microcosm for just your overall approach because most you know

479
00:32:11,040 --> 00:32:15,700
ProtonPass, Bitwarden, all these mainstream password managers aimed at consumers.

480
00:32:16,660 --> 00:32:18,920
Passkeys is like a priority one thing.

481
00:32:19,000 --> 00:32:20,180
Like this is a new technology.

482
00:32:20,440 --> 00:32:22,800
People expect it from us and they rush it out.

483
00:32:23,660 --> 00:32:25,940
And it's well received by the community.

484
00:32:27,080 --> 00:32:29,020
You guys are like, okay, this is way too early.

485
00:32:29,380 --> 00:32:30,580
Like we need to wait.

486
00:32:30,680 --> 00:32:32,500
We need to see, we need to make sure we do it right.

487
00:32:33,400 --> 00:32:38,300
So do you think that there is a speed difference in terms of features because of the different clientele that you're serving?

488
00:32:39,440 --> 00:32:39,680
Yes.

489
00:32:39,760 --> 00:32:44,640
and also like resources you know it's like to be completely transparent like it's what i was saying

490
00:32:44,760 --> 00:32:50,160
you know like you have like like companies in the us that raise like in several hundreds of millions

491
00:32:50,740 --> 00:32:56,280
obviously they kind of get it out of the door uh faster than us and that's all right that's you

492
00:32:56,280 --> 00:33:02,920
know that's part of the of like being the first mover or not and uh well we are like you know

493
00:33:03,260 --> 00:33:08,599
we're still participating we're still looking at what's happening and and our goal is is just like

494
00:33:08,760 --> 00:33:13,740
our advantage is basically being the last to do it. We can like take the good part, see how people

495
00:33:13,900 --> 00:33:18,780
have done it and see like which, which part works well, you know? So we have this, this, uh, this

496
00:33:18,840 --> 00:33:25,140
advantage of not having to maintain, uh, things that, you know, like have not worked. So it's,

497
00:33:25,340 --> 00:33:29,440
there's like a disadvantage, but also there are some, some advantages to that.

498
00:33:30,480 --> 00:33:33,520
Got it. And then do you guys support TOTP natively in your password?

499
00:33:33,600 --> 00:33:33,840
Yes.

500
00:33:35,280 --> 00:33:45,380
And what are kind of, you know, if an organization, you know, starts using you guys, they might inevitably ask, oh, should we be using TOTP within your app?

501
00:33:45,560 --> 00:33:48,620
Is that safe enough or should we be using a dedicated solution?

502
00:33:48,680 --> 00:33:54,860
Do you guys offer a dedicated solution or do you have something else you can recommend them if they want even more security with that separation?

503
00:33:56,620 --> 00:33:59,320
So the good answer is it depends.

504
00:34:00,740 --> 00:34:07,880
I would say, like, I've answered that question, like, pretty extensively, like, on the community forum, because it comes back every now and again.

505
00:34:08,320 --> 00:34:15,720
It really depends on what is your posture, like, your risk scenarios and, like, what is important for you or not.

506
00:34:15,919 --> 00:34:20,899
As opposed to not doing any MFA, storing them in Passport, is it better?

507
00:34:21,520 --> 00:34:21,620
Yes.

508
00:34:23,520 --> 00:34:28,659
Like, so it really depends where you're coming from and where you're going and, like, what's your threat model.

509
00:34:29,220 --> 00:34:35,760
So I would say it's probably not ideal if you're in a high-risk scenario.

510
00:34:36,440 --> 00:34:42,460
What I would recommend typically is that you have your second factor authenticator in a separate device.

511
00:34:43,050 --> 00:34:47,179
So it's the same if your password manager is on the same device, but on another app.

512
00:34:47,340 --> 00:34:50,340
Is this still better?

513
00:34:50,710 --> 00:34:51,139
I don't know.

514
00:34:52,000 --> 00:34:54,919
If you can compromise the OS, for example, you can compromise both.

515
00:34:55,320 --> 00:34:57,080
Is that like a scenario that you care about?

516
00:34:57,860 --> 00:35:02,860
Or are you like, okay, no, I only care if one of the app gets compromised and then that's basically my scenario.

517
00:35:03,460 --> 00:35:08,780
But if you care, for example, OS level stuff, then you would need a completely separate device.

518
00:35:09,280 --> 00:35:11,580
So I'm trying to give you a clear answer.

519
00:35:12,360 --> 00:35:14,020
You see, it really depends what you want to do.

520
00:35:15,380 --> 00:35:23,260
Yeah, I was just curious if maybe the way of looking at it from an organization's perspective is different.

521
00:35:23,700 --> 00:35:28,560
If you have, for example, a shared second factor authentication, then it makes sense.

522
00:35:28,770 --> 00:35:34,980
Because then you, like, it's the same if I give you a QR code, you know, we both scan the same QR code and we both have it on the TOTP app.

523
00:35:35,240 --> 00:35:36,540
Let's say you leave the organization.

524
00:35:37,040 --> 00:35:42,020
I need to remember to change that code because I shared it with you.

525
00:35:42,520 --> 00:35:49,760
But if you use Passbolt, then Passbolt will tell you, okay, that person left and you need to replace that code.

526
00:35:49,790 --> 00:35:51,400
It will directly be built in the interface.

527
00:35:52,180 --> 00:35:59,600
And how do you ensure, because what's stopping someone from still recovering the seed encryption key for the,

528
00:35:59,800 --> 00:36:05,460
I don't know if it's technically encryption, but what's stopping them from recovering the seed and just importing it to their own 2FA app?

529
00:36:06,240 --> 00:36:07,420
They can do that.

530
00:36:07,490 --> 00:36:08,980
So that's why you need to rotate it.

531
00:36:09,940 --> 00:36:14,340
So you still need to rotate it even if you kept TOTP in Passable.

532
00:36:14,760 --> 00:36:15,120
Yes, yes.

533
00:36:15,250 --> 00:36:19,500
Does Passable automatically notify you as someone who's managing that?

534
00:36:19,680 --> 00:36:22,360
"Oh, they left, hey, you need to reset the TOT for this?"

535
00:36:22,400 --> 00:36:22,700
Yes, exactly.

536
00:36:22,900 --> 00:36:23,300
That's pretty cool.

537
00:36:23,580 --> 00:36:29,820
So do you kind of like handhold a little bit for organizations that they can pick up on

538
00:36:29,820 --> 00:36:31,760
those habits if they don't know to do them?

539
00:36:33,460 --> 00:36:37,260
Yeah, the way it would be, it would be signaling in the interface would be like a little warning

540
00:36:37,480 --> 00:36:42,480
and it would be like, ideally you would not have like 50 warnings.

541
00:36:42,859 --> 00:36:46,000
So if there is a new warning, they will see it, they will click, they will be like, "Okay,

542
00:36:46,080 --> 00:36:47,160
you need to change."

543
00:36:47,340 --> 00:36:48,420
So it's pretty straightforward.

544
00:36:48,440 --> 00:36:52,440
forward. And do you guys integrate with things like have I been pwned? Like do you scan? Yes,

545
00:36:52,630 --> 00:36:58,360
we do that as well. Yeah. Cool. So when you create a credential, it's like, basically the goal for us

546
00:36:58,460 --> 00:37:03,480
is like you don't enter credentials. It's like you only have a random generated key and you have like

547
00:37:03,480 --> 00:37:09,660
a passphrase to encrypt this locally on your machine and that's it. And then the rest is just

548
00:37:09,840 --> 00:37:14,559
like credentials that are completely random. But if by some changes you need to have like something

549
00:37:14,580 --> 00:37:16,200
that is manually generated,

550
00:37:16,330 --> 00:37:17,700
then we would also check

551
00:37:17,920 --> 00:37:19,720
whether it was part of breach or not.

552
00:37:20,620 --> 00:37:21,360
All right, perfect segue

553
00:37:21,470 --> 00:37:23,420
because my next more technical question

554
00:37:23,560 --> 00:37:25,600
was going to be this two different keys

555
00:37:25,880 --> 00:37:26,760
essentially to get in.

556
00:37:26,920 --> 00:37:28,060
So this might be different.

557
00:37:29,040 --> 00:37:32,100
So I'm saying this to kind of open it up

558
00:37:32,260 --> 00:37:34,380
for you to correct my understanding of this.

559
00:37:35,040 --> 00:37:35,600
Totally fine.

560
00:37:36,080 --> 00:37:37,000
With like ProtonMail,

561
00:37:37,240 --> 00:37:38,720
by default, when you use ProtonMail,

562
00:37:38,820 --> 00:37:39,960
it's just a username and password,

563
00:37:40,220 --> 00:37:41,740
kind of like any other account out there.

564
00:37:42,060 --> 00:37:43,560
And they essentially,

565
00:37:44,020 --> 00:37:46,460
because it's end-to-end encrypted and they're not supposed to get access to the data,

566
00:37:46,940 --> 00:37:49,520
they derive an encryption key based on the password you choose.

567
00:37:49,660 --> 00:37:51,560
So it's really important to use a strong password

568
00:37:51,780 --> 00:37:54,000
because that's the password to get into your account

569
00:37:54,260 --> 00:37:57,200
and it's the password that's encrypting your data.

570
00:37:57,740 --> 00:37:59,020
It's two different things.

571
00:37:59,600 --> 00:38:03,900
You're saying you guys are essentially offering Proton's like 2Password mode

572
00:38:04,300 --> 00:38:06,900
because with Proton you can enable something called 2Password mode

573
00:38:07,180 --> 00:38:09,640
where you have an account login,

574
00:38:10,100 --> 00:38:12,060
but then you still need to type in a second password

575
00:38:12,200 --> 00:38:13,640
to essentially decrypt your data.

576
00:38:13,720 --> 00:38:20,320
is that essentially what you guys are doing as well or is it different i'm not 100 sure how proton

577
00:38:20,540 --> 00:38:26,600
works but my understanding is that when you uh type your password it's actually the password that is

578
00:38:26,840 --> 00:38:32,980
used to decrypt the private key so they basically they derive it two times they derive one for login

579
00:38:33,260 --> 00:38:38,360
and one to decrypt the private key that they download once you manage to log in so there are

580
00:38:38,620 --> 00:38:43,680
actually two separate uh credential one that is used for login and one that is used to download

581
00:38:43,700 --> 00:38:45,640
private key and decrypt it.

582
00:38:46,900 --> 00:38:52,240
And so from what you're saying, I'm thinking maybe they split and you would have one for

583
00:38:52,400 --> 00:38:56,220
authentication and one to decrypt your private key so that it's not the same one that is

584
00:38:56,290 --> 00:38:56,920
used for authentication.

585
00:38:57,210 --> 00:38:59,380
So this way, it cannot be phished.

586
00:38:59,640 --> 00:39:01,140
The way Passable Block is a little bit different.

587
00:39:01,610 --> 00:39:03,820
So your key is not stored server side.

588
00:39:03,850 --> 00:39:05,580
It stays only on your machine.

589
00:39:06,220 --> 00:39:09,860
So we don't store a copy on the server and you log in and you get that key.

590
00:39:09,940 --> 00:39:13,080
Basically, it's there on your device and you type your passphrase.

591
00:39:13,530 --> 00:39:16,140
It basically decrypts the private key.

592
00:39:16,140 --> 00:39:18,920
So it's like local database encryption, essentially.

593
00:39:20,380 --> 00:39:23,980
And then we use that key to produce cryptographic signature.

594
00:39:25,100 --> 00:39:27,580
And that cryptographic signature is used to authenticate.

595
00:39:27,910 --> 00:39:32,540
So it's not like a password that we send to the server and the server check whether it matches.

596
00:39:32,780 --> 00:39:34,520
It's very similar to passkeys.

597
00:39:34,660 --> 00:39:35,780
It's not the same protocol.

598
00:39:36,210 --> 00:39:39,700
So it's not Fido Alliance protocol.

599
00:39:39,780 --> 00:39:45,380
It's something that is specific to Passport, but it's still based on like cryptographic challenges and signatures.

600
00:39:46,000 --> 00:39:47,180
So it's more strong.

601
00:39:47,220 --> 00:39:51,420
So each authentication attempt is unique and you cannot fish this.

602
00:39:52,580 --> 00:39:53,880
Wow, that's really cool.

603
00:39:53,960 --> 00:39:56,360
Do any other password managers do this that you know of?

604
00:39:56,660 --> 00:39:59,520
I know that one password is using like a private key.

605
00:40:00,800 --> 00:40:09,260
So they have like this, like the collector recovery code, but it's basically like they use this to create the final key that is used for authentication.

606
00:40:09,340 --> 00:40:11,160
and for decryption.

607
00:40:11,640 --> 00:40:13,780
And so it adds quite a bit of entropy

608
00:40:14,360 --> 00:40:16,140
as opposed to just like, you know,

609
00:40:16,360 --> 00:40:17,720
like for example,

610
00:40:18,600 --> 00:40:22,060
Bitwarden is using like just a key derivation function

611
00:40:22,700 --> 00:40:26,320
from the password that is user generated.

612
00:40:26,720 --> 00:40:28,280
So LastPass was doing this as well.

613
00:40:28,280 --> 00:40:29,720
And the issue with LastPass is that

614
00:40:30,240 --> 00:40:31,940
because they were like very old account,

615
00:40:32,460 --> 00:40:36,880
the key derivation function uses a cost parameter.

616
00:40:37,140 --> 00:40:40,720
And that cost was for 10 years back.

617
00:40:41,230 --> 00:40:44,780
So the cost didn't catch up with what modern computer could do.

618
00:40:45,440 --> 00:40:48,160
So we didn't want to have these sets of problems,

619
00:40:48,690 --> 00:40:53,960
to have to recreate that key and change the parameters

620
00:40:54,260 --> 00:40:56,020
and re-encrypt everything because that key is changing

621
00:40:56,190 --> 00:40:57,360
because we are increasing the strength.

622
00:40:57,840 --> 00:41:00,560
We wanted to have something completely random, like 1Password.

623
00:41:01,560 --> 00:41:03,840
The way we're doing it compared to 1Password

624
00:41:03,860 --> 00:41:04,600
is a little bit different.

625
00:41:04,920 --> 00:41:10,840
Because ours is based on OpenPGP, which is an open standard, and they have developed their own thing.

626
00:41:12,220 --> 00:41:17,580
But in practice, I think we are the only two password managers that use a random private key.

627
00:41:18,420 --> 00:41:22,880
Definitely the only one that's doing it transparently, because 1Password isn't open source.

628
00:41:23,150 --> 00:41:24,120
You guys are open source.

629
00:41:24,230 --> 00:41:25,760
And it sounds like you're also using OpenPGP.

630
00:41:26,660 --> 00:41:33,360
But I think there are some other credential managers that use, for example, passkeys,

631
00:41:33,880 --> 00:41:38,400
and they store like an encryption key as part of the passkey.

632
00:41:38,500 --> 00:41:42,600
So for example, I know at least two password managers that do this.

633
00:41:43,000 --> 00:41:45,740
So they use like something that is called a PRF extension.

634
00:41:46,100 --> 00:41:49,760
They basically store cryptographic materials inside the passkey.

635
00:41:49,860 --> 00:41:56,400
So when you successfully log in, it gives you like basically this private key that can be like truly random.

636
00:41:56,520 --> 00:41:58,020
And then they build on that.

637
00:41:58,300 --> 00:42:02,040
Yeah, it's a different techniques, but like same kind of goals.

638
00:42:03,020 --> 00:42:03,340
Got it.

639
00:42:03,680 --> 00:42:08,760
And kind of the final way I wanted to finish out this interview was just kind of talking about yourself.

640
00:42:09,020 --> 00:42:14,060
I wanted to ask kind of what your favorite password manager is for yourself and kind of the people in your life.

641
00:42:14,200 --> 00:42:17,100
If you're not going to recommend Passport to them.

642
00:42:17,380 --> 00:42:21,280
So like how is Passport's community version for just regular people?

643
00:42:21,640 --> 00:42:24,460
And then how does that compare to maybe other options that people have?

644
00:42:24,840 --> 00:42:31,140
Yeah. So I would say like if I recommend the competition, it's going to be complicated.

645
00:42:31,160 --> 00:42:37,240
So like, I would say PassBolt, like I really like it.

646
00:42:37,260 --> 00:42:40,880
Like I use it on a daily basis and it's really nice.

647
00:42:41,120 --> 00:42:46,500
And I've seen like people like staff or like install it for their family and it works really well.

648
00:42:47,000 --> 00:42:52,680
Because it's like, you know, it's available on mobile phones and like it works pretty seamlessly.

649
00:42:53,020 --> 00:42:58,560
My other option would be I really like the Apple solution.

650
00:42:59,260 --> 00:43:05,020
like i think it's like pretty privacy uh respectful and i like the fact that you know it's like

651
00:43:05,180 --> 00:43:10,120
hardware baked and you know like so that that that part i i actually enjoy to be fair with

652
00:43:10,370 --> 00:43:15,420
other password managers like there's a lot of them like i'm in contact with a lot of their staff and

653
00:43:15,420 --> 00:43:22,400
we talk often about like threats and like what can we do as an industry to improve and i would say

654
00:43:22,420 --> 00:43:31,200
like everybody like is is um pretty dedicated and so there's no like uh you know bad uh bad actor

655
00:43:31,380 --> 00:43:37,920
that is so like if you use one of the major password manager and you like it then you know

656
00:43:37,960 --> 00:43:44,200
why not you know say got it and is there um like overall advice do you see like a common mistake

657
00:43:44,400 --> 00:43:49,480
people make with their password manager uh or for most of these services you think just getting on

658
00:43:49,500 --> 00:43:54,640
service and starting to use it is pretty much the main thing to be okay yes i would say like you

659
00:43:54,640 --> 00:44:00,440
know pick one you like and stick with it it's like uh this is one of the thing in the industry is

660
00:44:00,440 --> 00:44:04,740
like when people choose a password manager they generally like you know it becomes part of their

661
00:44:05,000 --> 00:44:09,540
daily life because every day you log in into something so it's like then it becomes an habit

662
00:44:10,030 --> 00:44:15,440
and you know and they are pretty emotional about it sometimes when it changes and so it's like

663
00:44:16,280 --> 00:44:24,540
yeah yeah i i do like to use and this is generally advice i give only use a password manager that

664
00:44:24,680 --> 00:44:30,600
makes it easy to leave because you never know what's going to happen and i i like password

665
00:44:30,780 --> 00:44:36,040
managers that allow easy exports um and all that kind of stuff and i i actually wanted to ask you

666
00:44:36,040 --> 00:44:41,740
know maybe there's something i'm missing but um without naming names there's a few password

667
00:44:41,760 --> 00:44:50,600
managers that have TOTP built in, but they never let you view the seeds of it. And that's even in

668
00:44:50,600 --> 00:44:58,600
their dedicated TOTP apps. And I view this as a consumer, as anti-consumer, because that means I

669
00:44:58,700 --> 00:45:04,840
never actually own the seed to the TOTP code and I can't ever take it to another service and they

670
00:45:04,920 --> 00:45:08,820
don't let you see it again and you have to reset it for every service. Devil's advocate, is there a

671
00:45:08,840 --> 00:45:11,560
reason they might do that that actually is advantageous to the user.

672
00:45:12,020 --> 00:45:14,960
It's more like obfuscation than like really hiding it.

673
00:45:15,130 --> 00:45:17,320
So they are not providing you the features to see it.

674
00:45:17,520 --> 00:45:22,060
But like in practice, you can't like if they have a web-based interface, you just open

675
00:45:22,130 --> 00:45:29,020
the code and you will find the actual seed, you know, because they use it for generating

676
00:45:29,090 --> 00:45:29,460
these numbers.

677
00:45:29,660 --> 00:45:30,780
So it's definitely there.

678
00:45:31,260 --> 00:45:31,480
Okay.

679
00:45:32,320 --> 00:45:33,300
But why hide it?

680
00:45:34,100 --> 00:45:34,600
Why hide it?

681
00:45:35,740 --> 00:45:36,180
I don't know.

682
00:45:36,230 --> 00:45:37,600
I don't know which one you're talking about.

683
00:45:37,600 --> 00:45:38,040
Yeah, I know.

684
00:45:38,240 --> 00:45:43,120
I'm not like, I'm just, I'm asking mainly to see if there is like something I'm missing here.

685
00:45:43,760 --> 00:45:46,800
And maybe there's like a valid security reason.

686
00:45:48,420 --> 00:45:57,920
Because I think you're the, I recorded an interview already with someone who's developing a password manager for that's very consumer oriented.

687
00:45:58,320 --> 00:46:00,480
But like, these are kind of my first password manager interviews.

688
00:46:00,580 --> 00:46:05,040
And so I'm trying to, I also have just like these lingering questions I've had over the years that I'm kind of asking.

689
00:46:05,880 --> 00:46:06,480
Yeah, that's cool.

690
00:46:06,980 --> 00:46:09,940
I can't think of any security reason why you would do this.

691
00:46:10,220 --> 00:46:12,900
For example, people sometimes ask us,

692
00:46:13,280 --> 00:46:16,900
can we insert in a page a password

693
00:46:17,540 --> 00:46:21,380
and make sure that there is no way for the user to see it?

694
00:46:21,780 --> 00:46:23,780
And I'm like, see it where?

695
00:46:24,460 --> 00:46:25,880
There is an HTTP request.

696
00:46:26,720 --> 00:46:30,380
The server on the other side is going to see that thing in clear text.

697
00:46:30,660 --> 00:46:35,680
There is no way for me to hide it from everybody

698
00:46:35,680 --> 00:46:39,180
but the destination server is not possible.

699
00:46:39,760 --> 00:46:41,080
Like you can do this with a proxy

700
00:46:41,300 --> 00:46:42,460
that replaces it with something else,

701
00:46:42,490 --> 00:46:44,520
but then it's not like end to end.

702
00:46:44,660 --> 00:46:46,520
It's like, it's different kind of service.

703
00:46:47,940 --> 00:46:48,220
Interesting.

704
00:46:49,130 --> 00:46:49,500
Yeah, okay.

705
00:46:49,570 --> 00:46:51,600
So is there, are there any kind of final things

706
00:46:51,630 --> 00:46:53,200
you wanted to mention to people listening,

707
00:46:53,450 --> 00:46:56,280
whether they're an organization or a regular person

708
00:46:56,960 --> 00:46:58,300
before we kind of log off?

709
00:46:58,540 --> 00:47:01,340
No, no specific, specific things.

710
00:47:01,540 --> 00:47:04,480
I'm just like, yeah,

711
00:47:04,580 --> 00:47:08,620
if you're interested about how Password Manager works,

712
00:47:09,460 --> 00:47:11,140
one of the things I invite you to do

713
00:47:11,270 --> 00:47:13,180
is have a look at their white papers.

714
00:47:13,860 --> 00:47:15,700
So for example, you have some of these questions

715
00:47:16,020 --> 00:47:19,260
and some white papers are pretty well written

716
00:47:19,480 --> 00:47:23,120
and they will give you how it works under the hood.

717
00:47:23,630 --> 00:47:26,160
And it's often an interesting read.

718
00:47:26,900 --> 00:47:28,820
So I would say if you're interested in Password Manager,

719
00:47:28,960 --> 00:47:30,500
definitely go into that.

720
00:47:30,800 --> 00:47:33,840
Great. And how can people find you and find Password?

721
00:47:34,160 --> 00:47:37,300
You can just go online, like vvv.passball.com.

722
00:47:37,620 --> 00:47:42,060
And we're also on social media as well.

723
00:47:42,520 --> 00:47:45,820
We're on MasterDome and Blue Sky, I think.

724
00:47:47,040 --> 00:47:47,140
Great.

725
00:47:47,660 --> 00:47:49,200
I'll leave links down in the description.

726
00:47:49,360 --> 00:47:51,460
And I want to thank you for your time, Remy.

727
00:47:51,880 --> 00:47:52,280
Thank you very much.

728
00:47:52,280 --> 00:47:53,560
And I know I learned quite a few things today.

729
00:47:54,560 --> 00:47:56,800
I'm glad I could clarify some things.

730
00:47:57,460 --> 00:47:57,860
It was great.

731
00:47:58,860 --> 00:47:59,020
Cool.

732
00:47:59,260 --> 00:47:59,400
Thank you.

733
00:47:59,720 --> 00:48:00,320
Thank you very much.

734
00:48:00,540 --> 00:48:01,400
And that is the interview.

735
00:48:01,500 --> 00:48:04,080
I want to thank Remy for coming on Techlore Talks.

736
00:48:04,140 --> 00:48:08,160
And I want to thank all of you for learning a little bit more about how to protect yourself

737
00:48:08,620 --> 00:48:12,560
out in this crazy world that is always, always seems like it's trying to get you.

738
00:48:12,620 --> 00:48:15,860
If you enjoy these podcasts and you want to see more of them and you want this podcast

739
00:48:16,080 --> 00:48:20,100
to keep growing with time, consider leaving a rating if you're on a platform that allows

740
00:48:20,320 --> 00:48:20,420
that.

741
00:48:20,540 --> 00:48:24,460
You can also support Techlore directly for free by just using one of our affiliate links.

742
00:48:24,580 --> 00:48:27,040
We have a support page down below that details how to do this.

743
00:48:27,420 --> 00:48:31,000
Or we also have paid support methods if you just want to directly contribute to the mission.

744
00:48:31,520 --> 00:48:35,200
I want to thank you all for listening, and I'll see you all next time on Techlore Talks.