In short
Software Engineering Daily Podcast Notes
Episode Title
Browser Security with Jeswin Mathai
Episode Overview
- Hosts: Gregor Vand and Jeswin Mathai
- Guest: Jeswin Mathai, Chief Architect at SquareX
- Focus: Browser security and its importance in modern workflows, particularly as they relate to cloud-based tools and SaaS platforms.
Key Themes
- Importance of Browser Security
- Protects users against online threats including phishing, malicious extensions, and malware.
- Increasingly critical due to the growth of cloud-based tools and collaborative applications.
- Jeswin Mathai's Background
- Early interest in cybersecurity sparked by a desire to understand online threats.
- Journey started in high school, leading to a career in cybersecurity with companies like Pentester Academy.
- Experience in building hands-on cybersecurity education platforms, leading to the founding of SquareX.
SquareX
Company Overview
- Mission: Provide enhanced browser security solutions focusing on user protection from scams and phishing attacks.
- Product Offerings:
- Consumer and enterprise versions of SquareX.
- Features include a "disposable browser" for secure internet access.
Key Features of SquareX
- Disposable Browser:
- Functions as a remote container that executes a browser session, isolating potentially harmful interactions from the user’s device.
- Offers a seamless user experience while maintaining a high level of security.
- Chrome Extension:
- Designed for easy user adoption; users can install it without significant workflow changes.
- Automatically detects dangerous links and prompts users to open them in the disposable browser.
Comparison with Traditional Security Solutions
- Endpoint Detection and Response (EDR):
- Traditional EDR solutions are effective for local applications but struggle with browser-based threats.
- SquareX focuses on browser detection and response, offering protection where most attacks occur.
- VPNs vs. SquareX:
- VPNs reroute traffic but do not prevent malware from affecting the device.
- SquareX provides a safer browsing environment by isolating potential threats in a remote container.
Threat Landscape Insights
- Emerging Threats:
- Attackers exploit user behavior (e.g., clicking on notifications or QR codes).
- Use of polymorphic websites that change their behavior to evade detection.
- User Education:
- Emphasis on educating users about security and the importance of proper online practices.
Future Directions for SquareX
- Continued Development:
- Expansion of detection capabilities to cover new threats as they emerge.
- Introduction of innovative features for enterprise clients to enhance security and productivity.
Conclusion
- Where to Find SquareX:
- Website: [sqrx.com](http://sqrx.com)
- Chrome Store: Search for “SquareX” for consumer extension.
- Listener Engagement:
- Jeswin encourages listeners to try the extension and explore the capabilities of SquareX, emphasizing its effectiveness and user-friendly nature.
Final Thoughts
- The episode provided deep insights into the evolving landscape of browser security, highlighting the innovative approaches taken by SquareX to address contemporary threats effectively. Jeswin's passion for cybersecurity and the mission of SquareX to improve user safety online were clear throughout the discussion.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00Browser security aims to protect users from cyber threats encountered online, such as phishing, malicious extensions, and malware. It's a complex, multifaceted challenge that's increasingly important as cloud-based tools, SaaS platforms, and collaborative applications become the backbone of modern workflows. Jeswin Matai is the Chief Architect at SquareX, which is a cybersecurity company focused on protecting users and companies from web-based threats. Jeswin joins the podcast to talk about SquareX and modern strategies for browser security. Gregor Vand is a security-focused technologist and is the founder and CTO of MailPass.
0:37Previously, Gregor was a CTO across cybersecurity, cyber insurance, and general software engineering companies. He has been based in Asia-Pacific for almost a decade and can be found via his profile at vand.hk.
1:04Hi, Jeswin. Welcome to Software Engineering Daily. Hi, Gregor. It's great to be here. Yeah, so Jeswin, great to have you on today. You're here from SquareX, which we're going to hear all about. Just, you know, sort of spoiler, it's all sort of in security, and we're going to be talking a lot about browser security today. And for once, we're actually both sitting in Singapore, which is nice. Just I'm usually talking to someone far, far away. But yeah, it's a very hot day in Singapore today. So nice to have you here. But let's start the normal way, so to speak. So Jessamyn, I think you got a pretty interesting sort of history before SquareX and a lot of security experience.
1:42Could you maybe just talk a bit about sort of from, I don't know, leaving high school to kind of SquareX? What was that sort of journey for you? Yeah, thank you so much, Gregor. So it started off in high school where I got a bit scared seeing all of the activity that happened online. and security the reason I got into it was primarily you know just to be aware of the hacks the attacks that happen and how I can protect you know myself as well as people I care about right so because someone losing a lot of money in any of the scams phishing it can impact or like you know I can have a scarring impact on the life so that was sort of you know a fear that I had that sort of pushed me in the direction of security and very early on I was very into computers so I'd be exploring various programming languages even exploring hardware whatnot so that's how it started during my university again and security is one of the most difficult field to get into because in order to break something you need to understand how it works so and to get to the first mile is like very very difficult so that's where in my university I just focused on computer science fundamentals ensuring I'm at least grasping how the world works how the internet works and then slowly I started to you know explore various courses and at that point in time there was not proper course material or a guide on how to start a career in cyber security so just you know throwing my hands around various various courses topics just to have some more context and I was a complete newbie in the field of security and luckily Vivek Ramachandran who was the CEO of Pentestra Academy was looking for interns at the time so I applied and everything went well and I got him and I absolutely loved the people there so it was a very small team but they were like very I'd say high performant as well as aligned to the vision what we were building everyone loved security so I remember having you know 4am calls with my manager and that is sort of unheard of at times we both were like workaholics of sorts so during my internship time it was just amazing run got to explore so many technologies that I felt like the amount of learning I had in just those six months was like massive and a lot of people won't get exposed to that and this was also the time where I was exploring masters options for masters who had gotten admit from some amazing university in the US but it was you know a leap of faith that I took that I have to join this startup and one good thing happened at the time was my work got published in two of the top conferences in security DEF CON and Black Hat so out of curiosity you know as an intern my work got there what is it that we can do full-time and how the ride is going to be and I knew that once I go for masters the opportunity can't come back but when it comes to you know later on at any point in time I can go for masters so that was like a sort of leap of faith I took and some of the folks in my university were like a bit skeptical about this because this was the time you know in startups you join and they'll get a lot of work out of you but the pay might not be good or it could turn out to be a complete scam so a lot of people are like oh why are you ditching the offers from such good university and going for a startup but luckily everything worked out the team was amazing and in just like a couple of months time I got to learn quite a lot and I'm a workaholic right so I put in crazy amount of effort and this was the time when we were building a lab platform with Pentester Academy so to provide context about Pentester Academy it was a cyber security education firm ran by Vivek Vivek Ramachandran is a cyber security veteran with over 20 years of experience he has found multiple zero day attack which is again he's the first to find some of the attacks in like wi-fi stack and so on so at the time again we had a course platform but now we wanted to make sure that everyone can go ahead and do some hands-on exercise and that's the best way to learn anything right you need to do hands-on and when it comes to cyber security that was lacking in the industry so Vivek's idea was that we need to make a lab platform that can be fully accessible from the web and if you think about it getting like hands-on experience on cyber security is a bit difficult reason being you have to attack something that is vulnerable so now you can't host something vulnerable in you know public internet so all of the other players uh the competitors what they used to do was they used to create a VPN and now you have to connect your device to the VPN network and there you'll get to attack those machines but now the big problem with using VPN is that it's a two-way street so you can attack the other machine but you can get attacked so in every corporate organization VPN is like a completely no-go so that's where Vivek thought that oh whatever solution we are building has to be served from the web so we constrained ourselves to just a web browser and we ended of building an elegant solution and at the start we were bashed up on that you know this is not going to work vpn is the route to take and so on but six months down the road everyone started copying the technology that we have built out which is through the web interface and we were the first to go ahead and provide like a full-blown desktop environment on a container people used to do it in vm that's why again it was so expensive but we were the first to sort of package everything in form of container and that sort of changed the whole industry for the months to come and while running Pentastry Academy again Vivek ran it brilliantly with like just four or five folks we were able to deliver so much and we were so ahead of the competitors that even if they started copying us they couldn't get to the point where we were and while running Pentastry Academy what ended up happening was Vivek is a very curious person right he's the hands down the most technical person I have met and he noticed a lot of issue in the whole browser security space and more importantly if you think about the technology is keeping evolving but the phishing scam the number keeps on compounding so even though there's better technology it is not going dumb because attackers are like finding a way to go ahead you know evade security solution and whatnot and none of the vendors are doing much about it google microsoft you know they aren't acting on it even though they know something is happening so a bit of frustration as well as various ideas Vivek had at that point in time and now we knew that we can't run two businesses parallelly and beyond a point again in cyber security education we had a massive impact right so we are talking about customers from fortune 500 companies US Department of Defense US Army and quite a lot of defense agencies that we have trained people from but we knew that at some point in time we'll hit the market cap because among the whole IT population we have small percentage of cybersecurity enthusiasts out of which again only small fraction is going to go for the courses so at that point in time Vivek decided that it would be best to sell the business to a US firm so we parked a big win and then one year down we started SquareX with the sole vision of you know providing better security solution on the browser and started off as you know going ahead and protecting the user from scams phishing attack that would be happening so I know this was like a long stint, but that's how the journey has been till the time SquareX started.
8:56That's a great little sort of history there. And sort of, I think definitely leads really sort of clearly into why SquareX is what it is today. So I think that's been really helpful, I imagine, for the listeners sort of in terms of, you know, SquareX is very much all to do with the browser. But I'd obviously love to hear it from you. So if you were to describe what is SquareX today, I'd love to hear that. And then obviously, we'll dive into a bit of detail in various aspects so what is square x so at this point in time we are having a consumer version as well as enterprise version but i'll talk about the vision first how it all started right so if you think about from a user's perspective we have antivirus solution to you know block any malware malicious files that would be coming in but now let's say you get an email that google marks as dangerous now but it is an important mail that is coming in so at that point in time you'll go ahead ignore the warning google prompted you you'll download the file now let's say your windows defender goes ahead blocks you from opening the file now it is important so you'll go ahead disable your windows defender and then you'll end up opening the file because again false positive can happen so the way the industry worked was again blocking the user from doing things and no one likes to be you know blocked or in a way deterred from what they wanted to do that's where our philosophy was let's not block the user but rather provide them an alternate way to you know access the web access the files in a secure environment so one of the examples I can give is anytime I get a resume right and we are a security company so I have to be careful about opening those resume and let's say someone sends a assignment with videos and files in it I have to literally spin up a VM to make sure again if I open the file even if it has some malware it doesn't end up compromising my device so all of these are like a lot of concerns about the files that you're getting from the internet and that's how a lot of hacks happen people accidentally go ahead disable the security solution one time they forget about it and now you're open to the sea of malwares that are out there and it takes just one opportunity for the attacker to get in once that is there then at that point in time you might end up losing your credentials you might incur like financial loss and to be honest the world is quite ruthless right people don't care about what would be happening to you so let's say you're in a very financially bad situation could be like medical situation whatnot they don't care they'll just take out the money so that's where our logic was that don't block the user from doing things but rather provide them an alternate way and a lot of people don't care about security that much so in a way also to educate the users that at times you have to take a secure measure so all of this led to like a couple of features called disposable browser disposable file gear disposable browser is like a remote container that runs on which again a lightweight desktop environment is running and on top of it a browser will open up so it's a very seamless interface imagine that you serve something right and now you'll notice a lot of google sponsored link coming on the search result to be honest i never click those because what attackers do is they'll pay google to make sure their website come up on top so instead of going to the legit website you'll be going to like a malicious website.
12:07So what I do usually is all of those websites I'll simply right-click and then open it in like disposable browser and that launches a remote container on SquareX's data center and now the browser is running there so you can access the website as you would on your regular browser. So in a way the container is running the browser is running and the view is getting streamed to you and the container is ephemeral in nature so you can destroy at any point in time no data retained also nice so yeah i mean there's a lot to sort of unpack here you know you've sort of described the experience and i think probably quite a few listeners are asking quite a few questions you know in their head right now sort of hang on how does this really work you know scurgex describes itself as browser detection and response which i really like i really like that sort of idea you know it's clearly a play on endpoint detection and response let's come back to that in a second just in terms of just in point is probably you're referring to just your os in general and then you know there's a reason now it's browser detection response but everything you just described there okay so i'm using my browser but i believe there's quite a sort of important chrome extension piece here so maybe you know because i think from what described okay i might be opening something malicious and the disposable browser aspect sort of kicks into play the missing link i think at the moment is perhaps the chrome extension i could be wrong but maybe you want to talk about so how does the browser know to sort of start spinning up a disposable browser for example that's a great question so again i'll explain the decision of why you went with the chrome extension approach so originally again square x is a new company right people won't trust it that much and to have our own let's say browser or installer it's a very high bar for the users to install it but if you think about a chrome extension people don't you know take a look that often they are very open to installing extension ever since the ai boom with the you know chat gpt and everything people want to enhance their productivity and again the usage of extension had squire rocketed so we took a look at the stats and then we decided that extension is the easiest way to get onboarded on the user's device and now we had like couple of features for example anytime we let's say you're surfing based on the links that you're seeing we ourself will identify that it looks a bit dangerous for you to directly open it in the browser so we'll open it automatically in the disposable browser that was like something that the extension is automatically doing additionally what you can do is you can simply right click any of the link and in the right click menu there will be option open with square x and disposable browser so click on it and then that link automatically opens so it was a seamless integration from the regular browser to the disposable browser provided directly and our idea was that slowly we have to go ahead package a lot of security features onto the end device because most of the security solution the way they work is they don't do any analysis on the end device they'll be sending it to the cloud where again your content will get analyzed and then it will fly now this is a big privacy concern because the data is moving out from the user's browser to the cloud so with extension and the browser itself have become much more powerful right we are seeing the end device at one point in time we were seeing like four gigs device but now you're talking about 8 16 or even 32 so the device itself has become powerful and the browser capability has increased quite a lot so for example web assembly has like skyrocketed you in terms of the usage that is happening.
15:38So big players, Adobe, Figma, Canva, all of these guys are using Wasm. So what we did was we took the similar approach that we can use WebAssembly to go ahead, perform some of the operation that the endpoint detection or the antivirus would be performing. So before the file touches the disk and to provide some more context, right? So all of the antivirus, they go ahead, act when the file touches the disk because that's where again they can access the full file and take a look at what's happening so even before that happens Square X can perform the checks on the browser in memory that was in a way our superpower to tell that oh you already have an end device it will catch something if Square X misses something so these sort of enhancement we were keeping on doing with the platform and it also to test out you know what's the performance impact on the end device because it's a free extension SquareX in case if anyone wants to try it out and the users don't have an incentive to you know use the product unless they really like it and it was a good test for us to figure out how well can it scale how well can it run and also to ensure that whether it is causing any difficulty with the user so if they feel that oh something is slowing down they'll immediately uninstall similarly again if it is getting too annoying they'll immediately uninstall but that which was a big exercise that we run so that we gather all of the user experience with people you know who are not associated with us in any way and it's like the raw you know just the likeliness of the product is it going to scale so a couple of these questions are answered with that exercise and even today again square x the extension is completely free for anyone to use at least a consumer version so yeah i mean i think in terms of okay so i think now is a good time browser detection and response and then versus probably a term that at least a good number of our listeners have heard before which is endpoint detection and response and you know I think it's no sort of secret that the browser is becoming almost the sort of almost OS for most people day to day you know so many things are moving into the browser that might have been able to or would have run you know as a native application and it's interesting that you mentioned WebAssembly because you know that's clearly this direction where we're able to package things you know again applications that would have needed a lot of resources to run in the browser or on the os and now we're finding ways to run them pretty interestingly and efficiently in the browser because of web assembly so you know if i'm using my browser you mentioned sort of well i guess i'm still just trying to understand it does square x if i've installed the extension does it sort of hate to use this phrase but does it sort of pop up and sort of say oh we think you're trying to download something malicious so and so and so or is it something different because i mean again to your point about productivity and not getting in the way of users you know i think many users including myself would probably say look if i'm just trying to do something and then this thing pops up and says are you sure that's already a friction point so i'm curious how you guys have like thought about that so the idea was again we have to make everything configurable as a setting for the user so by default a lot of things will be turned off and then they can selectively enable some of the feature so that again it's not intrusive we want to run as silently as possible without even user realizing that square x is running and that's where again everything was like an opt-in that they can enable from the settings and that way again they don't get blocked or you know annoyed in any way yeah gotcha so yeah i mean you talked a bit about performance there and that's obviously a very interesting piece so i mean as much as you can kind of reveal like how does this work behind the scenes you know how again user experience and performance these days is almost intrinsically linked so if you know something's going to take too long to tell me something and obviously we'll probably get to ai in a bit but you know ai is a great you know example of this where unless i'm getting a response within you know three to five seconds then i'm already kind of you've lost me so yeah how do you look at performance and sort of how is that being sort of looked at behind the scenes yeah so in terms of performance again the idea is we have to be in like sub millisecond and every action that we are performing some actions for example let's say file download and if you're analyzing the file depending upon the size of the file the analysis can take some time so that is one thing again let's say you're downloading gigs of file then definitely it can go up to like seconds and worst case it can go up to minute but there is nothing we can do about that but if you think about like users downloading files in general most of the files will be very small in nature right not everyone will be downloading you know a 100 gig file or even a 10 gig file every day and file download in general are very less unless again the profession itself requires a lot of file download upload and so on one thing which we did was again to make sure that we benchmark everything properly and a lot of optimization just keep on happening over time so in regular use it used to take like one to two percent of what the browser would be taking and the browser is like you know such a beautiful solution at this point in time it automatically optimizes the resources it consumes as well as again the resources that the extension consume so let's say you have quite a lot of memory cpu available and it is free to use there's no other application using the browser can go up to like maybe 70 80 percent at times because again there's some free resource available but now something comes up it will constrain that and it will also make sure that the extension automatically gets constrained as well as again it might go ahead kill off the service worker which is like the main thread that is running in case if it is exceeding some memory limits so in a way we are piggybacking on what the browser itself provides and again hats off to the chromium team as well as the firefox and safari team they have done a brilliant job in terms of you know managing the resources making sure that everything is optimized yeah so i think you know i'd like to sort of go into more of the security side in a second but yeah i definitely have a big question which is the decision around a chrome extension as opposed to we've seen some people i wouldn't say just in security but you know in some other realms say look chromium is the de facto browser framework now okay great so why don't we piggyback on that and we still come up with our own browser you know it doesn't deviate too far from chromium but it builds in these things i'm really interested to hear why a chrome extension was still the decision over you know saying this is the square x browser yeah so that's a great question we looked into you know the other companies who had rolled out the browser and we realized again it didn't pick up and these are like you know very large companies some of them were like public companies so the adoption of a new browser is like a very very high bar because in a way you're asking the user to transition all of their regular workflow from a browser to a new browser and plus again the I'd say credibility at that point in time because we are a startup right so that credibility to build it up to a level where users are comfortable in terms of privacy security that's going to take a while so we evaluated all of these options and one biggest concern is that anytime you're using or like building your own browser let's say there is a vulnerability that comes in right so all of those patch management is a very big thing to manage in like every place software patch management is like it's a management sort of hell I'd say so that was one reason because anytime a vulnerability comes on chromium right so the chrome the team will go ahead immediately roll out a patch but now we are deriving something on top of chromium so if something comes up in chromium as a vulnerability now if we have deviated too far we have to make sure that the patch is conveniently applied here and also the design decision right so we can't deviate in such a way that it becomes like you know completely something different from chromium so that all of those patches become like big pain to manage so from a security standpoint from a management standpoint we decided that at this point in time again just an enterprise browser it has to be something revolutionary it has to be something like you know it's not possible to do on chromium at that point in time we can go ahead decide so we evaluated the whole extension story we figured out for most of the security related feature we have the power with the browser extension which most people are unaware of browser extension are like super powerful and it sort of checked all of the boxes that we had in mind so that it was purely you know management plus security related decision to go with chrome extension so let's say again some vulnerability comes in in chromium chrome will automatically patch it now we are in the browser extension if some vulnerability comes in our software all we have to do is you know push a new update to chrome store or the private link that we have and the browser automatically will pull it in after you know a few hours time in case a day's time so it is much secure version of the solution that we are offering and the best part is again user doesn't have to go through any change management they don't have to you know change their regular workflow in any way everything works out of the box nice when i first saw the product so it was at the govware in singapore it's a bit of a strange name but it is basically the biggest cyber security conference in Singapore other than there's a black hat you know offshoot that comes to Singapore as well but yeah if you sort of think of I don't know almost like DEF CON the Singapore is sort of like that but yeah and I was really really impressed by just sort of seeing what actually the ultimate capabilities of a Chrome extension were I mean just to dive into some small details for a second I mean when Square Enix was started was that like I'm trying to sort of match up times now is it was that the v2 manifest versus v3 or did you guys get lucky and start on v3 or how did that work directly started with v3 okay even though again we were not leveraging a lot of heavyweight feature from v2 so again we could have done it for v2 as well but we decided that v3 is the best way to go nice okay so you avoided i think a lot of headaches there yeah we've had some other security companies on the podcast and you know obviously they've been around well they've been around a bit longer and yeah unfortunately one of the reasons that their extension was sort of lacking to users was just actually that v3 had come along and they were having to take a lot of effort and time to upgrade to v3 so so that's that's one of the powerful things of being a startup is if you can start at the right time then you can miss these things out so you mentioned i think it's interesting your chromium as a in terms of well if things get patched there then you know they deal with it and obviously you know if there's anything to do with the extension you would look at that but it's just in general from a the security landscape or rather the threat landscape how do you assess and keep on top of what you considered a threat i believe one example that you guys cover is you know a malicious qr code an example could you maybe give some other examples of like the kinds of things you cover and then also how do you what's your sort of process for sort of looking out for and keeping on top of what can be considered a threat within the browser context because i guess also you've talked about phishing and phishing is this ephemeral thing as you've just said you know it doesn't seem to matter what happens phishing just continues because people are smart and plus ai so yeah i'd love to hear all about that that sounds great yeah so just to provide some more context of like what square x is trying to solve so we have couple of big players in the market so we have like what's called edr endpoint detection and response for the consumer folks you'll familiarize with like antivirus solution so edr is like antivirus solution but for enterprises so now these solution you know they came up with at a time where everything was running on different application on the local machine so we're talking about ms office adobe your video player whatnot so they're great at detecting malware that directly comes on the desk but over time what happened was everything got transitioned to the browser and ever since the covid hit what ended up happening was a lot of work from home a lot of sas application like skyrocketed and the browser became the main interface through which everything is happening no longer we are using you know most of the time we won't be using local application and enterprise 95 of the time users spend on the browser and attackers are like the smartest folk on the planet right so even if we have the best security solution they'll find the way to be beat them and the way they are beating it right now is by remaining in the browser without triggering any file download they'll try to be on the browser could be like a phishing page or could be a qr code now imagine that you are on a corporate device with best security solution suddenly you see a qr code now the user will be incentivized to let's say it could be something related to travel deals it could be a financial tip whatnot they'll be incentivized to go ahead scan the qr code now the moment they scan the qr code you are on a smaller device more susceptible to phishing attacks and more importantly you're using a device that does not have any security solution that the enterprise would have provided so a couple of these vectors were coming in where attackers are just living on the browser another example is i'm not sure if you're familiar with the pop-up based scam.
29:10So basically what ends up happening is every website in today's time is asking for notification permission right so users are used to clicking allow allow allow. Now attackers are leveraging the same so let's say you go to a website that asks for notification permission you click on allow nothing will happen to you at that point in time but few hours later what you'll see is suddenly pop-up appearing from that website and the way the browser works is that that website doesn't even have to be active when you're seeing those pop-ups so suddenly you see quite a lot of pop-up that will show that your account has been compromised or malware detected on your device so this actually we noticed on like couple of our non-tech folks some of their again family members went ahead and clicked on one of those website and what ended up happening was the pop-up was spamming so much that it just filled the screen on the right side such that again you can't even click on the settings button to disable the notification permission for that website.
30:08So there's no way out all you have to do is you'll be forced to click on the pop-up. Now when you click on the pop-up it will take you to let's say either a malicious website or it will take you to a affiliate marketing link and the affiliate marketing link could be of genuine corporation could be like Norton or an anti-war solution. Now the users are thinking that oh their device has been compromised. Now when you click on it it takes you to Norton. So then you end up purchasing Norton and during this you are using affiliate link of the attacker so they make money regardless of you know the approach they are taking and this was one of the hardest attack to detect because the user is going to an official Norton website or antivirus company and there is nothing wrong about it so all of these attacks are happening at this point in time that again it's like so smart of them to use this and i think in 2022 alone close to 3.4 billion were lost to norton and some other companies due to this affiliate marketing fraud and the pop-up based attack that is happening now what attackers are also doing is they know that the website will get scanned right so there are like a lot of point of presence around the globe which are held by security companies and they're constantly scanning website from different location figuring out whether something is malicious or not and attackers the way they are evading that is by you know applying tactics such as they figure out the traffic is coming from data center so they'll suddenly change the website's behavior and show a very simple page that doesn't have anything malicious but now if the traffic is coming from a regular isp from where the user will be accessing they'll suddenly show the malicious website so this is one tactic based on again the origin of the request we show different behavior and this we are terming as like polymorphism or like polymorphic website it is popularly used in malware polymorphic malware they change their own behavior and this is exactly what is happening for the website in today's world another tactic is again they'll put a reCAPTCHA on top of their website now let's say a security scanner is scanning it can't go ahead bypass that reCAPTCHA only a human can so but again this way again the security scanner are unable to pick it up and a lot of these websites are out there in the wild for a long time.
32:26So even we tried you know reporting to Chrome and it takes them close to like even 16 to 24 hours to acknowledge and then fully take down the website and the process itself it could be possible that some websites are up till like you know couple of weeks to even months before they're finally classified as dangerous. So that's where again with SquareX the idea is that we sit on the browser we see what the user is seeing so we are acting on the last mile so let's say you go to a phishing site we can figure out that oh the sentiment is of login and the website looks like microsoft but it is not microsoft so and this could be like numerous number of indicators first is again the visual based on the text that we have similarly again text on the domains so for example if it's a domain it's like very newly registered then it's a red flag now attackers are very creative they'll go ahead use a they'll purchase a domain that is already there in the market for a long time to evade this sort of check but in this case again we can perform checks such as again who is the owner of the domain and it looks like microsoft the website looks like microsoft but the owner is not the same as what microsoft would be generally using similarly again from where the traffic is coming in a lot of parameters across like you know what is the server headers who is related information what are the way the ssl certificates are issued who is the in a way signer of the certificate all these key metrics we are able to gather by sitting as an extension and based on that we can reduce that oh this is like a bit risky bit dangerous for a user to go to so a lot of like in a way intelligence is embedded right there on the browser extension and we are also having like some ai models that are packaged with like the onyx model it's a good thing that we can run on the browser so all of those are packaged to go ahead analyze the content that the user sees and all of this is happening in a privacy safe way more importantly because we wanted to reduce the amount of data we'll be sending to the cloud so most of this thing that i mentioned is part of our enterprise offering how we are protecting the end users on for businesses and there again the challenge is we can't send a lot of data to the cloud because again it's corporate data so the more detection we do on the browser the more data we reduce the more again we are performant in terms of like cost as well as again in the whole user experience is much more seamless yeah that makes a lot of sense so you know you've talked quite a bit about i guess sort of learning and detecting from what's sort of happening from actions and also you talk just there about you know being able to use models ai models that again run on the browser there still must be some degree of threat intelligence that you have to be aware of and bring into the platform i'm curious about that because you know if we look at sort of other security domains like attack service management you know i would say without naming names of companies i would say that the leaders now are the ones who have you know internal threat intelligence teams who are able to bring that right into the product you know leading edge effectively how are you guys sort of looking at that because you know as you just said the attackers are the smartest people on the planet and i i would agree with that in the sense that they're very smart and there's no rules right so they can they can kind of do almost whatever they want and try whatever they want so how are you guys bringing that into squarex so yeah that's a great question at this point in time our idea is not to reinvent the wheel for some of the things for example we don't want to dwell into you know threat intel for malware analysis we don't want to do that that we are building our own full-blown malware analysis platform because the past two decades industries have established and a lot of big players are there so we leverage threat intel for like some of the things that are already there for example we integrate with like crowd strike reversing lab to get insights from them and then our analysis runs on let's say parallelly to catch the points that they wouldn't be analyzing so in a way again bit of our own intelligence is there for based on our experience right so we are a bit disappointed that again the big players some of them are not doing that great of a job when it comes to like let's say office documents and we did a full research publication on the same that google outlook all of the big players email vendors none of them are doing as aggressive check as they should be and we're able to demonstrate that a simple malicious office file can go through and virus total will only give like certain hits where everyone should be flagging up at that point in time so again leveraging the intel where we can plus again our own intelligence is built out similarly for web application we are leveraging the intels that are around provided by the big players because anytime let's say a malicious website has been classified by someone if it is malicious then we immediately block on top of this what we are doing is we are building our own intelligence for the web because again the intelligence everyone has is a bit outdated it is not capable of capturing the new attack that we are seeing out there so that's where again the whole analogy of browser detection and response comes in so we are the first browser detection and response solution and the idea is the same that will provide the threat intel for the web-based attacks that are happening any attacks that other vendors are not capable of you know detecting that is something the void we are going to fill and that's that's our positioning at this point in time so and slowly we'll go behind other vendors as well but we realize that there's a big market for us to capitalize on the whole browser security space and again once we do that at that point in time we'll definitely dwell into the limitations various vendors are having and maybe have our own analysis engine and all of those segments.
38:11Again, just to sort of paint a picture for I think listeners in this space, am I right in saying if it's not what the solution that SquareX is providing, it's actually more of a solution where you're almost kind of using a sort of VM browser almost. I'm sort of trying to think of some other vendors i'm not going to name the names exactly but you know some of other big players there where i say oh you know our browser is like the safe browser and it's there's no latency and so on so forth but you're kind of effectively using a like a vm virtual browser or something to that extent like how would you categorize sort of the competition just from a sort of technology standpoint yeah that's a great question so in our case we are running as a browser extension on users browser so in terms of performance everything is super good there's no vm or container based access being provided for their regular workflow now what we have a feature is called isolation so let's say enterprise is not comfortable with you know users accessing a website on their regular device they can either block it so if you block it they can't access it or you allow it they can access but now with the isolation feature what happens is that's where we have a container that is created on the cloud and we have a desktop environment that runs on the container and that view is streamed back to the end device so this way again any website you access in the container it's completely isolated and the user wouldn't be in a way in the risk of you know security threat setup so that is one and our preference to be honest was to avoid isolation technology as much as possible because again it is running remotely right and it is a remote browser and users are used to using their regular browser they are way more familiar with it and they wouldn't be able to you know get that 100 % of the feel on the remote browser so our recommendation is to only use isolation for like some website not make the isolation as the main browser which a lot of other vendors are doing because again it gets super frustrating super annoying when you're seeing you know the latency go up and suddenly you're trying to watch a video it starts to lag and all of those things start to happen so yeah that's it again with square x the detection the analysis everything happens locally to make sure again the user experience is the best in any website they're visiting nice i think it's still helpful to call out to our listeners this is still quite evolving space right you know it's i think it's only been sort of fairly understood quite recently that actually the browser is basically where most of the problems happen and you know whether it's you know email as you've called out phishing is where this happens a lot and you know that that can obviously be where the email providers are saying look we'll we'll try and take care of this but equally at the end of the day it's still mostly happening in the browser to some degree so it makes a lot of sense that we evolve the solutions around you know what is happening in the browser from a security standpoint and you know unfortunately we can't just rely on you know i know google building in things into chrome like there's a big enough job there just to run chromium you know itself and unfortunately we're seeing things like firefox unfortunately kind of dying away a little bit because it's just it is too hard to keep up with sort of the the requirements of today and obviously on their side that's purely open source and you know i'm sure there's some funding there but it's difficult for firebox to kind of really keep up with the juggernaut that is chromium and chrome and etc you know as we sort of kind of come to a close here i mean where does square x go from here and like what are the sort of anything that you can share in terms of you know i know over the next six to twelve months like what what are the sort of things that we can maybe expect to start to see from square x i think that's a great question so at this point in time what we realized was that all of the vendor right so we have a couple of competitors I wouldn't say the name but all of them are not very security or attack focused and the they lack sufficient background for you know to go ahead build the detection to prevent the threats that are happening if they had then they would have definitely built it by now so our approach is again to go ahead and build out a full suite of detection across all the attacks we already have a lot of them build out but again to make sure that we just keep on compounding on the library of the detections that we have to make sure again anytime a user visits a website even before they see it we can go ahead block it so that is one thing additionally again there are a lot of features in the pipeline such as again private app access vdi replacement all of those those things are also coming in in a way to make it easy for the any enterprise that is out there to become like sort of a one shop for again all the all the requirements they would have in terms of security as well as making sure that the productivity is is amazing within the organization so that is something and just making sure that we are the thought leaders we are the innovators in the industry and that is in our dna you know knowing Vivek we can run or establish a business you know it's relatively easy to rephrase it that we can build a decent business by doing certain thing but here again it's just in our dna that we have to be the best in the world and make sure that we are the pioneers innovators and again super excited to envision the next couple of months a lot of these features parallel research are happening where we are trying to go ahead and block all of the attacks that that will be happening on the web so that's on the horizon i can't reveal a lot of information even though i'm tempted to but again i'll have to check with the company on how much I can deliver it yeah oh good I mean that's the great thing about having startups on the software engineering daily we don't expect to be able to hear about sort of the next 12 months that's usually sort of larger companies so it's just great to be able to have you here anyway one final point and this might be a question that a few people are just sort of still asking in terms of you know SquareX versus a VPN because I'm just thinking you know that might be the product that they're most familiar with in terms of something that might be helping them block malicious things could you maybe just summarize actually just how squarex goes beyond a vpn so that's a great question with vpn again you're still vulnerable to a lot of attacks it's just you know routing your traffic through a secure network or a secure location but if you think about it and let's say you get a malicious website right so now it is opening on your end device.
44:56Now at that point in time that website could lead to some zero-day attack that could happen and your device gets compromised. So that is one big concern we have around all VPN solution and what will end up happening is with VPN sadly macOS removed the support for split tunneling so all of your devices traffic is now going through like some location and in a way it will affect the user experience because again the websites will slow down. With SquareX disposable browser a couple of these features again it's a browser running within a tab of your regular browser so anything you do there again it's just a tab and that way again the surfing experience is much more better compared to vpn and more importantly from a security standpoint anything that happens there can't impact your regular device in any way let's say you go to malicious website it will impact the container that is running and these containers are like hardened from day-to-day basis, making sure it's properly updated, patched, and best, let's say, security hardening mechanisms are put in place to ensure nothing happens.
46:01In case, again, worst cases, some zero day happens and there's no way SquareX can block it on the container level, you're still safe because, again, it's a remote container that gets compromised. It's SquareX is a part of small part of info that might get compromised, but the user won't be impacted in any way. I think that's a great explanation. So as you've heard, any user kind of get going with SquareX. So just to be clear, where's the best place to go and what do they do from there? Best part about SquareX. So the domain is pretty short. It is sqrx.com. So again, just head to squarex.com and take a look at the videos that are there.
46:39In case if you want to try out the consumer version of the extension, then head over to the Chrome store and search for SquareX. we have above i think 4.9 rating with 200 000 users actively using the product that will again tell the story for itself so yeah on chrome store you can find us as well as on squarex.com and do check out the enterprise offering that we have it's quite innovative and it is relevant for every organization out there everyone is impacted by the attacks that are happening and sadly there is no security solution apart from us who can provide protection on the browser to combat such attacks nice that was sqrx.com so head there and check it out jesswin great to have you here nice to as always to have someone also in singapore to speak to slight novelty for us software engineering daily so thank you so much for making the time in your evening and hope we get to catch up again in the future here here how squarex is doing sure sure sounds great thank you so much gregor it was awesome to be here
From the publisher
Browser security aims to protect users from cyber threats encountered online, such as phishing, malicious extensions, and malware. It’s a complex, multifaceted challenge that’s increasingly important as cloud-based tools, SaaS platforms, and collaborative applications become the backbone of modern workflows. Jeswin Mathai is the Chief Architect at SquareX which is a cybersecurity company focused on
The post Browser Security with Jeswin Mathai appeared first on Software Engineering Daily.
