The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Azure Security Podcast
The Azure Security Podcast artwork

Episode 129: John Savill's Top of Mind

The Azure Security Podcast · 2026-06-12 · 43 min

0:00--:--

Key moments - from our scoring

Substance score

47 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber13 / 20
Specificity & Evidence10 / 20
Conversational Craft8 / 20

John Savill, Microsoft's CTO for Americas markets and industries and renowned YouTube educator, joins to explore the pressing concerns dominating enterprise security conversations. The episode reveals that while AI dominates every customer discussion, the real pain point is trusting what AI actually does - particularly around hallucinations, prompt injection, jailbreaking, and reasoning faults. The conversation emphasizes that zero trust and defense-in-depth principles remain foundational, but must now extend to AI agents through identity controls. Savill makes a compelling case for extending Entra ID capabilities (conditional access, risk detection) to agent identities rather than creating separate security models. The hosts highlight how AI implementations are forcing long-overdue data governance initiatives - companies implementing semantic indexing, data virtualization layers, and classification to support AI quality, which simultaneously surfaces and helps remediate years of deferred data security work. The discussion also covers passkey adoption, drawing parallels to early MFA resistance, and explores how synced passkeys (iCloud Keychain, Google Password Manager) can maintain security through conditional access even outside device-bound scenarios. This is essential listening for security leaders architecting AI governance frameworks, identity strategies for autonomous agents, and data governance programs.

Key takeaways

  • →AI security requires extending proven identity controls like conditional access and risk detection from humans to agents rather than inventing new authentication models.
  • →Data virtualization layers implemented for AI quality enable data governance teams to finally discover, classify, and protect siloed corporate data that's been neglected for years.
  • →Passkey adoption faces similar resistance patterns to early MFA deployment, requiring time and user education to overcome friction in setup and cross-platform usability.
  • →Trusting AI outputs demands least privilege access, read-only permissions where possible, and defense-in-depth guardrails that assume AI will behave unexpectedly.
  • →Semantic indexing and data quality directly drive AI outcome quality - organizations must treat data governance as a prerequisite for AI success, not an afterthought.

Guests

John Savill

Topics in this episode

prompt injectionAI agentsData virtualizationEntra IDPasskeysZero Trust securityLeast-privilege accessConditional accessSemantic indexingAgent identity management

Questions this episode answers

How should organizations approach securing AI agents and autonomous systems?

Extend existing Entra ID identity controls like conditional access and risk detection to agents rather than creating separate models, apply zero trust and defense-in-depth principles, use least privilege access, and implement read-only permissions where possible.

Why are companies suddenly investing in data governance and classification?

AI implementations require semantic indexing and data virtualization layers to achieve quality outcomes, which surface previously hidden data silos and permission issues, forcing companies to finally address deferred data governance work.

What are the main security concerns customers have about AI beyond traditional software security?

Customers are concerned about prompt injection, jailbreaking, hallucinations, reasoning faults, and the fundamental challenge of trusting non-deterministic AI outputs, especially when AI operates with broad permissions.

How do synced passkeys maintain security if they exist in multiple locations?

Conditional access policies still apply to synced passkeys, allowing organizations to enforce device health requirements and other controls, while benefiting from passkeys' resistance to phishing and domain-binding protections.

What role does data quality play in AI system outcomes?

Data quality directly drives AI outcome quality - organizations get garbage outputs from garbage data inputs, so implementing proper data governance, classification, and protection is essential for AI success.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

Genuine technical points exist - prompt injection vs. parameterized queries, harvest-now-decrypt-later, qubit durability jumps, Grover's algorithm - but they are buried in substantial filler: gas-station anecdotes, dogs in demos, parents refusing Apple Pay, and general conversational meandering that consumes easily half the runtime.

with prompt injection, it's not as easy as that. There is no single solution to implement to validate the input
the proximity element of it to stop people getting tricked to go and authenticate some bad actors

Originality

7 / 20

The framing of AI as surfacing pre-existing data governance debt rather than creating new problems is the one mildly fresh take; everything else - least privilege for agents, passkeys as phishing-resistant MFA, post-quantum urgency - is standard security-community consensus recycled without a contrarian angle.

AI has introduced a new problem and surfaced. It's not a new problem. It's surfaced a problem that's been there for a really long time
extending what we're doing with Entra to agents, extending what we do with Purview to agents. That to me it makes a lot of sense

Guest Caliber

13 / 20

John Savill holds a legitimate senior role (CTO, Americas) at Microsoft and brings 30-plus years of hands-on technical depth visible in his nuanced discussion of Entra, post-quantum, and agent identity; however, he functions primarily as an educator and Microsoft advocate rather than a practitioner who has implemented enterprise-scale security systems, and he frequently defers back to the hosts on security specifics.

my current role is I'm the CTO for America's markets and industries
I've been doing this stuff for over 30 years now

Specificity & Evidence

10 / 20

A handful of concrete anchors exist - Majorana 2 chip name, milliseconds-to-20-seconds qubit durability with a claimed 1000x increase, 2029 scalable-quantum target, MLChem/ML-KEM in Windows 11 S channel, SimCrypt, Grover's algorithm - but there are zero customer case studies, adoption metrics, or dollar figures, and the quantum claims are stated without sourcing.

We were getting milliseconds of durability for the things. Suddenly we're at 20 seconds now a thousand fold increase
we're now saying, Hey, 20, 29 scalable quantum computer

Conversational Craft

8 / 20

The hosts contribute their own substantive views (prompt-injection mitigation, crypto inventory complexity) which elevates the discussion above a pure PR chat, but the opening admission of 'no agenda' is fulfilled too literally - questions are loose, no claim is meaningfully challenged, and several minutes are lost to an entirely off-topic gas-station and Apple Pay exchange.

we really don't have an agenda. We're just going to talk about stuff
I don't trust it. I don't trust it at all

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker D42%
  • Speaker C35%
  • Speaker A23%
  • Speaker B1%

Most-used words

john24quantum24security15suddenly15data14point14start13understand13pass13mind12keys12back12customers11real11podcast10post10

Episode notes

In this episode, Michael and Sarah interview a man who needs no introduction, John Savill, the CTO of America's Markets and Industries at Microsoft. In this episode, John talks about a few security items that are top of mind for him, and what he is hearing from customers. We also covered news from Microsoft Build, Michael's new book, as well as the latest post-quantum crypto news.

Full transcript

43 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: M.

Speaker B: Welcome to the Azure Security Podcast, where we discuss topics relating to security, privacy, reliability and compliance on the Microsoft cloud platform.

Speaker C: Hey, everybody. Welcome to episode 129. This week it's myself, Michael, with Sarah. And I guess this week probably needs no introduction, but it's John Savill here to talk about what's kind of top of mind for John. Uh, but before we get to our guest, let's take a little lap around the news. Uh, Sarah, why don't you kick things off?

Speaker A: Well, I'm going to do the really obvious news. Uh, well, for. For the time we're recording from me, which is last week, it was Microsoft build. Uh, you may have seen this person's face in the keynote. If you didn't, obviously you should go and watch that. But, um, in all seriousness, I was, uh, showing M Dash, which is. Which we're hoping to have an episode on soon, actually, if I can grab one of them. They're just very busy at the moment. EM Dash is our code scanning harness. It's very cool. Um, it's currently in a private preview when we're recording this, but you can sign up and request access. Keep an eye out. It will go public preview in ga, hopefully in the not too distant future. Or there were also some other sessions that build around managing, uh, your agent estate with Agent365, which obviously has a security aspect. So all the sessions are now up on YouTube. So if you were not there, if you weren't lucky enough to go to build, you should go check those out, uh, because they're all online now. Um, that's it for me this time, Michael.

Speaker C: And make sure everyone spots the little Easter eggs. About your dogs, right?

Speaker A: Uh, yes. Yes. Okay, so if you watch my demo, the EM Dash demo, see if you can see the Easter eggs for my dogs. And my shadow demoer's daughter, uh, there are some Easter eggs for her too, because that's what we do if. Well, some benign Easter eggs in the corner.

Speaker C: I always add Easter eggs to things like that.

Speaker A: Always.

Speaker C: Just little subtle things.

Speaker A: Oh, you have to. Yeah, you have to. You have to. As long as it doesn't. It's only in the corner. And there were a few people who found them unprompted. They were like, team Grayson. And I was like, yeah, of course, like Team Grayson. And, uh, they were like, sarah, you put your dogs in your demo. I was like, of course I did. Like, what kind of a question. Of course I did. If I can. If I can, I will.

Speaker C: All right, so as to my news, uh, first of all, I have a new book coming out. Um, it will be available the first or second week of July this year. Uh, it is called Threat Driven Software Development. I've talked a little bit about this in the past on the podcast, or at least hinted at it. Uh, it's quite different to other books that I've written. It still focuses on software engineering and software security and so on, but it pulls in information at Microsoft around the Secure Future Initiative as well as Microsoft Security Development Lifecycle or the sdl. However, every chapter looks at whatever the topic is through the, through the lens of Threat Intel. Uh, so one of the co authors we've had on this podcast before is Sherrod de Grippo and she wrote some flavor text at the start of every chapter called the Threat Intel Perspective. Then after that, uh, the three of us, myself and Sean Hernan and Lee Holmes would then go and write the actual technical content. Um, Sherrod also has a chapter on Threat intel, like modern Threat intel, right at the very beginning again to really set the tone of the book. The other, uh, two news items that I have, uh, both of them are to do with post quantum cryptography. The first one is that Azure SQL database now supports transparent data encryption AES wrapping keys using managed hsm. As you're probably well aware, um, in a post quantum world, RSA and ellipset curve become essentially destroyed and we now have to look for alternate methods. And the symmetric way of doing that is to use AES key wrapping. So that's available. There's also a asymmetric way of doing it, MLChem M, but that's not available just yet. So yeah, AES key wrapping is available manage hsm. The other one, which is really cool, uh, this came out at Build, is that we've now got a version of S channel in Windows Windows 11 that supports MLChem on TLS 1.3. So MLChem, if you listen to our last podcast that I did with Jack Richards, was on MLChem, uh, well, um, all sorts of post Quantum stuff. But MLChem was the big one, which is the key encapsulation mechanism, uh, that is now available uh, in Windows 11. You have to enable it though. Um, so you have to call, uh, set TLSECC curve and then the actual um, hybrid group and that will then turn it back on. So I'm going to write a blog post on this in the next few weeks. But yeah, it's great to see that it's available now in Windows 11 and eventually will be in Windows Server as well. So a couple of post quantum announcements. There's a lot of headway being made by Microsoft and it's uh, good to see these things coming out. All right, let's turn our attention to our guest. As I mentioned at the top, our, uh, guest this week needs absolutely zero introduction, but, uh, it is John Savill. John, welcome to the podcast. We'd like to take a moment and introduce yourself to our listeners.

Speaker D: Uh, thank you. Uh, firstly, thrilled to be on the show and it's nice uh, to talk to you both. Bit intimidating uh, talking to both of you, but, uh, I've been a Microsoft fan, I guess, since I was 18. Like I've been doing this stuff for over 30 years now. It was a, uh, a hobby. And I was lucky enough that my hobby turned into a job. But my current role is I'm the CTO for America's markets and industries. But I think if anyone does know me, they know me because of the YouTube channel. I've been sort of focused on that for maybe like seven or eight years now. And just, it's my way of learning and my way of trying to help other people, like, give back. And so it's just a lot of fun creating content to help people understand something. Because I think if you understand something, you're not scared of it anymore. And if you're not scared of it, you'll go and use it and take advantage of it. So that's just something I enjoy doing.

Speaker C: I think it's more than that though. I mean, I mean the number of people who've asked a question and my response is always, well, just go and watch one of John's videos. It's 15 minutes, 20 minutes. And uh, you know, I'll answer the questions that I love the format of your videos in front of the, you know, electronic whiteboard diagramming things out. And there's something that really irks me. Not about you. There's something that really irks me about people who do technical presentations. And that is they assume the people watching, you know, a whole bunch of stuff. And you go as an angle of assuming the people don't know what you're about to talk about. And look, don't get me wrong, people who know this stuff. Oh God, can John just like, just get, just get to the concept of

Speaker D: the point, you know.

Speaker C: But the other 97% are like, thank you for explaining that stuff to me.

Speaker A: Right.

Speaker C: Um, because you got to build upon baseline knowledge. Right. So I love your videos. I think they're awesome.

Speaker D: And the benefit I have is I'm not that smart. And so it works out really well for me. So I have to try and how did I understand it? And then I try and like replay the steps and the layers of knowledge I had to do to get there. So it's very natural for me to do it that way.

Speaker A: So, John, I have had an actual, uh, conversation where someone said to do this, you would need John Savile level knowledge. So you've actually become like a rating of knowledge.

Speaker D: Now what they were saying, though, was a very low level of knowledge. You're interpreting it the wrong way. It was a just. This is just a John Saville level of knowledge to get this one.

Speaker C: So I want to ask you honest question of you, honest question, how many, how much do you learn preparing for the videos? Because whenever I write, write anything, whether it's a blog post, whether it's a book, I learn a lot researching to be able to put it into some form that can be understood by more people. So do you learn a lot while you're doing the videos?

Speaker D: Oh, I do. No, I mean, so, I mean, what I said is very true. Like, part of the content is, yes, I create stuff because I want to help people. Like, to me, it's my way of giving back a little bit. It's why I don't monetize the channel. But I learned a phenomenal amount because if you want to explain something to someone and if you want to be able to explain it in a way they can digest, you have to really understand it. You have to go to a level of understanding way beyond what you're actually teaching so you can try and frame it the right way so someone can take the concept and do something useful with it. So no, I, I do not know most of what I, I cover at the start. I have to go and learn it and play with it and break the thing. And then, yeah, I, I learn a massive amount doing the videos.

Speaker C: Do you find bugs along the way? I always find bugs.

Speaker D: I have found bugs along the way. It's funny, especially funny enough with some of the Entra stuff. A lot of I do stuff early on with the Entra things and then other times I found this is not working right as I. Oh yeah, don't mention that. And then they'll go and we'll work on that. It'll be fixed by the time you release.

Speaker C: Okay, all right, so let's get stuck into the actual content now. We're talking about your YouTube channel, which, by the way, we will put A link in the show notes. Um, so this topic, no one's ever heard of it. Yeah. Right. Um, so the topic of this episode is, uh, John Savill's Top of Mind. So let's just start with. Look, I want to tell everyone, by the way, we really don't have an agenda. We're just going to talk about stuff. So, uh, let's see how this goes. Um, so let's just go. Let's start off with, um, you know, what's top of mind? Like what are customers talking to you about? What sort of, you know, is really sort of bugging you right now? What's, you know, what, what things are changing that are of real interest to you, you know, so what's really, what really is number one top of mind right now?

Speaker D: Yeah, I mean, what's interesting about when my role changed beginning of the year and I have a lot more customer conversations now with like the leadership and what's concerning to them. And obviously, as you would expect, AI is kind of on every conversation we ever do. But what is really interesting, it's not just AI, it's about trusting what AI is doing. And so we've moved into this new shift in thinking that in the past with software, hey, we had test harnesses, we had test scripts, input A, do we get output? B, we're good. Like, it doesn't work with AI because suddenly it's this creative thing and this non deterministic nature is massively concerning to every customer because there's the element of security and AI introduces a whole new set of security concerns. Like, yes, all the other stuff we always think about still applies, but now you have the prompt injections and the jailbreaking and the hallucinations and the reasoning faults and all these other things. But they're super concerned about trusting what the thing is actually outputting. And that is something that we're constantly trying to help the customers understand in terms of how do you trust what this creative intelligence is generating, but also making sure it's staying within what you need it to stay within in terms of like security policies and other guard rails. So that is the number one thing that's keeping customers up right now is how do we control this AI thing? And that's great for me to be on this show is like, I know what I think about and I know we talk about evaluations and we talk about governance and we talk about permissions, but like, what do you see? I mean, that's kind of interesting to me is like, how do you answer that question? With customers like, hey, how do you trust the agents?

Speaker C: I don't. And that's why you have to have things like least privilege. And that's why you have to have a whole bunch of other guardrails in place, assuming that the AI is going to go all wonky. I don't. I mean, I think if you look at some of the very earliest incarnations of openclaw, you know, people were just running it without regard for any security boundaries, any guardrails whatsoever. And you know, it got a bad name for itself, right, because it could do anything. Well, if it's running as you with no other guardrails in place, then sure, then it matured, you know, and then we saw changes and so on and so forth. So I don't trust it. I don't trust it at all. I don't mean that in a really cynical way. Perhaps I'm just too old to trust input of any kind. I mean, it's just an input problem. Again, it's actually harder than that. Right, because in the old days, with SQL injection, for example, we know how to mitigate that with parameterized queries, but with prompt injection, it's not as easy as that. There is no single solution to implement to validate the input. I mean, don't get me wrong, we have a whole bunch of guardrails that can take the input and check if it thinks it's good or bad. But even then you don't really know. Using AI to check AI. And so that's why I just run absolutely everything, um, least privilege and a whole bunch of other guardrails read only where possible, as opposed to read write, which is just least privilege. That's where things like identities come into play as well.

Speaker D: Well, I think that's, I mean, that's the super interesting thing. I think initially with the AI, people just like, oh great, it's intelligent. You, you do all these things, you give it all this access. And I think they forgot about a lot of kind of the zero trust and the defense in depth. And I think a lot of companies are coming back to that now, which is why suddenly companies care to your word. The identity, it isn't just, hey, it should always just run with my permissions. And if we think about autonomous agents and AI teammates as we go in the future, the identity is also saying that everyone is talking about and what is the right way of doing it and how you secure it. And that's one of the things I enjoy talking about. So identity has always been a passion of mine, like I love the, I was an ad guy and then obviously Azure AD and Entra id, but I like the agent ID and the agent user ID stuff because to me it's supernatural. Like if you think of humans and we're used to the idea of we're giving the mentor identities and we have conditional access and we have the risk detections and we've built up a pretty strong set of capabilities and we understand it like companies understand it. So I don't understand why you'd want to do something different for agents, which fundamentally are going to be doing a very similar thing to humans. And so why recreate a wheel? Like to me it makes a lot more sense that you've got something you trust in already, you've got skills around, you just have to tweak it a little bit. Like Sarah, if, If Sarah works 247 I'll be suspicious. Um, if Sarah downloads 500 documents in a minute, I'll be suspicious. But hey, we just tweaked the behavior of what we expect a little bit and I think we can take the same solution. So I, obviously, I'm a Microsoft person, I've always been a Microsoft fan, but I genuinely like the approach of just extending what we're doing with Entra to agents, extending what we do with Purview to agents. That to me it makes a lot of sense for the organization.

Speaker A: I think, I think one of the things that is very obvious to me having conversations with folks though is that obviously like with Purview and Entra, we've had all this stuff, a lot of these controls in the non agentic, non AI field for a while, but people haven't always done them super well because they're difficult and they take a while. And so now what I find is one of the biggest things which I think is a good thing is that a lot of folks are particularly with data security because I feel like data security was always something people just, ah, we'll get back to that, we'll get back to that. Like, you know, we're going to label it later. It's too big a job now people are realizing that they can't really, really well, they can do AI without doing it, but it increases the risk because AI is really good at finding data that you shouldn't have access to and haven't protected way more than human manually. And suddenly people are like putting more focus on stuff that's been kicked the cans been kicked down the road for years, which I think is a good thing. Uh, I know it adds more Stuff on people's plates to do. But I think long term will be a good thing. I don't know. What, uh, what do you think, John? You've talked to way more customers than me now.

Speaker D: So it sounds like you're saying security for obscurity is not a good corporate strategy. I don't know. It sounds like that's not, not the answer.

Speaker A: Uh, yeah, no, it might not be.

Speaker D: No, I mean, you're right like this. It comes up every time because we've, I, we've kind of accepted now, I think the fact that the quality of the data, uh, drives the quality of the outcome. Like we used to have garbage in, garbage out. With AI, it's the garbage in colorful, different shapes of garbage, but it's, it's garbage all the same. And so suddenly every company, to your point, is putting a semantic index over their corporate sort of data structures. So suddenly I can find everything. And so those over, uh, permission sites, those, all those things suddenly get found out. But also, if they want a really good AI application, it has to be able to talk to all of the data. And so suddenly they're putting these data virtualization layers in their company that they either shortcut or mirror, but everything is suddenly available, which is great for the AI to work, but it's actually an opportunity for the company to suddenly get a handle on the data. Because for once, there's now an endpoint that the data governance can talk to. So suddenly I can find the stuff, I can classify the stuff, and I can protect it. Whereas in the past it was just all siloed. So I think to your point, AI has introduced a new problem and surfaced. It's not a new problem. It's surfaced a problem that's been there for a really long time. But fortunately, the technologies we have to put in place to make AI work like that data virtualization layer is also the way we can kind of solve it. Because suddenly the data governance can see all the data, uh, and actually start to protect it. So yes, it's a whole new set of problems, but it's a problem that had to be solved anyway. So I don't know. I think it's a good thing in the end that it'll actually get fixed and then it fixes it for the humans as well.

Speaker C: I have a take on the obscurity thing. I don't mind security through obscurity, as long as it's not your only defense. That's, uh, you know, slowing an attacker down is fine. But yes, it can't just Be your only defense. That's the, that's my, my take on it.

Speaker D: Well, I guess we found it was the only solution for some companies because it was just as soon as it found it, like, hey, I can read everything.

Speaker C: I was like, absolutely, absolutely not the best day.

Speaker A: So John, what is next on your hit list of uh, things. Things that are top of mind for customers?

Speaker D: I don't know if it's always top of mind for customers, but it's something that always comes up as something they should be doing. And it, it's that fundamental. Like we talked about least privilege. And one of the huge challenges I think people still struggle with is just that authentication and strong authentication and I think passkeys, like, I'm uh, a big fan of the passkeys. Funny, I just did a video on now we have passkey registration campaigns that we've kind of got in entry id and I would love to see like a greater uh, adoption of pass keys because I think for the, the average user it adds so much protection for them. Like to me the, the two biggest things is yes, they're technically easy to use and yes, it's a strong oath, but the proximity element of it to stop people getting tricked to go and authenticate some bad actors like, hey, I'm the help desk, just gonna check this, give me your code. And then the fact that it will only work against the legitimate domain that it was given for, so I can't be tricked to do something slightly similar to me, I really think there needs to be a great uh, push on getting these pass keys adopted. And I know we've sort of recently added support for the synced pass keys now within the ecosystem. So hey, I can put it in my icloud keychain or the Google password manager. And I know that terrifies some sort of corporate uh, identity sort of people that the key is now not in a place that key is now floating. And one of the things we talk about is, well with conditional access is still applying, I could still lock down the use to be a sort uh, of a healthy device, the managed device. I don't know what you see. So like from a passkey perspective, again, I'm trying to learn from you guys on this call. Like how do you position the confidence in a synced pass key where device bound is lovely. I know it only lives in this one place if it's synced. How do you have that conversation around? Well, yes, it exists in multiple places, but hey, we can still trust it because of X.

Speaker A: Well, I'll Say that I think the conversations I've had with past keys, which are probably not as extensive as YouTube, is that I feel like it's a bit deja vu y. Because do you remember when we first started doing mfa? And, um, you would get pushback from people being like, it's too hard. I don't want to do it. And it's holding up our workflow and for particular. And then that sort of went away over time, but you'd still have certain groups of kind of users, um, who would still kind of hold out about wanting to use mfa. And I feel like we've almost got past that now, but I'm seeing it kind of start again with pass keys almost. Um, because pass keys are a little bit. Sometimes they're fiddly to set up. I. I find. And. And then. And. And like, for someone like me, I'm gonna. Like. Because I'm stubborn and I'm like, no, I will make this work, because that's me and my. But for a lot of user bases, they're just like, nah, this is too hard. And so I think. I think we've got like that adoption challenge again that we saw with mfa, at least for certain types of oops. And I'm sure we'll get through it with time. I'm not sure I have, like, a magical answer. I feel like it's just same as we did with mfa. It's going to take a bit of time and education and of course, listening to what the, um, what the gotchas are. I mean, I can tell you that on my phone for ages, I made a pass key on my Gmail and it wouldn't work. And it kept saying I would try and log in and it would be like, nah, nah, nah. Like. And I was like, I know how to make a passkey. How dare you. And it turns out that there was something. After I did some research, and when I say research, I asked AI of obviously, obviously, the iPhone defaults to using different stores and because the passkey was somewhere else. But it doesn't explicitly say that anywhere. It's not. It just says, oh, your passkey isn't working. And I remember being really grouchy because I was like, uh, I think I can do a passkey, or I hope I can make a pass key that works. And, um, it took me a little while, but I'm the kind of person who will go and dig into it and understand. And there's a lot of user bases. And if we think we want everybody to use passkeys, which we do. I'm like a tiny proportion of a user base that would go and try and troubleshoot it myself because I'm a stubborn so and so and so. I guess. Yeah, that would be my thing, I think about passkeys is there's going to be a bit of like, adoption friction again. So it's going to take a little while, but I don't know. Michael, what do you think?

Speaker C: Yeah, I think the number one question I get is how is it different from mfa? Um, and I just keep it really simple with people and just say it's essentially. And John, you correct me here if m. I'm wrong, but I sort of simplify things a little bit. It's like essentially phishing resistant mfa. It's still mfa. It's just something that's stronger than mfa. To your point, it can be tied to a domain and, uh. And it's phishing resistant. Is that a fair comment or am

Speaker D: I. Yeah, no, I, I think we even call it that when we talk about like, authentication strengths. In Entra, we have phishing resistant MFA and we have pass keys in there because to your point, it. It's supposed to be out to protect the user from being tricked. They can't authenticate some remote person and they can't click on a fake domain because it won't let it. So I, I think it's a great thing that anything that adds protection to the user because it's in the movies we see the hacking and the hacking is always, hey, they're dropping a payload into something or other and it's exploiting. Really most of the hacking is they're phoning up Bob and it's like, hey, I'm from the it. Uh, I'm just checking you've been hacked. Do this. And like, if we can stop the users being able to be tricked, that closes probably a massive portion of the attack surface. That's real. Yeah, I don't think there's that many people really dropping these worm, um, payloads to go and hack into X, Y and Z. It's Bob is really the problem.

Speaker C: Bob in it. Yeah, it's funny you should bring that up. Like, my two recommendations to sort of normal human beings outside of IT are one, use passkeys for your norm. Like at least for your. Anything that you care, like, really, really care about. Like, you know, uh, your bank or anything like that. Just set up passkeys for everything. And the second one is use your cell phone and Apple Pay or you know, Google Pay or whatever. When you're buying gas. Um, as opposed to using a credit card. As opposed to swiping a credit card. You know, from a skimming perspective.

Speaker A: You know what's really funny on that? So, uh, my parents came to stay recently and they are fairly technically literate for people in their age bracket, but they will not. I discovered, uh. And um, particularly my. They, I discovered when they came to stay with me, my dad will not use Apple Pay. And I was like, why? He's like, I don't think it's secure. And I was like, dad, it's fine. In fact, it's probably better.

Speaker C: Yeah.

Speaker A: And, and, and he was like, oh, no, no, no, no. And I was like. So I was, I was trying to educate him. I was like, honestly, dad, also then you don't have to carry cards around because. And they can't be skimmed and blah, blah. And I was explaining it to him. He wasn't having it. And I would say that my, uh. Luckily my parents do not listen to this podcast. I would not call my parents Luddites as far as, uh, tech goes in general. And I was really surprised. So Apple Pay all the way or whatever. Electronic wallet.

Speaker D: Everything's scary if you don't understand it. It's scary and it can be compromised. It's just, hey, if you can get people to understand. Twice I've had my credit card stolen from gas stations, like doing that skimming thing when I was younger.

Speaker A: So, yeah, uh, I've had my card details used, but it hasn't been at petrol. Petrol stations, by the way,

Speaker D: my adopted country. It's a gas station now. That's right.

Speaker A: But I've definitely had my car details stolen. Someone bought flights in Japan, budget flights in Japan on my card once. I have no idea how they got my, my, uh, number, but there's so many ways, right?

Speaker C: So I will not buy gas from a gas station that doesn't allow me to use my phone. I just, it's just not worth the risk. I mean the fact that you've got something that can read a credit card outside, unprotected, accessible to the bad guys so easily, I just don't. If I have to, if I absolutely, like, again, I'm on E for enough. I will choose the gas pump that is closest to the. The shop or whatever is associated with the gas station in the hope that they haven't put a skimming device on. I always check. I don't know you. I always wiggle and see if there's anything moves.

Speaker A: Wow, Michael. And you know what? I just Remembered as well. Uh, obviously, uh, for people who might remember, I did live in the US For a year. Um, I forgot. So for those of you who have not been to my side of the world, and actually quite a lot of places in Europe, there is a difference, uh, about buying petrol, gas, whatever you want to call it, um, is that we don't always have card machines outside at the pump. You go in to pay, and you pay after you have put the petrol in, which I know shocks many Americans because in theory, you could drive off. Except we don't. Because we're good people. Well, most people are. So we don't have that same problem in Australia because you have to go in to pay. Like, there are no card machines at the pump.

Speaker D: The things you cover in this podcast. And I've learned E for enough. That's a new one on me as well.

Speaker C: That's the eternally optimistic side of me. Um, all right, I think we've done pass keys to death. Everyone use pass keys.

Speaker D: Yes. Yeah, they're good.

Speaker C: But we didn't ask.

Speaker D: No.

Speaker C: You know, though, John, we didn't answer the question about what, you know, what, uh, what feedback have we heard about potentially having roaming pass keys between devices? Personally, I've not heard anybody complain about them. A lot of people, certainly outside of it. Uh, the normal question I get is what the heck is a passkey? So I haven't got past that door yet. But from a corporate perspective, I mean, if people don't want it, then, uh, my guess is it's policy. You can turn it on or turn it off. Is my.

Speaker D: It's just a policy. Yep. Yeah, it's easy to turn it off. It's just. I think somebody have got scared of it. But not a valid. Some people you do want to know exactly where the pass is at all times, but for a lot of people, you don't need that level. And again, this process still applies. It's still done at part the sort of the actual authorization to use it for a thing. So, yeah, I don't think it's as big a problem as people make out.

Speaker C: Yeah. All right, so what's number three? Top of mind for John Savile from a nerdy perspective.

Speaker D: And I think it's becoming a very real perspective. I think the quantum thing. And obviously, because this is security.

Speaker A: Oh, here we go. I just. I'm ducking out here because this is Michael's baby.

Speaker C: I did not page on to say

Speaker D: that, you know, I. I spent a whole bit. I did a video on what is quantum Computing. And you talk about learning stuff like I had no clue.

Speaker C: It's a good video, man.

Speaker D: And that video must have been some of the hardest research because I'm not that smart. I'm not that good at math and everything you look at quantum math comes into it at a certain point. But I think it, it's fascinating and, and you look at uh, the behaviors, it's like, well, that's impossible. How can. If you measure it, it collapses. Like how does it know? I looked at the thing like how can it transmit state over infinite distance? It like. But I think from a quantum perspective and what we just announced at Build. So you talked about the build stuff. So the Majorana 2 and Qubits kind of the quantum version of the thing. We were getting milliseconds of durability for the things. Suddenly we're at 20 seconds now a thousand fold increase to me and that, that's massive. And we're now saying, Hey, 20, 29 scalable quantum computer. So if we think about quantum is fantastic from a, uh, hey, there are things you cannot model with a classical computer because of the way the combinations and the dependencies between them. Um, suddenly I can model like real world and solve medical things and find new materials. But it also suddenly thing you mentioned at the start about, okay, the new capabilities we're adding our old sort of asymmetric encryption that relies on some math things are really hard to solve. Like longer than I think it's like history of the universe thing. Suddenly there are these algorithms in quantum, um, that nudge you to the right answer, I think in minutes. And so if in three years potentially we now have this way to break what most of our communication kind of relies on, I think the, the post quantum cryptography stuff. And even today, stopping people just storing the data they can't decrypt, but then harvest it later, it becomes a really real thing. And I can't remember the name of the technology. I know it's based on lightsabers and warp cores. Like there's two things that we kind of do that I forgot the exact terms for it. Well, I remember I did the video that I was holding a lightsaber because I know it's sort of the crystal that would get the lightsabers to work. The code name. But I think, oh, uh, crystals.

Speaker C: Kyber.

Speaker D: Yes, Kyber. Yeah, that's it. And right. And then the warp core stuff. But like I think it's not being taken seriously by enough companies today that this really is around the corner. I think people said no. Is this 50 years away or it's 100 years away. And it's really not like there are things that I think everyone should be thinking about today, like does that traffic have to be on a public network today? Or can I keep this within a private network so someone can't harvest the thing? And what work am I doing for my services to start looking at the post quantum cryptography stuff? Like, I, I think it's a really real thing that people are going to leave till the last minute and then be like, oops. And. And I know that's Michael. So I was excited, so I was like, oh, okay. I know Michael's into this stuff. And it's like. And I know we're doing a lot of work on it as Microsoft. Uh, I'm curious, what, what are your thoughts on that?

Speaker C: So you talk about the Majorana 2 chips. What's fascinating about that is not just the fact that it exists, but the. Like, I was going to say that the quantum increase, but I figured that would be a dad's joke. Dad joke. Um, but the huge increase, like you say, in durability of the qubits is. And that's in a short amount of time. So give it another four or five years. Right? I mean, we're going to make even more leaps and bounds. I want to throw something at you two right now, and I hope you're sitting down because this, which I know you are, but this is going to. When I say this, you're going to be blown away and obvious at the same time. Quantum computers actually model the real world. Our current computers do not. Like at the end of the day, when you go all the way down to the minutiae of the quantum world, we're just modeling the quantum world. That's all we're doing. And because we're doing it natively, it's incredibly efficient. Um, but also the fact that you have. To your point, we have these qubit things where they can all hold all the values at the same time, where they're probability and then you observe them and then it collapses and then you have a higher probability of one of the qubits being a specific set of, or some of the qubits having a specific set of values. And you run that multiple times and it's basically just an averaging out of the probabilities of the results that you get. But it's just modeling the real world. That's all it really is. Um, but to your point, uh, yes. RSA elliptic curve, Diffie, Hellman, all These, the asymmetric algorithms essentially become incredibly weak, um, because quantum computers are very good at sort of algorithms. So for example, factoring large numbers, which is the root of RSA, or the mathematical problem that's hard in RSA is very easy with quantum computers. And they've got discrete logarithms with elliptic curve and so on those functions, those sort of algorithms are very easy to model um, in quantum computing. And they're very efficient with AES, which is symmetric. There is a speed up called Grover's algorithm, but it's still basically brute force. It's not an algorithm, it's just brute force, uh, of checking keys. But there is a speed up from Grover's algorithm that uh, came out in the mid-90s. So yeah, it's a fascinating area. And to your point John, you're seeing a lot of customers sort of what seems to be like waiting till the last minute. Think Y2K. How many people waited till the last minute for Y2K? Virtually nobody. And do we have any real problems once 2000 rolled over? No, because people have done the work. You can't wait until the last minutes. And I really want to, the last minute and I really want to point something else out and that is from my perspective, from the customer calls that I get, the customers that really care, really care, like they really want to know what our plans are, what we're doing, what the industry's doing. And we're sort of looking at their plans as well for rolling things out. They know that no one can do all of this overnight. It does take time because it's very, very layered. You got to get all the, the substrate done and then you got to build on top of that substrate. For example, you got to get the low level crypto in place. That's all in place in Windows and Linux. Now in Windows it's a thing called SimCrypt. And on top of that you've got things like TLS, TLS 1.3 with MLChem for doing the key encapsulation. Then on top of that you got the applications that now got to take advantage of all of these things. And to your point John, if you can do something where you have like a, you don't have to go over a public network, even better, right? Because that way it's not being exposed for um, harvest now, decrypt later. I could keep going, but I won't.

Speaker D: No, I mean, and this is interesting to hear your thought on it because to your point, like I've maybe had two customers Actually ask seriously about it this year and it should be a lot higher because, yeah, I think there really is a, uh, I don't know, a, uh, denial going on about that it's coming and it's real.

Speaker A: I feel like it's. Because I haven't had a ton of chats about it with people. I feel like it's one of those, ah, yeah, Ah. But, uh, it's a bit like, you know, back in the day, I. I feel like again, we've mostly moved past this when people would say, oh, but why would someone hack me? You know, why would someone hack me? I'm so small. I'm just this and blah. And, um, the answer is because they can. And you're on the Internet, so you expose yourself. And we also know now that threat actors will actually purposely go for, like, smaller businesses because they know their protections tend to. To be less and it's less effort. But I feel like it's a bit of that mindset that, ah, yeah, we'll be fine. It still ages off. And even if it does become a thing, who would hack us? It's like almost like conscious naivety, like, sort of. I don't know how else to call it, like sort of being like, mindfully kind of like, it's not us, we'll be fine.

Speaker D: And I think it comes back to that thing. I think a lot of people don't really understand. Understand it. And it seems like there's movies out the quantum route. Like, it seems like pure science fiction. It's like, this is not real. Like this is not going to happen. And so it's just like, I'm not gonna think about it. It won't impact me if I don't think about it, but it's just not the case. Like, we really think we're a few years away from this knocking on the door. And, uh, I think it's critical people really start to look at, uh, their services, their apps, their capabilities and plan. To your point, Michael, like, we have it now in our library. Like, you can start to use and look at these things now and start planning for it. Like, go and discover where you're doing encryption and start thinking about how you're going to address it.

Speaker C: Like, yeah, that's the first thing is you got to know where you're doing crypto, right? I mean, you got to know where it is everywhere. And that's the, that's the first thing. I've actually been working on a few things because the problem m. Is some of, Some of the. Some of it you can do statically and some of it you need to do dynamically. So there's no like one single way of like, determining where you're using crypto. One thing that's really hard inside of Azure is we're very dynamic. Like, it's incredible. It's an incredibly dynamic back end. And so, you know, we've done our crypto inventory work at the back end, but it's, it's incredible. You know, it changes every day. Um, but yeah, to your point, you've got to know where you're doing crypto and if you're doing any sort of, any kind of key wrapping or key exchange with asymmetric algorithms, that's the biggest, the big issue right now. Um, and that's why TLS 1.3 has to be used everywhere, because once everybody has the post quantum algorithms, they can essentially just turn them on. Um, and as I mentioned at the top of the podcast, we now have a version of Windows 11 that has S channel which does the TLS support. And um, it has the post quantum. Yeah, it's in preview, but you can start kicking the tires on it right now. Very important.

Speaker D: Yeah, don't wait.

Speaker A: Let's sort of wrap up this episode, bring it to a close. Otherwise we will be here forever. We'll have to get you back on for John's thought version two in like six months or a year to see, see what's changed with customers. But John, we, uh, we always ask our guests a couple of questions, which is, what does a day in the life of John Savile look like?

Speaker D: It is highly consistent and highly boring. So every day I get up at 3:30, I work out from 4 to 7, then 7 till sort of 4 or 5, work, then family time, um, go out in the woods and try and get a bit of nature in and then go to bed and, and the work day is customer meetings. Sometimes I'm traveling for customer things, meeting with product groups. Um, I am lucky. My, my job is for the most part my hobby as well. So I'm always learning like to me, staying curious. Like, I'm still as curious as I've ever been. I'm still trying to learn stuff and find out what this thing is and what this thing can do. And I still love to be challenged and find new things. So for most days it's a, it's a good, happy, positive day.

Speaker A: That's pretty cool. And I can confirm, by the way, because I have been on work trips with John that he does indeed work out for Three hours and, and I've also talked to you at times in my afternoon where you most m. People would be asleep. So can confirm that John really does get up that early to work out. It is true. And then last question is. So the last thing that we uh, ask our guests, John, is for our listeners, if you wanted to leave them with a final thought, what would it be?

Speaker D: Joe, Honestly, I think in this day and age more than ever it's just keep an open mind and be curious. Like I think today it's the most important thing. Like don't be afraid of something. And so then close your mind and say I'm not going to look at that thing. Know what I'm doing today is the right thing. You're quickly gonna become irrelevant. So I, I think if you keep an open mind and look at everything that's out there, some of it's not going to be anything useful. But if you take a look, try the thing out, I think that's how you stay ahead and that's how you stay relevant and informed. So just be curious and keep an open mind. I think that's, that's the key to success in this day and age.

Speaker C: Yeah, I really couldn't have said it better. I mean just stay curious. It's, I think it's just so important, you know, really important too. Just little silly things that just interest you and I think it makes you a more well rounded person. Uh, John, thank you so much for joining us this week. I always learn something from my guests and, and uh, this was absolutely no exception. So it was an absolute pleasure having you on the podcast.

Speaker D: Thank you for having me. It was a lot of fun and

Speaker C: as Sarah said and hopefully we can have you back in 6 or 12 months. Version 2 and to all our listeners, we hope you found this episode of use and of interest. Uh, stay safe and we'll see you next time.

Speaker B: Thanks for listening to the Azure Security podcast. You can find show notes and other resources at our website az. If you have any questions, please find us on twitter@azuresecpod. Background music is from, um, ccmixter.com and licensed under the Creative Commons license.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • AI Agents, False Productivity, and the Sales Team Reset with Gabe LarsenMake It Happen Mondays · on AI agents91 / 100
  • Pricing in the Age of SaaSpocalypse | Emanuel MartoncaProductized Podcast · on AI agents89 / 100
  • How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200MThe SaaS Podcast · on Zero Trust security87 / 100
  • Why a $1.2B exit felt like his biggest failure, and the customer-obsession thesis behind AgencyThe GTMnow Podcast · on AI agents86 / 100
  • Unresolved.cx - Resolution means something different at every company - Craig Stoss - KODIFUnresolved.cx · on AI agents84 / 100
  • SPECIAL GUEST!! ClickUp's Co-Founder Chris Cunningham 💸 The $1,000 Content Hack Big Brands Miss | Ep. 532Do This, NOT That: Marketing Tips with Jay Schwedelson · on AI agents82 / 100

More from The Azure Security Podcast

All episodes →
  • Episode 128: Post Quantum Cryptography87 / 100
  • Episode 127: Threat intel update and AI87 / 100
  • Episode 126: Microsoft Baseline Security Mode80 / 100
  • Episode 125: Origins of MITRE ATT&CK84 / 100
  • Episode 124: Microsoft Security Response Center for AI81 / 100
Explore the best B2B Engineering & DevTools podcasts →
All The Azure Security Podcast episodes →