Security

Dashlane, Google launch ‘OpenYOLO,’ an API-based password project for Android apps

Comment

Image Credits: veriflow.net (opens in a new window) under a license. (Image has been modified)

Password management is one of the key defenses — or key weaknesses — when it comes to protecting your data and identity online, and today Dashlane — the digital wallet and password manager startup — announced that it has teamed up with Google to develop another route to trying to fix that. The two have unveiled OpenYOLO — not this YOLO, but short for “you only login once” — an open-source API project for app developers to access passwords stored in password managers, whichever one you happen to use.

OpenYOLO will first target apps built for Android, but the hope is to include other platforms over time, “universal implementation by various apps and password managers across all platforms and operating systems,” Dashlane said in a separate release. From what we understand, Google will be announcing its own involvement on its developer blog soon (but not at the time of our posting; we’ll update when we see the post).

It also noted that while Google and Dashlane are the founding contributors, it will also be working with other “leading password managers” on OpenYOLO, although it did not specify which ones.

Asked about this, a Dashlane spokesperson tells us that “The leading password managers are either already participating or have expressed strong interest: 1Password, LastPass, and Keeper, and Keepass. There will be many other partners, as the project is meant to be open, as soon as the technical documentation and code is made public.” It is for that reason that there isn’t even a dedicated web site yet for OpenYOLO, he added.

OpenYOLO speaks to a wider trend in the industry for more centralized password protection, particularly in light of the fact that so many breaches have been traced back to passwords being hacked. The move comes a day after another password manager startup, 1Password, announced a new subscription pricing tier and other upgrades to its services.

And there are others that have also tried to tackle this problem, including Google itself, which last year launched a password manager service called Smart Lock, also for signing into Android apps, and has also said that it is working to launch by the end of this year a password-free authenticator — currently named Project Abacus — that instead uses things like biometrics to identify you.

Smart Lock will integrate with OpenYOLO, Dashlane says, and make it easier for apps to tap whichever password manager you use.

“OpenYolo is not meant to replace Smart Lock,” Stanojko Markovikjm, Android Engineering Lead at Dashlane, said in an email to me. “Rather it complements it by providing a mechanism to query other password providers installed on the device.”

In an example he provided to me, take Smart Lock today on an app like Slack. “When a user reaches the login screen it would directly query Smart Lock for a credential. If the user is using an alternative password manager, they will have to enter the credentials manually,” he said. “With the Open YOLO API, the user will still see the Smartlock credential as before, but the app would be able to query other sources of credentials, such as Dashlane, another password manager, or even another browser, if it contains a credential for the app.”

The main idea with the API is to expose the password solution chosen by the end-user and its content to applications, which actually use the data stored, he added, “to make the password manager more proactive, and more transparent, which means it will be seamlessly available when you needed it, every time you need it.”

It’s also notable that the Google software engineer who worked on Smart Lock has also been involved with OpenYOLO.

“Google is excited to support the launch of this project with Dashlane and help create a new open standard for app authentication,” said Google’s Iain McGinniss in a statement. “This project is part of our longstanding support of open technology standards that provide great, secure user experience to end users.”

For Dashlane, this is also a progression on how the company — which originally started with a focus on password and digital wallet management for desktop — has been turning increasingly to figure out its position in the world of mobile apps.

“This is an important initiative for our industry and for the state of user security,” said Emmanuel Schalit, CEO of Dashlane, in a statement. “Collectively, we are committed to increasing user security and believe that the best way to do this is to champion open source security projects–which Dashlane has done earlier this year by becoming the first password manager to adopt the FIDO Alliance’s Universal Second Factor (U2F) authentication standard. We look forward to expanding this collaborative project that will benefit the entire security industry.”

Originally founded in Paris and now headquartered in New York, Dashlane has raised just over $50 million in funding.

More TechCrunch

The person who claims to have 49 million Dell customer records told TechCrunch that he brute-forced an online company portal and scraped customer data, including physical addresses, directly from Dell’s…

Threat actor says he scraped 49M Dell customer addresses before the company found out

The social network has announced an updated version of its app that lets you offer feedback about its algorithmic feed so you can better customize it.

Bluesky now lets you personalize its main Discover feed using new controls

Microsoft will launch its own mobile game store in July, the company announced at the Bloomberg Technology Summit on Thursday. Xbox president Sarah Bond shared that the company plans to…

Microsoft is launching its mobile game store in July

Smart ring maker Oura is launching two new features focused on heart health, the company announced on Friday. The first claims to help users get an idea of their cardiovascular…

Oura launches two new heart health features

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI considers allowing AI porn

Garena is quietly developing new India-themed games even though Free Fire, its biggest title, has still not made a comeback to the country.

Garena is quietly making India-themed games even as Free Fire’s relaunch remains doubtful

The U.S.’ NHTSA has opened a fourth investigation into the Fisker Ocean SUV, spurred by multiple claims of “inadvertent Automatic Emergency Braking.”

Fisker Ocean faces fourth federal safety probe

CoreWeave has formally opened an office in London that will serve as its European headquarters and home to two new data centers.

CoreWeave, a $19B AI compute provider, opens European HQ in London with plans for 2 UK data centers

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

1 day ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3