Security

Decrypted: Post-coronavirus, Auth0’s close call, North Korea warning, Awake’s Series C

Comment

Image Credits: Treedeo (opens in a new window) / Getty Images

Welcome to a look back at the past week in security and what it means for you. Each week we’ll look at the big news of the week and why it matters.

What will the world look like after the coronavirus pandemic subsides?

Some of us are now in our fifth week of sheltering in place, but there’s no fixed end-date in sight. We’ve gone from a period of confusion and concern to testing and mitigation. Now we’re starting to look ahead at the world post-coronavirus. Things still have to get done. But how do we regain a semblance of normality in the middle of a pandemic?

Tech can be the answer but it’s not a panacea; Apple and Google have explained more about their contact tracing efforts to help better understand the spread of the virus seems promising. But privacy concerns and worries that the system could be abused have raised justified concerns. On the other hand, with a U.S. presidential election slated for later this year, many experts want tech out of the picture in favor of a secure solution that uses paper ballots.

Will tech save the day, or will it kick us while we’re down? Let’s dive in.


THE BIG PICTURE

Voting by mail should be having its moment. Will it?

This year’s U.S. presidential election will still go ahead — it’s in the constitution as an immutable fact — but a pandemic throws a wrench in the works.

But security experts say electronic voting isn’t secure or resilient enough to protect from foreign interference. Even the more established mobile voting offerings have been shown to be deeply flawed.

The obvious answer is to embrace what five states already do: vote-by-mail. It’s low-tech but reliable, more secure, and accessible to the vast majority. But political resistance threatens to get in the way. TechCrunch’s Taylor Hatmaker reports on the vote-by-mail effort. Much of the holdup is a matter of politics: Democrats say mailed ballots will protect public health, while Republicans who prefer in-person voting have hit back with unfounded claims of voter fraud.

“You have to put this in context of where we are,” said Sen. Ron Wyden, speaking to Hatmaker. “At this point in the middle of a pandemic, I don’t think this is a partisan issue.”

Security lapse exposed Clearview AI source code

Surveillance startup Clearview AI has faced a barrage of headlines since it exploded onto the startup scene in January after an exposé in The New York Times.

Its already faced investigations from authorities in New Jersey and San Diego, and several tech companies — including Facebook and Twitter — have demanded that the company stop scraping user photos from its site to fill up its massive facial recognition database. It’s also had to deal with a data breach that saw its customer list stolen. That was a problem for a company that claims it serves only law enforcement clients because its customer list said otherwise.

Now it’s had another security lapse: a backend server that stored Clearview AI source code, internal files, and apps — as well as secret keys and credentials — was left exposed. A security researcher found the exposed system and reported it to the company. Clearview AI has since changed the keys.

North Korea hacking sparks U.S. government warning

For years, the U.S. government has indicted dozens of North Korea-backed hackers, which have for years been at the forefront of some of the most grandiose and damaging cyberattacks in history: the WannaCry ransomware attack, the Sony Pictures breach and a major bank heist in Bangladesh, to name a few.

These financially-focused cyberattacks are said to be core to funding North Korea’s nuclear weapons program.

But playing the blame game isn’t working. North Korea retains some of the most powerful and skilled hackers in the world, and the rogue nation has shown no signs of slowing down. And with no diplomatic way to extradite the hackers, they’re likely to keep on hacking.

Now the U.S. government has put some (but likely not all) of its cards on the table, accusing North Korea of having “the capability to conduct disruptive or destructive cyber activities affecting U.S. critical infrastructure.” That same warning, published this week, is intended to “raise awareness” to private businesses about the threat from the hermit nation, per a statement from the State Department.


MOVERS AND SHAKERS

Auth0 escaped what could’ve been a pretty nasty security incident.

“On July 31st 2019, at 5:11am, we received an email from Insomnia reporting a service vulnerability. By 11:00pm the same day, we had fixed the issue in production,” wrote Auth0’s chief security officer Joan Pepin in a blog post. Insomnia Security found and reported the bug. In its own blog post, Insomnia researcher Ben Knight said the bug could’ve been exploited to bypass two-factor authentication. That’s a pretty big deal for a company whose core offering is two-factor security.

Auth0 is one of the underdogs in the identity management and security space. Now a unicorn, the company rivals Okta, OneLogin and Duo. Thankfully for Auth0, responsible disclosure prevailed and the bug was fixed and a disclosure was put out, helping Auth0 and others to understand what could’ve gone wrong.

It also prompted Auth0 to launch its own bug bounty, something we discussed last week on Extra Crunch.


$ECURITY $TARTUPS

Onfido this week scored more than $100 million in its latest fundraise led by TPG Ventures. The London-based startup uses artificial intelligence to “read” a person’s identity documents and uses biometrics to confirm who they say they are, providing a method of authentication for online services, like banks, governments and other businesses. The company didn’t disclose its valuation but it’s now taken in $200 million to date.

Awake Security, a network traffic analysis startup, raised $36 million, the company announced this week. The Series C round was led by Evolution Equity Partners. The startup also leverages artificial intelligence and a mix of human expertise to spot attack behavior and malicious traffic. Awake has now raised $80 million to date.

And, Q-CTRL also secured an investment from In-Q-Tel, the CIA’s non-profit venture arm. Terms of the investment were not disclosed. The Los Angeles-based startup builds software to reduce noise and errors on quantum computer machines. The funding from In-Q-Tel will help support the startup develop quantum technologies for use in protecting national security. Last year the company raised $15 million.


Send tips securely over Signal and WhatsApp to +1 646-755–8849.

More TechCrunch

Flock Safety is a multi-billion dollar startup that’s got eyes everywhere. As of Wednesday, with the company’s new Solar Condor cameras, those eyes are solar-powered and using wireless 5G networks…

Flock Safety’s solar-powered cameras could make surveilliance more widespread

Since he was very young, Bar Mor knew that he would inevitably do something with real estate. His family was involved in all types of real estate projects, from ground-up…

Agora raises $34M Series B to keep building the Carta for real estate

Poshmark, the social commerce site that lets people buy and sell new and used items to each other, launched a paid marketing tool on Thursday, giving sellers the ability to…

Poshmark’s ‘Promoted Closet’ tool lets sellers boost all their listings at once

Google is launching a Gemini add-on for educational institutes through Google Workspace.

Google adds Gemini to its Education suite

More money for the generative AI boom: Y Combinator-backed developer infrastructure startup Recall.ai announced Thursday it’s raised a $10 million Series A funding round, bringing its total raised to over $12M.…

YC-backed Recall.ai gets $10M Series A to help companies use virtual meeting data

Engineers Adam Keating and Jeremy Andrews were tired of using spreadsheets and screenshots to collab with teammates — so they launched a startup, Colab, to build a better way. The…

Colab’s collaborative tools for engineers line up $21M in new funding

Reddit announced on Wednesday that it is reintroducing its awards system after shutting down the program last year. The company said that most of the mechanisms related to awards will…

Reddit reintroduces its awards system

Sigma Computing, a startup building a range of data analytics and business intelligence tools, has raised $200 million in a fresh VC round.

Sigma is building a suite of collaborative data analytics tools

European Union enforcers of the bloc’s online governance regime, the Digital Services Act (DSA), said Thursday they’re closely monitoring disinformation campaigns on the Elon Musk-owned social network X (formerly Twitter)…

EU ‘closely’ monitoring X in wake of Fico shooting as DSA disinfo probe rumbles on

Wind is the largest source of renewable energy in the U.S., according to the U.S. Energy Information Administration, but wind farms come with an environmental cost as wind turbines can…

Spoor uses AI to save birds from wind turbines

The key to taking on legacy players in the financial technology industry may be to go where they have not gone before. That’s what Chicago-based Aeropay is doing. The provider…

Cannabis and gaming payments startup Aeropay is now offering an alternative to Mastercard and Visa

Facebook and Instagram are under formal investigation in the European Union over child protection concerns, the Commission announced Thursday. The proceedings follow a raft of requests for information to parent…

EU opens child safety probes of Facebook and Instagram, citing addictive design concerns

Bedrock Materials is developing a new type of sodium-ion battery, which promises to be dramatically cheaper than lithium-ion.

Forget EVs: Why Bedrock Materials is targeting gas-powered cars for its first sodium-ion batteries

Private equity giant Thoma Bravo has announced that its security information and event management (SIEM) company LogRhythm will be merging with Exabeam, a rival cybersecurity company backed by the likes…

Thoma Bravo’s LogRhythm merges with Exabeam in more cybersecurity consolidation

Consumer protection groups around the European Union have filed coordinated complaints against Temu, accusing the Chinese-owned ultra low-cost e-commerce platform of a raft of breaches related to the bloc’s Digital…

Temu accused of breaching EU’s DSA in bundle of consumer complaints

Here are quick hits of the biggest news from the keynote as they are announced.

Google I/O 2024: Here’s everything Google just announced

The AI industry moves faster than the rest of the technology sector, which means it outpaces the federal government by several orders of magnitude.

Senate study proposes ‘at least’ $32B yearly for AI programs

The FBI along with a coalition of international law enforcement agencies seized the notorious cybercrime forum BreachForums on Wednesday.  For years, BreachForums has been a popular English-language forum for hackers…

FBI seizes hacking forum BreachForums — again

The announcement signifies a significant shake-up in the streaming giant’s advertising approach.

Netflix to take on Google and Amazon by building its own ad server

It’s tough to say that a $100 billion business finds itself at a critical juncture, but that’s the case with Amazon Web Services, the cloud arm of Amazon, and the…

Matt Garman taking over as CEO with AWS at crossroads

Back in February, Google paused its AI-powered chatbot Gemini’s ability to generate images of people after users complained of historical inaccuracies. Told to depict “a Roman legion,” for example, Gemini would show…

Google still hasn’t fixed Gemini’s biased image generator

A feature Google demoed at its I/O confab yesterday, using its generative AI technology to scan voice calls in real time for conversational patterns associated with financial scams, has sent…

Google’s call-scanning AI could dial up censorship by default, privacy experts warn

Google’s going all in on AI — and it wants you to know it. During the company’s keynote at its I/O developer conference on Tuesday, Google mentioned “AI” more than…

The top AI announcements from Google I/O

Uber is taking a shuttle product it developed for commuters in India and Egypt and converting it for an American audience. The ride-hail and delivery giant announced Wednesday at its…

Uber has a new way to solve the concert traffic problem

Google is preparing to launch a new system to help address the problem of malware on Android. Its new live threat detection service leverages Google Play Protect’s on-device AI to…

Google takes aim at Android malware with an AI-powered live threat detection service

Users will be able to access the AR content by first searching for a location in Google Maps.

Google Maps is getting geospatial AR content later this year

The heat pump startup unveiled its first products and revealed details about performance, pricing and availability.

Quilt heat pump sports sleek design from veterans of Apple, Tesla and Nest

The space is available from the launcher and can be locked as a second layer of authentication.

Google’s new Private Space feature is like Incognito Mode for Android

Gemini, the company’s family of generative AI models, will enhance the smart TV operating system so it can generate descriptions for movies and TV shows.

Google TV to launch AI-generated movie descriptions

When triggered, the AI-powered feature will automatically lock the device down.

Android’s new Theft Detection Lock helps deter smartphone snatch and grabs