Author: azeeadmin

08 Mar 2019

On #IWD2019, Safe & The City launches their new app for women’s safety

It’s International Women’s Day today, but sadly the world remains far more unsafe for women than men. Every day, all over the world, women experience unsafe or uncomfortable environments or incidents of verbal, non-verbal or physical sexual harassment. Just to take one statistic, UK Government research showed that while 85% of women experience some form of harassment, 90% cent of the incidents remains unreported.

Smartphone apps have appeared in the last few years to at least try and alleviate this situation to some extent. These include RedZone and Citizen

However, few have focused specifically on women, or take a more data-led approach which might really change the game for women’s safety.

The Safe & The City (SatC) app (available on Android and iOS) was founded last year by a public health expert who has decided to take a far smarter approach, by using GPS, crowdsourced information and Police risk data to reduce the victims of opportunistic crimes and sexual harassment.

SatC today releases a large swathe of new features, with a brand new look, and all with an emphasis on the female experience, especially for those women living in London (though the app plans to roll out globally in due course).It’s also launching its partnership with UNwomen U.K. to pilot research for their global safe public spaces and safe cities programme.

Founder and CEO Jillian Kowalchuk told me: “When I just moved to London, I had an incident in a dark street at night with little footfall, involving three men who verbally abused me and got very close to me, which could have escalated, but, thankfully, didn’t. I looked for a solution or platform that would help me decide where it would be safer to walk. When I couldn’t find anything, I decided to bring to market my own idea, validated by my friends and acquaintances, as well as data!”

This personal safety navigation app uses geolocation tech and Metropolitan Police Service (MPS) data in its app, with the aim of preventing sexual harassment on streets.

It covers personal safety navigation; route sharing; rating and geo-tagging of different aspects of walks; and sharing data with businesses and authorities to help tackle insecurity. So, pretty comprehensive!

The new features include better navigation with turn-by-turn directions, integration with location startup what3words for greater accuracy, and pinned locations of police stations and licensed premises involved in the ground-breaking ‘Ask for Angela’ campaign in the UK.

As well as all this, tech co-working spaces are being added to the apps Safe Sites locations, and identified to users as places in the app where they can get support if they need it.

Kowalchuk should know what she’s talking about. She holds an MSc in Public Health and BA in Psychology and has over 5 years of experience as a global researcher, evaluator and program implementer in Public Health.

“The way to think about the app,” she told me “is that we want to be the ‘Waze for pedestrian safety’. Long term, we plan to analyze the data in conjunction with businesses and government to propose change and build safer cities all over the world.”

How does her startup plan to make revenues? The service will become a subscription service for companies, allowing businesses to be identified on the map as ‘safe sites’. They will have to have trained staff prepared capable of helping potential victims of gender violence.

Additionally, businesses will be able to make the claim they are certified safe sites by SatC and use this for their own purposes.

The launch of the app is being backed by none other than, Peter Barron, ex-Head of Crime Performance and Strategic Risk at the London Met Police; Mariam Critchton, Founder of FindMaps; Matt Rogers serial entrepreneur; Phillip Green, ex-CFO Deliveroo; and David White, Founder of big data/AI company Import.io.

Commander Richard Smith, Head of Safeguarding at the Met Police says: “This is an innovative use of our crime data that we can use together to keep people safe. Preventing people from becoming victims of crime in the first place must be a part of any sustainable strategy.”

So far Safe & the City has forged strong working partnerships with several key organizations including UN Women UK, the UN Women’s Global Safe Cities and the Safe Public Spaces initiative.

08 Mar 2019

Salesforce at 20 offers lessons for startup success

Salesforce is celebrating its 20th anniversary today. The company that was once a tiny irritant going after giants in the 1990s Customer Relationship Management (CRM) market, such as Oracle and Siebel Systems, has grown into full-fledged SaaS powerhouse. With an annual run rate exceeding $14 billion, it is by far the most successful pure cloud application ever created.

Twenty years ago, it was just another startup with an idea, hoping to get a product out the door. By now, a legend has built up around the company’s origin story, not unlike Zuckerberg’s dorm room or Jobs’ garage, but it really did all begin in 1999 in an apartment in San Francisco, where a former Oracle executive named Marc Benioff teamed with a developer named Parker Harris to create a piece of business software that ran on the internet. They called it Salesforce .com.

None of the handful of employees who gathered in that apartment on the company’s first day in business in 1999 could possibly have imagined what it would become 20 years later, especially when you consider the start of the dot-com crash was just a year away..

Party like it’s 1999

It all began on March 8, 1999 in the apartment at 1449 Montgomery Street in San Francisco, the site of the first Salesforce office. The original gang of four employees consisted of Benioff and Harris and Harris’s two programming colleagues Dave Moellenhoff and Frank Dominguez. They picked the location because Benioff lived close by.

It would be inaccurate to say Salesforce was the first to market with Software as a Service, a term, by the way, that would not actually emerge for years. In fact, there were a bunch of other fledgling enterprise software startups trying to do business online at the time including NetLedger, which later changed its name NetSuite, and was eventually sold to Oracle for $9.3 billion in 2016.

Other online CRM competitors included Salesnet, RightNow Technologies and Upshot. All would be sold over the next several years. Only Salesforce survived as a stand-alone company. It would go public in 2004 and eventually grow to be one of the top 10 software companies in the world.

Co-founder and CTO Harris said recently that he had no way of knowing that any of that would happen, although having met Benioff, he thought there was potential for something great to happen. “Little did I know at that time, that in 20 years we would be such a successful company and have such an impact on the world,” Harris told TechCrunch.

Nothing’s gonna stop us now

It wasn’t entirely a coincidence that Benioff and Harris had connected. Benioff had taken a sabbatical from his job at Oracle and was taking a shot at building a sales automation tool that ran on the internet. Harris, Moellenhoff and Dominguez had been building salesforce automation software solutions, and the two visions meshed. But building a client-server solution and building one online were very different.

Original meeting request email from Marc Benioff to Parker Harris from 1998. Email courtesy of Parker Harris.

You have to remember that in 1999, there was no concept of Infrastructure as a Service. It would be years before Amazon launched Amazon Elastic Compute Cloud in 2006, so Harris and his intrepid programming team were on their own when it came to building the software and providing the servers for it to scale and grow.

“I think in a way, that’s part of what made us successful because we knew that we had to, first of all, imagine scale for the world,” Harris said. It wasn’t a matter of building one CRM tool for a large company and scaling it to meet that individual organization’s demand, then another, it was really about figuring out how to let people just sign up and start using the service, he said.

“I think in a way, that’s part of what made us successful because we knew that we had to, first of all, imagine scale for the world.” Parker Harris, Salesforce

That may seem trivial now, but it wasn’t a common way of doing business in 1999. The internet in those years was dominated by a ton of consumer-facing dot-coms, many of which would go bust in the next year or two. Salesforce wanted to build an enterprise software company online, and although it wasn’t alone in doing that, it did face unique challenges being one of the early adherents.

“We created a software that was what I would call massively multi-tenant where we couldn’t optimize it at the hardware layer because there was no Infrastructure as a Service. So we did all the optimization above that — and we actually had very little infrastructure early on,” he explained.

Running down a dream

From the beginning, Benioff had the vision and Harris was charged with building it. Tien Tzuo, who would go on to be co-founder at Zuora in 2007, was employee number 11 at Salesforce, starting in August of 1999, about five months after the apartment opened for business. At that point, there still wasn’t an official product, but they were getting closer when Benioff hired Tzuo.

As Tzuo tells it, he had fancied a job as a product manager, but when Benioff saw his Oracle background in sales, he wanted him in account development. “My instinct was, don’t argue with this guy. Just roll with it,” Tzuo relates.

Early prototype of Salesforce.com. Photo: Salesforce

As Tzuo pointed out, in a startup with a handful of people, titles mattered little anyway. “Who cares what your role was. All of us had that attitude. You were a coder or a non-coder,” he said. The coders were stashed upstairs with a view of San Francisco Bay and strict orders from Benioff to be left alone. The remaining employees were downstairs working the phones to get customers.

“Who cares what your role was. All of us had that attitude. You were a coder or a non-coder.” Tien Tzuo, early employe

The first Wayback Machine snapshot of Salesforce.com is from November 15, 1999, It wasn’t fancy, but it showed all of the functionality you would expect to find in a CRM tool: Accounts, Contacts, Opportunities, Forecasts and Reports with each category represented by a tab.

The site officially launched on February 7, 2000 with 200 customers, and they were off and running.

Prove it all night

Every successful startup needs visionary behind it, pushing it, and for Salesforce that person was Marc Benioff. When he came up with the concept for the company, the dot-com boom was in high gear. In a year or two, much of it would come crashing down, but in 1999 anything was possible and Benioff was bold and brash and brimming with ideas.

But even good ideas don’t always pan out for so many reasons, as many a failed startup founder knows only too well. For a startup to succeed it needs a long-term vision of what it will become, and Benioff was the visionary, the front man, the champion, the chief marketer. He was all of that — and he wouldn’t take no for an answer.

Paul Greenberg, managing principal at The 56 Group and author of multiple books about the CRM industry including CRM at the Speed of Light (the first edition of which was published in 2001), was an early user of Salesforce, and says that he was not impressed with the product at first, complaining about the early export functionality in an article.

A Salesforce competitor at the time, Salesnet, got wind of Greenberg’s post, and put his complaint on the company website. Benioff saw it, and fired off an email to Greenberg: “I see you’re a skeptic. I love convincing skeptics. Can I convince you?” Greenberg said that being a New Yorker, he wrote back with a one-line response. “Take your best shot.” Twenty years later, Greenberg says that Benioff did take his best shot and he did end up convincing him.

“I see you’re a skeptic. I love convincing skeptics. Can I convince you?” Early Marc Benioff email

Laurie McCabe, who is co-founder and partner at SMB Group, was working for a consulting firm in Boston in 1999 when Benioff came by to pitch Salesforce to her team. She says she was immediately impressed with him, but also with the notion of putting enterprise software online, effectively putting it within reach of many more companies.

“He was the ringmaster I believe for SaaS or cloud or whatever we want to call it today. And that doesn’t mean some of these other guys didn’t also have a great vision, but he was the guy beating the drum louder. And I just really felt that in addition to the fact that he was an exceptional storyteller, marketeer and everything else, he really had the right idea that software on prem was not in reach of most businesses,” she said.

Take it to the limit

One of the ways that Benioff put the company in the public eye in the days before social media was guerrilla marketing techniques. He came up with the idea of “no software” as a way to describe software on the internet. He sent some of his early employees to “protest” at the Siebel Conference, taking place at the Moscone Center in February, 2000. He was disrupting one of his major competitors, and it created enough of a stir to attract a television news crew and garner a mention in the Wall Street Journal. All of this was valuable publicity for a company that was still in its early stages.

Photos: Salesforce

Brent Leary, who had left his job as an industry consultant in 2003 to open his current firm, CRM Essentials, said this ability to push the product was a real differentiator for the company and certainly got his attention. “I had heard about Salesnet and these other ones, but these folks not only had a really good product, they were already promoting it. They seemed to be ahead of the game in terms of evangelizing the whole “no software” thing. And that was part of the draw too,” Leary said of his first experiences working with Salesforce.

Leary added, “My first Dreamforce was in 2004, and I remember it particularly because it was actually held on Election Day 2004 and they had a George W. Bush look-alike come and help open the conference, and some people actually thought it was him.”

Greenberg said that the “no software” campaign was brilliant because it brought this idea of delivering software online to a human level. “When Marc said, ‘no software’ he knew there was software, but the thing with him is, that he’s so good at communicating a vision to people.” Software in the 90s and early 2000s was delivered mostly in boxes on CDs (or 3.5 inch floppies), so saying no software was creating a picture that you didn’t have to touch the software. You just signed up and used it. Greenberg said that campaign helped people understand online software at a time when it wasn’t a common delivery method.

Culture club

One of the big differentiators for Salesforce as a company was the culture it built from Day One. Benioff had a vision of responsible capitalism and included their charitable 1-1-1 model in its earliest planning documents. The idea was to give one percent of Salesforce’s equity, one percent of its product and one percent of its employees’ time to the community. As Benioff once joked, they didn’t have a product and weren’t making any money when they made the pledge, but they have stuck to it and many other companies have used the model Salesforce built.

Image: Salesforce

Bruce Cleveland, a partner at Wildcat Ventures, who has written a book with Geoffrey Moore of Crossing the Chasm fame called Traversing the Traction Gap, says that it is essential for a startup to establish a culture early on, just as Benioff did. “A CEO has to say, these are the standards by which we’re going to run this company. These are the things that we value. This is how we’re going to operate and hold ourselves accountable to each other,” Cleveland said. Benioff did that.

Another element of this was building trust with customers, a theme that Benioff continues to harp on to this day. As Harris pointed out, people still didn’t trust the internet completely in 1999, so the company had to overcome objections to entering a credit card online. Even more than that though, they had to get companies to agree to share their precious customer data with them on the internet.

“We had to not only think about scale, we had to think about how do we get the trust of our customers, to say that we will protect your information as well or better than you can,” Harris explained.

Growing up

The company was able to overcome those objections, of course, and more. Todd McKinnon, who is currently co-founder and CEO at Okta, joined Salesforce as VP of Engineering in 2006 as the company began to ramp up becoming a $100 million company, and he says that there were some growing pains in that time period.

Salesforce revenue growth across the years from 2006-present. Chart: Macro Trends

When he arrived, they were running on three mid-tier Sun servers in a hosted co-location facility. McKinnon said that it was not high-end by today’s standards. “There was probably less RAM than what’s in your MacBook Pro today,” he joked.

When he came on board, the company still had only 13 engineers and the actual infrastructure requirements were still very low. While that would change during his six year tenure, it was working fine when he got there. Within five years, he said, that changed dramatically as they were operating their own data centers and running clusters of Dell X86 servers — but that was down the road.

Before they did that, they went back to Sun one more time and bought four of the biggest boxes they sold at the time and proceeded to transfer all of the data. The problem was that the Oracle database wasn’t working well, so as McKinnon tells it, they got on the phone with Larry Ellison from Oracle, who upon hearing about the setup, asked them straight out why they were doing that? The way they had it set up simply didn’t work.

They were able to resolve it all and move on, but it’s the kind of crisis that today’s startups probably wouldn’t have to deal with because they would be running their company on a cloud infrastructure service, not their own hardware.

Window shopping

About this same time, Salesforce began a strategy to grow through acquisitions. In 2006, it acquired the first of 55 companies when it bought a small wireless technology company called Sendia for $15 million. As early as 2006, the year before the first iPhone, the company was already thinking about mobile.

Last year it made its 52nd acquisition, and the most costly so far, when it purchased Mulesoft for $6.5 billion, giving it a piece of software that could help Salesforce customers bridge the on-prem and cloud worlds. As Greenberg pointed out, this brought a massive change in messaging for the company.

“With the Salesforce acquisition of MuleSoft, it allows them pretty much to complete the cycle between back and front office and between on-prem and the cloud. And you notice, all of a sudden, they’re not saying ‘no software.’ They’re not attacking on-premise. You know, all of this stuff has gone by the wayside,” Greenberg said.

No company is going to be completely consistent as it grows and priorities shift,  but if you are a startup looking for a blueprint on how to grow a successful company, Salesforce would be a pretty good company to model yourself after. Twenty years into this, they are still growing and still going strong and they remain a powerful voice for responsible capitalism, making lots of money, while also giving back to the communities where they operate.

One other lesson that you could learn is that you’re never done. Twenty years is a big milestone, but it’s just one more step in the long arc of a successful organization.

08 Mar 2019

Uber pays $2.6M to settle historical charges it violated Dutch taxi laws

Another fine for Uber’s historical playbook: The ride-hailing giant has agreed to pay around $2.6 million (€2.3M) to settle charges in the Netherlands related to violations of local taxi law, dating back to when it was operating a peer-to-peer ride-hailing service in contravention of local transport laws.

Uber offered its UberPop service in the Netherlands between July 2014 and November 2015, when it pulled the plug — saying the service “had become a blog to regulatory progress”. Which is a long-winded way of saying it wasn’t legal to operate it.

The Dutch Public Prosecution Service (DPPS) announced the settlement today, saying it consists of a €2,025,000 fine across the four Uber companies — Uber International BV, Uber Netherlands BV, Uber BV and Rasier Operations BV — in addition to €309,409 in “criminally earned capital”, via Uber’s 20% commission on rides, which is being clawed back.

The DPPS said it’s happy to settle with Uber as it believes the courts would have reached the same penalizing conclusion.

In a press release announcing the settlement it writes that the four named Uber entities “co-perpetrated” the violation of local taxi law, which requires transport services to have a taxi license to operate (whereas with UberPop Uber allowed anyone with a vehicle to sell a ride).

Uber BV has been given the maximum possible fine (€810,000). The other three entities have been fined half the maximum — as a result of smaller roles in the violation, the DPPS said.

“The person responsible for the rollout of UberPop in the Netherlands has performed a 90-hour [community service] penalty,” it adds.

Commenting on the settlement in a statement, an Uber spokesperson said: “We have changed the way we do business across the world, putting integrity in the core of everything that we do. We are committed to being a good partner to Dutch cities. We have shut down UberPOP services in 2015. Since then, we only allow professional and certified drivers on the app, through uberX, Van and Black services.”

Also since 2015: Europe’s top court judged Uber to be a transport company — firmly closing the regional book on any more attempts to circumvent taxi laws by claiming it’s ‘just a technology platform’.

08 Mar 2019

Cookie walls don’t comply with GDPR, says Dutch DPA

Cookie walls that demand a website visitor agrees to their Internet browsing being tracked for ad-targeting as the ‘price’ of entry to the site are not compliant with European data protection law, the Dutch data protection agency clarified yesterday.

The DPA said it has received dozens of complaints from Internet users who had had their access to websites blocked after refusing to accept tracking cookies — so it has taken the step of publishing clear guidance on the issue.

It also says it will be stepping up monitoring, adding that it has written to the most complained about organizations (without naming any names) — instructing them to make changes to ensure they come into compliance with GDPR.

Europe’s General Data Protection Regulation, which came into force last May, tightens the rules around consent as a legal basis for processing personal data — requiring it to be specific, informed and freely given in order for it to be valid under the law.

Of course consent is not the only legal basis for processing personal data but many websites do rely on asking Internet visitors for consent to ad cookies as they arrive.

And the Dutch DPA’s guidance makes it clear Internet visitors must be asked for permission in advance for any tracking software to be placed — such as third party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained. Ergo, a free choice must be offered.

So, in other words, a ‘data for access’ cookie wall isn’t going to cut it. (Or, as the DPA puts it: “Permission is not ‘free’ if someone has no real or free choice. Or if the person cannot refuse giving permission without adverse consequences.”)

“This is not for nothing; website visitors must be able to trust that their personal data are properly protected,” it further writes in a clarification published on its website [translated via Google Translate].

“There is no objection to software for the proper functioning of the website and the general analysis of the visit on that site. More thorough monitoring and analysis of the behavior of website visitors and the sharing of this information with other parties is only allowed with permission. That permission must be completely free,” it adds. 

We’ve reached out to the DPA with questions.

In light of this ruling the cookie wall on the Internet Advertising Bureau (IAB)’s European site (screengrabbed below) looks like a textbook example of what not to do — given the online ad industry association is bundling multiple cookie uses (site functional cookies; site analytical cookies; and third party advertising cookies) under a single ‘I agree’ option.

It does not offer visitors any opt-outs at all. (Not even under the ‘More info’ or privacy policy options pictured below).

If the user does not click ‘I agree’ they cannot gain access to the IAB’s website. So there’s no free choice here. It’s agree or leave.

Clicking ‘More info’ brings up additional information about the purposes the IAB uses cookies for — where it states it is not using collected information to create “visitor profiles”.

However it notes it is using Google products, and explains that some of these use cookies that may collect visitors’ information for advertising — thereby bundling ad tracking into the provision of its website ‘service’.

Again the only ‘choice’ offered to site visitors is ‘I agree’ or to leave without gaining access to the website. Which means it’s not a free choice.

The IAB told us no data protection agencies had been in touch regarding its cookie wall.

Asked whether it intends to amend the cookie wall in light of the Dutch DPA’s guidance a spokeswoman said she wasn’t sure what the team planned to do yet — but she claimed GDPR does not “outright prohibit making access to a service conditional upon consent”; pointing also to the (2002) ePrivacy Directive which she claimed applies here, saying it “also includes recital language to the effect of saying that website content can be made conditional upon the well-informed acceptance of cookies”.

So the IAB’s position appears to be that the ePrivacy Directive trumps GDPR on this issue.

Though it’s not clear how they’ve arrived at that conclusion. (The fifteen+ year old ePrivacy Directive is also in the process of being updated — while the flagship GDPR only came into force last year.)

The portion of the ePrivacy Directive that the IAB appears to be referring to is recital 25 — which includes the following line:

Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose.

However “specific website content” is hardly the same as full site access, i.e. as is entirely blocked by their cookie wall.

The “legitimate purpose” point in the recital also provides a second caveat vis-a-vis making access conditional on accepting cookies — and the recital text includes an example of “facilita[ting] the provision of information society services” as such a legitimate purpose.

What are “information society services”? An earlier European directive defines this legal term as services that are “provided at a distance, electronically and at the individual request of a recipient” [emphasis ours] — suggesting it refers to Internet content that the user actually intends to access (i.e. the website itself), rather than ads that track them behind the scenes as they surf.

So, in other words, even per the outdated ePrivacy Directive, a site might be able to require consent for functional cookies from a user to access a portion of the site.

But that’s not the same as saying you can gate off an entire website unless the visitor agrees to their browsing being pervasively tracked by advertisers.

That’s not the kind of ‘service’ website visitors are looking for. 

Add to that, returning to present day Europe, the Dutch DPA has put out very clear guidance demolishing cookie walls.

The only sensible legal interpretation here is that the writing is on the wall for cookie walls.

08 Mar 2019

PolyAI scores $12M Series A to put its ‘conversational AI agents’ in contact centres

PolyAI, a London startup founded by experts in the field of “conversational AI” — including CEO Nikola Mrkšić who was previously the first engineer at Apple-acquired VocalIQ — has raised $12 million in Series A funding to deploy its tech in customer support contact centres.

The round was led by Point72 Ventures, with participation from Sands Capital Ventures, Amadeus Capital Partners, Passion Capital, and Entrepreneur First (EF). PolyAI’s founders are graduates of EF, although they didn’t meet during the company building program but already knew each other from their time at Cambridge’s Dialog Systems Group, part of the Machine Intelligence Lab at the University of Cambridge.

“We started PolyAI in 2017, straight after submitting our PhD theses,” Mrkšić tells me. “At Cambridge, we developed state-of-the-art conversational technology, and starting a company was the best way to get this tech used in the real world. We brought many of our Cambridge colleagues with us and started building the commercial version of our conversational platform”.

Targeting contact centres — in a bid to help make these low-margin businesses more scalable — PolyAI’s AI tech doesn’t just attempt to understand customer queries but ensure they can be conducted in a truly conversational way, regardless of the medium, which could be over email, messaging or voice. Where a lot of conversation AI or voice assistants fall down, says Mrkšić, is that they aren’t able to really follow a conversation, often lacking the ability to understand meaning within the context of a conversation’s history or follow-up dialogue.

“Our proprietary technology allows the AI agents to support really complex use cases,” he says. “Our agents are built around a framework for modelling context, which means they can hold long conversations and remember all pieces of information that users had previously shared. The backend models are data-driven, and they are domain and language agnostic. This allows them to seamlessly scale across different use cases and world languages. In practice, this means that we don’t have to hand-craft agent behaviour — AI agents can learn by observing human agents at work”.

That’s a hard nut to crack, which is why Mrkšić believes deep vertical integration with contact centres will produce the best outcomes. He doesn’t rule out either buying a small to medium-sized contact centre or forming a strategic partnership to expedite improvements in PolyAI’s offering and the company’s understanding of how contact centres operate. His thesis is that AI can help make contact centres more profitable, although, early on in the startup’s life, the case is not yet proven.

Related to this, Mrkšić and his team aren’t proposing that “AI agents” replace human agents altogether but work alongside them, quite literally, with each playing to their respective strengths. PolyAI co-founder and CTO Shawn Wen argues that machines can do many things that humans struggle with, including having “instant access” to all of relevant information needed to support a customer. At peak times, this can mean AI agents handling calls autonomously if human agents aren’t available, while leaving human agents with the more complex edge cases or ones where they can bring the most value through human empathy and EQ.

“We plan to pursue very tight integration with contact centres — be that through M&A, investment or other profit-sharing arrangements,” adds Mrkšić. “Whichever model we end up pursuing, we want full alignment between PolyAI and contact centres. Too many AI companies have died trying to find favourable software licensing agreements years before their technology was ready for wide-scale deployment. We believe vertical integration is the best way to fast-track the development of our ML platform, as well as for PolyAI to stay independent in the long-term”.

08 Mar 2019

Car alarms with security flaws put 3 million vehicles at risk of hijack

Two popular car alarm systems have fixed security vulnerabilities that allowed researchers to remotely track, hijack and take control of vehicles with the alarms installed.

The systems, built by Russian alarm maker Pandora and California-based Viper — or Clifford in the U.K., were vulnerable to an easily manipulated server-side API, according to researchers at Pen Test Partners, a U.K. cybersecurity company. In their findings, the API could be abused to take control of an alarm system’s user account — and their vehicle.

It’s because the vulnerable alarm systems could be tricked into resetting an account password because the API was failing to check if it was an authorized request, allowing the researchers to log in.

Although the researchers bought alarms to test, they said “anyone” could create a user account to access any genuine account or extract all the companies’ user data.

The researchers said some three million cars globally were vulnerable to the flaws, since fixed.

In one example demonstrating the hack, the researchers geolocated a target vehicle, track it in real-time, follow it, remotely kill the engine and force the car to stop, and unlock the doors. The researchers said it was “trivially easy” to hijack a vulnerable vehicle. Worse, it was possible to identify some car models, making targeted hijacks or high-end vehicles even easier.

According to their findings, the researchers also found they could listen in on the in-car microphone, built-in as part of the Pandora alarm system for making calls to the emergency services or roadside assistance.

Ken Munro, founder of Pen Test Partners, told TechCrunch this was their “biggest” project.

The researchers contacted both Pandora and Viper with a seven-day disclosure period, given the severity of the vulnerabilities. Both companies responded quickly to fix the flaws.

When reached, Viper’s Chris Pearson confirmed the vulnerability has been fixed. “If used for malicious purposes, [the flaw] could allow customer’s accounts to be accessed without authorization.”

Viper blamed a recent system update by a service provider for the bug and said the issue was “quickly rectified.”

“Directed believes that no customer data was exposed and that no accounts were accessed without authorization during the short period this vulnerability existed,” said Pearson, but provided no evidence to how the company came to that conclusion.

In a lengthy email, Pandora’s Antony Noto challenged several of the researcher’s findings, summated: “The system’s encryption was not cracked, the remotes where not hacked, [and] the tags were not cloned,” he said. “A software glitch allowed temporary access to the device for a short period of time, which has now been addressed.”

The research follows work last year by Vangelis Stykas on the Calamp, a telematics provider that serves as the basis for Viper’s mobile app. Stykas, who later joined Pen Test Partners and also worked on the car alarm project, found the app was using credentials hardcoded in the app to login to a central database, which gave anyone who logged in remote control of a connected vehicle.

08 Mar 2019

Leica’s Q2 is a beautiful camera that I want and will never have

Leica is a brand I respect and appreciate but don’t support. Or rather, can’t, because I’m not fabulously rich. But if I did have $5,000 to spend on a fixed-lens camera, I’d probably get the new Q2, a significant improvement over 2015’s Q — which tempted me back then.

The Q2 keeps much of what made the Q great: a full-frame sensor, a fabulous 28mm F/1.7 Summilux lens, and straightforward operation focused on getting the shot. But it also makes some major changes that make the Q2 a far more competitive camera.

The sensor has jumped from 24 to 47 megapixels, and while we’re well out of the megapixel race, that creates the opportunity for a very useful cropped shooting mode that lets you shoot at 35, 50, and 75mm equivalents while still capturing huge pixel counts. It keeps the full frame exposure as well so you can tweak the crop later. The new sensor also has a super low native ISO of 50, which should help with dynamic range and in certain exposure conditions.

Autofocus has been redone as well (as you might expect with a new sensor) and it should be quicker and more accurate now. Ther’s also an optical stabilization mode that kicks in when you are shooting at under 1/60s. Both features that need a little testing to verify they’re as good as they sound, but I don’t expect they’re fraudulent or anything.

The body, already a handsome minimal design in keeping with Leica’s impeccable (if expensive) taste, is now weather sealed, making this a viable walk-around camera in all conditions. Imagine paying five grand for a camera and being afraid to take it out in the rain! Well, many people did that and perhaps will feel foolish now that the Q2 has arrived.

Inside is an electronic viewfinder, but the 2015 Q had a sequential-field display — meaning it flashes rapidly through the red, green, and blue components of the image — which made it prone to color artifacts in high-motion scenes or when panning. The Q2, however, has a shiny new OLED display with the same resolution but better performance. OLEDs are great for EVFs for a lot of reasons, but I like that you get really nice blacks, like in an optical viewfinder.

The button layout has been simplified as well (or rather synchronized with the CL, another Leica model), with a new customizable button on the top plate, reflecting the trend of personalization we’ve seen in high-end cameras. A considerably larger battery and redesigned battery and card door rounds out the new features.

As DPReview points out in its hands-on preview of the camera, the Q2 is significantly heavier than the high-end fixed-lens competition (namely the Sony RX1R II and Fuji X100F, both excellent cameras), and also significantly more expensive. But unlike many Leica offerings, it actually outperforms them in important ways: the lens, the weather sealing, the burst speed — it may be expensive, but you actually get something for your money. That can’t always be said of this brand.

The Leica Q2 typifies the type of camera I’d like to own: no real accessories, nothing to swap in or out, great image quality and straightforward operation. I’m far more likely to get an X100F (and even then it’d be a huge splurge) but all that time I’ll be looking at the Q2 with envious eyes. Maybe I’ll get to touch one some day.

08 Mar 2019

Netflix star and tidying expert Marie Kondo is looking to raise $40M

Marie Kondo, the woman who stole millions of Netflix viewers hearts this year with her show, “Tidying Up,” is in talks to raise up to $40 million in venture capital funding to scale KonMari, the business behind her personal brand, books and TV series.

The news was first reported by The Information, which wrote that this wouldn’t be KonMari’s first infusion of venture investment, surprisingly. Last year, the company closed a financing round “in the low millions of dollars” led by top-tier VC fund Sequoia Capital, a detail that hadn’t been previously reported. In an email to TechCrunch, a spokesperson for the business said KonMari isn’t commenting on fundraising at this time.

“Tidying Up with Marie Kondo” debuted on Netflix on January 1, 2019 to near-instant success, spurring a wave of internet-fandom for Kondo with her catchphrase “does it spark joy?” and efficient method of cleaning and organizing. The KonMari Method encourages cleaners to tidy by category, starting with clothes, then books, papers, miscellaneous items and sentimental items. “Keep only those things that speak to the heart, and discard items that no longer spark joy. Thank them for their service – then let them go,” Kondo explains on her website.

According to The Information’s reporting, Kondo is looking for additional capital to help drive her personal brand forward, whether that be through editorial content or other digital elements. I guess the question for VCs is does KonMari spark joy? (Sorry, I had to).

KonMari was founded in 2015 by Kondo and her husband, Takumi Kawahara.

 

08 Mar 2019

Netflix star and tidying expert Marie Kondo is looking to raise $40M

Marie Kondo, the woman who stole millions of Netflix viewers hearts this year with her show, “Tidying Up,” is in talks to raise up to $40 million in venture capital funding to scale KonMari, the business behind her personal brand, books and TV series.

The news was first reported by The Information, which wrote that this wouldn’t be KonMari’s first infusion of venture investment, surprisingly. Last year, the company closed a financing round “in the low millions of dollars” led by top-tier VC fund Sequoia Capital, a detail that hadn’t been previously reported. In an email to TechCrunch, a spokesperson for the business said KonMari isn’t commenting on fundraising at this time.

“Tidying Up with Marie Kondo” debuted on Netflix on January 1, 2019 to near-instant success, spurring a wave of internet-fandom for Kondo with her catchphrase “does it spark joy?” and efficient method of cleaning and organizing. The KonMari Method encourages cleaners to tidy by category, starting with clothes, then books, papers, miscellaneous items and sentimental items. “Keep only those things that speak to the heart, and discard items that no longer spark joy. Thank them for their service – then let them go,” Kondo explains on her website.

According to The Information’s reporting, Kondo is looking for additional capital to help drive her personal brand forward, whether that be through editorial content or other digital elements. I guess the question for VCs is does KonMari spark joy? (Sorry, I had to).

KonMari was founded in 2015 by Kondo and her husband, Takumi Kawahara.

 

08 Mar 2019

Voatz, the blockchain-based voting app, gets another vote of confidence as Denver agrees to try it

A blockchain-based mobile voting app called Voatz is getting put to the test again.

The city of Denver revealed today that it has agreed to implement a mobile voting pilot in its May municipal election using the four-year-old, Boston-based startup’s technology. It will be offered exclusively to active-duty military, their eligible dependents and overseas voters using their smartphones.

All were notified that they could use Voatz via a newsletter this morning, along with a link to sign up to participate if they so choose.

Voatz — which had raised $2.2 million in funding led by the venture arm of Overstock.com last year — says it has conducted more than 30 successful pilots already. Two of these in West Virginia attracted the financial backing of Tusk Philanthropies, the philanthropic operation of investor, operator, and strategist Bradley Tusk, who was featured last year in the New Yorker for his involvement in both efforts.

One was a small pilot project in West Virginia that gave overseas citizens and members of the military stationed abroad access to Voatz to cast ballots on their phones, though it was open only to residents of two counties. The technology was put to the test again in last November’s mid-term elections, in which nearly 150 people voted from 24 out of state’s 55 counties.

We talked with Tusk in early December about both efforts and about Voatz more generally, which Tusk hasn’t but whose mission of enabling more people to vote, more easily, he aggressively advocates. Though mobile voting, blockchain-based apps, and Voatz in particular have been criticized as potentially vulnerable to hacking, Tusk spent the first 20 years of his career in politics, and in his view, unless more people are empowered to “advocate politically” from their phones, politicians will continue to respond to the far smaller number of voters who actually show up at the polls.

Tusk also believes Voatz works, having hired outside examiners to assess the first West Virginia pilot, including Andre McGregor, a former F.B.I. cyber special agent who is now the global head of security for TLDR, a company that specializes in blockchain technology. It may explain why, in partnering with the city of Denver and the National Cybersecurity Center, a federal agency that was created as an office within the U.S. Department of Homeland Security back in 2008, Tusk Philanthropies again invited Voatz as a partner in Denver’s mobile voting endeavor. (A spokesperson for Tusk Philanthropies tells us that Colorado has also explored developing an open source mobile voting platform but that it simply doesn’t exist yet.)

Certainly, it’s conceivable that Voatz is no less secure than existing options for overseas military personnel, who often submit their votes via email. With Voatz, ballots are transmitted between up to 32 “permissioned” computers that have to agree algorithmically that a ballot is legitimate before it gets recorded and counted, and this only after a voter has been identified through numerous other steps. Among these: a voter must provide a phone number, an eight-digit pin, and submit a photo of his or her driver’s license. The voter must then they shoot and submit a video of their face, which is then processed by facial recognition technology that can confirm (or not confirm) that the face in the video belongs to the same person registered as a state voter.

To assuage any lingering concerns, the city of Denver will additionally conduct its own audit. Meanwhile, Tusk Philanthropies will work with a cybersecurity partner, ShiftState, to conduct an independent audit, in addition to the internal audit done by of Voatz.

The city of Denver says that 4,000 international voters are eligible to use the app.

Interestingly, despite the efficiencies Voatz promises, the voting process still won’t be an easy one. Fully 65 candidates have tossed their hats in the ring for public offices, according go the region’s city magazine, 5280. And while far-flung military personnel may be using a blockchain-based app, the placement of each mayoral candidate on the ballot is being determined in decidedly old-school fashion – –  by drawing names out of a bingo ball turner.