Author: azeeadmin

04 Mar 2019

Scytale grabs $5M Series A for application-to-application identity management

Scytale, a startup that wants to bring identity and access management to application-to-application activities, announced a $5 million Series A round today.

The round was led by Bessemer Venture Partners, a return investor which led the company’s previous $3 million round in 2018. Bain Capital Ventures, TechOperators and Work-Bench are also participating in this round.

The company wants to bring the same kind of authentication that individuals are used to having with a tool like Okta to applications and services in a cloud native environment. “What we’re focusing on is trying to bring to market, a capability for large enterprises going through this transition to cloud native computing to evolve the existing methods of application to application authentication, so that it’s much more flexible and scalable,” Sunil James, company CEO told TechCrunch.

To help with this, the company has developed the open source, cloud native project, Spiffe, that is managed by the Cloud Native Computing Foundation (CNCF). The project is designed to provide identity and access management for application-to-application communication in an open source framework.

The idea is that as companies transition to a containerized, cloud native approach to application delivery, there needs to a smooth automated way for applications and services to prove they are legitimate very quickly in much the same way individuals provide a username and password to access a website. This could be, for example, as applications pass through API gateways, or as automation drives the use of multiple applications in a workflow.

Webscale companies like Google and Netflix have developed mechanisms to make this work in-house, but it’s been out of reach of most large enterprise companies. Scytale wants to bring this capability to authenticate services and applications to any company.

In addition to the funding announcement, the company also announced Scytale Enterprise, a tool that provides a commercial layer on top of the open source tools that the company has developed. The enterprise version helps companies, who might not have the personnel to deal with the open source version on their own by providing training, consulting and support services.

Bain Capital Venture’s Enrique Salem sees a startup solving a big problem for companies who are moving to cloud native environments and need this kind of authentication.”In an increasingly complex and fragmented enterprise IT environment, Scytale has not only built Spiffe’s amazing open-source community but has also delivered a commercial offering to address hybrid cloud authentication challenges faced by Fortune 500 identity and access management engineering teams,” Salem said in a statement.

The company, which is based in the Bay area, launched in 2017 and currently has 24 employees.

04 Mar 2019

JetBlue contest asks users to delete their Instagram pics to fly free for a year

In a move that’s both bold and bizarre, JetBlue is introducing a new contest that will give three winners a year of free flights on the carrier. But entrance to the contest comes at a steep price. Users must delete all of their Instagram photos, post a new photo using a JetBlue template, and hope to be one of the lucky three.

Entrants must keep their Instagram clear, and set to Public, through March 8.

On the one hand, the Instagram-decimating contest may tap into some of the anti-social sentiment that’s cropped up over the past couple years. In the wake of data misuse and privacy mishandling by Facebook, which owns Instagram, conversations around deleting social media and one’s own digital imprint have grown more frequent.

Plus, Instagram has tools to let users download all of their photos. Starting fresh on social media may be an attractive prospect to some people.

On the other hand, Instagram has been a modern-day photo album for many people, representing a place where they record the various steps of their life. For many, the request to delete their IG history is a very tall order.

The situation is made more baffling by the fact that JetBlue doesn’t really explain why you must delete all your Instagram photos before posting their promotional garbage content.

Perhaps the carrier would like to replicate the same viral moment that #FyreFestival did with that burnt orange square. Or maybe I’m falling into their trap as we speak, as a seemingly crazy request to delete an entire Instagram history is inherently a bit of a publicity stunt.

Whatever the case, we all have a very first-world decision to make. What’s worth more: your Instagram or the slim chance of free flights for a year?

04 Mar 2019

Sam’s Club to test new Scan & Go system that uses computer vision instead of barcodes

In October, Walmart-owned Sam’s Club opened a test store in Dallas where it planned to trial new technology including mobile checkout, an Amazon Go-like camera system, in-store navigation wayfinding technology, electronic shelf labels, and more. This morning, the retailer announced it will now begin testing a revamped Scan & Go service as well, which leverages computer vision and machine learning to make mobile scanning easier and faster.

The current Scan & Go system, launched two years ago, requires Sam’s Club shoppers to locate the barcode on the the item they’re buying, before scanning it using the Sam’s Club mobile app. The app allows shoppers to account for items they’re buying as they place them in their shopping cart, then pay in the app instead of standing in line at checkout.

However convenient, the system itself can still be frustrating at times because you’ll need to actually find the barcode on the item – often turning the item over from one side to the other to find the sticker or tag. This process can be difficult for heavier items, and frustrating when the barcoded label or tag has fallen off.

It can also end up taking several seconds to complete – which adds up when you’re filling a cart with groceries during a big stocking up trip.

The new scanning technology will instead use computer vision and ML (machine learning) to recognize products without scanning the barcode, cutting the time it takes for the app to identify the product in question, the retailer explains.

In a video demo, Sam’s Club showed how it might take a typical shopper 9.3 seconds to scan a pack of water using the old system, versus 3.4 seconds using the newer technology.

Of course, the times will vary based on the shopper’s skill, the item being scanned, and how well the technology performs, among other factors. A large package of water is a more extreme example, but one that demonstrates well the potential of the system…if it works.

The idea with the newly opened Dallas test store is to put new technology into practice quickly in a real-world environment, to see what performs well and what doesn’t, while also gathering customer feedback. Dallas was chosen as the location for the store because of the tech talent and recruiting potential in the area, and because it’s a short trip from Walmart’s Bentonville, Arkansas headquarters, the company said earlier.

Sam’s Club says it has filed a patent related to the new scanning technology, and will begin testing it this spring at the Dallas area “Sam’s Club Now” store. It will later expand the technology to the tools used by employees, too.

 

04 Mar 2019

Huawei reportedly plans to sue US government over ban

Huawei’s already proven that a ban in the world’s second largest smartphone market won’t hamper its rapid success, but the company still won’t go down in the States without a fight. Word is that the consumer electronics giant is planning to unveil a lawsuit against the U.S. government later this week.

That news comes via two anonymous sources reported in The New York Times this morning. The reported impending suit is pushback against long-standing bans in the States that have barred the company’s equipment from infrastructural projects ahead of a nationwide push into 5G. It’s also made the nation’s carriers and retail stores wary of stocking Huawei products.

The suit is reportedly set to be filed in the Eastern District of Texas — the location of of Huawei’s U.S. headquarters, as well as a notorious haven for patent trolls.

U.S. officials have long recommended against using Huawei  devices over alleged ties to the Chinese government. On Friday, meanwhile, the Canadian DOJ allowed an extradition case against Huawei CFO Meng Wanzhou to proceed after her arrest in Vancouver late last year. Those charges stem from allegations that the company circumvented sanctions on Iran.

Earlier today it was announced that Meng was filing a civil suit in the country, alleging that authorities didn’t advise her of her constitutional rights prior to questioning and detaining her.

We’ve reached out to Huawei for comment on the suits.

04 Mar 2019

Seraphim attracts the UK’s Ministry of Defence to its SpaceTech accelerator

In the US the links between private sector technology and the defense industry are long and well known. And in the realm of startups, DARPA, has long fostered new technologies such as those around drones.

But despite the world-class defense sector in the UK, historically speaking, it has not reached out quite so overtly to startups. That is beginning to change with the announcement today of a brand new link between the pioneering UK space accelerator Seraphim Space Camp accelerator and the Defence, Science and Technology Laboratory. Dstl will now become the newest corporate partner to support the programme in 2019, joining joins others including: Rolls Royce, Inmarsat, Airbus and the European Space Agency.

In summer last year Seraphim unveiled its first 6 startups.

Through its sponsorship, Dstl will be able to engage with Seraphim’s pipeline of emerging technologies to address upcoming defense and security challenges facing, as well as develop proof-of-concepts and pilots to work out whether these technologies could have real applications within the agency.

Michael O’Callaghan, Space Programme Manager at Dstl told us this was a new move for the agency working in this way with a private sector tech accelerator: “From advanced space technologies, through to state-of-the-art earth observation start-ups; Seraphim Space Camp’s deal-flow of companies has huge applications within the defense and security Sector”.
Dstl is an Executive Agency of the MOD, run along commercial lines and is one of the principal government organizations dedicated to space and tech in the defense and security field, with six sites, including the famous Porton Down, near Salisbury.

Rob Desborough, Seraphim Capital Investment Director and Director of Seraphim Space Camp commented: “Bringing on the Defence Science and Technology Laboratory is a big deal for us. Not only are our visions very much aligned but I believe the start-ups on our programme will really benefit from having such a big player in the UK’s defence and Space Sector so closely involved; and will be a great addition to the high pedigree of corporate partners we’ve been lucky enough to have on board so far.”

04 Mar 2019

AirAsia launches a $60M fund to help startups get into Southeast Asia

Budget airline AirAsia is getting into the VC game after it unveiled a venture capital fund that aims to invest in startups across the world.

The airline today announced Redbeat Capital, a $60 million fund that it says will operate independently and seek deals with startups worldwide in areas such as travel, lifestyle, fintech and logistics startups worldwide. The big selling point to prospective companies is the opportunity to tap into AirAsia’s business in Southeast Asia, which claims to cater to 90 million flyers each year.

The fund is targeting a $60 million close, although AirAsia didn’t reveal how much it has secured so far. It will be run out San Francisco and Southeast Asia, and it is working with 500 Startups to source deal flow and exchange ideas.

AirAsia has suffered a stock tumble on financial concerns but is still valued at over $2 billion. Redbeat Capital is part of an ambitious strategy to widen AirAsia’s focus and take it beyond simply being an airline, according to group CEO Tony Fernandes.

“I’m determined to change AirAsia from just moving people into something different in five years time. This is a serious step in the whole transformation piece [that’s] no different to when I set up the airline,” Fernandes told TechCrunch in an interview. ”

“Our first transformation was being a low-cost carrier that uses the web, so our culture has always been in tech,” he added.” We’re now going for our second sage with our platforms” — those include its BigPay payment service, BigLife app and logistics business.

But a corporate fund this isn’t, at least according to Fernandes.

Redbeat Capital has raised its money from LPs — though it declined to provide details on them — and Fernandes said it will balance both making investments for financial return and boosting AirAsia, too. The company already has a corporate vehicle — Redbeat Ventures — but that will switch to being an incubator and company-aligned investment vehicle, while its portfolio will transition to Redbeat Capital, Fernandes said.

“We wanted to give it a bit more independence, as opposed to just being an arm of AirAsia… it’s to be seen whether we can execute,” he added.

In terms of deals, Fernandes was fairly coy about precise details other than that it is “post-seed.” He said the fund could write checks as high as $5 million or around $1 million as needed.

Tony Fernandes has set a goal of five years for broadening AirAsia’s business beyond air travel (Photo: Paul Miller/Bloomberg)

Silicon Valley is a tough market to break into for any first-time investor, and AirAsia isn’t a known brand in California. But the AirAsia chief believes Redbeat Capital can offer a unique gateway into Southeast Asia, which he believes is frequently overlooked in favor of India or China.

“Competing in India and China is expensive but Southeast Asia is just starting,” he said. “We are looking for companies that want to be strategic with us and use our database and platforms for mutual benefit.”

By that, he explained that AirAsia can use its platform and customer base to help companies acquire users and do marketing, typically two of the largest expenses, in the region.

There’s plenty of optimism around Southeast Asia — a recent report co-authored by Google forecast that the region’s digital economy will triple to reach $240 billion by 2025.

That’s echoed by 500, which operates funds in Southeast Asia and is currently raising a new global fund.

“[Southeast Asia] has more internet users than the U.S, which presents a huge opportunity for entrepreneurs. To have an industry titan like AirAsia building a bridge with Silicon Valley through its partnership with 500 is exciting for our startups, many of which have ambitions for global scale,” added Christine Tsai, CEO of 500 Startups, in a statement.

Still, it remains to be seen if Redbeat Capital can balance the very different demands of corporate investing with financial-driven deals. Large company funds tend to have less focus on financial, with ROI typically focused on encouraging ‘innovation’ within the parent company or enabling deals to help the bottom line. Profession funds, of course, exist to return the fund and more to their LPs.

Still, Fernandes — whose diverse business interests have included music, British soccer and formula — is characteristically up for the challenge. He won’t directly be involved, though. The venture will be led by Aireen Omar — deputy group CEO who leads AirAsia’s digital strategy — but her boss is looking on eagerly.

“This is unconventional but the early fruits are encouraging,” Fernandes said.

04 Mar 2019

Tide Foundation gives consumers full control of personal data on blockchain

It seems that on a regular basis, we hear about massive data breaches or companies sharing highly personal information with third parties without a consumer’s permission or knowledge. The Tide Foundation wants to change that by giving consumers complete control over their personal data on the blockchain by allowing them to manage their own encryption keys.

The startup wants to take that notion a step further by giving users the ability to sell that personal information in an open marketplace that the company is announcing today.

“The overall concept is that when a consumer engages with a business and provides that business with personally identifiable information, the Tide Protocol encrypts that information and provides the consumer with the only key to decrypt it,” Issac Elnekave, Tide co-founder told TechCrunch.

With full control over their data, companies could not transfer any information to a third party without the consumer granting permission first. The marketplace provides a way for companies who need data, the vendors who manage that data and the consumers who ultimately own the data to negotiate a fair market value for access to it. What’s more, the companies buying the data know that they are getting much more valuable and accurate information, delivered with the full knowledge of the consumer.

In the event of a massive data breach like Equifax or Marriott, if customers had been using the Tide Protocol, the hackers couldn’t have actually used the PII in the breached databases because consumers would control the keys to decrypt it, rendering it useless to the data thieves.

Technically, the protocol works in a kind of standard business blockchain fashion. “Tide Protocol uses forked EOS nodes, smart contracts and additional proprietary decentralized layers to manage permissioned access to encrypted consumer data stored by businesses (vendors),” the company explained in a statement.

As for consumers controlling encryption keys, the company says it has created a patented technology to simplify the process of managing those keys in order to put that process within reach of anyone, one that passes what they call “the Grandpa Test.”

“We have developed a layer, a decentralized way to dumb down blockchain to a ubiquitous user experience on the web,” Yuval Hertzog, the other company co-founder explained. He said the idea is to simplify the highly complex and make key management a typical kind of web experience.

Elnekave says that the company has also found a way to comply with GDPR, the strict EU privacy regulations that went into effect last year that includes the right to be forgotten. Because the protocol gives consumers full control over the encryption keys, the user simply has to stop giving access to the business, essentially throwing away the encryption key and blocking access, he explained.

Tide launched three years ago in Sydney, Australia and developed the Tide Protocol, the basis of its blockchain data privacy solution, two years ago. Today it has 13 employees. The company raised a $2 million seed round in November.

The startup believes data ownership should be a basic human right in a similar fashion to Hu-manity.co, the startup that wants to provide a similar set of tools as Tide, but focussed on medical information.

04 Mar 2019

FlixBus, the German Uber-like bus service, is buying rival Eurolines from Transdev

While all eyes are on what Uber Lyft and Didi will do this year as private transportation-on-demand services continue to consolidate, there’s also some interesting moves being played out in the adjacent business of bus and coach services.

Today, FlixBus, the German startup backed by Daimler, General Atlantic, Silver Lake and others that has built an Uber-like network to manage bus logistics, drivers and passengers on intercity routes, announced that it is entering a deal to acquire Eurolines, a competing service currently owned by Transdev, a European public transport giant.

The move is being made to expand its services specifically in Europe.

“This acquisition would strengthen our position as market leader in France and allows us to expand our European reach even further by integrating the Eurolines and isilines long-distance route networks,” said Jochen Engert, founder and CEO of FlixBus, in a statement. “With this integration, FlixBus would have an even more-complete and diverse offer to entice even more passengers. We aim to be the number one choice for travelers across Europe.” The companies say they are currently in negotiations with workers’ groups as part of the acquisition process.

Terms of the deal are not being disclosed, spokespeople for Transdev and Flixbus said in a statement to TechCrunch. FlixBus has never disclosed how much it has raised, nor its valuation.

But it is currently Europe’s largest bus service network, with routes in 29 countries and serving some 45 million passengers in 2018. It is rumored both to be eyeing up an IPO and is also valued at over $1 billion.

Transdev, meanwhile, was last valued at around $1.3 billion, according to PitchBook, after raising nearly $400 million earlier this year. The company, based out of France, has a plan to orient itself away from B2C services under new CEO Theirry Mallet (who took over the role last month), to instead focus on public transportation. Divesting Eurolines would be in keeping with that.

“The decision to enter exclusive negotiations with FlixBus regarding the potential divestment from Eurolines is in line with Transdev’s strategic plan,” said Mallet in a statement. “It would enable us to focus our resources on the core of our business, public transit and B2B transportation services by combining performance at best cost, technological and digital innovation, specifically to improve the customer experience.”

It’s not clear how big Eurolines/isilines is relative to Transdev overall, but the former business appears to be growing: it transported 2.5 million passengers in 2018, up 10 percent compared to 2017, a spokesperson told TechCrunch. (Still, a small business compared to FlixBus’ operation.)

The deal represents a big consolidation move in the area of bus services — and specifically services that help manage the movement of buses, rather than the physical bus companies themselves.

Similar to Uber, FlixBus and Eurolines do not take on the capital expenditure and operational costs of owning fleets of vehicles, instead providing a service to scores of companies that operate fleets to provide them with an efficient network to sell tickets and organise schedules around their services.

They also take a hand in customising the buses that work on their services with WiFi and other features.

While Greyhound-style long-distance bus services may not be the first thing that comes to mind when you think of when the concept of state-of-the-art travel, both Transdev and FlixBus have been trying to change that. FlixBus, which recently also entered the US market, started to pilot VR services on specific routes this year. Transdev, meanwhile, has been one of the companies building autonomous driving for buses.

With this deal, FlixBus would be bulking up in Europe specifically to help it take on not just other modes of transport like trains, planes and automobiles, but also to compete against bus companies.

Just a few months ago, France’s BlaBlaCar announced that it would acquire yet another hopeful in the space, Ouibus, from SNCF (France’s public transport provider). With others like Uber also recently launching its first forays into bus services as well, coach companies will have to bust a move if they hope to stay ahead in the bus game.

04 Mar 2019

Go-Jek pulls in $100M more for its massive Series F round

U.S. ride-hailing giants Lyft and Uber are going public in the U.S. imminently, but over in Southeast Asia, the two largest on-demand companies are still madly fueling up on investment capital.

The latest update to that story today saw Go-Jek, the Indonesian ride-hailing firm aiming to go regional in Southeast Asia, announced that it has pulled in $100 million from conglomerate Astra, an existing investor, as part of the Series F round it is raising right now. We know Go-Jek is aiming to bring in at least $2 billion from that round — and that it has closed around half of that capital — so the addition from Astra is likely one of many that will take it towards that target.

There’s also a strategic component to this deal.

Astra, for those who are not aware of it, is a $20 billion conglomerate that specializes in manufacturing, automotive and infrastructure industries. It plans to start a joint venture with Go-Jek to equip its cars with Astra’s fleet management system to help improve the way Go-Jek manages its fleet and on-demand services. The rollout will start with “thousands” of Go-Car drivers.

The capital is being raised to expand Go-Jek’s services in Southeast Asia.

The company recently went official with the launch of its Thailand-based Get business. It has also expanded to Vietnam and Singapore over the last year and it is primed to offer its services in the Philippines soon.

Grab, meanwhile, Go-Jek’s key adversary, recently raised $2 billion for its recent Series H round. The company is working to extend that figure to $5 billion with a planned investment of up to $1.5 billion from SoftBank’s Vision Fund in the offing.

04 Mar 2019

Flawed visitor check-in systems let anyone steal guest logs and sneak into buildings

Security researchers at IBM have found, reported and disclosed 19 vulnerabilities in five popular visitor management systems, which they say can be used to steal data on visitors — or even sneak into sensitive and off-limit areas of office buildings.

You’ve probably seen one of these visitor check-in systems before: they’re often found in lobbies or reception areas of office buildings to check staff and visitors onto the work floor. Visitors check in with their name and who they’re meeting using the touch-screen display or tablet, and a name badge is either printed or issued.

But the IBM researchers say flaws in these systems provided “a false sense of security.”

The researchers examined five of the most popular systems: Lobby Track Desktop, built by Jolly Technologies, had seven vulnerabilities; eVisitorPass, recently rebranded as Threshold Security, had five vulnerabilities; EasyLobby Solo, built by HID Global, had four vulnerabilities; Envoy’s flagship Passport system had two vulnerabilities; and The Receptionist, an iPad app, had one vulnerability.

According to IBM, the vulnerabilities could only be exploited by someone physically at check-in. The bugs ranged from allowing someone to download visitor logs, such as names, driver license and Social Security data, and phone numbers; or in some cases, the buggy software could be exploited to escape “kiosk” mode, allowing access to the underlying operating system, which the researchers say could be used to pivot to other applications and on the network, if connected.

Worse of all, the use of default admin credentials that would give “allow complete control of the application,” such as the ability to edit the visitor database. Some systems “can even issue and provision RFID badges, giving an attacker a key to open doors,” the researchers wrote.

Daniel Crowley, research director at IBM X-Force Red, the company’s pen-testing and vulnerability hunting team, told TechCrunch that all of the companies responded to the team’s findings.

“Some responded much more quickly than others,” said Crowley. “The Lobby Track vulnerabilities were acknowledged by Jolly Technologies, but they stated that the issues can be addressed through configuration options. X-Force Red tested the Lobby Track software in its default configuration,” he added.

We contacted the companies and received — for the most part — dismal responses.

Kate Miller, a spokesperson for Envoy, confirmed it fixed the bugs but “customer and visitor data was never at risk.”

Andy Alsop, chief executive of The Receptionist, did not respond to a request for comment but instead automatically signed us up to a mailing list without our permission, which we swiftly unsubscribed from. When reached, Michael Ashford, director of marketing, did not comment.

David Jordan, a representative for Jolly, declined to comment. And, neither Threshold Security and HID Global responded to our requests for comment.