Application Security

1/25/2018
11:01 AM
50%
50%

Facebook Buys Identity Verification Firm

Facebook has purchased startup Confirm, which uses pattern analysis to confirm identities.

Confirm, a Boston-based identity verification startup, has agreed to be acquired by Facebook. The two companies have not disclosed the terms of their deal.

For three years Confirm has specialized in building technology that confirms user identities using photos of their driver's licenses or other forms of ID. The company has developed APIs and SDKs that can be integrated into applications for verification purposes.

Following the acquisition, Confirm has updated its website to state its current digital identity authentication software offerings will be wound down. It will join Facebook's office in Cambridge, Mass., but has not confirmed how many employees will stay with the company.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/27/2018 | 11:20:50 PM
Re: More intrusion?
@jenshadus: In many cases, they already know most of that!
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/26/2018 | 4:57:10 PM
Re: More intrusion?
What would Amazon want with FB? Amazon's ways of spying on us are far more reliable and expansive. Moreover, FB's forays into infrastructure and hardware still don't quite hold a candle to those of Amazon's.
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
1/26/2018 | 2:55:18 PM
Re: More intrusion?
You are onto something. 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/26/2018 | 2:48:49 PM
Re: More intrusion?
WE can all worry when Amazon buys Facebook.  THEN the cat will indeed be out of the bag and in a box with that stupid smile on it.
jenshadus
50%
50%
jenshadus,
User Rank: Strategist
1/26/2018 | 1:09:19 PM
More intrusion?
So FB wants to verify who you are, where you are, what you are buying, when you go to sleep?  What the heck?  If this is for on-line shopping, I can see it, for anything else it's a no go for me.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/25/2018 | 11:50:58 PM
Boston
Good to know that FB is effectively expanding its footprint here in Boston. I wonder to what extent, if it all, this will impact Amazon's decision in the run-off for HQ2.

(Charitably assuming, of course, that Amazon has not already secretly made its decision and is simply using the 20-city list as a negotiating tactic.)
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Intel Reveals New Spectre-Like Vulnerability
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/15/2018
Data Privacy Careers Are Helping to Close the IT Gender Gap
Dana Simberkoff, Chief Compliance and Risk Management Officer, AvePoint, Inc,  8/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15601
PUBLISHED: 2018-08-21
apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism.
CVE-2018-15603
PUBLISHED: 2018-08-21
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen.
CVE-2018-15598
PUBLISHED: 2018-08-21
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
CVE-2018-15599
PUBLISHED: 2018-08-21
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
CVE-2018-0501
PUBLISHED: 2018-08-21
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.