Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations //

Identity & Access Management

Startup Armor Scientific Launches Multifactor Identity System

Company aims to replace usernames and passwords by combining GPS location, biometrics, and keys issued through a blockchain-based network.

RSA CONFERENCE 2019 – San Francisco – Many security firms have focused on multifactor authentication (MFA), but startup Armor Scientific hopes that its recipe of location-based authentication paired with biometrics along with a blockchain ledger for key management will help companies improve security and do away with usernames and passwords.

The company, which emerged from stealth on March 4 at the RSA Conference, said it plans to focus initially on first responders and critical jobs that require high security, such as healthcare and financial institutions. Many of those jobs deal with sensitive data, but the workers often do not have time to log in with multiple factors of authentication. The combination exposes high-value data to compromise.

"Law enforcement, first responder — there is automated log-in everywhere in a law enforcement environment," said Scott Mohr, chief security officer at Armor Scientific. "They have to log in, tap in, touch in, or leverage some multiple set of keys, and when an officer leaves the dashcam of his car behind, they don't know where that officer is."

By marrying location information — provided by the GPS-based technology — and biometric information, the company's system will allow first responders and others to access necessary data securely. As an added benefit for first responders, the technology will provide location data on officers and workers, Mohr says.

"What we are able to do is provide the red dot on the map for first responders," he said.

MFA Resistance Fierce
Increasingly, companies are moving to two-factor (2FA) authentication or MFA to allow authorized users and workers access to their systems and services. However, nearly two-thirds of companies have reported facing stiff resistance from workers to adopt two-factor authentication, according to an August 2018 study.

2FA can be slow, so many services providers have adopted a more flexible approach, known as adaptive authentication — allowing additional factors to be requested only during suspicious attempts to access a system or service. While those adaptive solutions are appropriate, often they involve poorly integrated authentication systems, increasing the vulnerability surface area, Mohr said.

"What is happening in today's world, the multifactor solutions that are coming to the table, really all they do is stack multiple technologies on top of one another and create additional layers that ultimately allow hackers more access," he said. "We believe it is compounding the problem and not making us more secure. In addition, you see that the frustration level is going through the roof."

Using Blockchain for Authenticating Devices
Armor Scientific designed its system from the ground up to integrate all the components and reduce the potential attack surface area, says Nick Buchanan, CTO of Armor Scientific. The company's blockchain approach is not based on code from an open source solution but is created to the specifications required by Armor Scientific's clients, he said.

By using a consensus approach, the blockchain's distributed nature prevents new devices from accessing the network unless three — or more — nodes have verified its authenticity.

"If someone tries to enter the network surreptitiously, none of the nodes respond — it needs to have a signature," Buchanan said. "There is no such thing as anonymous communication on our network. You are either identified or you are not."

While the 2FA market is crowded, Armor Scientific's Mohr and Buchanan said that the focus on specific markets, such as first responders and high-security networks, will help the company stand out.

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
7 Truths About BEC Scams
Ericka Chickowski, Contributing Writer,  6/13/2019
DNS Firewalls Could Prevent Billions in Losses to Cybercrime
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/13/2019
Can Your Patching Strategy Keep Up with the Demands of Open Source?
Tim Mackey, Principal Security Strategist, CyRC, at Synopsys,  6/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-2729
PUBLISHED: 2019-06-19
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise ...
CVE-2019-3737
PUBLISHED: 2019-06-19
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application.
CVE-2019-3787
PUBLISHED: 2019-06-19
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending ?unknown.org? to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to ...
CVE-2019-12900
PUBLISHED: 2019-06-19
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
CVE-2019-12893
PUBLISHED: 2019-06-19
Alternate Pic View 2.600 has a User Mode Write AV starting at PicViewer!PerfgrapFinalize+0x00000000000a8868.