Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations //

Identity & Access Management

Startup Armor Scientific Launches Multifactor Identity System

Company aims to replace usernames and passwords by combining GPS location, biometrics, and keys issued through a blockchain-based network.

RSA CONFERENCE 2019 – San Francisco – Many security firms have focused on multifactor authentication (MFA), but startup Armor Scientific hopes that its recipe of location-based authentication paired with biometrics along with a blockchain ledger for key management will help companies improve security and do away with usernames and passwords.

The company, which emerged from stealth on March 4 at the RSA Conference, said it plans to focus initially on first responders and critical jobs that require high security, such as healthcare and financial institutions. Many of those jobs deal with sensitive data, but the workers often do not have time to log in with multiple factors of authentication. The combination exposes high-value data to compromise.

"Law enforcement, first responder — there is automated log-in everywhere in a law enforcement environment," said Scott Mohr, chief security officer at Armor Scientific. "They have to log in, tap in, touch in, or leverage some multiple set of keys, and when an officer leaves the dashcam of his car behind, they don't know where that officer is."

By marrying location information — provided by the GPS-based technology — and biometric information, the company's system will allow first responders and others to access necessary data securely. As an added benefit for first responders, the technology will provide location data on officers and workers, Mohr says.

"What we are able to do is provide the red dot on the map for first responders," he said.

MFA Resistance Fierce
Increasingly, companies are moving to two-factor (2FA) authentication or MFA to allow authorized users and workers access to their systems and services. However, nearly two-thirds of companies have reported facing stiff resistance from workers to adopt two-factor authentication, according to an August 2018 study.

2FA can be slow, so many services providers have adopted a more flexible approach, known as adaptive authentication — allowing additional factors to be requested only during suspicious attempts to access a system or service. While those adaptive solutions are appropriate, often they involve poorly integrated authentication systems, increasing the vulnerability surface area, Mohr said.

"What is happening in today's world, the multifactor solutions that are coming to the table, really all they do is stack multiple technologies on top of one another and create additional layers that ultimately allow hackers more access," he said. "We believe it is compounding the problem and not making us more secure. In addition, you see that the frustration level is going through the roof."

Using Blockchain for Authenticating Devices
Armor Scientific designed its system from the ground up to integrate all the components and reduce the potential attack surface area, says Nick Buchanan, CTO of Armor Scientific. The company's blockchain approach is not based on code from an open source solution but is created to the specifications required by Armor Scientific's clients, he said.

By using a consensus approach, the blockchain's distributed nature prevents new devices from accessing the network unless three — or more — nodes have verified its authenticity.

"If someone tries to enter the network surreptitiously, none of the nodes respond — it needs to have a signature," Buchanan said. "There is no such thing as anonymous communication on our network. You are either identified or you are not."

While the 2FA market is crowded, Armor Scientific's Mohr and Buchanan said that the focus on specific markets, such as first responders and high-security networks, will help the company stand out.

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-9717
PUBLISHED: 2019-09-19
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
CVE-2019-9719
PUBLISHED: 2019-09-19
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVE-2019-9720
PUBLISHED: 2019-09-19
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVE-2019-16525
PUBLISHED: 2019-09-19
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.
CVE-2019-9619
PUBLISHED: 2019-09-19
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.