TechCrunch News 03月11日
Some say passkeys are clunky — this startup wants to change that
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Hawcx是一家网络安全初创公司,致力于通过其创新的无密码验证技术解决Passkey的局限性。Passkey作为密码的替代方案被广泛采用,但由于其缺乏便携性和操作繁琐,用户接受度不高。Hawcx的技术不依赖于传输或存储设备上的私钥,而是每次用户登录时动态生成私钥,从而解决了Passkey在多设备登录和旧设备兼容性方面的问题。该公司已获得300万美元的pre-seed轮融资,并计划与大型银行和游戏公司合作进行试点,以验证其技术的有效性,并最终成为企业统一的身份验证平台。

🔑Hawcx旨在解决Passkey的痛点,例如多设备登录的复杂性和旧设备不兼容的问题,通过不存储设备私钥,而是每次登录时动态生成私钥的方式,简化用户体验。

🛡️Hawcx的无密码验证技术旨在提供更高级别的安全性,因为它不依赖于存储在设备上的私钥,从而降低了密钥被盗的风险。

🚀Hawcx计划与大型银行和游戏公司合作进行试点,并在斯坦福大学寻求密码学专家的验证,以加速产品开发并获得市场认可。同时,该公司致力于成为企业统一的身份验证平台,整合文档验证、视频验证和背景调查等服务。

Passwords are ubiquitous, despite not being foolproof and cannot alone protect your online identity. Almost one-third of data breaches reported over the past decade happened due to stolen credentials, per Verizon, including some of the biggest breaches of all time.

Instead, the industry has largely found passkeys arguably the most prominent solution to replace passwords. More than 15 billion accounts online can use passkeys, and big tech companies — Amazon, Apple, Google, and Microsoft, and others — are working together to promote passkey adoption.

But users are still shying away from passkeys due to their lack of portability and a general state of clunkiness.

Cybersecurity startup Hawcx aims to fix some of the headaches with passkeys by using its new passwordless authentication technology, which takes the best of passkeys but without their limitations.

Users can find setting up passkeys on their accounts cumbersome and challenging when logging in using passkeys across multiple devices, as noted by Dan Goodin at Ars Technica. While passkeys undoubtedly offer better security over passwords, account lock-outs and recoveries can become a costly affair for businesses that use passkeys at scale.

Founded in 2023 by Riya Shanmugam, who spent almost two decades at Adobe, Google, and New Relic; along with chief technology officer Selva Kumaraswamy and chief scientist Ravi Ramaraju, Hawcx says it offers a platform-agnostic solution that allows developers to add five lines of code to enable its passwordless tech.

Hawcx said its solution doesn’t rely on transmitting or storing private keys from devices, like passkeys. Instead, Shanmugam told TechCrunch that Hawcx cryptographically generates private keys every time the user signs in.

Hawcx co-founders Selva Kumaraswamy, Riya Shanmugam, and Ravi Ramaraju (From Left to Right)

Since the generated private keys are not stored on a user’s devices, Hawcx says its technology works on older devices that don’t have the modern chips to support the typical passkey setup.

“We are not reinventing the wheel fundamentally in most of the processes we have built,” Shanmugam told TechCrunch.

In one example, if a user switches from one device to another, Hawcx’s solution asks if they want the new device to be registered on their account and verify the user’s authenticity to let them in.

However, in this case, the solution will not create another private key that will be stored on the new device or in a cloud service — unlike a typical passkey setup in which a new private key is either generated and stored on the new hardware, validated using the older device, or synced via a cloud service.

“No one is challenging beyond the foundation,” Shanmugam said while referring to the competition in the digital identity management space. “What we are challenging is the foundation itself. We are not building on top of what passkeys as a protocol provides. We are saying this protocol comes with an insane amount of limitations for users, enterprises, and developers, and we can make it better.”

Hawcx has filed patents, but has not seen its deployed by companies or technology validated by third parties, which could hamper trust in its service.

Nonetheless, Hawcx has raised $3 million in a pre-seed round led by Engineering Capital, along with participation from Boldcap, to speed up its product development and get to the market.

Shanmugam told TechCrunch that the startup is in discussions with large banks and gaming companies to start its pilots in the next few weeks, which will run between three to six months with a limited set of users. The startup also plans to get the tech validated with a “couple of cryptography experts” at Stanford University.

“As we are rolling out passkeys, the adoption is low. It’s clear to me that as good as passkeys are and they have solved the security problem, the usability problem still remains,” Tushar Phondge, director of consumer identity at ADP, told TechCrunch.

Phondge is bullish on Hawcx’s tech and is set to deploy it at ADP for a pilot to test if it addresses the issues passkeys bring along, including device dependencies and core system lockups.

Ultimately, Shanmugam said Hawcx aims to be a unified authentication platform for businesses over time and partner with different players to integrate services such as document verification, live video verification, and even background checks.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Hawcx 无密码验证 Passkey 网络安全
相关文章