computing

Auto Added by WPeMatico

We’ll talk even more Kubernetes at TC Sessions: Enterprise with Microsoft’s Brendan Burns and Google’s Tim Hockin

You can’t go to an enterprise conference these days without talking containers — and specifically the Kubernetes container management system. It’s no surprise then, that we’ll do the same at our inaugural TC Sessions: Enterprise event on September 5 in San Francisco. As we already announced last week, Kubernetes co-founder Craig McLuckie and Aparna Sinha, Google’s director of product management for Kubernetes, will join us to talk about the past, present and future of containers in the enterprise.

In addition, we can now announce that two other Kubernetes co-founders will join us: Google principal software engineer Tim Hockin, who currently works on Kubernetes and the Google Container Engine, and Microsoft distinguished engineer Brendan Burns, who was the lead engineer for Kubernetes during his time at Google.

With this, we’ll have three of the four Kubernetes co-founders onstage to talk about the five-year-old project.

Before joining the Kuberntes efforts, Hockin worked on internal Google projects like Borg and Omega, as well as the Linux kernel. On the Kubernetes project, he worked on core features and early design decisions involving networking, storage, node, multi-cluster, resource isolation and cluster sharing.

While his colleagues Craig McLuckie and Joe Beda decided to parlay their work on Kubernetes into a startup, Heptio, which they then successfully sold to VMware for about $550 million, Burns took a different route and joined the Microsoft Azure team three years ago.

I can’t think of a better group of experts to talk about the role that Kubernetes is playing in reshaping how enterprise build software.

If you want a bit of a preview, here is my conversation with McLuckie, Hockin and Microsoft’s Gabe Monroy about the history of the Kubernetes project.

Early-Bird tickets are now on sale for $249; students can grab a ticket for just $75. Book your tickets here before prices go up.

Powered by WPeMatico

Higher Ground Labs is betting tech can help sway the 2020 elections for Democrats

When Shomik Dutta and Betsy Hoover first met in 2007, he was coordinating fundraising and get-out-the-vote efforts for Barack Obama’s first presidential campaign and she was a deputy field director for the campaign.

Over the next two election cycles the two would become part of an organizing and fundraising team that transformed the business of politics through its use of technology — supposedly laying the groundwork for years of Democratic dominance in organizing, fundraising, polling and grassroots advocacy.

Then came Donald J. Trump and the 2016 election.

For both Dutta and Hoover, the 2016 outcome was a wake-up call against complacency. What had worked for the Democratic party in 2008 and 2012 wasn’t going to be effective in future election cycles, so they created the investment firm Higher Ground Labs to provide financing and a launching pad for new companies serving Democratic campaigns and progressive organizations.

As the political world shifts from analog to digital, we need a lot more tools to capture that spend,” says Dutta. “Democrats are spending on average 70 cents of every dollar raised on television ads. We are addicted to old ways of campaigning. If we want to activate and engage an enduring majority of voters we have to go where they are (and that’s increasingly online) and we have to adapt to be able to have these conversations wherever they are.”

Social media and the rise of “direct to consumer” politics

While the Obama campaign effectively used the internet as a mobilization tool in its two campaigns, the lessons of social media and mobile technologies that offer a “direct-to-consumer” politics circumventing traditional norms have, in the ensuing years, been harnessed most effectively by conservative organizations, according to some scholars and activists.

“The internet is a tool and in that sense it’s neutral, but just like other communication tools from the past, people with more power, with more resources, with more organization, have been able to take advantage of it,” Jen Schradie, an assistant professor at the Observatoire sociologique du changement at Sciences Po in Paris, told Vox in an interview earlier this month.

Schradie is a scholar whose recent book, “The Revolution That Wasn’t,contends that the internet’s early application as a progressive organizing tool has been overtaken by more conservative elements. “The idea of neutrality seems more true of the internet because the costs of distributing information are dramatically lower than with something like television or radio or other communication tools,” she said. “However, to make full use of the internet, you still need substantial resources and time and motivation. The people who can afford to do this, who can fund the right digital strategy, create a major imbalance in their favor.”

Schradie contends that a web of privately funded think tanks, media organizations, talk radio and — increasingly — mobile applications have woven a conservative stitch into the fabric of social media. The medium’s own tendency to promote polarizing and fringe viewpoints also served to amplify the views of pundits who were previously believed to be political outliers.

Essentially, these sites have enabled commentators and personalities to create a patchwork of “grassroots” organizations and media operations dedicated to reaching an audience receptive to their particular political message that’s funded by billionaire donors and apolitical corporate ad dollars.

Then there’s the technology companies, like Cambridge Analytica, which improperly used access to Facebook data for targeting purposes — also financed by these same billionaires.

“The last six years have witnessed millions and millions of dollars of private Koch money and Mercer money that have gone to pretty sophisticated data and media efforts to advance the Republican agenda,” says Dutta. “I want to even the scale.”

Dutta is referring to Charles and David Koch and Robert Mercer, the scions and founder (respectively) of two family dynasties worth billions. The Koch brothers support a web of political advocacy groups, while Mercer and his daughter were large backers of Breitbart News and Cambridge Analytica, two organizations that arguably provided much of the policy underpinnings and online political machinery for the Trump presidential campaign.

But there’s also the simple fact that Donald Trump’s digital strategy director, Brad Parscale, was able to effectively and inexpensively leverage the social media tools and data troves amassed by the Republican National Committee that were already available to the candidate who won the Republican primary. In fact, in the wake of Romney’s loss, Republicans spent years building up profiles of 200 million Americans for targeted messaging in the 2016 election.

“Who controls Facebook controls the 2016 election,” Parscale said during a speaking engagement at the Romanian Academy of Sciences, according to a report in Forbes.

Parscale, now the campaign manager for the president’s 2020 reelection campaign recalled, “These guys from Facebook walked into my office and said: ‘we have a beta … it’s a new onboarding tool … you can onboard audiences straight into Facebook and we will match them to their Facebook accounts,’ ” according to Forbes .

During the 2016 campaign, Hillary Clinton’s team made 66,000 visual ads, according to Parscale, while the Trump campaign made 5.9 million ads by leveraging social media networks and the language of memes. And in the run-up to the 2020 election, Parscale intends to go back to the same well. The Trump campaign has already spent more than $5 million on Facebook ads in the current election cycle, according to The New York Times outspending every single Democratic candidate in the field and roughly all of the Democrats combined.

Reaching higher ground

Dutta and Hoover are working to offset this movement with investments of their own. Back in 2017, the two launched Higher Ground Labs, an early-stage company accelerator and investment firm dedicated to financing technology companies that could support progressive causes.

The firm has $15 million committed from investors, including Reid Hoffman, the co-founder of LinkedIn and a partner at Greylock; Ron Conway, the founder of SV Angel and an early backer of Google, Facebook and Twitter; Chris Sacca, an early investor in Uber; and Elizabeth Cutler, the founder of SoulCycle. Already, Higher Ground has invested in more than 30 companies focused on services like advocacy outreach, polling and campaign organizing — among others. 

Screen Shot 2019 07 01 at 5.36.26 AM

The latest cohort of companies to receive backing Higher Ground Labs

“It is vitally important that Democrats learn to do their campaigns online,” says Dutta. “The way you recruit volunteers; the way you poll sentiment; the way you target and mobilize voters has to be done with online tools and has to improve in the progressive movement and that’s the job of Higher Ground Labs to fix.”

For-profit companies have a critical role to play in election organizing and mobilization, Dutta says. Thanks to government regulation, only private companies are allowed to trade data across organizations and causes (provided they do it at fair market value). That means advocacy groups, unions and others can tap the information these companies collect — for a fee.

The Democratic Party already has one highly valued private company that it uses for its technology services. Formed from the merger of NGP Software and Voter Activation Network, two companies that got their start in the late 1990s and early 2000s, NGP VAN is the largest software and technology services provider for Democratic campaigns. It’s also a highly valued company, which received roughly $100 million in financing last year from the private equity firm Insight Venture Partners, according to people familiar with the investment. Terms of the deal were not disclosed.

“Our vision has been to build a platform that would break down the painful data silos that exist in the campaigns and nonprofit space, and to offer truly best-in-class digital, fundraising and organizing features that could serve both the largest and the smallest nonprofits and campaigns, all with one unified CRM,” wrote Stu Trevelyan, the chief executive of NGP VAN + EveryAction, in an August blogpost announcing the investment. “We’re so excited that others, like our new partners at Insight, share that vision, and we can’t wait to continue innovating and growing together in the coming years.”

Can startups lead the way?

Even as private equity dollars boost the firepower of organizations like NGP VAN, venture capitalists are financing several companies from the Higher Ground Labs portfolio.

Civis Analytics, a startup founded by the former chief analytics officer of Barack Obama’s 2012 reelection campaign, raised $22 million from outside investors, and counts Higher Ground Labs among its backers. Qriously, another Higher Ground Labs portfolio company, was acquired by Brandwatch, as was GroundBase, a messaging platform acquired by the nonprofit progressive advocacy organization ACRONYM.

Other companies in the portfolio are also attracting serious attention from investors. Standouts like Civis Analytics and Hustle, which raised $30 million last May, show that investors are buying into the proposition that these companies can build lasting businesses serving Democratic and progressive political campaigns and corporate businesses that would also like to rally employees or personalize a marketing pitch to customers.

These are companies like Change Research, an earlier-stage company that just launched from Higher Ground Labs accelerator last year. That company, founded by Mike Greenfield, a serial Silicon Valley entrepreneur who was the first data scientist working on the problem of fraud detection at PayPal, and Pat Reilly, a communications professional who worked with state and local Democratic politicians, is slashing the cost of political polling.

“I wanted to do something for American democracy to try and improve the state of things,” Greenfield said in an interview last year.

For Greenfield, that meant increasing access to polling information. He cited the test case of a Kansas special election in a district that Donald Trump had won by 27 points. Using his own proprietary polling data, Greenfield predicted that the Democratic challenger, James Thompson, would pose a significant threat to his Republican opponent, Mike Estes.

Estes went on to a 7% victory at the ballot, but Thompson’s campaign did not have access to polling data that could have helped inform his messaging and — potentially — sway the election, said Greenfield.

“Public opinion is used to ween out who can be most successful based on how much money they’re able to raise for a poll,” says Reilly. It’s another way that electoral politics is skewed in favor of the people with disposable income to spend what is a not-insignificant amount of money on campaigns.

Polls alone can cost between $20,000 to $30,000 — and Change Research has been able to cut that by 80% to 90%, according to the company’s founders.

“It’s safe to say that most of the world was stunned by the outcome [of the presidential election] because most polls predicted the opposite,” says Greenfield. “Being a good American and as a parent of a 10-year-old and a 12-year-old, providing forward-thinking candidates and causes with the kind of insight they needed to win up and down the ballot could not only be a good business, but really help us save our democracy.”

Change Research isn’t just polling for politicians. Last year, the company conducted roughly 500 polls for political candidates and advocacy groups.

“The way that I’ve described Change Research to investors is that we want to simultaneously move the world in a better direction and having a positive impact while building a substantial business,” says Greenfield. “We’re only going to work with candidates and causes that we’re aligned with.”

Being exclusively focused on progressive causes isn’t the liability that many in the broader business community would think, says Dutta. Many Democratic organizations won’t work with companies that sell services to both sides of the aisle.

For Higher Ground Labs, a stipulation for receiving their money is a commitment not to work with any Republican candidate. Corporations are okay, but conservative causes and organizations are forbidden.

“We’re in a moment of existential crisis in America and this Republican party is deeply toxic to the health and future of our country,” says Dutta. “The only path out of this mess is to vote Republicans out of office and to do that we need to make it easier for good candidates to run for office and to engage a broader electorate into voting regularly.”

Powered by WPeMatico

Atlassian’s co-CEO Scott Farquhar will join us at TC Sessions: Enterprise

Few companies have changed the way developers work as profoundly as Atlassian. Its tools like Jira and Confluence are ubiquitous, and over the course of the last few years, the company has started to adapt many of them for wider enterprise usage outside of developer teams.

To talk about Atlassian’s story from being a small shop in Australia to a successful IPO — and its plans for the future — the company’s co-founder and co-CEO Scott Farquhar will join us at our inaugural TechCrunch Sessions: Enterprise event on September 5 in San Francisco.

Farquhar co-founded Atlassian with Mike Cannon-Brookes, in 2001. It wasn’t until 2010, though, that the company raised its first major venture round ($60 million from Accel Partners). Even by that point, though, the company already had thousands of customers and a growing staff in Sydney and San Francisco.

Today, more than 150,000 companies use Atlassian’s tools. These range from the likes of Audi to Spotify, Twilio and Visa, with plenty of startups and small and medium businesses in between.

It’s no secret that Farquhar and Cannon-Brookes consider themselves accidental billionaires, so it’s maybe no surprise that in 2015, ahead of Atlassian’s successful IPO that valued it at well above $10 billion, he also signed on to the 1% Pledge movement.

Today, Farquhar also makes his own venture investments as part of Skip Capital, which he co-founded.

TC Sessions: Enterprise (September 5 at San Francisco’s Yerba Buena Center) will take on the big challenges and promise facing enterprise companies today. TechCrunch’s editors will bring to the stage founders and leaders from established and emerging companies to address rising questions, like the promised revolution from machine learning and AI, intelligent marketing automation and the inevitability of the cloud, as well as the outer reaches of technology, like quantum computing and blockchain.

Tickets are now available for purchase on our website at the early-bird rate of $395; student tickets are just $245.

We have a limited number of Startup Demo Packages available for $2,000, which includes four tickets to attend the event.

For each ticket purchased for TC Sessions: Enterprise, you will also be registered for a complimentary Expo Only pass to TechCrunch Disrupt SF on October 2-4.

Powered by WPeMatico

For pen testing firm IOActive, security is cultural not transactional

IOActive may not be a household name but you almost certainly know its work.

The Seattle-headquartered company has been behind some of the most breathtaking hacks in the past decade. Its researchers have broken into in-flight airplanes from the ground and reverse engineered an ATM to spit out gobs of cash. One of the company’s most revered hackers discovered a way to remotely shock a pacemaker out of rhythm. And remember that now-infamous hack that remotely killed the engine of a Jeep? That was IOActive, too.

If it’s connected, they will bet that they can hack it.

IOActive has made a name for itself with its publicly reported findings, but its bread and butter is helping its corporate customers better understand how they approach security.

Since its founding more than two decades ago, the penetration testing and ethical hacking company now serves customers mostly in the Global 1000 largest companies to help assess and test their security posture.

“You can have the absolute most sophisticated alarm in the entire world, and I guarantee our team can break in,” said Jennifer Steffens, IOActive’s chief executive, in a call with TechCrunch. “But if you left your front door unlocked lock, hackers are going to walk right through”

“Don’t pay us to show you how to break into the alarm before someone learns how to lock the door,” she said.

Powered by WPeMatico

MongoDB gets a data lake, new security features and more

MongoDB is hosting its developer conference today and, unsurprisingly, the company has quite a few announcements to make. Some are straightforward, like the launch of MongoDB 4.2 with some important new security features, while others, like the launch of the company’s Atlas Data Lake, point the company beyond its core database product.

“Our new offerings radically expand the ways developers can use MongoDB to better work with data,” said Dev Ittycheria, the CEO and president of MongoDB. “We strive to help developers be more productive and remove infrastructure headaches — with additional features along with adjunct capabilities like full-text search and data lake. IDC predicts that by 2025 global data will reach 175 Zettabytes and 49% of it will reside in the public cloud. It’s our mission to give developers better ways to work with data wherever it resides, including in public and private clouds.”

The highlight of today’s set of announcements is probably the launch of MongoDB Atlas Data Lake. Atlas Data Lake allows users to query data, using the MongoDB Query Language, on AWS S3, no matter their format, including JSON, BSON, CSV, TSV, Parquet and Avro. To get started, users only need to point the service at their existing S3 buckets. They don’t have to manage servers or other infrastructure. Support for Data Lake on Google Cloud Storage and Azure Storage is in the works and will launch in the future.

Also new is Full-Text Search, which gives users access to advanced text search features based on the open-source Apache Lucene 8.

In addition, MongoDB is also now starting to bring together Realm, the mobile database product it acquired earlier this year, and the rest of its product lineup. Using the Realm brand, Mongo is merging its serverless platform, MongoDB Stitch, and Realm’s mobile database and synchronization platform. Realm’s synchronization protocol will now connect to MongoDB Atlas’ cloud database, while Realm Sync will allow developers to bring this data to their applications. 

“By combining Realm’s wildly popular mobile database and synchronization platform with the strengths of Stitch, we will eliminate a lot of work for developers by making it natural and easy to work with data at every layer of the stack, and to seamlessly move data between devices at the edge to the core backend,”  explained Eliot Horowitz, CTO and co-founder of MongoDB.

As for the latest release of MongoDB, the highlight of the release is a set of new security features. With this release, Mongo is implementing client-side Field Level Encryption. Traditionally, database security has always relied on server-side trust. This typically leaves the data accessible to administrators, even if they don’t have client access. If an attacker breaches the server, that’s almost automatically a catastrophic event.

With this new security model, Mongo is shifting access to the client and to the local drivers. It provides multiple encryption options; for developers to make use of this, they will use a new “encrypt” JSON scheme attribute.

This ensures that all application code can generally run unmodified, and even the admins won’t get access to the database or its logs and backups unless they get client access rights themselves. Because the logic resides in the drivers, the encryption is also handled totally separate from the actual database.

Other new features in MongoDB 4.2 include support for distributed transactions and the ability to manage MongoDB deployments from a single Kubernetes control plane.

Powered by WPeMatico

Why identity startup Auth0’s founder still codes: It makes him a better boss

If you ask Eugenio Pace to describe himself, “engineer” would be fairly high on the list.

“Being a CEO is pretty busy,” he told TechCrunch in a call last week. “But I’m an engineer in my heart — I am a problem solver,” he said.

Pace, an Argentinan immigrant to the U.S., founded identity management company Auth0 in 2013 after more than a decade at Microsoft. Auth0, pronounced “auth-zero,” has been described as like Stripe for payments or Twilio for messaging. App developers can add a few lines of code and it immediately gives their users access to the company’s identity management service.

That means the user can securely log in to the app without building a homebrew username and password system that’s invariably going to break. Any enterprise paying for Auth0 can also use its service to securely logon to the company’s internal network.

“Nobody cares about authentication, but everybody needs it,” he said.

Pace said Auth0 works to answer two simple questions. “Who are you, and what can you do?” he said.

“Those two questions are the same regardless of the device, the app, or whether if I’m an employee of somebody or if I am an individual using an app, or if I am using a device where there’s no human attached to it,” he said.

Whoever the users are, the app needs to know if the person using the app or service is allowed to, and what level of access or functionality they can get. “Can you transfer these funds?,” he said. “Can you approve these expense reports? Can you open the door of my house?” he explained.

Pace left Microsoft in 2012 and founded Auth0 during the emergence of Azure, which transformed Microsoft from a software giant into a cloud company. It was at Microsoft where he found identity management was one of the biggest headaches for developers moving their apps to the cloud. He wrote book after book, and edition after edition. “I felt like I could keep writing books about the problem — or I can just solve the problem,” he said.

So he did.

Instead of teaching developers how to become experts in identity management, he wanted to give them the tools to employ a sign-on solution without ever having to read a book.

Powered by WPeMatico

Google Cloud gets capacity reservations, extends committed use discounts beyond CPUs

Google Cloud made two significant pricing announcements today. Those, you’ll surely be sad to hear, don’t involve the usual price drops for compute and storage. Instead, Google Cloud today announced that it is extending its committed-use discounts, which give you a significant discount when you commit to using a certain number of resources for one or three years, to GPUs, Cloud TPU Pods and local SSDs. In return for locking yourself into a long-term plan, you can get discounts of 55% off on-demand prices.

In addition, Google is launching a capacity reservation system for Compute Engine that allows users to reserve resources in a specific zone for later use to ensure that they have guaranteed access to these resources when needed.

At first glance, capacity reservations may seem like a weird concept in the cloud. The promise of cloud computing, after all, is that you can just spin machines up and down at will — and never really have to think about availability.

So why launch a reservation system? “This is ideal for use cases like disaster recovery or peace of mind, so a customer knows that they have some extra resources, but also for retail events like Black Friday or Cyber Monday,” Google senior product manager Manish Dalwadi told me.

These users want to have absolute certainty that when they need the resources, they will be available to them. And while many of us think of the large clouds as having a virtually infinite amount of virtual machines available at any time, some machine types may occasionally only be available in a different availability zone, for example, that is not the same zone as where the rest of your compute resources are.

Users can create or delete reservations at any time and any existing discounts — including sustained use discounts and committed use discounts — will be applied automatically.

As for committed-use discounts, it’s worth noting that Google always took a pretty flexible approach to this. Users don’t have to commit to using a specific machine type for three years, for example. Instead, they commit to using a specific number of CPU cores and memory, for example.

“What we heard from customers was that other commit models are just too inflexible and their utilization rates were very low, like 70, 60% utilization,” Google product director Paul Nash told me. “So one of our design goals with committed-use discounts was to figure out how we could provide something that gives us the capacity planning signal that we need, provides the same amount of discounts that we want to pass on to customers, but do it in a way that customers actually feel like they are getting a great deal and so that they don’t have to hyper-manage these things in order to get the most out of them.”

Both the extended committed-use discounts and the new capacity reservation system for Compute Engine resources are now live in the Google Cloud.

Powered by WPeMatico

How Kubernetes came to rule the world

Open source has become the de facto standard for building the software that underpins the complex infrastructure that runs everything from your favorite mobile apps to your company’s barely usable expense tool. Over the course of the last few years, a lot of new software is being deployed on top of Kubernetes, the tool for managing large server clusters running containers that Google open-sourced five years ago.

Today, Kubernetes is the fastest growing open-source project, and earlier this month, the bi-annual KubeCon+CloudNativeCon conference attracted almost 8,000 developers to sunny Barcelona, Spain, making the event the largest open-source conference in Europe yet.

To talk about how Kubernetes came to be, I sat down with Craig McLuckie, one of the co-founders of Kubernetes at Google (who then went on to his own startup, Heptio, which he sold to VMware); Tim Hockin, another Googler who was an early member on the project and was also on Google’s Borg team; and Gabe Monroy, who co-founded Deis, one of the first successful Kubernetes startups, and then sold it to Microsoft, where he is now the lead PM for Azure Container Compute (and often the public face of Microsoft’s efforts in this area).

Google’s cloud and the rise of containers

To set the stage a bit, it’s worth remembering where Google Cloud and container management were five years ago.

Powered by WPeMatico

The Slack origin story

Let’s rewind a decade. It’s 2009. Vancouver, Canada.

Stewart Butterfield, known already for his part in building Flickr, a photo-sharing service acquired by Yahoo in 2005, decided to try his hand — again — at building a game. Flickr had been a failed attempt at a game called Game Neverending followed by a big pivot. This time, Butterfield would make it work.

To make his dreams a reality, he joined forces with Flickr’s original chief software architect Cal Henderson, as well as former Flickr employees Eric Costello and Serguei Mourachov, who like himself, had served some time at Yahoo after the acquisition. Together, they would build Tiny Speck, the company behind an artful, non-combat massively multiplayer online game.

Years later, Butterfield would pull off a pivot more massive than his last. Slack, born from the ashes of his fantastical game, would lead a shift toward online productivity tools that fundamentally change the way people work.

Glitch is born

In mid-2009, former TechCrunch reporter-turned-venture-capitalist M.G. Siegler wrote one of the first stories on Butterfield’s mysterious startup plans.

“So what is Tiny Speck all about?” Siegler wrote. “That is still not entirely clear. The word on the street has been that it’s some kind of new social gaming endeavor, but all they’ll say on the site is ‘we are working on something huge and fun and we need help.’”

Maybe I make a terrible boss, but at least I know it. Work with me: http://tinyspeck.com/jobs/cptl/

— Stewart Butterfield (@stewart) July 10, 2009

Siegler would go on to invest in Slack as a general partner at GV, the venture capital arm of Alphabet .

“Clearly this is a creative project,” Siegler added. “It almost sounds like they’re making an animated movie. As awesome as that would be, with people like Henderson on board, you can bet there’s impressive engineering going on to turn this all into a game of some sort (if that is in fact what this is all about).”

After months of speculation, Tiny Speck unveiled its project: Glitch, an online game set inside the brains of 11 giants. It would be free with in-game purchases available and eventually, a paid subscription for power users.

Powered by WPeMatico

A cryptocurrency stealing app found on Google Play was downloaded over a thousand times

Researchers have found two apps masquerading as cryptocurrency apps on Android’s app store, Google Play.

One of them was largely a dud. The second was designed to steal cryptocurrency, the researchers said.

Security firm ESET said one of the two fake Android apps impersonated Trezor, a hardware cryptocurrency wallet. The good news is that the app couldn’t be used to steal cryptocurrency stored by Trezor. But the researchers found the app was connected to a second Android app that could have been used to scam funds out of unsuspecting victims.

Lukas Stefanko, a security researcher at ESET — who has a long history of finding dodgy Android apps — said the fake Trezor app “appeared trustworthy at first glance” but was using a fake developer name to impersonate the company.

The fake app was designed to trick users into turning over a victim’s login credentials. Uploaded to Google Play on May 1, the app quickly ranked as the second-most popular search result when searching for “Trezor” behind the legitimate app, said Stefanko. Users on Reddit also found the fake app and reported it as recently as two weeks ago.

According to Stefanko, the server where user credentials were sent was linked to a website linked to another fake wallet, purportedly to store cryptocurrency, and also listed on Google Play since February 25.

“The app claims it lets its users create wallets for various cryptocurrencies,” said Stefanko. “However, its actual purpose is to trick users into transferring cryptocurrency into the attackers’ wallets – a classic case of what we’ve named wallet address scams in our previous research into cryptocurrency-targeting malware.”

Both apps were collectively downloaded more than a thousand times. After ESET contacted Google, the apps were pulled offline the next day.

Read more:

Powered by WPeMatico