Enterprise

Smallstep takes big step toward authenticating machine-to-machine communications

Comment

Illustration that symbolizes the certification process.
Image Credits: Yurii Karvatskyi / Getty Images

Smallstep founder and CEO Mike Malone calls big, distributed systems his happy place, but these systems involve a lot of machine-to-machine communications, an area identity vendors haven’t been able to solve. The central issue is that when there are no humans involved, how do you authenticate the hand-off between machines to ensure it’s going to the right place?

“Fundamentally, identity in distributed systems is an unsolved problem. So all these different components that need to talk to one another, they need to identify one another just like a person logging into a website,” Malone explained.

“All of those connections need to be mutually authenticated, which means you need to identify and issue credentials and manage credentials for everything — and that’s the problem that we’re trying to solve,” he said.

The solution Malone came up with involves using certificates, the same concept that websites use, to hand off credentials between systems. Smallstep is delivering an open source solution to create and manage these certificates at scale, and a commercial version where they manage the underlying infrastructure for the customer.

The company launched in 2016 and launched their first open source product a couple of years ago. He said it was a tough problem to solve and they took their time building it and nurturing the open source community.

“The open source piece is the core technology. So, if you want to issue certificates, and especially if you want to follow modern best practices, our open source solution is really built to cater to those short-lived certificates that are automatically provisioned, automatically rotated,” he said.

He says the open source part is crucial because he believes everyone should have access to this core technology from a philosophical perspective. The commercial part comes into play when companies want or need someone else to manage the underlying infrastructure for them.

The company currently has 17 employees and expects to double that number in the coming year. As he adds employees, he wants to build a diverse organization, but admits as a person who is entrenched in Silicon Valley, it’s hard not to simply tap into his network. He looks to some best practices to break that cycle though.

“We don’t ask people to work for free, and we don’t have silly coding challenges. We’re not looking for unreasonable experience. I think our hiring philosophy is: Are you smart and are you passionate and are your passions overlapping with our needs? And if that is all true, then you’re thumbs up,” he said.

Tapping into the open source community also definitely helps, as does being mostly remote, something he says he didn’t really embrace prior to COVID, but the pandemic changed his perspective and allows him to hire from anywhere.

The company has received two tranches of funding so far, a $7 million seed led by Accel with help from Boldstart and a $19 million Series A led StepStone Group. Eliot Durbin, who is general partner at Boldstart says that Smallstep is filling in a big gap in cloud native technology.

“There’s a big gap in tooling to secure enterprise infrastructure, and it’s only getting worse with cloud native adoption accelerating. Smallstep’s PKI tools shift this left, empowering developers and operators with an ‘identity dial tone’ that makes it much easier to implement zero trust policies and observe all their certificates in one dashboard,” Durbin told me.

More TechCrunch

Slack CEO Denise Dresser Speaking At TechCrunch Disrupt 2024

Slack CEO Denise Dresser is coming to TechCrunch Disrupt this October

Apple kicked off its weeklong Worldwide Developers Conference (WWDC 2024) event today with the customary keynote at 1 p.m. ET/10 a.m. PT. The presentation focused on the company’s software offerings…

Watch the Apple Intelligence reveal, and the rest of WWDC 2024 right here

The TechCrunch the team runs down all of the biggest news from the Apple WWDC 2024 keynote in an easy-to-skim digest.

Here’s everything Apple announced at the WWDC 2024 keynote, including Apple Intelligence, Siri makeover

Apple’s SDKs (software development kits) have been updated with a variety of new APIs and frameworks.

Apple brings Apple Intelligence to developers via SiriKit and App Intents

Older iPhones or iPhone 15 users won’t be able to use these features.

Apple Intelligence features will be available on iPhone 15 Pro and devices with M1 or newer chips

Soon, Siri will be able to tap ChatGPT for “expertise” where it might be helpful, Apple says.

Apple brings ChatGPT to its apps, including Siri

Apple Intelligence will have an understanding of who you’re talking with in a messaging conversation.

Apple debuts AI-generated … Bitmoji

To use InSight, Apple TV+ subscribers can swipe down on their remote to bring up a display with actor names and character information in real time.

Apple TV+ introduces InSight, a new feature similar to Amazon’s X-Ray, at WWDC 2024

Siri is now more natural, more relevant and more personal — and it has new look.

Apple gives Siri an AI makeover

The company has been pushing the feature as integral to all of its various operating system offerings, including iOS, macOS and the latest, VisionOS.

Apple Intelligence is the company’s new generative AI offering

In addition to all the features you can find in the Passwords menu today, there’s a new column on the left that lets you more easily navigate your password collection.

Apple is launching its own password manager app

With Smart Script, Apple says it’s making handwriting your notes even smoother and straighter.

Smart Script in iPadOS 18 will clean up your handwriting when using an Apple Pencil

iOS’ perennial tips calculating app is finally coming to the larger screen.

Calculator for iPad does the math for you

The new OS, announced at WWDC 2024, will allow users to mirror their iPhone screen directly on their Mac and even control it.

With macOS Sequoia, you can mirror your iPhone on your Mac

At Apple’s WWDC 2024, the company announced MacOS Sequoia.

Apple unveils MacOS Sequoia

“Messages via Satellite,” announced at Apple’s WWDC 2024 keynote, works much like the SOS feature does.

iPhones will soon text via satellite

Apple says the new design will lead to less time searching for photos.

Apple revamps its Photos app for iOS 18

Users will be able to lock an app when they hand over their phone.

iOS 18 will let you hide and lock apps

Apple’s WWDC 2024 keynote was packed, including a number of key new updates for iOS 18. One of the more interesting additions is Tap to Cash, which is more or…

Tap to Cash lets you pay by touching iPhones

In iOS 18, Apple will now support long-requested functionality, like the ability to set app icons and widgets wherever you want.

iOS 18 will finally let you customize your icons and unlock them from the grid

As expected, this is a pivotal moment for the mobile platform as iOS 18 is going to focus on artificial intelligence.

Apple unveils iOS 18 with tons of AI-powered features

Apple today kicked off what it promised would be a packed WWDC 2024 with a handful of VisionOS announcements. At the top of the list is the ability to turn…

VisionOS can now make spatial photos out of 3D images

The Apple Vision Pro is now available in eight new countries.

Apple to release Vision Pro in international markets

VisionOS 2 will come to Vision Pro as a free update later this year.

Apple debuts VisionOS 2 at WWDC 2024

The security firm said the attacks targeting Snowflake customers is “ongoing,” suggesting the number of affected companies may rise.

Mandiant says hackers stole a ‘significant volume of data’ from Snowflake customers

French startup Kelvin, which uses computer vision and machine learning to make it easier to audit homes for energy efficiency, has raised $5.1M.

Kelvin wants to help save the planet by applying AI to home energy audits

A last call and a major shoutout to any and all early-stage founders. It’s time to dig deep and take advantage of an unparalleled opportunity at TechCrunch Disrupt 2024 —…

Only hours left to apply to Startup Battlefield 200 at Disrupt

Privacy watchdogs in the U.K. and Canada have launched a joint investigation into the data breach at 23andMe last year.  On Monday, the U.K,’s Information Commissioner’s Office (ICO) and the…

UK and Canada privacy watchdogs investigating 23andMe data breach

Dubai-based fractional property investment platform Stake has raised $14 million in Series A funding.

Stake raises $14M to bring its fractional property investment platform to Saudi Arabia, Abu Dhabi

“We were motivated to fundraise because we think the ’24 vintage is going to be a good one,” founder Craig Shapiro said.

After hits like Reddit and Scopely, Collaborative Fund easily raised a $125M fund to tackle climate, health and food