Tech News : No More Passwords For Microsoft Logins
In a bold step, Microsoft has announced that it is getting rid of all password logins, and that users will have to use an authenticator app or other solution instead.
Vision
Back in 2019, Microsoft announced that 100 million people were already using Microsoft’s passwordless sign-in (Ignite) each month, and in December 2020, Microsoft announced that 2020 had been “a banner year for passwordless technology” and laid out its vision for a passwordless future. This latest announcement, therefore, marks a major step towards the company making its vision a reality.
The Trouble With Passwords
Microsoft is not the only company wanting to escape from the many negative aspects of relying on password-based logins. Some of the key challenges with passwords are:
– They are a target for attacks. For example, one in every 250 corporate accounts is compromised each month, and 579 password attacks every second (18 billion every year).
– They’re inconvenient and difficult to manage across multiple accounts. For example, users are expected to create complex and unique passwords, remember them, and change them frequently. Also, 20 to 50 per cent of all help desk calls are for password resets (Gartner).
– They’re open to human error. People often choose passwords that are too simple (and very easy to remember), which makes them more vulnerable to being cracked. Also, password sharing (using the same password for multiple websites/platforms) increases the risk.
“The Passwordless Future is Here”
Microsoft has, therefore, announced that in line with its vision of the passwordless future, with immediate effect (and the rollout time over the coming weeks) its users can completely remove the need to use a password for their Microsoft accounts. Microsoft says that instead of a password-based login, users can now choose to use the Microsoft Authenticator app, Windows Hello, a security key, or a verification code sent to the user’s phone or email to sign in to Microsoft’s apps and services including Outlook, OneDrive, Microsoft Family Safety, and more. Microsoft says that those who have two-factor authentication will need to have access to two different recovery methods.
Like Microsoft’s In-House Passwordless System
Microsoft says that almost 100 per cent of its employees already use the new, more secure system for their corporate account and when passwordless login is enabled, users re-logging in to a Microsoft accounts are asked to give their fingerprint, or other secure unlock, on their mobile phone.
What Does This Mean For Your Business?
Businesses need to make sure that their IT systems are secure and compliant. Also, businesses need to be sure that users, perhaps in different locations (remote or hybrid working), can access their accounts (convenience) and maintain the company’s security at the same time. This bold move by Microsoft seems to tick these boxes and can be a way to help businesses to stay one good step away from cybercriminals who have already found many ways to beat password-based systems. Passorwordless and biometric systems have been highlighted, for a few years now, as the way forward, and Microsoft has now taken the first big step towards this.
Tech News : Apple Issues Patch To Stop iPhone ‘Zero-Click’ Spyware
Apple has issued a security update following the discovery of a zero-day, zero-click “spyware” that could infect iPhones and iPads.
Discovered By Researchers
The threat was discovered by independent researchers from the University of Toronto’s Citizen Lab while they were analysing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware.
What Is It?
The Citizen Lab has described the threat as a zero-day (unknown, or known but with no patch yet), zero-click “spyware”. This is spying malware that doesn’t need users to click on a link or file to launch it. The Citizen Lab, which has identified the threat as being “in the wild” (already in circulation), says that a “maliciously crafted” PDF file could lead to arbitrary code execution. The threat uses malicious Adobe PDF files disguised to look like GIF (files with the “.gif” extension). The exploit has been dubbed “FORCEDENTRY” and, is believed to target Apple’s image rendering library, and works by exploiting an integer overflow vulnerability in Apple’s image rendering library (CoreGraphics).
iOS, MacOS, and WatchOS Devices At Risk
The researchers found the threat to be effective against Apple iOS, MacOS, and WatchOS devices, and that it has been used by a mercenary spyware company called “NSO Group” to remotely exploit and infect the latest Apple devices with the Pegasus spyware.
Patch Issued In Response
After The Citizen Lab passed the details of its findings to Apple, the tech giant released a patch/security update. Apple issued iOS 14.8 and iPadOS 14.8 patches for iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation). Apple says that it is “aware of a report that this issue may have been actively exploited”.
Bad Timing
The news of the discovery of the exploit, which may have been in use since at least February this year, came at a bad time for Apple as the company prepared to unveil its new devices, including its new iPhones and updates to its AirPods and Apple Watch, at its annual launch event (Tuesday).
What Does This Mean For Your Business?
The Citizen Lab researchers have blamed the Israel-based NSO Group for selling technology that is being used as “despotism-as-a-service” by unaccountable government security agencies. Even though this is a real threat to iPhones, iPads, and Apple watches, security commentators say that the vast majority of iPhone owners don’t need to be too concerned because this type of attack is usually highly targeted. Nevertheless, the discovery has come at an unfortunate moment for Apple which has been busy trying to promote the benefits of its new products while competitors like Microsoft have announced the launch of a new, secure, passwordless login system.
Featured Article: Charging Electric Vehicles – What You Need to Know
In this article, we look at the different types and locations of EV charging in the UK, plus the challenges and legislation relating to it.
How Many Electric Cars In The UK?
By the end of August 2021, there were more than 600,000 plug-in vehicles, and nearly 300,000 BEVs (Battery-Powered Electric Vehicles) and 300,000 PHEVs (Plug-in Hybrid Electric Vehicle ) registered in the UK. Electric vehicles are often simply referred to as EVs.
Charging EVs
Electronic vehicles contain batteries that need charging. Although hybrid EVs are powered by an internal combustion engine and electric motor (which uses energy stored in batteries), they can’t be plugged in to charge the battery (the engine and regenerative braking charge the battery).
For normal EVs, three main types of charging are available (rapid, fast, and slow). These represent the power outputs (measured in kilowatts kW) and charging speeds. Each charger type has a different type of connector for low or high-power use, and for AC or DC charging.
Rapid chargers, using tethered cables, are the fastest way to charge an EV, and they supply high power as direct or alternating current (DC or AC). Typically (depending on the model), rapid charging can recharge EV batteries to 80 per cent in around 20 minutes. Types of rapid chargers include rapid DC chargers (providing power at 50 kW/125A, ultra-rapid DC chargers providing power at 100 kW or more, Tesla’s own Supercharger network providing rapid DC charging (using the Tesla Type 2 connector or a Tesla CCS connector) up to 150 kW, and rapid AC chargers providing power at 43 kW.
Fast chargers (mostly AC charging) can typically recharge an EV with a 40-kWh battery in 4-6 hours using a 7-kW charger, or in 1-2 hours using a 22-kW charger. Most fast chargers are 7 kW and untethered (a cable that is not permanently fixed to the charge point connects the EV with the charge point). Some home and workplace units have cables attached.
Slow chargers are mostly untethered, and a 3-kW unit typically takes 6-12 hours to fully charge a car battery.
Different Connectors for Charging
Connectors (to the car from the charging point) differ depending on the charger type (socket) and the vehicle’s inlet port. For example, rapid chargers use CHAdeMO, CCS (Combined Charging Standard) or Type 2 connectors, whereas fast and slow units tend to use Type 2, Type 1, Commando, or 3-pin plug outlets.
Where?
The choices of where EV owners can charge their vehicles include vary. For example, there are 20+ EV charging networks are currently available in the UK. Examples of these networks include the ESB Energy public network (rapid charge points, London, and Coventry plus charge points for taxi drivers), Osprey (formerly Engenie) with its UK-wide network of rapid chargers, and bp pulse (formerly Polar) which is one of the UK’s largest public charging networks.
EV charger types and their location typically include:
– Rapid chargers, which can be found (typically) at motorway services and near main travel routes.
– Fast chargers, found (typically) at car parks, supermarkets, and leisure centres.
– Slow Charging points are mainly used outside private homes (for charging overnight), at workplaces, and in some other public places. Slow public chargers tend to be older devices.
Paying
Different networks offer different payment methods for using their chargers. Payment methods include Zap-Pay (an app-based, pay-as-you-go credit or debit card system), contactless credit or debit card payments, MFG app contactless payments, subscription memberships, and more.
Most Use Public Chargers
A Zap-Map survey (of 2,200 people) found that 90 per cent use public chargers when they’re out. Supermarkets are the most popular public charging place (48 per cent of respondents), followed by motorway service stations (47 per cent) and public car parks (32 per cent).
Ultra-Rapid Charging Point Growth
Recent figures have also shown a growth in ultra-rapid charge points with 16 per cent of EV owners now using them. This trend has been helped by more cars being able to take higher charge rates as well as an almost doubling of the number of ultra-rapid charge points available.
The UK Law
In the UK, the Automated and Electric Vehicles Act 2018 (AEV Act), was essentially designed to ensure that the UK’s infrastructure and insurance system could cope with the large-scale switch from petrol/diesel to electronic vehicles. Whereas the first part of the Act is mainly concerned with how insurers deal with claims related to operating EVs in automated technology mode and keeping the software up to date, the second part deals with the EV charging infrastructure (availability, compatibility vehicle types, reliability standards and standardising how they are paid for).
Government Consultation
In 2019, the UK government held a consultation with stakeholders in response to the introduction of the Act. Some of the key points in the responses include:
– The time of day at which Electric Vehicle (EV) charging occurs could have significant implications for the electricity system. With more people getting home charging points, this could lead to most EVs being charged at peak times (between 5pm and 7pm), this could mean that greater investment is needed in the charging networks, and in and in electricity generation capacity to meet increased demand.
– Shifting EV charging to a different time of day (e.g. overnight) when there is lower demand on the electricity system, or to times of high renewable energy generation, could help reduce the need for costly electricity network reinforcement to meet increased demand, and could give consumers savings on their energy bills.
– The AEV Act 2018 gives the UK Government powers through secondary legislation to mandate that all EV charge points sold and installed in the UK have smart functionality and meet minimum device-level requirements.
Peak Times?
Due to the increased demand and possible disruptive effect on the UK energy supply from EV owners all charging their cars at the same time, there have been concerns that new EV chargers could be preset to turn off for nine hours a day, and automatically set to not function at ‘peak times.’ However, public chargers and rapid chargers (e.g. on motorways) are exempt from peak times. Smart charge points may, however, come pre-set to prevent automatic charging during peak times (8 am to 11 am, 4 pm to 10 pm weekdays) but the legislation specifies time windows instead of an off-peak period.
Although the UK government requires smart EV charger makers to include a function that randomly delays the start time of any load control action (to delay EV charging when there is grid instability), they have also said that users should be allowed to override this delay function.
New Build Homes and Offices Must Include EV Chargers
One of the big challenges to getting people to buy an EV vehicle is whether they can have charging points available at home (or at work). The UK government is therefore introducing legislation later this year that will require all newly built homes and offices in England to feature EV chargers.
What Does This Mean For Your Business?
Having a charging network that is widespread, effective, easy, and cheap to use, and having home and/or office charging points as well as public charging points are of major importance in influencing more people to make the switch to EV ownership. There is, however, still some confusion in the marketplace about charging options which is one of the reasons why The Department for Transport (DfT) has introduced contactless payment at charge points, forcing operators to provide a 24/7 call helpline for drivers and making location data, power rating and price information more accessible, with the hope of reassuring motorists that charging EV’s can be easier than refuelling with petrol or diesel. Also, the government needs to be able to ensure that the energy infrastructure is capable of dealing with the demands of EV charging (e.g. home charging) on a large scale, and that this will not disrupt/destabilise the grid, especially at peak times, hence the government’s consultation. This is a challenge that must be tackled soon due to legislation coming in to require all new homes and offices to have a charging point. The EV charging network market is also likely to expand, thereby providing more new opportunities for energy companies and charging network suppliers. How the situation is balanced and managed as EV ownership takes off is a critical matter for government, businesses, and individuals over the next few years.
Tech Insight : What Is A Solid State Battery?
In this tech-insight, we take a brief look at what solid-state batteries are, their benefits and challenges, and how why they hold a great deal of promise for use in electric vehicles in the near future.
Solid State
A solid-state battery is a battery that has solid electrodes and solid electrolytes to transfer ions from the cathode to the anode when charging (and vice versa when discharging). This differs from lithium-ion/ lithium polymer batteries which have a liquid or polymer gel as the electrolyte.
The Benefits of Solid-State Batteries
Some of the main benefits of solid-state batteries are:
– Longer battery run time in relation to the battery size due to higher energy density.
– Safety. There’s no risk of explosion or fire, as there is with some batteries with liquid electrolytes.
– Better use of space and lower costs (compared to lithium-ion batteries) because there is no need for (fire/explosion) safety components.
– Increased battery capacity due to the better use of space, allowing for the inclusion of more active materials.
– Compact/small and light, therefore giving flexibility in where they can be used.
– Longer lifespans, plus solid-state batteries can be charged more times than lithium-ion batteries.
– Fast charging time, better performance over time, a longer life cycle, and better recycling potential than lithium-ion batteries.
Disadvantages and Challenges
Some of the disadvantages and challenges of solid state batteries include:
– Expensive to manufacture because it’s an emerging technology, so the economies of scale aren’t in place, and electrolytes are expensive to produce (and are prone to cracking).
– Uncertainty about the best chemical and atomic composition for a solid electrolyte between metallic anodes and cathodes.
– Difficult to manufacture at scale.
Applications of Solid-State Batteries
Some of the current places where solid-state batteries are used include within pacemakers, smartwatches/wearable devices, and RFID tags (in industry).
Electric Vehicles
Factors such as the high energy density per unit area (providing a higher capacity and longer run time) have made solid-state batteries a very promising prospect for the EV market, with many automobile and tech companies investing in moving solid-state technology forwards. For example, Samsung’s Advanced Institute of Technology (SAIT) claims to have made a breakthrough in solid electrolyte technology which has enabled the size of a solid-state battery to be halved. This could, in theory, double the range of today’s first-generation EVs on one charge. Many tech commentators are predicting that solid-state batteries may take over from lithium-ion batteries.
What Does This Mean For Your Business?
Smaller, more powerful, longer-lasting batteries that offer the promise of greater sustainability are surely an attractive prospect in many industries, particularly the emerging EV industry. All the major car companies are now committed to electric vehicle production and how well a battery performs is an important value-adding factor for motorists to consider as they buy their first electric vehicles. There are still several challenges to overcome with solid-state batteries (e.g. finding the best composition and manufacturing at scale) but momentum is now building towards making the breakthroughs that could see solid-state batteries delivering benefits in more industries.
Tech Tip – A Quick Look At Your Desktop
If you’re browsing the Internet or working on file in Windows 10 but you need a fast look at your desktop here’s how:
– While in a browser or working on a Microsoft Office file e.g., Word, find the tiny vertical line to the far, right hand-side of the bottom taskbar.
– Click on the line. Everything will be minimised so you can see your desktop.
– Click on the same line again to restore your Windows.
Alternatively, you can:
– Right-mouse click over the line (far right of the taskbar) and select ‘Show desktop’.
OR
– Right-mouse click over the line (far right of the taskbar) and select ‘Peek at desktop’. Clicking on it will make a checkmark will appear to its left.
– If you hover your cursor over the “Show Desktop” button, you will see a quick peek at the desktop.
Tech News : Birthdates Becoming Required For Social Logins
The introduction of the Age Appropriate Design Code (also known as the Children’s Code) by the ICO means that Facebook has decided to ask Instagram users to give their date of birth as part of the login.
Age Appropriate Design Code
The statutory Children’s Code (‘The Age Appropriate Design Code’), which came into force on 2 September 2020, is a set of 15 “flexible standards” that should act as a data protection code of practice for online services, such as apps, online games, and web and social media sites, likely to be accessed by children. The idea is that it should help provide more protection for children online and companies/organisations must conform to the code and demonstrate that their services use children’s data fairly and in compliance with data protection law. The ICO says that developers and those in the digital sector must act, but gave a maximum transition period of 12 months, which is now up, and which is why Facebook’s services (including Instagram) are starting to flag up the new conditions.
Insta Login
In line with the allowed transition period, and to let Instagram users know that the changes are coming in, users will be asked for their date of birth upon login but will be able to dismiss the prompt for now. Instagram has already started blurring content that’s unsuitable for under-18s and a date of birth will be required at some point in the near future to enable people to continue using the Insta app.
Instagram’s owner, Facebook, is also now defaulting any new accounts for under 16 s to a private setting in order to help with its compliance.
Facebook Criticised Last Year
In addition to a statutory need for compliance, Facebook may also be extra keen to show that it is taking prompt action to protect young users of its platforms following reports from the Home Office and six other countries last October that Facebook was responsible for 94 percent of 69 million child sex abuse images reported by US tech firms. This figure appears to refer to its end-to-end encrypted WhatsApp chat app being used for criminal purposes by some users.
What Does This Mean For Your Business?
This story highlights the fact that the transition period for the Children’s Code/’The Age Appropriate Design Code’ coming into force is now at an end. Facebook/Instagram introducing these measures should, therefore, be an extra reminder to all developers and those in the digital sector that they need to comply with these ‘flexible’ standards to protect young users of their services, avoid any problems with the ICO, and avoid bad publicity. Many would argue that these standards are long overdue and that young people, for whom the Web and mobile technology have always been around need much better personal and data protection online. Putting the responsibility on providers of digital services, backed by the law, and overseen by the data regulator is one way to get the attention of the big social media platforms and could be an important tool in starting to clean-up some public areas of digital life. Policing private end-to-end encrypted apps however, which is where many criminals may be most likely to interact, is a greater challenge. The Children’s Code may be a good start.