Connect with us

Technologies

New iOS Login Tech Makes It Super Hard to Hack Your iCloud Account

Hardware security keys are the most secure way to lock down your online accounts. Just don’t lose the keys.

Apple now lets you protect your Apple ID and iCloud account with hardware security keys, a significant upgrade for those who want maximum protection from hackers, identity thieves, or snoops.

Hardware security keys are small physical devices that communicate with USB or Lightning ports or with NFC wireless data connections when you’re logging on to a device or in to an account. Because you must have keys in your possession to use them, they’re effective at thwarting hackers trying to reach your account remotely. And they won’t work on fake login sites, so they can thwart phishing attacks that try to fool you into typing your password onto a counterfeit website.

Support for the keys arrived Monday with iOS 16.3 and MacOS 13.2, and on Tuesday, Apple published details on how to use security keys with iPhones, iPads and Macs. The company requires you to set up at least two keys.

Apple has been working to tighten security in recent months, stung by iPhone breaches involving NSO Group’s Pegasus spyware. Apple’s Advanced Data Protection option arrived in December, giving a stronger encryption option to data stored and synced with iCloud. And in September, Apple added an iPhone Lockdown Mode that includes new guardrails on how your phone works to thwart outside attacks.

A big caveat, though: Although hardware security keys and the Advanced Data Protection program lock down your account better, they also mean Apple can’t help you recover access.

«This feature is designed for users who, often due to their public profile, face concerted threats to their online accounts, such as celebrities, journalists, and members of government,» Apple said in a statement. «This takes our two-factor authentication even further, preventing even an advanced attacker from obtaining a user’s second factor in a phishing scam.»

Industry tightens login security

The technology is part of an industrywide tightening of authentication procedures. Thousands of data breaches have shown the weaknesses of traditional passwords, and hackers now can thwart common two-factor authentication technologies like security codes sent by text message. Hardware security keys and another approach called passkeys offer peace of mind even when it comes to serious attacks like hackers gaining access to LastPass customers’ password manager files.

Hardware security keys have been around for years, but the Fast Identity Online, or FIDO, group has helped standardize the technology and integrate its use with websites and apps. One big advantage on the web is they’re linked to specific websites, for example Facebook or Twitter, so they thwart phishing attacks that try to get you to log in to fake websites. They’re the foundation for Google’s Advanced Protection Program, too, for those who want maximum security.

You need to pick the right hardware security keys for your devices. To communicate with relatively new models of both Macs and iPhones, a key that supports USB-C and NFC is a good option. Apple requires you to have two keys, but it isn’t a bad idea to have more in case you lose them. A single key can be used to authenticate to many different devices and services, like your Apple, Google and Microsoft accounts.

Yubico, the top maker of hardware security keys, announced on Tuesday two new FIDO-certified YubiKey models in its Security Key Series suited for consumers. They both support NFC, but the $29 model has a USB-C connector and the $25 model has an older style USB-A connector.

Google, Microsoft, Apple and other allies are also working to support a different FIDO authentication technology called passkeys. Passkeys are designed to replace passwords altogether, and they don’t require hardware security keys.

Technologies

Today’s NYT Mini Crossword Answers for Saturday, July 19

Here are the answers for The New York Times Mini Crossword for July 19.

Looking for the most recent Mini Crossword answer? Click here for today’s Mini Crossword hints, as well as our daily answers and hints for The New York Times Wordle, Strands, Connections and Connections: Sports Edition puzzles.


Today’s Mini Crossword is a delight. I was thrilled to spot a cute salamander with a funny name in the clue for 9-Across. Good thing I remembered how to spell it! Keep reading for help with today’s Mini Crossword. And if you could use some hints and guidance for daily solving, check out our Mini Crossword tips.

The Mini Crossword is just one of many games in the Times’ games collection. If you’re looking for today’s Wordle, Connections, Connections: Sports Edition and Strands answers, you can visit CNET’s NYT puzzle hints page.

Read more: Tips and Tricks for Solving The New York Times Mini Crossword

Let’s get to those Mini Crossword clues and answers.

Mini across clues and answers

1A clue: See-through
Answer: CLEAR

6A clue: «Anybody home?»
Answer: HELLO

7A clue: Winged horse of Greek myth
Answer: PEGASUS

9A clue: Salamander known for its regenerative abilities (and adorable appearance)
Answer: AXOLOTL

10A clue: Texting format, for short
Answer: SMS

11A clue: Birthplace of bossa nova
Answer: RIO

12A clue: Even score
Answer: TIE

13A clue: Insect seen in Dalí’s «The Persistence of Memory»
Answer: ANT

14A clue: Directory abbr.
Answer: EXT

15A clue: Metroid console, for short
Answer: NES

Mini down clues and answers

1D clue: Party snack made with cereal and pretzels
Answer: CHEXMIX

2D clue: Gift with many interlocking pieces
Answer: LEGOSET

3D clue: Airline whose name comes from the Book of Hosea
Answer: ELAL

4D clue: Election loser
Answer: ALSORAN

5D clue: Stand-up comic’s act
Answer: ROUTINE

7D clue: Command that uses the «V» key
Answer: PASTE

8D clue: Pulling their arms might win you money
Answer: SLOTS

Continue Reading

Technologies

It’s the End of the Road for Microsoft Store Movies and TV Shows. What It Means for You

Microsoft has abruptly stopped offering rentals and sales of TV shows and movies on its media platforms.

Microsoft is exiting the market for selling and renting TV and movies across its platforms. There was no reason given for the abrupt change, with Microsoft simply posting the news on a support page on its Xbox website.

«Microsoft has stopped selling new movie and TV content. Existing customers can continue to access their previously purchased content on Windows and Xbox devices,» Microsoft said in the post.

The company said playback and download options will continue to be available for shows and movies people bought previously, but it’s the end of the road for new sales.

On the same page, Microsoft directed users to sign up for Movies Anywhere if they aren’t already members, which makes purchased content available across platforms, and to shop at other media stores including Amazon’s Prime Video, Apple TV and Fandango at Home.

A representative for Microsoft didn’t offer additional comment, but pointed CNET to a similar support blog post on Microsoft’s website.

Microsoft has partnered with many companies over the years to distribute video content since the early 2000s. The move comes as the company has been experiencing mass layoffs and cost cutting across many divisions, including its gaming studios, resulting in the cancellation of multiple upcoming Xbox games.

What happens to content I’ve bought from Microsoft?

Although Microsoft says previously purchased content isn’t going to be unavailable, there are some things to be aware of. According to the support page, you can’t transfer your purchases to another service (although they can be accessed on other services if Movies Anywhere makes them available, but that doesn’t apply to TV shows).

Microsoft isn’t offering refunds for any purchased content, either. 

Microsoft says that downloads of movies and TV shows will still work and will be available, «on Windows and in HD max resolution.» Movies and TV shows will still be playable on the Microsoft Movies & TV app.

The company says anyone who is having trouble accessing their purchases can reach out to Microsoft Support.

Continue Reading

Technologies

Microsoft Will Erase Your Passwords in 2 Weeks: What to Do Now

If the Authenticator app is your go-to password manager, you’ll need to pick a new one soon.

Microsoft is axing passwords starting in August — and if you use its Authenticator app, you’ll want to be prepared.

For years, Microsoft Authenticator has been a go-to for managing multifactor authentication and saved passwords. However, starting next month, it will no longer support passwords and will move to passkeys instead. That means your logins will soon rely more on things like PINs, fingerprint scans or facial recognition. 

Using a passkey can make your account safer, and it’s a move I’m excited about. I recently uncovered that 49% of US adults have risky password habits that can open the door to scammers getting access to your sensitive data.

If you’re a fan of Authenticator and not sure where to start before the switch, here are other password managers CNET recommends and steps you should take before August.

When will Microsoft Authenticator stop supporting passwords?

Microsoft Authenticator houses your passwords and lets you sign into all your Microsoft accounts using a PIN, facial recognition like Windows Hello, or other biometric data like a fingerprint. Authenticator can be used in other ways, such as verifying you’re logging in if you forgot your password, or using two-factor authentication as an extra layer of security for your accounts. In June, the company stopped letting users add passwords to Authenticator.

Starting this month, you won’t be able to use the autofill password function. And next month, you’ll no longer be able to use saved passwords.

If you still want to use passwords instead of passkeys, you can store them in Microsoft Edge. However, CNET experts recommend adopting passkeys during this transition. «Passkeys use public key cryptography to authenticate users, rather than relying on users themselves creating their own (often weak or reused) passwords to access their online accounts,» Tomaschek said.

Why are passkeys a better alternative to passwords?

So what exactly is a passkey? It’s a credential created by the Fast Identity Online Alliance that uses biometric data or a PIN to verify your identity and access your account. Think about using your fingerprint or Face ID to log into your account. That’s generally safer than using a password that is easy to guess or susceptible to a phishing attack.

«Passwords can be cracked, whereas passkeys need both the public and the locally stored private key to authenticate users, which can help mitigate risks like falling victim to phishing and brute-force or credential-stuffing attacks,» said Attila Tomaschek, CNET’s software senior writer and digital security expert.

Passkeys aren’t stored on servers like passwords. Instead, they’re stored only on your personal device. More conveniently, this takes the guesswork out of remembering your passwords and the need for a password manager.

How to set up a passkey in Microsoft Authenticator

Microsoft said in a May 1 blog post that it will automatically detect the best passkey to set up and make that your default sign-in option. «If you have a password and ‘one-time code’ set up on your account, we’ll prompt you to sign in with your one-time code instead of your password. After you’re signed in, you’ll be prompted to enroll a passkey. Then the next time you sign in, you’ll be prompted to sign in with your passkey,» according to the blog post.

To set up a new passkey, open your Authenticator app on your phone. Tap on your account and select «Set up a passkey.» You’ll be prompted to log in with your existing credentials. After you’re logged in, you can set up the passkey.

Other password manager alternatives 

Since Microsoft will get rid of all of your passwords in two weeks, you’ll need a new place to store your passwords safely. Tomaschek has a few of the best password manager recommendations after testing and reviewing several. 

The top recommendation is Bitwarden for its transparency. It’s open-source and audited annually. From a price perspective, the free plan lets you store infinite passwords across unlimited devices. The free plan also includes features most password managers would charge for, including password sharing and a username and password generator. 

Bitwarden’s upgraded plans have other upgraded features that could be worth the cost, too. 

Personally, Tomaschek has been using 1Password for a while, and he likes the interface and family plan. Even though it’s second on the list, Tomaschek says it’s just as good as Bitwarden. 

Continue Reading

Trending

Copyright © Verum World Media