<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/touch-id" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Touch-id ]]></title>
                <link>https://www.itpro.com/tag/touch-id</link>
        <description><![CDATA[ All the latest touch-id content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 16 Aug 2019 09:35:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Google: 1.5% of all login attempts use compromised passwords ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Figures from Google's recently released Password Checkup extension have revealed 1.5% of sign-in attempts are being made using details that have been compromised in data breaches.</p><p>Despite being regularly notified that their details have been leaked to hackers, a large proportion of users fail to change their passwords or deactivate accounts, according to the data.</p><p>Only 26% of users with compromised details changed their passwords after being notified by the extension, and just 60% of these changes were actually secure against brute force guessing.</p><p>The extension constantly monitors a user's login attempts and scans them against a database of 4 billion usernames and passwords known to have been involved in third-party data breaches.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33048/popular-password-managers-found-to-have-serious-flaws" data-original-url="/security/33048/popular-password-managers-found-to-have-serious-flaws">Popular password managers found to have serious flaws</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33158/random-password-ji32k7au4a83-used-in-141-data-breaches" data-original-url="/security/33158/random-password-ji32k7au4a83-used-in-141-data-breaches">'Random' password 'ji32k7au4a83' used in 141 data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/34206/massive-biometric-data-breach-found-in-system-used-by-banks-and-met-police" data-original-url="/data-breaches/34206/massive-biometric-data-breach-found-in-system-used-by-banks-and-met-police">Massive biometric data breach found in system used by banks and Met police</a></p></div></div><p>Around 650,000 users participated in the experiment which saw 21 million login attempts scanned and analysed. Google said 316,000 of these logins used unsafe credentials, equating to roughly 1.5% of all attempts.</p><p>"Hijackers routinely attempt to sign in to sites across the web with every credential exposed by a third-party breach," said Google. "If you use strong, unique passwords for all your accounts, this risk disappears."</p><p>Using anonymous telemetry gathered from the extension, Google was able to determine the relative credential stuffing risk to the type of website used.</p><p>For example, the highest risk of successful credential stuffing attacks using compromised login details would be on popular entertainment sites such as Netflix, while the likes of government online portals and online banking platforms, although at a much lower risk, were still vulnerable to these types of attacks.</p><p><a href="https://www.itpro.com/security/34070/lancaster-university-hit-by-double-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/34070/lancaster-university-hit-by-double-data-breach">Credential stuffing</a> is a crude method attackers use to break into people's accounts which involves taking stolen login details and spamming different sites with these details, often using automated programs, in the hope of gaining access to more potentially sensitive data.</p><p>It differs from <a href="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree" target="_blank" data-original-url="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree">brute force attacks</a> which involve trying to guess passwords or other details in multiple login attempts on a string of sites.</p><p>Until now, <a href="https://www.itpro.com/security/32928/google-launches-password-checkup-and-cross-account-protection" target="_blank" data-original-url="https://www.itpro.com/security/32928/google-launches-password-checkup-and-cross-account-protection">the extension</a> hasn't afforded users the right to opt-out of having their anonymised telemetry sent back to the company, however, Google has since made this an option.</p><p>"By design, the Password Checkup extension ensures that Google never learns your username or password, regardless of whether you enable telemetry, but we still want to provide this option if users would prefer not to share this information," said Google.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/34222/google-15-of-all-login-attempts-use-compromised-passwords</link>
                                                                            <description>
                            <![CDATA[ Report says popular sites like Netflix and a number of government portals are at risk of 'credential stuffing' ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a5tNnmJNyFzi78hXQxGHE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o7Ba9YusGCqBda7srKZKvJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Aug 2019 09:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o7Ba9YusGCqBda7srKZKvJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[person entering passcode on smartphone]]></media:description>                                                            <media:text><![CDATA[person entering passcode on smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[person entering passcode on smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o7Ba9YusGCqBda7srKZKvJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Figures from Google's recently released Password Checkup extension have revealed 1.5% of sign-in attempts are being made using details that have been compromised in data breaches.</p><p>Despite being regularly notified that their details have been leaked to hackers, a large proportion of users fail to change their passwords or deactivate accounts, according to the data.</p><p>Only 26% of users with compromised details changed their passwords after being notified by the extension, and just 60% of these changes were actually secure against brute force guessing.</p><p>The extension constantly monitors a user's login attempts and scans them against a database of 4 billion usernames and passwords known to have been involved in third-party data breaches.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33048/popular-password-managers-found-to-have-serious-flaws" data-original-url="/security/33048/popular-password-managers-found-to-have-serious-flaws">Popular password managers found to have serious flaws</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/33158/random-password-ji32k7au4a83-used-in-141-data-breaches" data-original-url="/security/33158/random-password-ji32k7au4a83-used-in-141-data-breaches">'Random' password 'ji32k7au4a83' used in 141 data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-breaches/34206/massive-biometric-data-breach-found-in-system-used-by-banks-and-met-police" data-original-url="/data-breaches/34206/massive-biometric-data-breach-found-in-system-used-by-banks-and-met-police">Massive biometric data breach found in system used by banks and Met police</a></p></div></div><p>Around 650,000 users participated in the experiment which saw 21 million login attempts scanned and analysed. Google said 316,000 of these logins used unsafe credentials, equating to roughly 1.5% of all attempts.</p><p>"Hijackers routinely attempt to sign in to sites across the web with every credential exposed by a third-party breach," said Google. "If you use strong, unique passwords for all your accounts, this risk disappears."</p><p>Using anonymous telemetry gathered from the extension, Google was able to determine the relative credential stuffing risk to the type of website used.</p><p>For example, the highest risk of successful credential stuffing attacks using compromised login details would be on popular entertainment sites such as Netflix, while the likes of government online portals and online banking platforms, although at a much lower risk, were still vulnerable to these types of attacks.</p><p><a href="https://www.itpro.com/security/34070/lancaster-university-hit-by-double-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/34070/lancaster-university-hit-by-double-data-breach">Credential stuffing</a> is a crude method attackers use to break into people's accounts which involves taking stolen login details and spamming different sites with these details, often using automated programs, in the hope of gaining access to more potentially sensitive data.</p><p>It differs from <a href="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree" target="_blank" data-original-url="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree">brute force attacks</a> which involve trying to guess passwords or other details in multiple login attempts on a string of sites.</p><p>Until now, <a href="https://www.itpro.com/security/32928/google-launches-password-checkup-and-cross-account-protection" target="_blank" data-original-url="https://www.itpro.com/security/32928/google-launches-password-checkup-and-cross-account-protection">the extension</a> hasn't afforded users the right to opt-out of having their anonymised telemetry sent back to the company, however, Google has since made this an option.</p><p>"By design, the Password Checkup extension ensures that Google never learns your username or password, regardless of whether you enable telemetry, but we still want to provide this option if users would prefer not to share this information," said Google.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung Galaxy S10’s ultrasonic sensor fooled by fake finger ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/mobile/33324/samsung-galaxy-s10-review-a-truly-stellar-smartphone" target="_blank" data-original-url="https://www.itpro.com/mobile/33324/samsung-galaxy-s10-review-a-truly-stellar-smartphone">Samsung Galaxy S10</a>'s 'ultrasonic' in-display fingerprint reader can be easily unlocked with a 3D-printed fingerprint, allowing hackers to break through the device's biometric security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/printers/28027/what-is-3d-printing" data-original-url="/printers/28027/what-is-3d-printing">What is 3D printing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="/mobile/20728/how-secure-apples-touch-id">How secure is Apple's Touch ID?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="/security/29705/what-are-biometrics">What are biometrics?</a></p></div></div><p>The exploit was discovered by a Reddit user going by the names of 'darkshark9', who cloned his own fingerprint from a photograph of the print left on a wine glass. Using common software tools Adobe Photoshop and Autodesk 3ds Max, he created an accurate replica of the print using a home 3D printer costing less than 400.</p><p>In a proof-of-concept uploaded to <a href="https://imgur.com/gallery/8aGqsSu" target="_blank">Imgur</a>, darkshark9 showed the device being unlocked by the fake print, stating that "the 3D print will unlock my phone...in some cases just as well as my actual finger does".</p><div><blockquote><p>I attempted to fool the new Samsung Galaxy S10's ultrasonic fingerprint scanner by using 3d printing. I succeeded.</p></blockquote></div><p>"If I steal someone's phone, their fingerprints are already on it," he explained. "I can do this entire process in less than three minutes and remotely start the 3D print so that it's done by the time I get to it. Most banking apps only require fingerprint authentication so I could have all of your info and spend your money in less than 15 minutes if your phone is secured by fingerprint alone."</p><p>The photo used in the exploit was taken with the S10+ itself, but he also theorised that by using a higher-quality DSLR camera, you could steal someone's digit "from across a room... or further".</p><p>The S10's in-display fingerprint reader was one of the main selling points of the new device, with Samsung saying its biometric security "provides a high level of protection for sensitive data". However, most security experts agree that using biometric security as a primary unlock method is less secure than a password or PIN.</p><p>Multiple tests have shown that the facial recognition technology used to unlock many smartphones <a href="https://www.bleepingcomputer.com/news/security/samsung-galaxy-s10-face-recognition-can-easily-be-bypassed" target="_blank">is not foolproof</a>, and Samsung itself advises during the setup of facial recognition that it is "considered less secure than other lock types".</p><p>However, when we reached out to Samsung, the company dismissed concerns about the hack, calling the phone's security "vault-like".</p><p>"The Galaxy S10's in-display Ultrasonic Fingerprint Scanner offers vault-like security that has been developed through rigorous testing to provide the level of accuracy and prevent against attempts to compromise its security, such as images of a person's fingerprint."</p><p>Samsung argued that the hack wasn't a threat, as it required using professional software and a 3D-printer, and that the copy "could only have been made under a very rare combination of circumstances". Both pieces of software used in the hack offer free trials, while the 3D printer used is available for less than 400, making it comparatively easy for even an amateur hacker to assemble the necessary toolkit.</p><p>"If at any time there is a potential vulnerability identified, we will act promptly to investigate and resolve the issue," Samsung said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/33393/samsung-galaxy-s10-s-ultrasonic-sensor-fooled-by-fake-finger</link>
                                                                            <description>
                            <![CDATA[ Samsung’s in-display fingerprint reader can be hacked ‘in 15 minutes’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3gqL4DYxmgwRuyv2LEBZLc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SNKxABmppo5vTsRBecsnK3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Apr 2019 09:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SNKxABmppo5vTsRBecsnK3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SNKxABmppo5vTsRBecsnK3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/mobile/33324/samsung-galaxy-s10-review-a-truly-stellar-smartphone" target="_blank" data-original-url="https://www.itpro.com/mobile/33324/samsung-galaxy-s10-review-a-truly-stellar-smartphone">Samsung Galaxy S10</a>'s 'ultrasonic' in-display fingerprint reader can be easily unlocked with a 3D-printed fingerprint, allowing hackers to break through the device's biometric security.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/printers/28027/what-is-3d-printing" data-original-url="/printers/28027/what-is-3d-printing">What is 3D printing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="/mobile/20728/how-secure-apples-touch-id">How secure is Apple's Touch ID?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="/security/29705/what-are-biometrics">What are biometrics?</a></p></div></div><p>The exploit was discovered by a Reddit user going by the names of 'darkshark9', who cloned his own fingerprint from a photograph of the print left on a wine glass. Using common software tools Adobe Photoshop and Autodesk 3ds Max, he created an accurate replica of the print using a home 3D printer costing less than 400.</p><p>In a proof-of-concept uploaded to <a href="https://imgur.com/gallery/8aGqsSu" target="_blank">Imgur</a>, darkshark9 showed the device being unlocked by the fake print, stating that "the 3D print will unlock my phone...in some cases just as well as my actual finger does".</p><div><blockquote><p>I attempted to fool the new Samsung Galaxy S10's ultrasonic fingerprint scanner by using 3d printing. I succeeded.</p></blockquote></div><p>"If I steal someone's phone, their fingerprints are already on it," he explained. "I can do this entire process in less than three minutes and remotely start the 3D print so that it's done by the time I get to it. Most banking apps only require fingerprint authentication so I could have all of your info and spend your money in less than 15 minutes if your phone is secured by fingerprint alone."</p><p>The photo used in the exploit was taken with the S10+ itself, but he also theorised that by using a higher-quality DSLR camera, you could steal someone's digit "from across a room... or further".</p><p>The S10's in-display fingerprint reader was one of the main selling points of the new device, with Samsung saying its biometric security "provides a high level of protection for sensitive data". However, most security experts agree that using biometric security as a primary unlock method is less secure than a password or PIN.</p><p>Multiple tests have shown that the facial recognition technology used to unlock many smartphones <a href="https://www.bleepingcomputer.com/news/security/samsung-galaxy-s10-face-recognition-can-easily-be-bypassed" target="_blank">is not foolproof</a>, and Samsung itself advises during the setup of facial recognition that it is "considered less secure than other lock types".</p><p>However, when we reached out to Samsung, the company dismissed concerns about the hack, calling the phone's security "vault-like".</p><p>"The Galaxy S10's in-display Ultrasonic Fingerprint Scanner offers vault-like security that has been developed through rigorous testing to provide the level of accuracy and prevent against attempts to compromise its security, such as images of a person's fingerprint."</p><p>Samsung argued that the hack wasn't a threat, as it required using professional software and a 3D-printer, and that the copy "could only have been made under a very rare combination of circumstances". Both pieces of software used in the hack offer free trials, while the 3D printer used is available for less than 400, making it comparatively easy for even an amateur hacker to assemble the necessary toolkit.</p><p>"If at any time there is a potential vulnerability identified, we will act promptly to investigate and resolve the issue," Samsung said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HSBC to replace passwords with biometric banking ]]></title>
                                                                                                <dc:content><![CDATA[ <p>HSBC is set to roll out biometric banking to more than 15 million customers in the UK, it announced today.</p><p>The high street bank's voice recognition technology, Voice ID, would replace the current requirement for customers to cite dates and passwords when using telephone banking services.</p><p>Instead, the tech supplied by a company called Nuance would be able to check 100 unique identifiers in a person's voice to confirm they are who they claim to be.</p><p>These identifiers include speech speed, cadence and pronunciation, but also physical features like the shape of the user's vocal tract.</p><p>HSBC's First Direct service will start rolling the feature out to customers in the coming weeks before the rest of HSBC follows in the summer.</p><p>Francesca McDonagh, HSBC UK's head of retail banking and wealth management, said: "This is the largest planned roll-out of voice biometric security technology in the UK.</p><p>"The launch of voice and touch ID makes it even quicker and easier for customers to access their bank account, using the most secure form of password technology the body."</p><p>The feature would accompany Touch ID, which is available on Apple iPhone 5s models and newer, and which HSBC or First Direct customers can use by downloading the mobile banking app and following instructions to link their fingerprint to their bank account. </p><p>Barclays, which introduced voice recognition for its 300,000 wealthiest UK customers in 2013, is considering rolling the feature out to its 12 million retail customers, saying it had cut log-in times from 90 seconds to under 10 seconds.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/26078/hsbc-to-replace-passwords-with-biometric-banking</link>
                                                                            <description>
                            <![CDATA[ Voice ID and fingerprints will make log-in processes easier ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vF8VbaEtTNY5q3cTt9QMSo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dbu69de4WLpWW6BtyvdYR4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Feb 2016 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Apps]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dbu69de4WLpWW6BtyvdYR4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dbu69de4WLpWW6BtyvdYR4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>HSBC is set to roll out biometric banking to more than 15 million customers in the UK, it announced today.</p><p>The high street bank's voice recognition technology, Voice ID, would replace the current requirement for customers to cite dates and passwords when using telephone banking services.</p><p>Instead, the tech supplied by a company called Nuance would be able to check 100 unique identifiers in a person's voice to confirm they are who they claim to be.</p><p>These identifiers include speech speed, cadence and pronunciation, but also physical features like the shape of the user's vocal tract.</p><p>HSBC's First Direct service will start rolling the feature out to customers in the coming weeks before the rest of HSBC follows in the summer.</p><p>Francesca McDonagh, HSBC UK's head of retail banking and wealth management, said: "This is the largest planned roll-out of voice biometric security technology in the UK.</p><p>"The launch of voice and touch ID makes it even quicker and easier for customers to access their bank account, using the most secure form of password technology the body."</p><p>The feature would accompany Touch ID, which is available on Apple iPhone 5s models and newer, and which HSBC or First Direct customers can use by downloading the mobile banking app and following instructions to link their fingerprint to their bank account. </p><p>Barclays, which introduced voice recognition for its 300,000 wealthiest UK customers in 2013, is considering rolling the feature out to its 12 million retail customers, saying it had cut log-in times from 90 seconds to under 10 seconds.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple Touch ID to work with RBS & Natwest mobile apps ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Natwest and RBS customers with an Apple iPhone 5s or higher can login to their mobile banking apps from tomorrow using Apple's Touch ID biometric fingerprint scanner.</p><p>The banks are the first in the UK to secure their mobile banking apps in this way, with others likely to follow.</p><p>Despite the presence of fingerprint scanners on an increasing number of smartphones including the Samsung Galaxy S5 the service is only being offered to Natwest and RBS customers with Apple iPhones that support Touch ID. At the moment, these include the iPhone 5S, iPhone 6 and the iPhone 6 Plus.</p><p>At present, the companies claim more than 1.8 million iPhone owners use their mobile banking apps around 40 times a month.</p><p>In a statement, the banks said the move was designed to make it easier and more convenient for users to access up-to-date information about the state of their finances without have to remember pass codes.</p><p>Stuart Haire, managing director of RBS and Natwest Dirct Bank, said it's also being introduced to reflect the growing number of customers using both firms' online banking services.</p><p>According to figures released by both banks, nearly half of their combined 15 million customers use online banking, while three million use their mobile apps each week.</p><p>"There has been a revolution in banking, as more and more of our customers are using digital technology to bank with us," said Haire.</p><p>"Adding Touch ID to our mobile banking app makes it even easier and more convenient for customers to manage their finances on the move.</p><p>"Our aim is to be the number one bank for customer trust, service and advocacy, as we want to continue adapting our service based on the valuable feedback we receive from our customers every day," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/apps/24074/apple-touch-id-to-work-with-rbs-natwest-mobile-apps</link>
                                                                            <description>
                            <![CDATA[ Banks claim to be first in UK to offer biometric security to customers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cg5EJ813fVXkDQCMrCmV4g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H9CmS8C8hMKxsmW5iXrrWh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Feb 2015 10:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Apps]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/H9CmS8C8hMKxsmW5iXrrWh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H9CmS8C8hMKxsmW5iXrrWh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Natwest and RBS customers with an Apple iPhone 5s or higher can login to their mobile banking apps from tomorrow using Apple's Touch ID biometric fingerprint scanner.</p><p>The banks are the first in the UK to secure their mobile banking apps in this way, with others likely to follow.</p><p>Despite the presence of fingerprint scanners on an increasing number of smartphones including the Samsung Galaxy S5 the service is only being offered to Natwest and RBS customers with Apple iPhones that support Touch ID. At the moment, these include the iPhone 5S, iPhone 6 and the iPhone 6 Plus.</p><p>At present, the companies claim more than 1.8 million iPhone owners use their mobile banking apps around 40 times a month.</p><p>In a statement, the banks said the move was designed to make it easier and more convenient for users to access up-to-date information about the state of their finances without have to remember pass codes.</p><p>Stuart Haire, managing director of RBS and Natwest Dirct Bank, said it's also being introduced to reflect the growing number of customers using both firms' online banking services.</p><p>According to figures released by both banks, nearly half of their combined 15 million customers use online banking, while three million use their mobile apps each week.</p><p>"There has been a revolution in banking, as more and more of our customers are using digital technology to bank with us," said Haire.</p><p>"Adding Touch ID to our mobile banking app makes it even easier and more convenient for customers to manage their finances on the move.</p><p>"Our aim is to be the number one bank for customer trust, service and advocacy, as we want to continue adapting our service based on the valuable feedback we receive from our customers every day," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ iPhone Touch ID lets users unlock Macs remotely ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A new app for the iPhone <a href="https://itunes.apple.com/gb/app/id932228994?mt=8">FingerKey</a> will allow Mac users to remotely unlock their computer using the <a href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="https://www.itpro.com/MOBILE/20728/HOW-SECURE-APPLES-TOUCH-ID">Touch ID</a> fingerprint sensor.</p><p>The app works with the iPhone 5s, iPhone 6 and iPhone 6 Plus, and users can use their phone's fingerprint sensor to unlock their computer remotely, eliminating the need to type in a password to gain access. It is currently priced at 1.49.</p><p>Touch ID had only previously been useful for unlocking iPhones where it is featured and for authenticating purchases from the App Store and iTunes.</p><p>This comes as a result of Apple <a href="https://www.itpro.com/mobile/22375/ios-8-download-release-date-arrives" data-original-url="https://www.itpro.com/mobile/22375/ios-8-download-release-date-arrives">opening up</a> Touch ID to third-party developers, with FingerKey emerging as one of the more interesting and potentially useful utilisations of the feature created so far.</p><p>The app also lets users unlock multiple computers from their phone and, judging by the app's iTunes page, is focused on offering security and convenience with more features to be added later. On the list of things "coming soon" is compatibility with Windows and Linux devices.</p><p>The app will encrypt any information sent between the iPhone and Mac, maintaining security.</p><p>Security app 1Password recently launched an <a href="https://www.itpro.com/apps/22808/1password-launches-extension-for-third-party-ios-8-apps" data-original-url="https://www.itpro.com/apps/22808/1password-launches-extension-for-third-party-ios-8-apps">iOS 8 extension</a> with Touch ID support, which allows its features to be used in third party apps automatically.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/apps/23647/iphone-touch-id-lets-users-unlock-macs-remotely</link>
                                                                            <description>
                            <![CDATA[ You can unlock your Mac via your iPhone’s Touch ID fingerprint sensor, with new FingerKey app ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aX5NJ1uRrRv2AszQZmvPST</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DBKH4Nira3pZBrchGnSs8W-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Dec 2014 15:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iPhone]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                    <category><![CDATA[Mobile Phones]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Preece ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/MfwwRmvRe3qucjt85cMgeg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/DBKH4Nira3pZBrchGnSs8W-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DBKH4Nira3pZBrchGnSs8W-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new app for the iPhone <a href="https://itunes.apple.com/gb/app/id932228994?mt=8">FingerKey</a> will allow Mac users to remotely unlock their computer using the <a href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="https://www.itpro.com/MOBILE/20728/HOW-SECURE-APPLES-TOUCH-ID">Touch ID</a> fingerprint sensor.</p><p>The app works with the iPhone 5s, iPhone 6 and iPhone 6 Plus, and users can use their phone's fingerprint sensor to unlock their computer remotely, eliminating the need to type in a password to gain access. It is currently priced at 1.49.</p><p>Touch ID had only previously been useful for unlocking iPhones where it is featured and for authenticating purchases from the App Store and iTunes.</p><p>This comes as a result of Apple <a href="https://www.itpro.com/mobile/22375/ios-8-download-release-date-arrives" data-original-url="https://www.itpro.com/mobile/22375/ios-8-download-release-date-arrives">opening up</a> Touch ID to third-party developers, with FingerKey emerging as one of the more interesting and potentially useful utilisations of the feature created so far.</p><p>The app also lets users unlock multiple computers from their phone and, judging by the app's iTunes page, is focused on offering security and convenience with more features to be added later. On the list of things "coming soon" is compatibility with Windows and Linux devices.</p><p>The app will encrypt any information sent between the iPhone and Mac, maintaining security.</p><p>Security app 1Password recently launched an <a href="https://www.itpro.com/apps/22808/1password-launches-extension-for-third-party-ios-8-apps" data-original-url="https://www.itpro.com/apps/22808/1password-launches-extension-for-third-party-ios-8-apps">iOS 8 extension</a> with Touch ID support, which allows its features to be used in third party apps automatically.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ iOS 8.1 available to download now: What's new? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple used its iPad Air 2 launch to confirm the final version of iOS 8.1 will be released to iPad and iPhone users on Monday 20 October, and now that day has been and gone we take a look at the new features it has to offer. </p><p>The update is designed to build on the mobile operating system Apple introduced with the iPhone 6 and iPhone 6 Plus.</p><p>iOS 8 was released in September and was warmly received, until a couple of concurrent bugs emerged, resulting in people losing signal and rendering the Touch ID biometric fingerprint scanner useless. </p><p>Apple sought to resolve these via a series of minor updates, but has now pushed out iOS 8.1 to enhance the functionality of the operating system.</p><p>The iOS update was officially released yesterday as an over-the-air update or through iTunes.</p><p>As is tradition whenever a new Apple mobile operating system drops - some users reported problems while trying to download and install it.</p><p>Most of the problems seem to stem from the sheer number of people rushing to download the update all at the same time, with many encountering download delays and interruptions. </p><p>Even so, there's no denying that iOS 8 has a lot to offer iPhone and iPad users, as our list of some if its main new features and bug fixes below shows.</p><p>Before we start our run through, it's worth remembering that iOS 8.1 is only compatible with the iPhone 4S and higher, the iPad 2 and later, as well as fifth generation iPod Touch devices and above. </p><p><strong>Apple Pay</strong></p><p>While Apple Pay - the firm's NFC payment system - is only available to US iPhone and iPad users at the moment, the iOS 8.1 update makes it possible for iPad and iPhone users to pay for goods and services using their devices.</p><p>The iPhone 6 and 6 Plus both contain an NFC chip allowing users to pay for items in stores by tapping their devices against a compatible point-of-sale sensor, while Touch ID allows them to verify the payment.</p><p>iPhones and iPads without NFC technology can still be used to pay for products online using Apple Pay, as the firm has partnered with more than 200,000 US retailers to make this possible.</p><p>SMS Continuity with Yosemite</p><p>One of the standout features of Apple's reworked desktop operating system OS X Yosemite was Continuity, which allows iPhone and iPad users to open documents stored on their smartphone or tablet remotely from a Mac and take calls. </p><p>With the launch of iOS 8.1 this functionality has been extended to SMS text messages. So Mac users can now read text messages from their friends, family and work colleagues sent to their smartphones on the Apple laptop or desktop.</p><p><strong>Connectvity improvements</strong></p><p>In the release notes for iOS 8.1, Apple claims to have resolved some unspecified Wi-Fi performance issues, as well as another pertaining to problems users have experienced while trying to pair their devices to others via Bluetooth.</p><p>Further to this, users now have the option to switch between 2G, 3G or 4G networks when downloading mobile data.</p><p><strong>Photos and video enhancements</strong></p><p>As discussed at the iPad Air 2 launch last week, iOS 8.1 introduces the iCloud Photo Library as a beta service. </p><p>This offering will sync and store any photos and videos users capture on their iPad or iPhone in iCloud, which should - one assumes - free up space on their devices. </p><p>The iOS update also introduces a feature that will alert users when space on their devices is running low before they embark on Time Lapse videos, and also fixes an issue that sometimes prevented videos from playing in Safari. </p><p>Developers got their hands on the first beta of iOS 8.1 at the end of last month, with the code containing information about the firm's <a href="https://www.itpro.com/mobile/23080/apple-pay-what-is-nfc-how-secure-is-it" target="_blank" data-original-url="https://www.itpro.com/mobile/23080/apple-pay-what-is-nfc-how-secure-is-it">Apple Pay system</a> and also suggesting the fingerprint scanner is coming to the iPad.</p><p>iOS 8.1 contains a brand new settings panel, showing options related to credit and debit cards, according to <a href="http://www.macrumors.com/2014/09/29/ios-8-1-apple-pay-ipad-touch-id" target="_blank">MacRumours</a>. There are also default card/billing address/email/phone options, along with a disclaimer from the company concerning privacy of the feature.</p><p>Apple Pay, the payment system being introduced with iOS 8, iPhone 6 and iPhone 6 Plus, is the company's first foray into offering NFC technology to its users.</p><p>The new feature means that users can either use the payment information they have already used on iTunes or upload a photo of their card to Passbook and use their device to make purchases thereafter.</p><p>There are also reportedly signs of Touch ID being introduced for the iPad, which ties in with the imminent introduction of Apple Pay for the iPhone and Apple Watch.</p><p>With Touch ID on the next generation iPad, users would not need to manually input payment data and information when making purchases in relevant apps, though it is unclear whether Apple Pay will become available for the devices or be limited to the iPhone and Apple Watch for the foreseeable future.</p><p>The company previously revealed that Apple Pay would be launching at some point in October, and is expected to be a part of the upcoming iOS 8.1 update.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/mobile/23209/ios-81-available-to-download-now-whats-new</link>
                                                                            <description>
                            <![CDATA[ iOS 8.1 is finally available to download for free. Here we run through what the latest version of the mobile OS has to offer ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3UNu5zGm3QFEKBGoXpRdf7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xyYsv8LMK77N5Zup7AbcJe-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Oct 2014 15:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Preece ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/MfwwRmvRe3qucjt85cMgeg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/xyYsv8LMK77N5Zup7AbcJe-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xyYsv8LMK77N5Zup7AbcJe-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple used its iPad Air 2 launch to confirm the final version of iOS 8.1 will be released to iPad and iPhone users on Monday 20 October, and now that day has been and gone we take a look at the new features it has to offer. </p><p>The update is designed to build on the mobile operating system Apple introduced with the iPhone 6 and iPhone 6 Plus.</p><p>iOS 8 was released in September and was warmly received, until a couple of concurrent bugs emerged, resulting in people losing signal and rendering the Touch ID biometric fingerprint scanner useless. </p><p>Apple sought to resolve these via a series of minor updates, but has now pushed out iOS 8.1 to enhance the functionality of the operating system.</p><p>The iOS update was officially released yesterday as an over-the-air update or through iTunes.</p><p>As is tradition whenever a new Apple mobile operating system drops - some users reported problems while trying to download and install it.</p><p>Most of the problems seem to stem from the sheer number of people rushing to download the update all at the same time, with many encountering download delays and interruptions. </p><p>Even so, there's no denying that iOS 8 has a lot to offer iPhone and iPad users, as our list of some if its main new features and bug fixes below shows.</p><p>Before we start our run through, it's worth remembering that iOS 8.1 is only compatible with the iPhone 4S and higher, the iPad 2 and later, as well as fifth generation iPod Touch devices and above. </p><p><strong>Apple Pay</strong></p><p>While Apple Pay - the firm's NFC payment system - is only available to US iPhone and iPad users at the moment, the iOS 8.1 update makes it possible for iPad and iPhone users to pay for goods and services using their devices.</p><p>The iPhone 6 and 6 Plus both contain an NFC chip allowing users to pay for items in stores by tapping their devices against a compatible point-of-sale sensor, while Touch ID allows them to verify the payment.</p><p>iPhones and iPads without NFC technology can still be used to pay for products online using Apple Pay, as the firm has partnered with more than 200,000 US retailers to make this possible.</p><p>SMS Continuity with Yosemite</p><p>One of the standout features of Apple's reworked desktop operating system OS X Yosemite was Continuity, which allows iPhone and iPad users to open documents stored on their smartphone or tablet remotely from a Mac and take calls. </p><p>With the launch of iOS 8.1 this functionality has been extended to SMS text messages. So Mac users can now read text messages from their friends, family and work colleagues sent to their smartphones on the Apple laptop or desktop.</p><p><strong>Connectvity improvements</strong></p><p>In the release notes for iOS 8.1, Apple claims to have resolved some unspecified Wi-Fi performance issues, as well as another pertaining to problems users have experienced while trying to pair their devices to others via Bluetooth.</p><p>Further to this, users now have the option to switch between 2G, 3G or 4G networks when downloading mobile data.</p><p><strong>Photos and video enhancements</strong></p><p>As discussed at the iPad Air 2 launch last week, iOS 8.1 introduces the iCloud Photo Library as a beta service. </p><p>This offering will sync and store any photos and videos users capture on their iPad or iPhone in iCloud, which should - one assumes - free up space on their devices. </p><p>The iOS update also introduces a feature that will alert users when space on their devices is running low before they embark on Time Lapse videos, and also fixes an issue that sometimes prevented videos from playing in Safari. </p><p>Developers got their hands on the first beta of iOS 8.1 at the end of last month, with the code containing information about the firm's <a href="https://www.itpro.com/mobile/23080/apple-pay-what-is-nfc-how-secure-is-it" target="_blank" data-original-url="https://www.itpro.com/mobile/23080/apple-pay-what-is-nfc-how-secure-is-it">Apple Pay system</a> and also suggesting the fingerprint scanner is coming to the iPad.</p><p>iOS 8.1 contains a brand new settings panel, showing options related to credit and debit cards, according to <a href="http://www.macrumors.com/2014/09/29/ios-8-1-apple-pay-ipad-touch-id" target="_blank">MacRumours</a>. There are also default card/billing address/email/phone options, along with a disclaimer from the company concerning privacy of the feature.</p><p>Apple Pay, the payment system being introduced with iOS 8, iPhone 6 and iPhone 6 Plus, is the company's first foray into offering NFC technology to its users.</p><p>The new feature means that users can either use the payment information they have already used on iTunes or upload a photo of their card to Passbook and use their device to make purchases thereafter.</p><p>There are also reportedly signs of Touch ID being introduced for the iPad, which ties in with the imminent introduction of Apple Pay for the iPhone and Apple Watch.</p><p>With Touch ID on the next generation iPad, users would not need to manually input payment data and information when making purchases in relevant apps, though it is unclear whether Apple Pay will become available for the devices or be limited to the iPhone and Apple Watch for the foreseeable future.</p><p>The company previously revealed that Apple Pay would be launching at some point in October, and is expected to be a part of the upcoming iOS 8.1 update.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple reveals inner workings of iPhone 5s Touch ID scanner ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple has published a white paper that reveals exactly how the Touch ID biometric scanner works on its latest iPhones.</p><p>The company has shared information regarding how Touch ID keeps biometric data private in an updated <a href="http://images.apple.com/iphone/business/docs/iOS_Security_Feb14.pdf">security document</a>. It posted the PDF to its <a href="http://www.apple.com/iphone/business">iPhones in Business</a> microsite.</p><p>The feature works by using what Apple calls a "Secure Enclave". This generates and communicates encrypted temporary information to the rest of the phone, ensuring that fingerprint data is left unexposed to the rest of the system.</p><p>Secure Enclave only stores data from scanned prints and not the actual images. With the secure boot process, the Enclave, a co-processor inside Apple's A7 chip, verifies and signs data independently of other iOS software and hardware. Apple said even if a device is compromised the data held in the Secure Enclave is completely inaccessible.</p><p>"Each Secure Enclave is provisioned during fabrication with its own UID (Unique ID) that is not accessible to other parts of the system and is not known to Apple. When the device starts up, an ephemeral key is created, tangled with its UID, and used to encrypt the Secure Enclave's portion of the device's memory space," the document said.</p><p>"Additionally, data that is saved to the file system by the Secure Enclave is encrypted with a key tangled with the UID and an anti-replay counter."</p><p>And while the A7 processor deals with data from Touch ID, this information is encrypted by the scanner, making it unreadable to the rest of the phone. Only Secure Enclave can authenticate the data.</p><p>"It's encrypted and authenticated with a session key that is negotiated using the device's shared key that is built into the Touch ID sensor and the Secure Enclave," the document reads. "The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption."</p><p>Researchers at FireEye recently published a <a href="http://www.fireeye.com/blog/technical/2014/02/background-monitoring-on-non-jailbroken-ios-7-devices-and-a-mitigation.html">post</a> about how keyboard presses, physical button presses, and TouchID interaction can be tracked on iOS devices, even if they are not jailbroken, with a simple monitoring app. The researchers said this information could be used to mount an attack on such a device and get access to the devices's input data.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/21722/apple-reveals-inner-workings-of-iphone-5s-touch-id-scanner</link>
                                                                            <description>
                            <![CDATA[ The consumer electronics giant explains how Touch ID keeps users' fingerprints safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4SANFv4VFfqVx4ReUBPswN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pLL7ZyLcCdsB54V95GfXk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Feb 2014 13:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Apple]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pLL7ZyLcCdsB54V95GfXk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pLL7ZyLcCdsB54V95GfXk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has published a white paper that reveals exactly how the Touch ID biometric scanner works on its latest iPhones.</p><p>The company has shared information regarding how Touch ID keeps biometric data private in an updated <a href="http://images.apple.com/iphone/business/docs/iOS_Security_Feb14.pdf">security document</a>. It posted the PDF to its <a href="http://www.apple.com/iphone/business">iPhones in Business</a> microsite.</p><p>The feature works by using what Apple calls a "Secure Enclave". This generates and communicates encrypted temporary information to the rest of the phone, ensuring that fingerprint data is left unexposed to the rest of the system.</p><p>Secure Enclave only stores data from scanned prints and not the actual images. With the secure boot process, the Enclave, a co-processor inside Apple's A7 chip, verifies and signs data independently of other iOS software and hardware. Apple said even if a device is compromised the data held in the Secure Enclave is completely inaccessible.</p><p>"Each Secure Enclave is provisioned during fabrication with its own UID (Unique ID) that is not accessible to other parts of the system and is not known to Apple. When the device starts up, an ephemeral key is created, tangled with its UID, and used to encrypt the Secure Enclave's portion of the device's memory space," the document said.</p><p>"Additionally, data that is saved to the file system by the Secure Enclave is encrypted with a key tangled with the UID and an anti-replay counter."</p><p>And while the A7 processor deals with data from Touch ID, this information is encrypted by the scanner, making it unreadable to the rest of the phone. Only Secure Enclave can authenticate the data.</p><p>"It's encrypted and authenticated with a session key that is negotiated using the device's shared key that is built into the Touch ID sensor and the Secure Enclave," the document reads. "The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption."</p><p>Researchers at FireEye recently published a <a href="http://www.fireeye.com/blog/technical/2014/02/background-monitoring-on-non-jailbroken-ios-7-devices-and-a-mitigation.html">post</a> about how keyboard presses, physical button presses, and TouchID interaction can be tracked on iOS devices, even if they are not jailbroken, with a simple monitoring app. The researchers said this information could be used to mount an attack on such a device and get access to the devices's input data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 8.1, Voice transcription and Touch ID: IT Pro's web comment roundup ]]></title>
                                                                                                <dc:content><![CDATA[ <p>This week IT Pro readers have been expressing their views on everything from Windows 8.1 to voice recognition technology.</p><p>There was a passionate defence of voice transcription technology, and the exchanges between readers with regards to Apple's Touch ID continue to roll in.</p><p><strong>The Windows 8.1 debate</strong></p><p>The web giant finally launched its <a href="https://www.itpro.com/desktop-software/19622/windows-81-release-date-arrives" target="_blank" data-original-url="https://www.itpro.com/desktop-software/19622/windows-81-release-date-arrives">Windows 8.1 update</a> bringing much needed functionality back to the operating system including the ability to boot straight to desktop.</p><p>"These updates are actually useful. Everything is more easily accessible and things that bugged me in Windows 8 are corrected in 8.1, such as viewing two windows at once and each taking up 50 per cent of the screen," <strong>Adriana</strong> explained.</p><p>However, not everyone has been quick to applaud Microsoft's changes with <strong>Shakeel</strong> still mourning over the loss of the old Start menu.</p><p>"I prefer Windows 7 any day as it still has a full start menu," he pointed out.</p><p>And it doesn't look like Microsoft has won any fans by making its SkyDrive repository the default location to save documents.</p><p>"Why in God's name do I need to store my files in Microsoft's cloud?" pondered <strong>Alex</strong>.</p><p><strong>Hear me out</strong></p><p>Last week, <a href="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times" target="_blank" data-original-url="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times">Nuance demonstrated how it was deploying speech transcription</a> services at NHS Trusts, and how this benefits patients and helps to clear admin backlog.</p><p>A reader named <strong>Derek</strong> claimed that voice transcription would lead to more mistakes, due to the inability to distinguish between accents. However, he's in the minority. <strong>Jim Robinson</strong> was the latest to talk up the benefits of the technology.</p><p>"There are significantly fewer mistakes [in transcriptions] due to: A the removal of the 'double handling' inherent in the traditional transcription process, : B removal of the time delay between thinking what to say and seeing the words in print immediately before you," <strong>Jim</strong> noted.</p><p>"Don't forget that 90 per cent of Radiologists were equally skeptical five years ago, and now at least 75 per cent of all Radiologists in the NHS are using speech recognition and would never go back to the old ways."</p><p>Everybody wins according to Jim, from patients, who will have improved services through to taxpayers who will save money because of increased efficiency within the NHS.</p><p><strong>Can't Touch ID</strong></p><p>The debate over whether criminals will resort to chopping off fingers from unsuspecting iPhone 5s users continues to rage on. <strong>Phila</strong> had previously been adamant that criminals wouldn't have second thoughts about taking a digit from their victim so they could bypass Touch ID.</p><p>But it's not that simple countered <strong>Twonker</strong>.</p><p>"Who says you have to use a thumb? Use a finger on your left hand. That itself increases security as you then use your right hand for typing (or vice versa for lefties). Yes, it would increase security to use 6 digit pins, but what if Apple set it up to use two different finger imprints in sequence for those of you truly paranoid," he suggested.</p><p>"A thief would then have to cut both your hands off and work quickly ;-) Then again, he could just hold a gun to your head to get you to unlock your phone and get at those military secrets you keep on it. (A touch of sarcasm here)."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/desktop-software/20851/windows-81-voice-transcription-and-touch-id-it-pros-web-comment-roundup</link>
                                                                            <description>
                            <![CDATA[ Readers not thrilled by Windows 8.1 and security of Touch ID continues to be debated. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eQx47gBVyY22R9zCQ7iUmK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pJeNNd5AC3PhdQmnTpyjYX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Oct 2013 16:16:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pJeNNd5AC3PhdQmnTpyjYX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pJeNNd5AC3PhdQmnTpyjYX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This week IT Pro readers have been expressing their views on everything from Windows 8.1 to voice recognition technology.</p><p>There was a passionate defence of voice transcription technology, and the exchanges between readers with regards to Apple's Touch ID continue to roll in.</p><p><strong>The Windows 8.1 debate</strong></p><p>The web giant finally launched its <a href="https://www.itpro.com/desktop-software/19622/windows-81-release-date-arrives" target="_blank" data-original-url="https://www.itpro.com/desktop-software/19622/windows-81-release-date-arrives">Windows 8.1 update</a> bringing much needed functionality back to the operating system including the ability to boot straight to desktop.</p><p>"These updates are actually useful. Everything is more easily accessible and things that bugged me in Windows 8 are corrected in 8.1, such as viewing two windows at once and each taking up 50 per cent of the screen," <strong>Adriana</strong> explained.</p><p>However, not everyone has been quick to applaud Microsoft's changes with <strong>Shakeel</strong> still mourning over the loss of the old Start menu.</p><p>"I prefer Windows 7 any day as it still has a full start menu," he pointed out.</p><p>And it doesn't look like Microsoft has won any fans by making its SkyDrive repository the default location to save documents.</p><p>"Why in God's name do I need to store my files in Microsoft's cloud?" pondered <strong>Alex</strong>.</p><p><strong>Hear me out</strong></p><p>Last week, <a href="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times" target="_blank" data-original-url="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times">Nuance demonstrated how it was deploying speech transcription</a> services at NHS Trusts, and how this benefits patients and helps to clear admin backlog.</p><p>A reader named <strong>Derek</strong> claimed that voice transcription would lead to more mistakes, due to the inability to distinguish between accents. However, he's in the minority. <strong>Jim Robinson</strong> was the latest to talk up the benefits of the technology.</p><p>"There are significantly fewer mistakes [in transcriptions] due to: A the removal of the 'double handling' inherent in the traditional transcription process, : B removal of the time delay between thinking what to say and seeing the words in print immediately before you," <strong>Jim</strong> noted.</p><p>"Don't forget that 90 per cent of Radiologists were equally skeptical five years ago, and now at least 75 per cent of all Radiologists in the NHS are using speech recognition and would never go back to the old ways."</p><p>Everybody wins according to Jim, from patients, who will have improved services through to taxpayers who will save money because of increased efficiency within the NHS.</p><p><strong>Can't Touch ID</strong></p><p>The debate over whether criminals will resort to chopping off fingers from unsuspecting iPhone 5s users continues to rage on. <strong>Phila</strong> had previously been adamant that criminals wouldn't have second thoughts about taking a digit from their victim so they could bypass Touch ID.</p><p>But it's not that simple countered <strong>Twonker</strong>.</p><p>"Who says you have to use a thumb? Use a finger on your left hand. That itself increases security as you then use your right hand for typing (or vice versa for lefties). Yes, it would increase security to use 6 digit pins, but what if Apple set it up to use two different finger imprints in sequence for those of you truly paranoid," he suggested.</p><p>"A thief would then have to cut both your hands off and work quickly ;-) Then again, he could just hold a gun to your head to get you to unlock your phone and get at those military secrets you keep on it. (A touch of sarcasm here)."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows XP, Ofcom fees and Touch ID: IT Pro's web comments round-up ]]></title>
                                                                                                <dc:content><![CDATA[ <p>It's that time of the week again where we take a look at some of the news stories, features and product reviews that have got <em>IT Pro</em> readers hot under the collar this week.</p><p>Some of the most popular topics of online conversation this week have centred on Windows XP's looming end of support deadline, Ofcom's proposed mobile licence spectrum fee hike and the pros and cons of using speech recognition software in a healthcare setting.</p><p>And, of course, no weekly web comments round-up is complete without someone kicking off about something to do with Apple, is it?</p><p><strong>Full support for XP</strong></p><p>This week marked the start of the <strong><a target="_blank" href="https://www.itpro.com/operating-systems/windows-xp-windows-7-migration/20762/windows-xp-enterprise-users-urged-ditch-aged" data-original-url="https://www.itpro.com/operating-systems/windows-xp-windows-7-migration/20762/windows-xp-enterprise-users-urged-ditch-aged">six month countdown until Microsoft finally pulls the plug</a></strong> on extended support for Windows XP, a thirteen year old operating system that is still used on more than 30 per cent of the world's PCs.</p><p>Microsoft has been bigging up the benefits of giving XP the slip for several years now.</p><p>But, despite Microsoft's best attempts to convince Windows XP users that there are better, faster, newer and more secure versions of the operation system out there, the message seems to be falling on deaf ears.</p><div><blockquote><p>I don't get attacked by Trojans or malware and at least I know my way around...I wish people would stop being taken in by the hype.</p></blockquote></div><p>Diehard Windows XP fan <strong>James B</strong> said he has Windows 7, but keeps an XP machine around for nostalgia purposes.</p><p>"I found a lot of the old games I still like to play will not work on Windows 7, so I keep Windows XP," he explained.</p><p><strong>Autoq</strong> said he would upgrade to Windows 7,8 or even Vista if it wasn't so gosh darn expensive.</p><p>"If Microsoft give me a license for Windows 7 Professional (or Windows 8) to match my Win XP Professional license for say $10, I'd upgrade," offered Autoq. At that price, I reckon Apple CEO Tim Cook might even consider a move over to Windows as well...</p><p>Meanwhile, <strong>Mr. Stressed</strong>, another happy XP user, called for people to stop paying attention to Microsoft hype about the OS no longer being fit for purpose.</p><p>"I don't get attacked by Trojans or malware and at least I know my way around and can actually use the machine, which is what it was built for," he fumed.</p><p>"I wish people would stop being taken in by the hype. Sure, if you enjoy tinkering with new operating systems then fine, go ahead, but many of us just want to use the machine."</p><p><strong>Ofcom's mobile spectrum price hikes</strong></p><p>Ofcom set out plans this week to <strong><a target="_blank" href="https://www.itpro.com/networking/mobile-networks/20764/vodafone-disappointed-ofcom-spectrum-price-hike-plans" data-original-url="https://www.itpro.com/networking/mobile-networks/20764/vodafone-disappointed-ofcom-spectrum-price-hike-plans">increase the annual fees mobile operators must pay to run services using the 900 MHz and 1800 MHz spectrum bands</a></strong>, much to the disgust of many.</p><p>These bands are used by the operator community to carry voice calls, as well as run 3G and 4G services, and Ofcom wants Three, EE, O2 and Vodafone to cough up an extra 245 million a year to use them.</p><p>It is feared the move could ultimately result in customers having to pay more to use mobile services, while Ofcom pleads a price hike is necessary because spectrum space is a finite resource and needs to be used as efficiently as possible.</p><p>Unfortunately, <em>IT Pro</em> readers weren't buying that, with some already kicking off at the prospect of having to pay the mobile operator community more for services (they claim) often cut out.</p><p>Regular <em>IT Pro</em> commenter <strong>Brianm101</strong> was among those opposed to the plan. "I think Ofcom's statement would be better worded as, We need more money and the spectrum is a finite resource so we can charge what we like," he scornfully added.</p><p><strong>Healthcare talk</strong></p><p>Speech technology vendor Nuance held an event in London this week looking at <strong><a target="_blank" href="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times" data-original-url="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times">how the use of its dictation software could help speed up treatment and diagnosis times within the NHS</a></strong>.</p><p>Several healthcare professionals shared their experiences of using the firm's tools at the event. For instance, one claimed the software has freed medical secretaries from the onerous task of transcribing doctors' letters, and made it easier for medical staff to keep contemporaneous appointment notes, as per the General Medical Council's guidelines.</p><div><blockquote><p>Although speech recognition has improved dramatically over the last few years, I can see multitudes of problems with this approach.</p></blockquote></div><p><em>IT Pro</em> reader Derek Knight sounds like he'll need some more convincing about whether speech recognition technology should become a common feature in GP surgeries.</p><p>"Although speech recognition has improved dramatically over the last few years, I can see multitudes of problems with this approach, not least: when you can barely understand what the doctor is saying, because he or she speaks with a strong accent," remarked Knight.</p><p>"At least a human has a vague chance of working out the gist of it from facial expressions and the situation. I really see a lot more mistakes from this sort of use of technology."</p><p>James Kippenberger, however, was far more supportive, explaining tools that allow doctors to cut down on the amount of admin they do and prioritise patient care are a good thing.</p><p>"The process of creating, disseminating, checking and signing discharge summaries and clinical letters can be timely and often prevents valuable patient-facing time," he explained.</p><p>"Some hospitals are forced to function without administrative support and there are still high numbers of clinical staff producing handwritten notes all of which eventually need typing.</p><p>Of course, it's quicker to talk than to type and with doctors under increasing pressure to spend more time with patients, undoubtedly technology that can improve the efficiency and productivity of care, can only benefit," he added.</p><p><strong>Mugged off by TouchID</strong></p><p>And finally, the inclusion of the <a target="_blank" href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id"><strong>Touch ID biometric fingerprint scanner</strong></a> on the iPhone 5s has sparked someseriously fanciful thoughts from readers in <strong><a target="_blank" href="https://www.itpro.com/strategy/20738/ios-7-bugs-bbm-delays-and-banking-security-it-pros-web-comments-round" data-original-url="https://www.itpro.com/strategy/20738/ios-7-bugs-bbm-delays-and-banking-security-it-pros-web-comments-round">recent weeks</a></strong>.</p><p>This time around the comments have mainly focused on the lengths muggers might go to pinch an iPhone 5s with Touch ID activated off its owner.</p><p>Long-time <em>IT Pro</em> commenter <strong>Phila</strong> suggested iPhone 5s owners could find themselves losing more than their devices, if muggers have their way.</p><div><blockquote><p>There are gangs which get around the finger print scanners on bigger devices with a very simple method: they take the fingers from the owner.</p></blockquote></div><p>"There are gangs which get around the fingerprint scanners on bigger devices with a very simple method: they take the fingers from the owner," he warned.</p><p>"Would a gang, who are stealing a device worth 700+, think twice about removing a thumb from someone they're stealing from? I very much doubt it."</p><p>Even so <strong>JLewis</strong> said he doesn't believe a thief would go to the trouble of cutting off a person's thumb for the sake of an iPhone, especially as there are no guarantees it's the digit they use to unlock the device.</p><p>"Do you really think it to be likely for a common thief to hack a finger off of someone not knowing if it's the correct finger," he asked.</p><p>In short, yes, <strong>Phila</strong> does. "Having been mugged in the past, at knife point, [muggers] have zero compunction in causing physical harm while taking items and money," he explained.</p><p>"It was only my compliance that meant that I wasn't injured, but I know people who have been harmed during muggings. So, would someone remove a finger for a 700 device? Yup, I'm sure they wouldn't have any second thoughts about it."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/strategy/20775/windows-xp-ofcom-fees-and-touch-id-it-pros-web-comments-round</link>
                                                                            <description>
                            <![CDATA[ Windows XP's demise, Ofcom fees and Touch ID have all got IT Pro readers talking this week. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3QUzd6qiQuauiU8Xw9mhnZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pJeNNd5AC3PhdQmnTpyjYX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Oct 2013 14:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pJeNNd5AC3PhdQmnTpyjYX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pJeNNd5AC3PhdQmnTpyjYX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's that time of the week again where we take a look at some of the news stories, features and product reviews that have got <em>IT Pro</em> readers hot under the collar this week.</p><p>Some of the most popular topics of online conversation this week have centred on Windows XP's looming end of support deadline, Ofcom's proposed mobile licence spectrum fee hike and the pros and cons of using speech recognition software in a healthcare setting.</p><p>And, of course, no weekly web comments round-up is complete without someone kicking off about something to do with Apple, is it?</p><p><strong>Full support for XP</strong></p><p>This week marked the start of the <strong><a target="_blank" href="https://www.itpro.com/operating-systems/windows-xp-windows-7-migration/20762/windows-xp-enterprise-users-urged-ditch-aged" data-original-url="https://www.itpro.com/operating-systems/windows-xp-windows-7-migration/20762/windows-xp-enterprise-users-urged-ditch-aged">six month countdown until Microsoft finally pulls the plug</a></strong> on extended support for Windows XP, a thirteen year old operating system that is still used on more than 30 per cent of the world's PCs.</p><p>Microsoft has been bigging up the benefits of giving XP the slip for several years now.</p><p>But, despite Microsoft's best attempts to convince Windows XP users that there are better, faster, newer and more secure versions of the operation system out there, the message seems to be falling on deaf ears.</p><div><blockquote><p>I don't get attacked by Trojans or malware and at least I know my way around...I wish people would stop being taken in by the hype.</p></blockquote></div><p>Diehard Windows XP fan <strong>James B</strong> said he has Windows 7, but keeps an XP machine around for nostalgia purposes.</p><p>"I found a lot of the old games I still like to play will not work on Windows 7, so I keep Windows XP," he explained.</p><p><strong>Autoq</strong> said he would upgrade to Windows 7,8 or even Vista if it wasn't so gosh darn expensive.</p><p>"If Microsoft give me a license for Windows 7 Professional (or Windows 8) to match my Win XP Professional license for say $10, I'd upgrade," offered Autoq. At that price, I reckon Apple CEO Tim Cook might even consider a move over to Windows as well...</p><p>Meanwhile, <strong>Mr. Stressed</strong>, another happy XP user, called for people to stop paying attention to Microsoft hype about the OS no longer being fit for purpose.</p><p>"I don't get attacked by Trojans or malware and at least I know my way around and can actually use the machine, which is what it was built for," he fumed.</p><p>"I wish people would stop being taken in by the hype. Sure, if you enjoy tinkering with new operating systems then fine, go ahead, but many of us just want to use the machine."</p><p><strong>Ofcom's mobile spectrum price hikes</strong></p><p>Ofcom set out plans this week to <strong><a target="_blank" href="https://www.itpro.com/networking/mobile-networks/20764/vodafone-disappointed-ofcom-spectrum-price-hike-plans" data-original-url="https://www.itpro.com/networking/mobile-networks/20764/vodafone-disappointed-ofcom-spectrum-price-hike-plans">increase the annual fees mobile operators must pay to run services using the 900 MHz and 1800 MHz spectrum bands</a></strong>, much to the disgust of many.</p><p>These bands are used by the operator community to carry voice calls, as well as run 3G and 4G services, and Ofcom wants Three, EE, O2 and Vodafone to cough up an extra 245 million a year to use them.</p><p>It is feared the move could ultimately result in customers having to pay more to use mobile services, while Ofcom pleads a price hike is necessary because spectrum space is a finite resource and needs to be used as efficiently as possible.</p><p>Unfortunately, <em>IT Pro</em> readers weren't buying that, with some already kicking off at the prospect of having to pay the mobile operator community more for services (they claim) often cut out.</p><p>Regular <em>IT Pro</em> commenter <strong>Brianm101</strong> was among those opposed to the plan. "I think Ofcom's statement would be better worded as, We need more money and the spectrum is a finite resource so we can charge what we like," he scornfully added.</p><p><strong>Healthcare talk</strong></p><p>Speech technology vendor Nuance held an event in London this week looking at <strong><a target="_blank" href="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times" data-original-url="https://www.itpro.com/desktop-software/voice-recognition/20758/doctors-use-speech-recognition-cut-nhs-waiting-times">how the use of its dictation software could help speed up treatment and diagnosis times within the NHS</a></strong>.</p><p>Several healthcare professionals shared their experiences of using the firm's tools at the event. For instance, one claimed the software has freed medical secretaries from the onerous task of transcribing doctors' letters, and made it easier for medical staff to keep contemporaneous appointment notes, as per the General Medical Council's guidelines.</p><div><blockquote><p>Although speech recognition has improved dramatically over the last few years, I can see multitudes of problems with this approach.</p></blockquote></div><p><em>IT Pro</em> reader Derek Knight sounds like he'll need some more convincing about whether speech recognition technology should become a common feature in GP surgeries.</p><p>"Although speech recognition has improved dramatically over the last few years, I can see multitudes of problems with this approach, not least: when you can barely understand what the doctor is saying, because he or she speaks with a strong accent," remarked Knight.</p><p>"At least a human has a vague chance of working out the gist of it from facial expressions and the situation. I really see a lot more mistakes from this sort of use of technology."</p><p>James Kippenberger, however, was far more supportive, explaining tools that allow doctors to cut down on the amount of admin they do and prioritise patient care are a good thing.</p><p>"The process of creating, disseminating, checking and signing discharge summaries and clinical letters can be timely and often prevents valuable patient-facing time," he explained.</p><p>"Some hospitals are forced to function without administrative support and there are still high numbers of clinical staff producing handwritten notes all of which eventually need typing.</p><p>Of course, it's quicker to talk than to type and with doctors under increasing pressure to spend more time with patients, undoubtedly technology that can improve the efficiency and productivity of care, can only benefit," he added.</p><p><strong>Mugged off by TouchID</strong></p><p>And finally, the inclusion of the <a target="_blank" href="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id" data-original-url="https://www.itpro.com/mobile/20728/how-secure-apples-touch-id"><strong>Touch ID biometric fingerprint scanner</strong></a> on the iPhone 5s has sparked someseriously fanciful thoughts from readers in <strong><a target="_blank" href="https://www.itpro.com/strategy/20738/ios-7-bugs-bbm-delays-and-banking-security-it-pros-web-comments-round" data-original-url="https://www.itpro.com/strategy/20738/ios-7-bugs-bbm-delays-and-banking-security-it-pros-web-comments-round">recent weeks</a></strong>.</p><p>This time around the comments have mainly focused on the lengths muggers might go to pinch an iPhone 5s with Touch ID activated off its owner.</p><p>Long-time <em>IT Pro</em> commenter <strong>Phila</strong> suggested iPhone 5s owners could find themselves losing more than their devices, if muggers have their way.</p><div><blockquote><p>There are gangs which get around the finger print scanners on bigger devices with a very simple method: they take the fingers from the owner.</p></blockquote></div><p>"There are gangs which get around the fingerprint scanners on bigger devices with a very simple method: they take the fingers from the owner," he warned.</p><p>"Would a gang, who are stealing a device worth 700+, think twice about removing a thumb from someone they're stealing from? I very much doubt it."</p><p>Even so <strong>JLewis</strong> said he doesn't believe a thief would go to the trouble of cutting off a person's thumb for the sake of an iPhone, especially as there are no guarantees it's the digit they use to unlock the device.</p><p>"Do you really think it to be likely for a common thief to hack a finger off of someone not knowing if it's the correct finger," he asked.</p><p>In short, yes, <strong>Phila</strong> does. "Having been mugged in the past, at knife point, [muggers] have zero compunction in causing physical harm while taking items and money," he explained.</p><p>"It was only my compliance that meant that I wasn't injured, but I know people who have been harmed during muggings. So, would someone remove a finger for a 700 device? Yup, I'm sure they wouldn't have any second thoughts about it."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How secure is Apple's Touch ID? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>One of the few hardware upgrades Apple introduced in the iPhone 5s was Touch ID, a fingerprint scanner built into the home button.</p><p>This allows users to log into the device without having to type a password and enables purchases from theiTunes Store, App Store, and iBooks Store to be authorised.</p><p>There's no doubting Touch ID is more convenient than tapping in a traditional pin number or passcode, but just how secure is it?</p><p><strong>Is Touch ID safer than a 4-digit password?</strong></p><p>Yes. The chances of a stranger guessing a 4-digit pin are 1 in 10,000. These odds reduce dramatically if you know the person. Friends or relatives know important dates such as anniversaries/birthdays, which could be used as a password. Of course it's also easy to look over someone's shoulder and memorise the short 4-digit sequence.</p><p>Because fingerprints are unique to individuals and tangible there's no chance they can be bypassed with guess work you either have the corresponding print or you don't. No two fingerprints are identical, and Apple claims the probability of strangers having fingerprints close enough to bypass its sensor are 1 in 50,000. You only have a maximum of ten attempts to use the fingerprint scanner before it asks you for a password - so the chances of this are slim.</p><div><blockquote><p>On the balance of probabilities Touch ID is five times more secure than the 4-digit pin.</p></blockquote></div><p>However, Touch ID is not impenetrable. German hacking group, Computer Chaos Club showed how to hack the system by replicating a fingerprint. The method is a laborious process - requiring a hacker to lift a fingerprint from a surface, clean it up using graphite power, take a high-res photo with a 2400dpi camera, and print it off at a resolution of 1200dpi onto a plastic or latex material.</p><p>A second way of hacking Touch ID is far easier, but depends on opportunity. Simply wait for the person whose fingerprint you require to fall asleep before gently prodding their finger on the home button. It's crafty and most probably restricted to nosy family members and friends. But it's far more likely to happen than the fake fingerprint method.</p><p><strong>The 6-digit combo</strong></p><p>On the balance of probabilities Touch ID is five times more secure than the 4-digit pin. But what if you up this to a unique 6-digit combination?</p><p>The chances of someone guessing a random 6-digit pin are one in a million in theory - making it 20 times more secure than Touch ID. If you use a 6-character alphanumeric password, the number of possible combinations increases to two billion.</p><p>So what's the takeaway? Touch ID isn't perfect, but it is safer than the 4-digit pin. We see it gaining mass adoption amongst Apple users due to the ease of use. But a combination of 6+ characters is still safe, and Apple hasn't killed off the password completely.</p><p>The iPhone 5s requires users to enter their password every time they reboot, when over48 hourshave elapsedbetween unlocks and when you want to enter the Passcode and Fingerprint setting.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/mobile/20728/how-secure-apples-touch-id</link>
                                                                            <description>
                            <![CDATA[ We pit the fingerprint scanner against the default 4-digit passcode. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">949boP9t8Wify3aKYhfaSJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H9CmS8C8hMKxsmW5iXrrWh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Oct 2013 13:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[iOS]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Apple]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/H9CmS8C8hMKxsmW5iXrrWh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H9CmS8C8hMKxsmW5iXrrWh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>One of the few hardware upgrades Apple introduced in the iPhone 5s was Touch ID, a fingerprint scanner built into the home button.</p><p>This allows users to log into the device without having to type a password and enables purchases from theiTunes Store, App Store, and iBooks Store to be authorised.</p><p>There's no doubting Touch ID is more convenient than tapping in a traditional pin number or passcode, but just how secure is it?</p><p><strong>Is Touch ID safer than a 4-digit password?</strong></p><p>Yes. The chances of a stranger guessing a 4-digit pin are 1 in 10,000. These odds reduce dramatically if you know the person. Friends or relatives know important dates such as anniversaries/birthdays, which could be used as a password. Of course it's also easy to look over someone's shoulder and memorise the short 4-digit sequence.</p><p>Because fingerprints are unique to individuals and tangible there's no chance they can be bypassed with guess work you either have the corresponding print or you don't. No two fingerprints are identical, and Apple claims the probability of strangers having fingerprints close enough to bypass its sensor are 1 in 50,000. You only have a maximum of ten attempts to use the fingerprint scanner before it asks you for a password - so the chances of this are slim.</p><div><blockquote><p>On the balance of probabilities Touch ID is five times more secure than the 4-digit pin.</p></blockquote></div><p>However, Touch ID is not impenetrable. German hacking group, Computer Chaos Club showed how to hack the system by replicating a fingerprint. The method is a laborious process - requiring a hacker to lift a fingerprint from a surface, clean it up using graphite power, take a high-res photo with a 2400dpi camera, and print it off at a resolution of 1200dpi onto a plastic or latex material.</p><p>A second way of hacking Touch ID is far easier, but depends on opportunity. Simply wait for the person whose fingerprint you require to fall asleep before gently prodding their finger on the home button. It's crafty and most probably restricted to nosy family members and friends. But it's far more likely to happen than the fake fingerprint method.</p><p><strong>The 6-digit combo</strong></p><p>On the balance of probabilities Touch ID is five times more secure than the 4-digit pin. But what if you up this to a unique 6-digit combination?</p><p>The chances of someone guessing a random 6-digit pin are one in a million in theory - making it 20 times more secure than Touch ID. If you use a 6-character alphanumeric password, the number of possible combinations increases to two billion.</p><p>So what's the takeaway? Touch ID isn't perfect, but it is safer than the 4-digit pin. We see it gaining mass adoption amongst Apple users due to the ease of use. But a combination of 6+ characters is still safe, and Apple hasn't killed off the password completely.</p><p>The iPhone 5s requires users to enter their password every time they reboot, when over48 hourshave elapsedbetween unlocks and when you want to enter the Passcode and Fingerprint setting.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ iPhone 5s: Can biometrics unlock Apple's enterprise appeal?  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The new iPhone 5s is tipped to popularise the use of biometrics within the smartphone market, but the jury's still out on whether its fingerprint scanning technology will be enough to win over enterprise users.</p><p>After much hype and speculation, the <a href="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives" data-original-url="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives">Apple iPhone 5s</a> was finally unleashed on the world yesterday, alongside a new budget device called the iPhone 5c.</p><p>A full breakdown of the features and technical specifications of both devices and how they differ can be <a target="_blank" href="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives" data-original-url="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives">found here</a>, but one of the standout features of the iPhone 5s was the Touch ID fingerprint scanner.</p><div><blockquote><p>If the iPhone 5s Touch ID feature actually works and is not too gimmicky, like for example Siri, this could be a very interesting feature for the enterprise.</p></blockquote></div><p>iPhone 5s users that enable the setting simply have to press on the device's home screen button, which now features a fingerprint detector around its perimeter, for it to unlock.</p><p>The system can also be used to authorise App Store and iTunes purchases, but for the time being at least can't be used to gain access to people's iCloud stores or Apple KeyChain Passwords.</p><p>During last night's launch event at Apple's Cupertino HQ, the consumer electronics giant assured users their fingerprint data would be encrypted and stored on the iPhone 5s A7 processor, and would not be backed up to its servers or iCloud.</p><p><strong>Privacy protection</strong></p><p>Apple's public declaration that Touch ID fingerprints will be encrypted has prompted several IT security experts to suggest to <em>IT Pro</em> the company is aware that users might take against the technology on privacy grounds.</p><p>Especially as people have much greater awareness of privacy issues these days, in the wake of the recent revelations about the NSA and GCHQ surveillance programmes.</p><p>Speaking to <em>IT Pro</em>, Alexander Hanff, an independent privacy expert, said even with Apple's assurances users should still tread carefully before handing over their fingerprints.</p><p>"They are a US company...so one should assume, if issued with an order under FISA or the Patriot [act] to provide access to the stored fingerprints, they will comply," he said.</p><p>"There is no way we can be certain that this fingerprint data will remain secure and, of course, any order to prevent access to it...would likely come with a gagging order to prevent Apple going public with the information," he added.</p><p><em>IT Pro</em> contacted Apple for clarification on the point above, but had received no response at the time of publication.</p><p><strong>Biometric boost</strong></p><p>Biometric technology has been included on laptops for some time now, but few attempts have been made to incorporate it into smartphones.</p><p>Granted, Motorola had a go in 2011 with its Atrix smartphone, but could Apple's decision to include the functionality boost the adoption of iPhones within the enterprise?</p><p>Bob Tarzey, service director at analyst firm Quocirca, is not convinced, but said biometrics would help tighten up the overall security of the devices.</p><p>This is a point Apple made last night, with its claim that less than half of smartphone users bother to activate passcode protection on their smartphones.</p><p>"[That being said] fingerprint scanners are not infallible, but it would take a lot of effort for a would-be hacker to spoof a given user's fingerprint," he told <em>IT Pro</em>.</p><p>"Any access protection is better than none, providing it is convenient for the user, and at least we always have our fingers with us."</p><p>Anecdotally, iPhones are often flagged as a major carrier of the Bring Your Own Device (BYOD) trend into enterprise environments, but many CIOs are still wary of encouraging their use because of security concerns.</p><p>Alexandre Mesguich, vice president of enterprise research at market watcher Context, said this has the potential to change with the arrival of the iPhone 5s.</p><p>However, enterprise acceptance will hinge on whether users favour the convenience of biometrics over having to input a pin code every time they want to use their phone.</p><p>"If the iPhone 5s Touch ID feature actually works and is not too gimmicky, like for example Siri, this could be a very interesting feature for the enterprise because the constant need to put in a pin to operate a phone can be very irritating," he told <em>IT Pro</em>.</p><p>That may well be the case, but as Tarzey hinted above anyone who thinks a fingerprint-based approach to security will render smartphones impenetrable to hackers could be in for a nasty shock.</p><p>Graham Cluley, an independent IT security expert, told <em>IT Pro</em>: "As soon as the new iPhone 5s falls into the hands of hackers (both whitehat and blackhat), they will begin to look for ways to subvert the technology.</p><p>"Of course, finding a weakness in the system is very different from finding a practical exploit that could be used by criminals in real-life, but any chinks in the armour will be sure to gain the hacker who manages it notoriety," he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/20583/iphone-5s-can-biometrics-unlock-apples-enterprise-appeal</link>
                                                                            <description>
                            <![CDATA[ Apple debuted a fingerprint scanner on its next-gen iPhone, but will this boost its appeal with security conscious CIOs? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mCUFt1kmWH8zMe6gnSLVo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Sep 2013 16:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rspMKVvJ8Fgeo5q2ek64oa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The new iPhone 5s is tipped to popularise the use of biometrics within the smartphone market, but the jury's still out on whether its fingerprint scanning technology will be enough to win over enterprise users.</p><p>After much hype and speculation, the <a href="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives" data-original-url="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives">Apple iPhone 5s</a> was finally unleashed on the world yesterday, alongside a new budget device called the iPhone 5c.</p><p>A full breakdown of the features and technical specifications of both devices and how they differ can be <a target="_blank" href="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives" data-original-url="https://www.itpro.com/mobile/20240/iphone-5s-iphone-5c-release-date-finally-arrives">found here</a>, but one of the standout features of the iPhone 5s was the Touch ID fingerprint scanner.</p><div><blockquote><p>If the iPhone 5s Touch ID feature actually works and is not too gimmicky, like for example Siri, this could be a very interesting feature for the enterprise.</p></blockquote></div><p>iPhone 5s users that enable the setting simply have to press on the device's home screen button, which now features a fingerprint detector around its perimeter, for it to unlock.</p><p>The system can also be used to authorise App Store and iTunes purchases, but for the time being at least can't be used to gain access to people's iCloud stores or Apple KeyChain Passwords.</p><p>During last night's launch event at Apple's Cupertino HQ, the consumer electronics giant assured users their fingerprint data would be encrypted and stored on the iPhone 5s A7 processor, and would not be backed up to its servers or iCloud.</p><p><strong>Privacy protection</strong></p><p>Apple's public declaration that Touch ID fingerprints will be encrypted has prompted several IT security experts to suggest to <em>IT Pro</em> the company is aware that users might take against the technology on privacy grounds.</p><p>Especially as people have much greater awareness of privacy issues these days, in the wake of the recent revelations about the NSA and GCHQ surveillance programmes.</p><p>Speaking to <em>IT Pro</em>, Alexander Hanff, an independent privacy expert, said even with Apple's assurances users should still tread carefully before handing over their fingerprints.</p><p>"They are a US company...so one should assume, if issued with an order under FISA or the Patriot [act] to provide access to the stored fingerprints, they will comply," he said.</p><p>"There is no way we can be certain that this fingerprint data will remain secure and, of course, any order to prevent access to it...would likely come with a gagging order to prevent Apple going public with the information," he added.</p><p><em>IT Pro</em> contacted Apple for clarification on the point above, but had received no response at the time of publication.</p><p><strong>Biometric boost</strong></p><p>Biometric technology has been included on laptops for some time now, but few attempts have been made to incorporate it into smartphones.</p><p>Granted, Motorola had a go in 2011 with its Atrix smartphone, but could Apple's decision to include the functionality boost the adoption of iPhones within the enterprise?</p><p>Bob Tarzey, service director at analyst firm Quocirca, is not convinced, but said biometrics would help tighten up the overall security of the devices.</p><p>This is a point Apple made last night, with its claim that less than half of smartphone users bother to activate passcode protection on their smartphones.</p><p>"[That being said] fingerprint scanners are not infallible, but it would take a lot of effort for a would-be hacker to spoof a given user's fingerprint," he told <em>IT Pro</em>.</p><p>"Any access protection is better than none, providing it is convenient for the user, and at least we always have our fingers with us."</p><p>Anecdotally, iPhones are often flagged as a major carrier of the Bring Your Own Device (BYOD) trend into enterprise environments, but many CIOs are still wary of encouraging their use because of security concerns.</p><p>Alexandre Mesguich, vice president of enterprise research at market watcher Context, said this has the potential to change with the arrival of the iPhone 5s.</p><p>However, enterprise acceptance will hinge on whether users favour the convenience of biometrics over having to input a pin code every time they want to use their phone.</p><p>"If the iPhone 5s Touch ID feature actually works and is not too gimmicky, like for example Siri, this could be a very interesting feature for the enterprise because the constant need to put in a pin to operate a phone can be very irritating," he told <em>IT Pro</em>.</p><p>That may well be the case, but as Tarzey hinted above anyone who thinks a fingerprint-based approach to security will render smartphones impenetrable to hackers could be in for a nasty shock.</p><p>Graham Cluley, an independent IT security expert, told <em>IT Pro</em>: "As soon as the new iPhone 5s falls into the hands of hackers (both whitehat and blackhat), they will begin to look for ways to subvert the technology.</p><p>"Of course, finding a weakness in the system is very different from finding a practical exploit that could be used by criminals in real-life, but any chinks in the armour will be sure to gain the hacker who manages it notoriety," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>