<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/encryption"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Encryption ]]></title>
                <link>https://www.itpro.com/uk/security/encryption</link>
        <description><![CDATA[ All the latest encryption content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Tue, 17 Feb 2026 12:56:51 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company responded ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/researchers-called-on-lastpass-dashlane-and-bitwarden-to-up-defenses-after-severe-flaws-put-60-million-users-at-risk-heres-how-each-company-responded</link>
                                                                            <description>
                            <![CDATA[ Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NfFxTg6XRsaJYwtUPGvTad</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Feb 2026 12:56:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/368049/best-password-managers-for-business">Password managers</a> may not be as secure as many assume, with researchers uncovering multiple attack vectors across three popular systems serving 60 million users. </p><p>Security researchers from ETH Zurich studied the architecture of Bitwarden, <a href="https://www.itpro.com/security/phishing/lastpass-issues-alert-as-customers-targeted-in-new-phishing-campaign">LastPass</a>, and <a href="https://www.itpro.com/software/368031/lastpass-vs-dashlane">Dashlane</a>, which between them hold 23% of the password manager market. </p><p>The researchers demonstrated 12 attacks that would work on <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a>, seven on LastPass, and six on Dashlane, prompting calls for each to bolster defense capabilities.</p><p>“We were surprised by the severity of the security vulnerabilities,” said Kenneth Paterson, Professor of Computer Science at ETH Zurich, in a <a href="https://ethz.ch/en/news-and-events/eth-news/news/2026/02/password-managers-less-secure-than-promised.html" target="_blank"><u>blog post</u></a> from ETH Zurich. </p><p>The study focused on password manager claims that they use "zero-knowledge encryption," which means the companies don't know what users have stored. </p><p>"The promise is that even if someone is able to access the server, this does not pose a security risk to customers because the data is encrypted and therefore unreadable," said ETH Zurich researcher Matilda Backendal. "We have now shown that this is not the case."</p><h2 id="testing-password-managers">Testing password managers</h2><p>To test security capabilities, researchers set up their own servers that would act as though they were hacked password manager servers. They found they could alter passwords, access vaults, and more. </p><p>The study revealed "strange code architecture" that PhD student Matteo Scarlata attributed to the companies trying to improve ease-of-use for customers, such as offering password recovery or account sharing, as well as using out-of-date cryptography for accessibility. </p><p>"As a result, the code becomes more complex and confusing, and it expands the potential attack surface for hackers," Scarlata said. </p><p>Researchers urged password manager providers to use the most up-to-date cryptographic standards for all new customers, while existing customers could be offered the chance to migrate to updated systems or stick with older, compatible ones – providing they’re informed of the potential risks. </p><p>“We want our work to help bring about change in this industry,” Paterson said. “The providers of password managers should not make false promises to their customers about security but instead communicate more clearly and precisely what security guarantees their solutions actually offer.” </p><h2 id="industry-response">Industry response</h2><p><em>ITPro </em>contacted each of the companies for comment, but did not receive a response by time of publication. </p><p>However, all three have already published blog posts addressing the paper and issued fixes for the addressable flaws and used hardening measures for other concerns, thanking the researchers for their efforts. </p><p>Dashlane said the methodology was "useful", though <a href="https://bitwarden.com/blog/security-through-transparency-eth-zurich-audits-bitwarden-cryptography/" target="_blank"><u>Bitwarden also noted</u></a> that the server-takeover scenario has never hit any password management product as far as it's aware. </p><p>Dashlane and LastPass stressed that there was no evidence that these flaws had been exploited as yet; Bitwarden added it has never suffered any security breach. </p><p>"Customers should continue using LastPass as normal," <a href="https://blog.lastpass.com/posts/details-on-hardening-in-response-to-eth-zurich-reported-security-issues" target="_blank"><u>LastPass noted</u></a>. "To continue to receive the best possible secure access experience, we always recommend that users check to ensure they are up-to-date and using the latest version of our browser extensions and apps."</p><p>Both companies noted they were selected by the researchers because their source code is publicly available. "We made that choice intentionally," Dashlane said in its <a href="https://www.dashlane.com/blog/zero-knowledge-malicious-server">blog post</a>. </p><p>"Transparency makes it easier for third parties to inspect our design and hold us accountable. Security improves when systems are open to review."</p><h2 id="fixing-the-flaws">Fixing the flaws</h2><p>Dashlane explained that it fixed an issue that allowed the use of legacy cryptography to enable backwards compatibility and migration flexibility that could have allowed the injection of code into a secure vault, weakening the encryption that protects keys and user data.</p><p> "It’s important to note that the exploitation of this issue would require full compromise of a password manager’s servers, paired with a highly sophisticated threat actor able to execute cryptographic attacks, and an extremely significant window of time," Dashlane added.</p><p>Dashlane added that two other attack vectors detailed in the report relate to wider architectural issues that are well known in the encryption community, namely public key authenticity in sharing and transaction-based synchronization. </p><p>The password manager firm noted it – and indeed the wider industry – were well aware of both concerns, and had built in additional protections with that in mind. </p><p>"Public key authentication at scale is a known challenge that we as an industry must solve," the post added. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move on ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on</link>
                                                                            <description>
                            <![CDATA[ Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S55GqKG3G2ceQEqEiFxHBQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pFTNqcPFFbbtsAPcxQXvMi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Jan 2026 11:20:00 +0000</pubDate>                                                                                                                                <updated>Thu, 22 Jan 2026 11:57:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pFTNqcPFFbbtsAPcxQXvMi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing and quantum security concept image showing digitized cube with binary code protected by overlapping defensive layer.]]></media:description>                                                            <media:text><![CDATA[Quantum computing and quantum security concept image showing digitized cube with binary code protected by overlapping defensive layer.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing and quantum security concept image showing digitized cube with binary code protected by overlapping defensive layer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pFTNqcPFFbbtsAPcxQXvMi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The vast majority of companies aren't ready for the security threats posed by <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a>, according to new research. </p><p>Analysis from <a href="https://www.bain.com/insights/how-businesses-can-prepare-for-post-quantum-cybersecurity-threats/" target="_blank"><u>Bain & Company</u></a>, which surveyed technology leaders at 180 companies, found 90% didn't yet have systems in place to defend against quantum security threats – despite widely expecting them to arrive within the next five years. </p><p>When quantum computers do arrive, they're expected to be able to crack existing encryption techniques used to protect everything from email to financial transactions. </p><div class="product"><a data-dimension112="aec7638d-861e-46b6-8d82-fc189970f922" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="aec7638d-861e-46b6-8d82-fc189970f922" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="aec7638d-861e-46b6-8d82-fc189970f922" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>The US National Institute of Standards and Technology (NIST) has been working for a decade on <a href="https://www.itpro.com/security/nist-aims-to-quantum-proof-encryption-with-new-algorithms"><u>new algorithms that can withstand such attacks</u></a> – but now companies need to roll them out, with NIST advising <a href="https://www.itpro.com/business/get-started-on-post-quantum-encryption-organizations-warned"><u>enterprises need to be ready by 2035</u></a>. </p><p>That message has been heard, according to Bain. Nearly three-quarters (71%) of those surveyed expect quantum-enabled attacks within five years, with a third predicting them within three years. </p><p>Similarly, two thirds believe quantum computing will exacerbate <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>challenges. </p><p>Yet despite that just one-in-ten believe their existing safeguards will be enough. The same number of enterprises have a roadmap in place to address the risks, with most waiting to see what happens and hoping a third party solves the problem first. </p><h2 id="no-time-to-wait-with-quantum-security">No time to wait with quantum security</h2><p>Companies shouldn't wait, Bain warned, pointing to rapid progress made by IBM, Google, and other industry leaders on this front.</p><p>"At a certain threshold, quantum computing will be able to easily and quickly break asymmetric cryptography protocols such as Rivest-Shamir-Adelman (RSA), Diffie-Hellman (DH), and <a href="https://www.itpro.com/security/rsac-in-focus-quantum-computing-and-security">elliptic-curve cryptography</a> (ECC) and reduce the time required, weakening symmetric cryptography such as <a href="https://www.itpro.com/security/29671/what-is-aes-encryption">advanced encryption standard (AES)</a> and hashing functions," the company noted in a <a href="https://www.bain.com/insights/how-businesses-can-prepare-for-post-quantum-cybersecurity-threats/" target="_blank"><u>blog post</u></a>.</p><p>In a separate report, analysts from Juniper Research echoed concerns that too many businesses still underestimate the danger of quantum-enabled attacks and aren't doing enough to get ready. </p><p>This is a burgeoning market, the consultancy found, with analysts predicting the post-quantum cryptography market will grow from $1.2 billion this year to $13 billion by 2035. </p><p>That growth suggests progress in preparing for what the analyst firm has dubbed "Q-Day" – which they define as when quantum computers can compromise existing encryption.</p><p>Juniper Research noted that governments are clearly considering milestones, as are "forward-thinking organizations". However, awareness of the danger remains a serious hurdle. </p><p>“Many businesses still underestimate the risk of quantum-enabled attacks; making clearer, more accessible education critical to securing internal buy-in,” said Louis Atkin, Research Analyst at Juniper Research. </p><p>That echoes <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>previous research by KeyFactor</u></a>, which found as many as half of companies are not yet prepared to deal with cryptography made obsolete by the arrival of quantum computing.  </p><h2 id="the-risks-of-quantum-decryption">The risks of quantum decryption</h2><p>Bain said quantum computing will render today's cryptographic standards obsolete. </p><p>The highest impact will be on secure keys and tokens, digital certificates, authentication protocols, data encrypted at rest, and even network security and <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity access management (IAM)</a> tools. Essentially, anything currently relying on encryption. </p><p>Beyond that, quantum computing could supercharge malware and make it easier to identify and weaponize "zero day" flaws, Bain warned. </p><p>Another risk highlighted by security experts is <em>"</em><a href="https://www.itpro.com/security/cyber-security/370298/what-is-steal-now-crack-later-quantum-computing"><u><em>steal now, crack later</em></u></a><em>"</em> techniques, whereby threat actors harvest data now to decrypt later. </p><p>"Beyond these new types of attacks powered by quantum computers on current controls, terabytes of sensitive data already harvested by nation states and criminal groups over the last several years – spanning defense designs, chip architectures, energy technologies, and state secrets – will also become accessible and exploitable," Bain noted. </p><h2 id="what-can-be-done">What can be done? </h2><p>To prepare, companies should roll out post-quantum cryptography using algorithms that are strong enough to withstand quantum-powered attacks, Bain noted. Companies that fail to do so risk "exposing decades of encrypted data and compromising real-time systems”. </p><p>However, the consultancy noted that most existing algorithms designed for that post-quantum world have already been compromised – without quantum computers, but using traditional exploit flaws. </p><p>Notably, not all suppliers or vendors will be on top of the problem, so security teams will need to develop their own workarounds to keep the corporate stack safe. </p><p>"Organizations that are heavy with legacy infrastructure may be particularly vulnerable—and more attractive targets for attackers," Bain added. </p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/b9cead78-7b3a-4caa-b7a4-2311070dc88c/"></iframe><p>Companies need a board-led – and funded – roadmap to consider post-quantum risks across their business decision making, ensuring quantum resilience across their own suppliers, existing technology, and even their products. </p><p>But so far, the Bain survey revealed only 12% of companies are considering quantum readiness as a key factor in procurement and risk assessments. </p><p>Juniper's Atkin noted that the rise of standards and regulations around post-quantum security has helped, <a href="https://www.itpro.com/security/368469/us-unveils-encryption-tools-to-withstand-quantum-computer-attack"><u>notably from NIST</u></a>, and investment in algorithms for encryption once Q-Day has passed is steadily increasing.</p><p>However, Juniper warned that for these technologies to be effectively adopted, organizations will need to collaborate to ensure interoperability across infrastructure – and borders. </p><p>"Many countries have accepted NIST’s standardized algorithms as the de facto quantum-safe option, even in nations with limited understanding of the quantum landscape," Atkin said. "It is vital this continues and that different sectors consider how their systems interoperate when implementing quantum-safe solutions."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The encryption stand-off is getting weirder ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/the-encryption-stand-off-is-getting-weirder</link>
                                                                            <description>
                            <![CDATA[ Opinion: Governments have the powers they said they wanted, so why won’t they use them? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4EQAcoPGptypXeuFvab7To</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F5jbQ94fiAvpvpf9CQoxAB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 May 2024 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 07 May 2024 14:34:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Ranger ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gFeXmAxutpTpGN7c98ZAwJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F5jbQ94fiAvpvpf9CQoxAB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital eye made of CGI fibers, representing encryption.]]></media:description>                                                            <media:text><![CDATA[A digital eye made of CGI fibers, representing encryption.]]></media:text>
                                <media:title type="plain"><![CDATA[A digital eye made of CGI fibers, representing encryption.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F5jbQ94fiAvpvpf9CQoxAB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you’ve ever wanted to see a real-world example of what happens when an unstoppable force meets an immovable object, you need only look at the stand-off between the tech industry and government over encryption.</p><p>In April 2024, European police have again warned that the rollout of <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it"><u>end-to-end encryption (E2EE)</u></a> is making it <a href="https://www.itpro.com/security/privacy/euro-police-chiefs-rekindle-end-to-end-encryption-battle-amid-continued-rollouts"><u>harder to investigate crime</u></a> and keep people safe. Tech companies, for their part, have insisted that the rollout of the technology is essential to keeping consumers safe and are in no mood to back down.</p><p>How did we get here? It’s a long story.</p><p>It used to be relatively easy for police to access emails or other communications they deemed necessary to their investigations. That’s because, while emails might be <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a> as they travel across the internet, they were also usually stored by the tech company providing the service in a way that the authorities could access. </p><p>The trouble is that – as was revealed a few years ago – many spy agencies around the world saw this rather trusting setup as an excellent opportunity to quietly scoop up as much data as they could, about everyone. And so, of course, they did just that. </p><p>Not everyone was happy about that, for understandable reasons. </p><p>This led to the introduction of E2EE by many tech companies. Once a message is protected in this way, it cannot be read by anyone until it arrives at the other end. There’s no database in the middle that tech companies can be made to hand over to the police, or that spy agencies and their hackers can target.</p><p>While this is good news for privacy, it’s bad news for law enforcement which continues to argue that poring over these messages is a necessary step to preventing crimes from being plotted or carried out.</p><p>We find ourselves in a tricky situation. User messages are largely safe from snooping due to E2EE and all the while police worry more about the fact that they can’t see everything they’d like to anymore. They argue for E2EE to be rolled back or somehow modified, so they can gain access through <a href="https://www.itpro.com/security/encryption/357390/five-eyes-nations-demand-encryption-backdoors-by-design">encryption &apos;backdoors&apos; by design</a>. </p><p>That’s led to a row between governments and police on one side, and tech companies and privacy campaigners on the other. As one has pushed, the other has responded – for example, the E2EE messaging app <a href="https://www.itpro.com/security/encryption/355956/signal-app-use-surges-as-protests-spread"><u>Signal saw a surge in users</u></a> during a parallel rise in protests across the US and Europe in 2020.</p><h2 id="no-right-answer-on-encrypted-safety-xa0">No right answer on encrypted safety </h2><p>What’s difficult about the encryption debate is that both sides see their actions as the ‘right thing’ to do. The government and the police are right: we cannot allow criminals to communicate in secret, with apps such as <a href="https://www.itpro.com/security/cyber-crime/telegrams-popularity-continues-to-soar-as-catalog-of-available-cyber-crime-services-matures">Telegram known to be  popular among cyber criminals</a>.</p><p>And yet, the privacy campaigners are right too. We cannot undermine the security of online communications simply so that police can comb through every message we send and many criminal communities rely on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> rather than <a href="https://www.itpro.com/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps">encrypted messaging apps</a>.</p><p>That’s your immovable object and your irresistible force. None of this is to say the police and governments haven’t suggested a way forward (or rather, back). The trouble is, everything they suggest inevitably weakens security for everyone all over again.</p><p>For example, so-called <a href="https://www.itpro.com/security/privacy/explained-the-state-of-end-to-end-encryption-in-the-uk-now-the-online-safety-bill-saga-is-over"><u>client-side scanning</u></a> would see tech companies adding features to effectively scan every image or every message for suspicious behavior before it was encrypted and sent. This neatly sidesteps the issue of breaking encryption, but introduces another problem by introducing a government-mandated scan of every message you send. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tkhgeudyCtXxUFiFfUfMLZ" name="Security operations use case guide (1).jpg" caption="" alt="man with brown jacket sitting on bench" src="https://cdn.mos.cms.futurecdn.net/tkhgeudyCtXxUFiFfUfMLZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-operations-use-case-guide"><em>Improve your cyber resilience </em></a></p></div></div><p>It’s not exactly hard to see how various global regimes could tweak the scan requirements to create an excellent way to crack down on protest.</p><p>Some governments have already enacted laws to force tech companies to provide their customers’ messages, regardless of whether they are E2EE or not. The strange part is governments don’t seem willing or able to use it. </p><p>In the UK, for example, the <a href="https://www.itpro.com/business/policy-and-legislation/online-safety-act-slammed-by-rights-groups-as-bill-gains-royal-assent"><u>Online Safety Act</u></a> effectively empowers the government to compel tech companies to hand over specific messages. But this can only be done without degrading the security of others, a feat the government itself has acknowledged is – at least for now – technically impossible.</p><p>Beyond the philosophical considerations, there is the harder reality. There are a small number of tech companies who are, in this situation at least, more powerful than governments. </p><p>If any government ordered them to remove E2EE there would likely be three main consequences.</p><p>First, most companies would stop providing services in that country. The encrypted messaging firm <a href="https://www.itpro.com/security/encryption/355294/messaging-app-signal-may-pull-out-of-us-if-encryption-bill-passes">Signal threatened to leave the US</a> in 2020, as it added its voice to opposition of the US <a href="https://www.itpro.com/business-strategy/public-sector/354836/encryption-under-threat-from-earn-it-act">EARN IT Act</a>, which is similar in scope to the Online Safety Bill. But who wants to be the politician explaining why voters suddenly can’t contact their friends or colleagues anymore? </p><p>Second, that country would become one of the least secure places to do business online, with customers offered no legal avenue for completely secure messaging – hardly a claim that any government wants to make. Third, it would make it a lot easier for various regimes to make similar demands to crack down on dissent. </p><p>As a result, we are left in a weird situation, with police and governments warning about encryption but not wanting to do anything about it.</p><p>The government has a power it likely doesn&apos;t want to enforce. Police are losing access to the intelligence that helps them do the job of keeping us all safe. Tech companies will <a href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">continue to add strong encryption</a> because it’s now a standard feature for many. </p><h2 id="the-future-for-encrypted-messages-is-uncertain">The future for encrypted messages is uncertain</h2><p>Perhaps chats with your distant relatives don’t really need <a href="https://www.itpro.com/security/privacy/369840/what-are-privacy-enhancing-technologies-pets">state-of-the-art privacy tech</a>. Others would argue we’ve already lost so much privacy in the information age that this small island of privacy is worth defending.</p><p>Either way, we’re unlikely to see the tech industry backing down on encryption, and in reality, there is little political will to force the matter. For now, it’s hard to know what would persuade tech users to give up on additional security, and even harder to know what would make tech companies change direction. Expect more broadsides against the tech industry, but little real action. </p><p>But now we know, at least, what happens when an unstoppable force meets an immovable object: a messy stalemate that serves nobody well.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The quantum security quandary ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/the-quantum-security-quandary</link>
                                                                            <description>
                            <![CDATA[ Businesses need to get ‘crypto-agile’ to win the quantum arms race ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MFswdNNckF3kERDDd7fWeX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KNNxDnap9j7KANbvetxe9N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jun 2023 10:37:35 +0000</pubDate>                                                                                                                                <updated>Fri, 09 Jun 2023 12:29:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KNNxDnap9j7KANbvetxe9N-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The words &#039;The quantum security quandry with ‘quantum security’ highlighted in yellow and the other words in white, against a lightly-blurred render of purple, green, and blue digital waves composed of tiny triangles.]]></media:description>                                                            <media:text><![CDATA[The words &#039;The quantum security quandry with ‘quantum security’ highlighted in yellow and the other words in white, against a lightly-blurred render of purple, green, and blue digital waves composed of tiny triangles.]]></media:text>
                                <media:title type="plain"><![CDATA[The words &#039;The quantum security quandry with ‘quantum security’ highlighted in yellow and the other words in white, against a lightly-blurred render of purple, green, and blue digital waves composed of tiny triangles.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KNNxDnap9j7KANbvetxe9N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Quantum computing is an inevitable technology, with the private sector and nation-states racing to be the first to unlock its potential. While it can be used for all kinds of good, quantum computing could also be used to unravel critical systems.</p><p>One of the most common ways to protect data is to encrypt it using an RSA algorithm. In simple terms, it relies on the fact that while you can easily multiply one prime number by another, it’s very hard to work out prime factors from any given number. Quantum computing could make this much easier, allowing criminals to decrypt sensitive data.</p><p>The UK is among a number of nations investing in quantum computing, with the government having recently announced £900 million for exascale quantum computer. Stakes are high as we enter into what some have dubbed a ‘quantum arms race’, with the first to successfully crack encryption holding all the cards when it comes to its myriad use cases.</p><p>In this episode, Rory and Jane speak to Tim Callan, chief experience officer at cyber security firm Sectigo, about the current state of quantum computing research and how the industry can prepare for this seismic shift.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=54147270&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights">Highlights</h2><p>“Think about those industrial secrets that, let&apos;s say, another nation-state might want to take away. Think about those military secrets, think about the plans for the stealth fighter. Those are the things that are very, very valuable. And those are the things that we need to worry about most immediately.”</p><p>“When I talk to people about this, I often say quantum computers are no longer a science project, they are now an engineering project. And what I mean by that is there&apos;s no question that it will work, and it will be commercially viable, and it will be practical. It&apos;s just about figuring out how to really get them all tuned in the way we want them.”</p><p>“What you should be doing now is you should be making yourself crypto-agile. Which means you have the ability to change your cryptography as needed at will. And there are a few steps for crypto agility. One of them is inventory or cryptography. Amazingly, most enterprises can&apos;t even tell you what cryptography they have implemented, where it is, how it&apos;s being used, whether or not it meets current standards.”</p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/technology/31818/what-is-quantum-computing"><u>What is quantum computing?</u></a></li><li><a href="https://www.itpro.com/security/cyber-security/370298/what-is-steal-now-crack-later-quantum-computing"><u>What is the ‘steal now, crack later’ quantum computing threat?</u></a></li><li><a href="https://www.itpro.com/policy-legislation/370266/2023-spring-statement-enhanced-tax-incentives-tech-smbs"><u>2023 Spring Statement brings 'enhanced' tax incentives to tech SMBs</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/dell-cto-ai-nothing-compared-to-the-oncoming-quantum-storm"><u>Dell CTO: AI is nothing compared to the oncoming quantum storm</u></a></li><li><a href="https://www.itpro.com/business/370374/skills-shortages-pose-threat-uks-quantum-ambitions"><u>Skills shortages could pose threat to UK’s quantum ambitions</u></a></li><li><a href="https://www.itpro.com/server-storage/high-performance-computing-hpc/370251/uk-startup-equinix-deal-broad-quantum-computing-access"><u>UK startup's Equinix deal marks step towards broad quantum computing access</u></a></li><li><a href="https://www.itpro.com/technology/369845/how-quantum-computing-can-fight-climate-change"><u>How quantum computing can fight climate change</u></a></li></ul><h2 id="subscribe">Subscribe</h2><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M"><u>Subscribe to The IT Pro Podcast on Google Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://www.itpro.co.uk/magazine-signup"><u>Subscribe to IT Pro 20/20</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Authenticator 2FA update accused of making service less secure ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/google-authenticator-2fa-update-accused-of-making-service-less-secure</link>
                                                                            <description>
                            <![CDATA[ Lack of end-to-end encryption in code backup has some developers worried ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WF83vCXzFWVzxLwArKvMNA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/W2wsfffmSmFeevSSUALCiU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Apr 2023 10:54:32 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Apr 2023 15:54:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/W2wsfffmSmFeevSSUALCiU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Authenticator logo, which is a grey &#039;G&#039; stylized to look like a tumbler lock]]></media:description>                                                            <media:text><![CDATA[Google Authenticator logo, which is a grey &#039;G&#039; stylized to look like a tumbler lock]]></media:text>
                                <media:title type="plain"><![CDATA[Google Authenticator logo, which is a grey &#039;G&#039; stylized to look like a tumbler lock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/W2wsfffmSmFeevSSUALCiU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new update for the Google Authenticator app has drawn criticism from developers for allegedly opening users up to privacy and security violations.</p><p>Earlier this week, Google rolled out an update for Android and iOS allowing users to back up their one-time authentication codes to the cloud, but researchers have noted that the network traffic for this process is not end-to-end encrypted.</p><p>Security researcher and programmer duo, speaking from the single online handle of Mysk, alleged that without proper encryption, users’ <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>two-factor authentication (2FA)</u></a> secrets could be viewed by Google or potentially accessed by threat actors.</p><p>“Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes,” the researchers <a href="https://twitter.com/mysk_co/status/1651021165727477763" target="_blank"><u>tweeted</u></a>.</p><p>“If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access to your Google Account, all of your 2FA secrets would be compromised.”</p><p>Mysk also stated that as 2FA <a href="https://www.itpro.com/marketing-comms/qr-codes/360864/are-qr-codes-safe"><u>QR codes</u></a> contain data relating to the name of the service to which they relate, Google could access this data to serve users <a href="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation"><u>personalized ads</u></a>.</p><p>Security analyst Graham Cluely echoed Mysk’s findings, <a href="https://twitter.com/gcluley/status/1651101156817489920" target="_blank"><u>saying</u></a> “you shouldn&apos;t enable the feature as Google hasn&apos;t implemented it in a way that properly defends your security”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qWsVUmLpRdEkf8fyizCyRM" name="Why MFA, why now_thumb.jpg" caption="" alt="Webinar screen with host image top right and centre image of man using a smartphone surrounded by brand logos including Salesforce" src="https://cdn.mos.cms.futurecdn.net/qWsVUmLpRdEkf8fyizCyRM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Why MFA? Why now?</strong></p><p class="fancy-box__body-text"><em>A discussion with Okta and Salesforce on the new MFA requirement</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/why-mfa-why-now"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The feature has been long requested, and Google said it has added it in acknowledgment of the frustration some users felt with one device being tied to crucial accounts.</p><p>“One major piece of feedback we’ve heard from users over the years was the complexity in dealing with lost or stolen devices that had Google Authenticator installed,” wrote Christiaan Brand, group product manager at Google in a <a href="https://security.googleblog.com/2023/04/google-authenticator-now-supports.html" target="_blank"><u>blog post</u></a>.</p><p>“Since one-time codes in Authenticator were only stored on a single device, a loss of that device meant that users lost their ability to sign in to any service on which they’d set up 2FA using Authenticator.”</p><p>With the new update, users will be able to access one-time codes again on a new phone once they have signed into the Authenticator app using their Google account.</p><p>Google Authenticator will automatically backup codes to the cloud, though users are able to use the app without a Google account.</p><p>Microsoft had already allowed cloud backups on Microsoft Authenticator, and its <a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/how-it-works-backup-and-restore-for-microsoft-authenticator/ba-p/1006678" target="_blank"><u>documentation page</u></a> has outlined the extent to which keys sent to the cloud are encrypted with <a href="https://www.itpro.com/security/29671/what-is-aes-encryption"><u>AES-256</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Some GitHub users must take action after RSA SSH host key exposed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370326/some-github-users-must-take-action-after-rsa-ssh-host-key-exposed</link>
                                                                            <description>
                            <![CDATA[ One cloud security expert likened the incident to the infamous HeartBleed bug from 2014 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r9BrN3q45JJ2DDdXCDKnSJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CxxHUnTvnCRzAQoWc6MqDo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Mar 2023 12:03:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CxxHUnTvnCRzAQoWc6MqDo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The GitHub sign in screen on a smartphone]]></media:description>                                                            <media:text><![CDATA[The GitHub sign in screen on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[The GitHub sign in screen on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CxxHUnTvnCRzAQoWc6MqDo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Some GitHub users will have to make changes to their terminal code after the platform replaced its RSA SSH host key after it was exposed.</p><p>The key was only "briefly exposed" in a public GitHub repository, it said, but took the measure to replace the key "out of an abundance of caution".</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/370307/github-launches-copilot-x-gpt-4-features" data-original-url="/technology/artificial-intelligence-ai/370307/github-launches-copilot-x-gpt-4-features">GitHub launches latest version of Copilot with GPT-4-powered features</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370298/what-is-steal-now-crack-later-quantum-computing" data-original-url="/security/cyber-security/370298/what-is-steal-now-crack-later-quantum-computing">What is the ‘steal now, crack later’ quantum computing threat?</a></p></div></div><p>Mike Hanley, CSO and SVP of engineering at GitHub, assured users that GitHub’s systems haven’t been compromised, but that the key was exposed due to “an inadvertent publishing of private information”.</p><p>“We did this to protect our users from any chance of an adversary impersonating GitHub or eavesdropping on their Git operations over SSH,” Hanley said in a <a href="http://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key">blog post</a>.</p><p>“This key does not grant access to GitHub’s infrastructure or customer data. This change only impacts Git operations over SSH using RSA. Web traffic to GitHub.com and HTTPS Git operations are not affected.”</p><p>Secure Shell (SSH) keys are used in the SSH protocol as an access credential. It allows users to securely access network resources, including servers, and use them as if they were local machines.</p><p>Host keys are unique to each SSH client and if one was stolen and then abused, attackers could perform man in the middle (MITM) attacks to access user passwords or execute commands.</p><p>GitHub said that only the RSA <a href="https://www.itpro.com/security/cyber-security/359457/what-are-ssh-keys" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/359457/what-are-ssh-keys">SSH key</a> was replaced, and users who rely on ECDSA or Ed25519 keys don’t need to make any changes.</p><p>However, GitHub users who see the message “WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!” when connecting to <a href="https://www.itpro.com/software/development/359246/how-to-download-from-github" target="_blank" data-original-url="https://www.itpro.com/software/development/359246/how-to-download-from-github">GitHub.com</a> through SSH will have to make some changes.</p><p>Users need to remove the old SSH key by running the command '$ ssh-keygen -R github.com'.</p><p>Alternatively, they can also update their ~/.ssh/known_hosts file manually to get rid of the old key, and add the new one by inserting a new line that can be found in the company’s blog post.</p><p>Another method users can deploy is automatically updating the key in their ~/.ssh/known_hosts by running specific code in their terminal, which can also be found on GitHub’s blog post.</p><p>“This is maybe as bad as <a href="https://www.itpro.com/security/22101/heartbleed-bug-everything-you-need-to-know" data-original-url="https://www.itpro.com/security/22101/heartbleed-bug-everything-you-need-to-know">Heartbleed</a>,” said Daniel Feldman, cloud security architect for HPE on Twitter. </p><p>"Everything was exposed, across many platforms and services, retroactively going back some period of time (we’re not sure how long yet).</p><p>“Like Heartbleed, it will be very difficult to prove whether or not someone actually used the exploit. They just might have.”</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1639152037307744258"></a></p></blockquote><div class="see-more__filter"></div></div><p>Heartbleed was a security bug introduced into the OpenSSL cryptography library in 2012 but only disclosed in 2014. The vulnerability allowed potential hackers to read the memory of websites affected with the bug, opening the possibility for cyber criminals to discover encryption keys.</p><p>In October 2021, GitHub <a href="https://www.itpro.com/security/cyber-security/361207/github-revokes-duplicate-ssh-auth-keys-generated-by-keypair-library" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/361207/github-revokes-duplicate-ssh-auth-keys-generated-by-keypair-library">revoked all</a> SSH keys used in its GUI client GitKraken after it discovered that the software client was generating weak SSH keys.</p><p>GitKraken disclosed the flaw, detailing that weak keys could lead to a higher probability of key duplication. GitHub notified users whose keys had been revoked, and recommended developers to review SSH keys linked to GitHub accounts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the ‘steal now, crack later’ quantum computing threat? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/370298/what-is-steal-now-crack-later-quantum-computing</link>
                                                                            <description>
                            <![CDATA[ The rise in quantum computing this decade is pushing cyber criminals into stealing encrypted business data with the hopes of cracking it in the future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c6DuTXmrzwHXehqyWNrLbp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yJFJgavypp9fVdfpQShr9N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Mar 2023 10:24:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yJFJgavypp9fVdfpQShr9N-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of encrypted data on a screen]]></media:description>                                                            <media:text><![CDATA[An image of encrypted data on a screen]]></media:text>
                                <media:title type="plain"><![CDATA[An image of encrypted data on a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yJFJgavypp9fVdfpQShr9N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The capabilities of quantum computing have been rapidly developing over the last decade, and are expected to mature over the next. By 2030, in fact, the industry widely expects commercial quantum computing offerings to be available in the mainstream. </p><p>While the business use cases of <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing" target="_blank" data-original-url="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> are being contemplated, so too has the advent of this technology piqued the interest of cyber criminals who now prefer to retain – rather than discard – heavily <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted data</a> where possible. These groups are embracing the idea of ‘steal now, crack later’, which involves harvesting and storing encrypted data until quantum computing gives them the tools to access the information. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/31818/what-is-quantum-computing" data-original-url="/technology/31818/what-is-quantum-computing">What is quantum computing?</a></p></div></div><p>Although the <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> industry doesn’t expect cyber gangs to get access to powerful quantum computers next week, or even next month, businesses must begin preparing for the prospect of these machines one day cracking the encrypted data they hold dear today.</p><h2 id="how-long-will-your-data-remain-secure">How long will your data remain secure? </h2><p>A <a href="http://gartner">recent Gartner report</a> noted the Rivest-Shamir-Adelman (RSA) <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" target="_blank" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithm</a> has been used in almost every aspect of security over the last 30 years, but that key cracking is one of the small set of mathematically approachable problems quantum computing can solve.</p><p>“Quantum computers are advancing steadily, gaining the power and stability needed to pose a realistic threat to the widely-used public key encryption currently in place to protect sensitive data, applications and transactions,” says Greg Wetmore, VP software development at Entrust Cybersecurity Institute. </p><p>“There’s some uncertainty about when exactly there will be a quantum computer powerful enough to break the cryptographic algorithms currently in use, however many are operating under the assumption that this can happen within the next ten years.”</p><p>According to Gartner, conventional asymmetric cryptography is set to become unsafe to use as soon as 2029 – and will require the support of larger key sizes in just three years. Gartner's senior director analyst and co-author of the report, Mark Horvath, says, though, there's at least a decade before something like 2048-bit key can be broken.</p><h3 class="article-body__section" id="section-steal-now-crack-later-attacks-likely-won-t-be-feasible"><span>Steal now, crack later attacks likely won’t be feasible</span></h3><p>There’s no need for full-scale panic and just because this is possible, it doesn't mean cyber gangs will be routinely cracking encrypted files. In reality, most organisations won’t have access to the very large <a href="https://www.itpro.com/strategy/29134/what-is-a-datacentre" target="_blank" data-original-url="https://www.itpro.com/strategy/29134/what-is-a-datacentre">data centres</a> needed to store this information long-term, and then access the <a href="https://www.itpro.com/infrastructure/355422/quantum-supremacy-is-here-so-what" target="_blank" data-original-url="https://www.itpro.com/infrastructure/355422/quantum-supremacy-is-here-so-what">quantum computing power necessary</a> to decrypt this information once (eventually) available. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9mQMUXD2hbjcrqywmx5WDK" name="9mQMUXD2hbjcrqywmx5WDK.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9mQMUXD2hbjcrqywmx5WDK.jpg" mos="https://cdn.mos.cms.futurecdn.net/9mQMUXD2hbjcrqywmx5WDK.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Enabling secure hybrid learning</strong></p><p class="fancy-box__body-text">Cyber security in Higher Education</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370338/enabling-secure-hybrid-learning" data-original-url="/security/cyber-security/370338/enabling-secure-hybrid-learning">FREE DOWNLOAD</a></p></div></div><p>“For most cyber criminals the cost of accessing the quantum computing power is going to put it out of their reach, plus the need to resort to such sophisticated tools is not currently there,” says Will Richmond-Coggan, a litigator at law firm Freeths.</p><p>This is because the majority of cyber criminals focus on low-hanging fruit, where information can be accessed using traditional methods like <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" target="_blank" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> or <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>. Experts agree those using quantum computing for nefarious means will mainly be <a href="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses" target="_blank" data-original-url="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses">nation state actors or state-sponsored groups</a> looking to access highly sensitive information that could potentially affect national security. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses" data-original-url="/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses">What threat do nation state hackers pose to businesses?</a></p></div></div><p>“This kind of attack only makes sense for nation-states, who can reasonably expect to have powerful enough quantum capability in the near to medium term,” says Dr Chris Heunen, reader in quantum informatics and director of the Cisco Software Centre of Excellence at the University of Edinburgh. </p><p>“It’s also more likely to be high-value data with a long useful shelf life, such as intellectual property if its enterprise data, or defence and government-related data and intelligence,” adds Heidi Shey, a principal analyst at Forrester, highlighting that only certain organisations will appeal to these attackers.</p><h3 class="article-body__section" id="section-security-risks-extend-beyond-steal-now-crack-later"><span>Security risks extend beyond ‘steal now, crack later’</span></h3><p>It’s worth noting, however, that security risks from quantum computing extend beyond the nature of harvesting encrypted data now with a view to decrypting it at an indeterminate future date. Shey points to the fact that breaking existing public key cryptography will also have an impact on the encryption used for secure communications and digital signatures. </p><p>“It impacts critical infrastructure if the hardware and software on devices used in these environments rely on public key cryptography,” she says. “<a href="https://www.itpro.com/security/28031/what-is-blockchain" target="_blank" data-original-url="https://www.itpro.com/security/28031/what-is-blockchain">Blockchains</a> are also technically breakable by quantum computing,” adds Horvath, “and so the major blockchain companies like <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin</a> and Ethereum are (already) working on quantum-safe protocols for blockchains.” </p><h2 id="how-to-prepare-for-quantum-powered-attacks">How to prepare for quantum-powered attacks</h2><p>These <a href="https://www.itpro.com/technology/cryptocurrencies/369149/the-cryptocurrency-implosion-shows-were-heading-for-the-end" target="_blank" data-original-url="https://www.itpro.com/technology/cryptocurrencies/369149/the-cryptocurrency-implosion-shows-were-heading-for-the-end">cryptocurrencies</a> aren’t alone in preparing for the dawn of quantum computing and its potential effect on cyber security.</p><p>In the US, for example, the National Institute of Standards and Technology (NIST) has been working on its post-quantum competition for standardising protocols since 2017. At the end of last year, too, President Biden signed the Quantum Computing Cybersecurity Preparedness Act. Shey adds a White House memo recently asked US agencies to perform a cryptographic inventory, alongside proposed legislation on post-quantum cryptography.</p><h3 class="article-body__section" id="section-what-do-businesses-need-to-do"><span>What do businesses need to do? </span></h3><p>I’ll be many years before the wider cyber criminal community has access to the quantum computing tools necessary to hack heavily encrypted data. Only a handful of businesses, too, are likely targets for those most likely nation-state attackers. This means the majority of organisations have little to fear from <a href="https://www.itpro.com/technology/369274/getting-started-with-the-quantum-cloud" target="_blank" data-original-url="https://www.itpro.com/technology/369274/getting-started-with-the-quantum-cloud">the arrival of quantum computing</a>.</p><p>It’s also important to remember the benefits will far outweigh any cyber security risks. Even so, it’s important for organisations to establish risk level clearly, and what steps they might, therefore, need to take to protect encrypted data. </p><p>Both Horvath and Shey agree the responsibility for this preparation starts with the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do" target="_blank" data-original-url="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> or <a href="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do" target="_blank" data-original-url="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do">CIO</a> within the organisations, and that the first steps should be to look at the sensitivity and long-term value of an organisation’s data. Sensitivity will help you establish risk level, while lifespan will point to the steps you may need to be taken. </p><p>“If its lifespan is going to be two or three years you don’t have to worry about it,” says Horvath. “If it’s more like four to seven years, then you can extend the key lengths that you use today. Something like 3072-bit will extend the lifetime of your data security well into the 2030s.</p><p>“If you have data, such as mortgages, bonds or financial instruments, that have a lifespan of more than ten years, then you need to start thinking about what your strategy is going to be regarding the introduction of quantum safe encryption.”</p><h2 id="getting-ready-for-the-post-quantum-world">Getting ready for the post-quantum world</h2><p>In the end, all organisations will need to ensure they’re ready for a post-quantum world. Every business needs to begin working on its strategy to ensure post-quantum readiness, which should include building maturity into how cryptographic assets such as certificates, keys, secrets and crypto libraries are managed.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/3eBmL2VD2a8MbfF0GMLq2O"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution" data-original-url="/security/encryption/361581/ncsc-telecoms-quantum-key-distribution">Why the NCSC and telecoms firms are at loggerheads over quantum key distribution</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TzriL8GCKKzhvYPMPhhawT" name="TzriL8GCKKzhvYPMPhhawT.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TzriL8GCKKzhvYPMPhhawT.jpg" mos="https://cdn.mos.cms.futurecdn.net/TzriL8GCKKzhvYPMPhhawT.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to build a cyber-resilient business ready to innovate and thrive</strong></p><p class="fancy-box__body-text">Outperform your peers in your successful business outcomes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370146/how-to-build-a-cyber-resilient-business-read-to-innovate-and-thrive" data-original-url="/security/cyber-security/370146/how-to-build-a-cyber-resilient-business-read-to-innovate-and-thrive">FREE DOWNLOAD</a></p></div></div><p>Organisational changes can take time to implement, so it’s imperative to get a head start. But Wetmore points out that previous cryptographic transitions, such as the migration from SHA-1 to SHA-2, resulted in disruption and proved costly and time-consuming for organisations to implement. </p><p>The transition to <a href="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution" target="_blank" data-original-url="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution">post-quantum encryption</a> will be much more complex, as quantum doesn’t act like the cryptography we have today.</p><p>This means it’s not as simple as a drop-in replacement, as the post-quantum algorithms currently identified have completely different key generation, exchange, encryption and decryption properties from the ones they’re replacing. Each business will have different steps it needs to take to make sure it’s ready for the incoming quantum era, but there will be something for every organisation to do. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What you need to know about Gmail's new client-side encryption feature ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370143/what-you-need-to-know-about-googles-new-client-side-encryption-gmail</link>
                                                                            <description>
                            <![CDATA[ The new encryption feature will bolster security and give businesses greater control over access to data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">syXH7Wqcki68nVuTPT9R8T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RGdbdhooayWrvdJmHCkBKC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Feb 2023 12:36:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RGdbdhooayWrvdJmHCkBKC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Gmail logo on a smartphone on top of a keyboard]]></media:description>                                                            <media:text><![CDATA[The Gmail logo on a smartphone on top of a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The Gmail logo on a smartphone on top of a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RGdbdhooayWrvdJmHCkBKC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has revealed that client-side encryption (CSE) will be now generally available for Gmail business customers as the company looks to bolster security features for users.</p><p>In a blog post, the company revealed that CSE will take “existing encryption capabilities to the next level” for Workspace customers, providing users with “sole control” over encryption keys and complete control over access to data. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/369668/apple-steps-up-user-security-with-end-to-end-encryption-for-icloud" data-original-url="/security/encryption/369668/apple-steps-up-user-security-with-end-to-end-encryption-for-icloud">Apple steps up user security with end-to-end encryption for iCloud</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/369614/dropbox-acquires-boxcryptor-assets-encryption" data-original-url="/business-strategy/mergers-and-acquisitions/369614/dropbox-acquires-boxcryptor-assets-encryption">Dropbox adds end-to-end, zero-knowledge encryption with acquisition of Boxcryptor assets</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/productivity/367946/best-gmail-tips-and-tricks" data-original-url="/business-operations/productivity/367946/best-gmail-tips-and-tricks">Best Gmail tips and tricks</a></p></div></div><p>The inclusion of CSE means that Google can’t see the contents of emails hosted on the platform as data is “encrypted before it reaches Google servers.” </p><p>Google said this will provide greater protection for business users required to store sensitive or regulated data. </p><p>“Google Workspace already uses the latest cryptographic standards to <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypt all data</a> at rest and in transit between our facilities,” the company <a href="https://workspaceupdates.googleblog.com/2023/02/client-side-encryption-for-gmail-generally-available.html">said</a>. “Client-side encryption helps strengthen the confidentiality of your data while helping to address a broad range of data sovereignty and compliance needs.” </p><p>“Using client-side encryption in Gmail ensures sensitive data in the email body and attachments are indecipherable to Google servers. Customers retain control over encryption keys and the identity service to access those keys."</p><p>Gmail users will also be able to encrypt emails sent within their organisation, in addition to emails they send to users of other <a href="https://www.itpro.com/email-providers/24794/gmail-vs-outlookcom-which-one-is-better" data-original-url="https://www.itpro.com/email-providers/24794/gmail-vs-outlookcom-which-one-is-better">email providers</a>. </p><h2 id="client-side-encryption-rollout">Client-side encryption rollout </h2><p>The launch of the feature follows a successful beta testing period for selected users announced in December last year. </p><p>CSE is already available for <a href="https://www.itpro.com/google-docs/33273/google-g-suite-review-suite-like-chocolate" data-original-url="https://www.itpro.com/google-docs/33273/google-g-suite-review-suite-like-chocolate">Google Drive, Docs, Sheets, Slides, and Google Meet</a>. However, this move will expand CSE features and will be officially rolled out for customers using Google Workspace Enterprise Plus, Education Plus, and Education Standard. </p><p>The new feature will not be available for personal accounts or users of Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, or Legacy G Suite and Business customers. </p><p>Customers already enrolled in the beta will not be required to make changes following the launch, the company confirmed. </p><h2 id="how-to-turn-on-client-side-encryption-in-gmail">How to turn on client-side encryption in Gmail </h2><p>In its blog post, Google said CSE will be switched off by default, meaning admins will be required to enable the feature at the domain, OU, and group levels. </p><p>Admins can do this by following: <em><strong>Admin console > Security > Access and data control > Client-side encryption</strong></em>. </p><p>“With Google Workspace Client-side encryption (CSE) for Gmail, you need to enable the Gmail API and give it access to your entire organisation,” the company notes in an <a href="https://support.google.com/a/answer/10741897?hl=en&ref_topic=10742486">explainer</a>. </p><p>“Then, for each user, you need to use the <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a> to upload an S/MIME (Secure/Multipurpose internet Mail Extensions) certificate and private key metadata encrypted by your key service.” </p><p>Once CSE has been enabled by a Workspace admin, individual end users will be able to add this feature to any message by clicking the ‘lock’ icon and selecting the additional encryption option. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tips for Boosting your Organisation’s Security Posture with Encryption ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370003/tips-for-boosting-your-organisations-security-posture-with-encryption</link>
                                                                            <description>
                            <![CDATA[ Encryption should be as much a part of your cyber security as firewalls and antimalware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tSkbMzaWvVca15ADaRfyfS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ANRHWZtB9kL4844wb5q3NN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Feb 2023 15:43:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ANRHWZtB9kL4844wb5q3NN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop with their right hand while holding a see through padlock in their left]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop with their right hand while holding a see through padlock in their left]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop with their right hand while holding a see through padlock in their left]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ANRHWZtB9kL4844wb5q3NN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you work in the corporate world, you’ll be familiar with cybersecurity rules and regulations. Unfortunately, cyber-attacks are taking place at an astounding rate and have become a key challenge for companies across sectors, sizes and geographies. </p><p>According to Cybersecurity Ventures, <a href="https://www.enterpriseappstoday.com/stats/cybersecurity-statistics.html">more than 2,000 cyber-attacks occur around the globe each day</a> – that’s an incident every 39 seconds. And these attacks have significant consequences. Estimates suggest that by 2025, <a href="https://cybersecurityventures.com/cybercrime-damages-6-trillion-by-2021">global cybercrime will cost $10.5 trillion annually</a>, not to mention the personal security risks and reputational damage that can occur as a result of a hack. With stakes this high, there’s no doubt that cybersecurity must be top of every organisation’s agenda.</p><p>Many different solutions and approaches exist, but no matter the tactics, encryption should be central to any cybersecurity strategy. Encryption technology converts sensitive data into code that only the intended recipient can decipher, thus facilitating the safe transfer and access of important information. Let’s take a look at some of the key encryption-based offerings that businesses can utilise to protect against malicious and costly attacks. </p><h2 id="website-security">Website Security</h2><p><a href="https://shop.actalis.com/store/gb-en/?site=aruba">SSL Certificates</a> play a critical role in securing websites for businesses of all sizes. Installing SSL Server Certificates on a website lets companies enable the Transport Layer Security (TLS) protocol, a standard solution used to ensure online transaction security. TLS guarantees that a user’s session on a website remains fully encrypted and that all the data transferred between the user and the website is kept secure. This is evidenced by a padlock icon displayed in the browser bar. SSL Certificates also provide server authentication, which allows the user to verify the authenticity of a given site. </p><p>There are three categories of SSL Certificates: Extended Validation (EV), Organisation Validation (OV) and Domain Validation (DV), all of which offer the same level of encryption but with different approaches to vetting and verification. In addition to these categories, there are also several types of SSL Certificates available, including Single Domain, SAN and Wildcard. Which you use depends on how many domains and subdomains you’re looking to protect with the certificate. </p><p>When considering an SSL Certificate provider, it’s important to choose one with experience implementing all categories and types of certificates, as well as the knowledge to help you pick the best option for protecting your business. For increased flexibility, look for a security partner that enables clients to request and issue their own certificates with a Certificate Signing Request (CSR). This can help expedite processes and reduce reliance on external teams to implement new certificates. Some providers also offer services that deliver certificates automatically – another plus for increasing efficiency. </p><h2 id="email-security">Email Security </h2><p>Encryption also play an invaluable role in email communications. Business emails are a common entry point for cyber criminals and a source of costly attacks. In fact, according to the Federal Bureau of Investigation (FBI), as of December, 2021 global Business Email Compromise attacks had resulted in more than <a href="https://www.tripwire.com/state-of-security/43-billion-stolen-through-business-email-compromise-since-2016-reports-fbi">$43 Billion in losses</a>. </p><p>Safeguarding the confidentiality and integrity of all business emails has never been more important and obtaining S/MIME certificates is a crucial step in keeping communications secure. S/MIME Certificates provide powerful protection against email hacks with end-to-end encryption and a digital signature. They ensure that email material is accessed only by the intended recipient and allow that recipient to easily confirm the sender’s identity. </p><p>When selecting an email security solution, consider vendors with Corporate S/MIME Certificate options that can configure the technical signature method to a company’s specific regulatory framework, as well as other particular needs. The ability to tailor the solution in this way can help ease adoption. If you want to test the effectiveness of S/MIME Certificates on your personal email, look for a vendor that offers free options for this use. </p><h2 id="software-security">Software Security </h2><p><a href="https://www.actalis.com/code-signing-certificates-best-practices.aspx">Code Signing Certificates</a>, which are essential in protecting against harmful malware attacks, are a third tool that all businesses should have in their cybersecurity arsenal. These certificates allow users to put a digital signature on a wide range of software or application components to confirm their origin, guarantee authorship and ensure code has not been altered. Code Signing Certificates connect the identity of an IT organisation to a private key used by the developer or distributor to sign the code, as well as a public key that allows the end-user to verify the identity of the signing party, thus ensuring the software is reliable. </p><p>These certificates can provide valuable protection against potentially crippling malware attacks, but there are a few best practices to consider to ensure their effective use. First, limit the number of personnel who are able to access the machines used for the code signing process – the fewer people with access to the private keys, the lower the chance of error or misuse that could compromise the protection. Keep close track of all code signing operations to prevent the signature of unapproved or malicious code, and store the keys with security-compliant tools to reduce the chance of attacks. It’s also recommended to scan for viruses before signing any code and add a timestamp to the signed code. Finally, don’t sign all software with the same certificate and be sure to change keys frequently. </p><p>There’s no doubt that cyber-attacks have become a constant threat for today’s businesses. Fortunately, encryption technology exists to help organisations protect themselves in today’s hostile cyber environment. By utilising encryption and implementing critical safety solutions and measures, businesses have the ability to thwart malicious attackers and protect against damaging hacks. Encryption may only be one piece of the puzzle, but its applications are far-reaching across the security space – making it central to any cybersecurity strategy. </p><p>To boost your organisation’s security with Actalis certificates, <a href="https://shop.actalis.com/store/it-en/?utm_source=itpro-co-uk&utm_campaign=ssl-certificates&utm_medium=article-marketing&utm_content=tips-for-boosting-your-organisation">click here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What are privacy-enhancing technologies (PETs)? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/369840/what-are-privacy-enhancing-technologies-pets</link>
                                                                            <description>
                            <![CDATA[ As businesses need to consider privacy now more than ever, privacy-enhancing technologies (PETs) are gaining traction ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c5bNontmAKtbBgkkQNARZp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/thCdknGN4MYKQvwnRS6v5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Jan 2023 08:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/thCdknGN4MYKQvwnRS6v5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A graphic of a padlock in a digital blue colour, with effects]]></media:description>                                                            <media:text><![CDATA[A graphic of a padlock in a digital blue colour, with effects]]></media:text>
                                <media:title type="plain"><![CDATA[A graphic of a padlock in a digital blue colour, with effects]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/thCdknGN4MYKQvwnRS6v5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As companies struggle to get the most out of their data while adhering to strict regulations, privacy-enhancing technologies (PETs) have started to gain traction. Among the benefits, this set of technologies allows firms to extract data without compromising individuals’ privacy. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" data-original-url="/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">The risks and strategies of using privacy as a business differentiator</a></p></div></div><p>PETs are particularly useful for performing analytics on customer <a href="https://www.itpro.com/strategy/28185/what-is-data-mining" target="_blank" data-original-url="https://www.itpro.com/strategy/28185/what-is-data-mining">data</a> – something that Facebook owner Meta has been doing to <a href="https://about.fb.com/news/2021/08/privacy-enhancing-technologies-and-ads">boost the success</a> of its digital advertising business in an increasingly privacy-conscious consumer market. </p><p>Other big tech firms are also taking advantage, with Google and Apple among those creating, championing and using PETs. The pair used <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">privacy-friendly technologies</a> when rolling out <a href="https://www.apple.com/uk/newsroom/2020/04/apple-and-google-partner-on-covid-19-contact-tracing-technology">contact tracing</a> schemes during COVID-19. </p><p>PETs are gaining so much attention that the US and UK governments <a href="https://www.nist.gov/news-events/news/2021/12/nist-take-part-us-uk-partnership-advance-privacy-enhancing-technologies">announced</a> a joint initiative last year to boost adoption. Businesses will now rightfully consider how PETs can be integrated into their core processes.</p><h2 id="what-are-privacy-enhancing-technologies">What are privacy-enhancing technologies?</h2><p>PETs are a set of technologies that offer the ability to analyse or manipulate data without compromising privacy. “PETs provide a way of <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics" target="_blank" data-original-url="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics">analysing data</a> in a privacy-friendly way to continue reaping the benefits, while at the same time minimising the risks associated with maintaining and safeguarding it,” says Michael Markevich, senior director of risk and security at browser company Opera.</p><p>One of the core pillars of PETs is homomorphic <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a>, which allows complex computations to be performed without decrypting the data. Another type of PET is a trusted execution environment, which allows processing by a secure part of the computer isolated from the main operating system. </p><p>Secure multiparty computation, meanwhile, allows different parties to jointly process a dataset without sharing information with each other.</p><p>The power of PETs lies in their ability to protect data while it’s being used or processed. This allows searches, analytics and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" target="_blank" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> models to extract value securely and privately from multiple data sources, says Dr Ellison Anne Williams, founder and CEO at Enveil.</p><p>The use of PETs can therefore boost consumer trust, as well as offer a basis to adhere to regulations such as <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">UK Data Protection Act (DPA) 2018</a>.</p><h3 class="article-body__section" id="section-39-soft-39-pets-vs-39-hard-39-pets"><span>'Soft' PETs vs 'hard' PETs</span></h3><p>There are already multiple types of PETs, which all fall into ‘soft’ and ‘hard’ categories. A soft PET assumes you can trust a third party to process personal data. Luke Dixon, partner, IT and data specialist at law company Freeths cites the example of an organisation using controls to authorise certain parties to have access to data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" data-original-url="/network-internet/email-providers/358887/the-most-secure-email-services">The most secure email services of 2023</a></p></div></div><p>Transport Layer Security (TLS) used in email, instant messaging, and the HTTPS protocol are examples of soft PETs. “TLS relies on a number of third-party certificate authorities that are trusted to verify the authenticity of digital certificates,” Markevich explains.</p><p>In contrast, a hard PET works on the basis that third parties cannot be trusted in relation to the data. Examples include <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private networks (VPNs)</a>.</p><h2 id="what-do-pets-look-like-in-a-real-world-setting">What do PETs look like in a real-world setting? </h2><p>PETs are only just starting to be used in real-world settings. The most common uses for businesses are encryption and pseudonymisation, adds Simon Walsh, partner at Oury Clark Solicitors. “Businesses tend to use these types of software as a way to collect data and assess the behaviours of individuals without the need to process large amounts of personal information.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wE3UT9aDVGm6fZh2yRZMu6" name="wE3UT9aDVGm6fZh2yRZMu6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" mos="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An EDR buyer's guide</strong></p><p class="fancy-box__body-text">How to pick the best endpoint detection and response solution for your business</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368443/an-edr-buyers-guide" data-original-url="/security/cyber-security/368443/an-edr-buyers-guide">FREE DOWNLOAD</a></p></div></div><p>PETs can benefit multiple vertical industries, including financial services, where they can help with anti-fraud and money laundering initiatives. “Data silos and privacy boundaries continue to cripple financial organisations’ ability to fight criminal activity such as fraud and money laundering,” says Williams. </p><p>PETs allow banks to perform encrypted searches on data containing sensitive customer information. “This allows them to gain insights in near real-time while ensuring personal information is never exposed outside of its original jurisdiction,” she explains.</p><p>In healthcare, PETs are being used to analyse patient data and drive insights into drug interactions, clinical trials and research to improve health outcomes,” says Michael Hughes, chief business officer at Duality Technologies. </p><p>For example, genomic data, clinical data, patient disease registries and electronic health registries exist separately and are distributed across thousands of hospitals and research firms. “PETs are being used to allow healthcare researchers and firms to combine these disparate data sources together to fuel discovery, identify patterns and develop more effective interventions and treatments.” </p><h2 id="how-to-integrate-pets-into-business-processes">How to integrate PETs into business processes</h2><p>The advantages of PETs are clear, so how can businesses start to integrate PETs into their tools and services? Firstly, it's important not to rush into PETs and to determine relevant use cases for the technology. Businesses need to “think long and hard” about how best to implement PET systems into their workflows, says Markevich. </p><p>He says the primary challenges are technical. “For example, having a distributed trust system would be a prerequisite for most forms of PETs, and those are very difficult to implement at the moment.”</p><p>Taking this into account, firms should also ensure they have the right skills in place – or make sure they can access these through partners. </p><p>PETs are hailed as a tool to help firms comply with regulations, but official guidance around this is still at an early stage. In the UK, the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/09/ico-publishes-guidance-on-privacy-enhancing-technologies">issued draft guidance</a> on the use of PETs in September 2022. As part of this, the organisation recommends businesses conduct <a href="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr" target="_blank" data-original-url="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr">data protection impact assessments (DPIAs</a>) to assess their use of PETs.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="/data-protection/28177/data-protection-policies-and-procedures">Data protection policies and procedures</a></p></div></div><p>“The ICO recognises that PETs can ‘unlock safe and lawful data sharing where people can enjoy better services and products without trading their privacy rights’,” says Lauren Wills-Dixon, a solicitor at Gordons. Yet, she warns organisations to exercise caution in their implementation. PETs should be utilised to augment existing frameworks “rather than as a panacea to satisfy all their data protection compliance needs”, says Wills-Dixon. </p><p>They are new technologies but in an era where both data and consumer trust are key to doing business, the future for PETs looks bright. “Data is arguably the biggest commodity in the world, and this creates a need for technology that protects the privacy of individuals and helps to demonstrate compliance with strict data protection laws,” Wills-Dixon continues. “PETs are very much here to stay and hopefully, we will see more regulatory guidance and codes of conduct to help organisations implement these technologies safely.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp to combat internet blackouts with proxy server support ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/369812/whatsapp-to-combat-internet-blackouts-with-proxy-server-support</link>
                                                                            <description>
                            <![CDATA[ The newest version of the communication platform offers a new way to bypass state-imposed internet limitations, but concerns remain over IP visibility ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bPLYQfzLHAxG4fPh86Yfh9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8Z8noSoku2cTDxLzRGuy9Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 13:27:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8Z8noSoku2cTDxLzRGuy9Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person holding a smartphone with the WhatsApp logo displayed on screen]]></media:description>                                                            <media:text><![CDATA[A person holding a smartphone with the WhatsApp logo displayed on screen]]></media:text>
                                <media:title type="plain"><![CDATA[A person holding a smartphone with the WhatsApp logo displayed on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8Z8noSoku2cTDxLzRGuy9Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WhatsApp has announced new support for proxy server connectivity, allowing its users to retain access to the messaging service in areas with state-controlled internet.</p><p>The firm stated that the update was driven by a concern for users that are being cut off from the outside world by government internet restrictions, and will shield users from communications blackouts.</p><p>The Iranian government has restricted access to Meta platforms such as WhatsApp and Instagram in recent months, and engaged in a shutdown of internet services as human rights protests have escalated across the country.</p><p>Proxy servers work by acting as an intermediary between a user and the internet-hosted service that's trying to be accessed. In cases where states limit or outright block access to WhatsApp, users will be able to connect to a proxy server that's separated from WhatsApp which then acts as a bridge to access the communications platform, bypassing state-imposed blocks.</p><p>“Our wish for 2023 is that these internet shutdowns never occur,” said WhatsApp.</p><p>“Disruptions like we’ve seen in Iran for months on end deny people’s human rights and cut people off from receiving urgent help. Though in case these shutdowns continue, we hope this solution helps people wherever there is a need for secure and reliable communication.”</p><p>In a <a href="https://blog.whatsapp.com/connecting-to-whatsapp-by-proxy">blog post</a>, WhatsApp confirmed that the change will not affect the <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption (E2EE)</a> of messages sent using the app, and reaffirmed that neither those running <a href="https://www.itpro.com/server-storage/30246/what-is-a-proxy-server" data-original-url="https://www.itpro.com/server-storage/30246/what-is-a-proxy-server">proxy servers</a>, nor WhatsApp and Meta, will be able to intercept messages sent using the new method.</p><p>To activate the feature, users simply select ‘Use Proxy’ in WhatsApp’s settings, and enter a valid proxy address. These can be shared on social media, or prior to a blackout to ensure that users can continue WhatsApp communication even with heavy network restrictions in place.</p><p>Speaking to <em>IT Pro</em>, Mona Schroedel, a technology and privacy expert at law firm Freeths, welcomed the news but highlighted concerns around the management of volunteer servers and the potential powers afforded to criminals.</p><p>"From a data protection perspective, users are being assured that end-to-end-encryption remains in place. However, it should not be forgotten that the third party proxy server will receive the users’ IP addresses in the process," she said.</p><p>"The difficulty with this, at least in theory, may well be that not much is known about the volunteer proxy server, its location and the technical and organisational safeguards the volunteer organisation may have in place to protect that information.</p><p>"Repressive regimes who may have an interest in identifying those individuals using such a service - potentially even through setting up a proxy server themselves - regardless of whether they can decode the messages sent. Democratic regimes may also be concerned about the ability that this might give to terrorists or criminals to set up and operate their own unsupervised encrypted communications networks."</p><h2 id="the-issue-at-hand">The issue at hand</h2><p>Protests intensified in Iran following the death of 22-year-old Mahsa Amini under suspicious circumstances in ‘morality police’ custody. The suspicious deaths of further protesters such as Nika Shakarami have since increased anti-government activity.</p><p>In September 2022 the hacktivist collective <a href="https://www.itpro.com/security/cyber-attacks/369130/anonymous-hacks-iran-government-and-state-broadcasters-following-nationwide-internet-shutdown" data-original-url="https://www.itpro.com/security/cyber-attacks/369130/anonymous-hacks-iran-government-and-state-broadcasters-following-nationwide-internet-shutdown">Anonymous hacked Iranian government websites</a>, as well as pro-government media organisations, in support of the protestors. The group has encouraged protesters to utilise the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">deep web</a> onion router TOR to use the internet without censorship, as the Iranian government has blocked access to traditional <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private networks (VPN)</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nkJY2faZ4P9fjuCkSx3EiA" name="nkJY2faZ4P9fjuCkSx3EiA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" mos="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Unified Endpoint Management and Security in a work-from-anywhere world</strong></p><p class="fancy-box__body-text">Management and security activities are deeply intertwined, requiring integrated workflows between IT and security teams</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere" data-original-url="/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere">FREE DOWNLOAD</a></p></div></div><p>According to <a href="https://www.statista.com/statistics/258749/most-popular-global-mobile-messenger-apps">Statista</a>, WhatsApp is the most popular messaging app in the world with over 2 billion users, and the app has strong business use cases. Approximately 400 million people in India use WhatsApp, and the app plays a major role as a go-between for companies and customers throughout the country. It is also used for in-house communications channels in many companies.</p><p>The Indian government has shut down internet access in Kashmir several times over the past decade, in response to anti-government protests in the region. While past bans have included a region-wide communications blackout, specific action has also been taken to block messaging platforms such as WhatsApp and Twitter.</p><p>The company has encouraged volunteers and organisations worldwide to set up proxy servers, in order to establish a network free from blackouts, and stated that the feature will work with servers on ports 80, 443, and 5222.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/collaboration/369453/whatsapp-communities-to-unify-workplace-group-chats" data-original-url="/business-strategy/collaboration/369453/whatsapp-communities-to-unify-workplace-group-chats">WhatsApp Communities to unify workplace group chats, expand functionality</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/369130/anonymous-hacks-iran-government-and-state-broadcasters-following-nationwide-internet-shutdown" data-original-url="/security/cyber-attacks/369130/anonymous-hacks-iran-government-and-state-broadcasters-following-nationwide-internet-shutdown">Anonymous hacks Iran government and state broadcasters following nationwide internet shutdown</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a></p></div></div><p>In recent years, Meta has championed the use of E2EE, against backlash from the UK government. It plans to <a href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023" data-original-url="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">extend E2EE to all its messaging services</a>, including Facebook Messenger and Instagram throughout 2023, having delayed this rollout due to legislative pressure over harmful online content.</p><p>The government’s much-delayed <a href="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn" data-original-url="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn">Online Safety Bill</a> seeks to compel social media firms to scan all messages sent on their platforms for harmful content, which would mean installing a backdoor that privacy rights campaigners such as Big Brother Watch have <a href="https://bigbrotherwatch.org.uk/2022/11/big-brother-watch-respond-to-governments-proposed-online-safety-bill-changes">criticised</a> as a threat to free speech. </p><p>For more information on establishing a proxy server, WhatsApp has outlined the process in more detail on a dedicated <a href="https://github.com/WhatsApp/proxy">GitHub repository.</a></p><p>WhatsApp via proxy is available now in the latest version of the app.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple steps up user security with end-to-end encryption for iCloud ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/369668/apple-steps-up-user-security-with-end-to-end-encryption-for-icloud</link>
                                                                            <description>
                            <![CDATA[ Apple’s new data protection feature comes as users contend with an increasingly sophisticated threat landscape ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5nnrpBmbYu7xNRKPAYK9Lw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/REzWNQu5SHmSubAPuSuNGJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Dec 2022 13:37:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/REzWNQu5SHmSubAPuSuNGJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[iCloud logo appearing on a smartphone being held in outstretched arms by a silhouetted person against a multicoloured background]]></media:description>                                                            <media:text><![CDATA[iCloud logo appearing on a smartphone being held in outstretched arms by a silhouetted person against a multicoloured background]]></media:text>
                                <media:title type="plain"><![CDATA[iCloud logo appearing on a smartphone being held in outstretched arms by a silhouetted person against a multicoloured background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/REzWNQu5SHmSubAPuSuNGJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple has announced it will begin allowing users to secure data backed up to their iCloud using end-to-end encryption. </p><p>The feature, dubbed Advanced Data Protection for iCloud, will debut for users participating in the company’s beta software programme. The tech giant revealed the feature will be available for US-based users by the end of 2022 and will roll out globally early next year. </p><p>At present, Apple offers end-to-end encryption for data already stored in its cloud platform, including passwords, credit card and payment details, and health-related data. </p><p>The advanced feature will extend this protection, allowing users to back up other sensitive information such as photos, notes and iCloud backups. </p><p>This change will not cover all data, however. The company has confirmed that contacts, calendar information and email info will not be encrypted. </p><p>Craig Federighi, Apple’s senior vice president of software engineering said the new privacy features are a signal of Apple’s “unwavering” commitment to providing users with the “best data security in the world”. </p><p>“We constantly identify and mitigate emerging threats to their personal data on device and in the cloud,” he said. </p><p>“Our security teams work tirelessly to keep users’ data safe, and with iMessage Contact Key Verification, Security Keys, and Advanced Data Protection for iCloud, users will have three powerful new tools to further protect their most sensitive data and communications.” </p><p>Initially, Apple users will be required to opt-in to the new feature and granted a specific encryption key which will be stored on their device. </p><p>Ivan Krstic, Apple’s head of security engineering and architecture, revealed that a key benefit of the Advanced Data Protection feature is that it will ensure iCloud data will be protected in the event of a cloud breach. </p><p>“Advanced Data Protection is Apple’s highest level of cloud data security, giving users the choice to protect the vast majority of their most sensitive iCloud data with <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption</a> so that it can only be decrypted on their trusted devices,” he said. </p><p>However, Jamie Akhtar, CEO & co-founder of CyberSmart, warned that the proposed opt-in requirement could leave users unprotected and place responsibility for data protection in their hands. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eNyWocwZkU6AFRW4cbpF2B" name="eNyWocwZkU6AFRW4cbpF2B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" mos="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Getting board-level buy-in for security strategy</strong></p><p class="fancy-box__body-text">Why cyber security needs to be a board-level issue</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy" data-original-url="/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">FREE DOWNLOAD</a></p></div></div><p>"With increased cybersecurity awareness among the general public, cultivating digital trust is imperative to business survival. Apple has long been the exemplar of this, having time and again invested in its user security,” he said. </p><p>“Unfortunately, the downside of Apple’s latest measures is the requirement for users to ‘opt-in’ which will likely leave many unprotected as the onus is on them to take action,” Akhtar added. </p><p>Similarly, Tony Sabaj, mobile security expert at Check Point Software noted that the added layers of security - including encryption keys - could inhibit users. </p><p>“This added layer of security is not without drawbacks as the end user is now responsible for storing, backing up and securing their own encryption keys,” he explained. </p><p>“From our experience in mobile security, even though Apple is taking steps to improve privacy, malicious apps, text/iMessage <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> and <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero day threats</a> will be unaffected by these measures.” </p><p>In a thread on Twitter, Matthew Green, professor of cryptography at Johns Hopkins University, said the encryption move “sets the standard on what secure consumer cloud backup looks like” and marks an important precedent for users globally. </p><p>“Even as an opt-in feature, this move will have repercussions all over the industry as competitors chase them,” he said. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1600569491658018818"></a></p></blockquote><div class="see-more__filter"></div></div><h2 id="bolstering-data-security">Bolstering data security</h2><p>The move by Apple forms part of a broader strategy focused on bolstering security, with the company adding that the releases come “as threats to user data become increasingly sophisticated and complex”. </p><p><a href="https://www.apple.com/newsroom/pdfs/The-Rising-Threat-to-Consumer-Data-in-the-Cloud.pdf">Research</a> conducted by Apple found that the number of <a href="https://www.itpro.com/security/data-breaches/368810/large-scale-data-breaches-are-in-decline-but-hacking-remains-a-threat" data-original-url="https://www.itpro.com/security/data-breaches/368810/large-scale-data-breaches-are-in-decline-but-hacking-remains-a-threat">data breaches</a> has more than tripled between 2013 and 2021. In addition, the study found that 1.1 billion personal records were exposed globally during 2021 alone. </p><p>In 2023, the company plans to begin supporting the use of hardware keys to improve <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a>. Similarly, toward the end of 2023, Apple also plans to launch a feature called ‘iMessage Contact Key Verification’. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/369655/apple-and-amd-will-both-be-major-customers-of-tsmcs-new-arizona-fabs" data-original-url="/hardware/369655/apple-and-amd-will-both-be-major-customers-of-tsmcs-new-arizona-fabs">Apple and AMD will both be 'major customers' of TSMC's new Arizona fabs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-phones/369417/apple-iphone-14-pro-review-a-dynamic-phone-from-top-to-bottom" data-original-url="/mobile/mobile-phones/369417/apple-iphone-14-pro-review-a-dynamic-phone-from-top-to-bottom">Apple iPhone 14 Pro review: A dynamic phone from top to bottom</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/369150/apple-must-get-behind-the-eus-usb-c-decision-or-be-left-behind" data-original-url="/hardware/369150/apple-must-get-behind-the-eus-usb-c-decision-or-be-left-behind">Apple must get behind the EU's USB-C decision or be left behind</a></p></div></div><p>This new feature will enable users to confirm they are interacting with an intended contact. The verification scheme will also issue users with a warning if they are communicating with a contact or individual with “compromised” iMessage infrastructure. </p><p>Melissa Bischoping, endpoint security research director at Tanium, welcomed the move as a positive step to ensure that users are safeguarded amidst escalating global security threats. </p><p>“Apple has introduced these important security features to keep pace with the threat landscape and threats to privacy,” she said. </p><p>“By leveraging these features, you can know that your <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">data is encrypted</a>; even if the company holding the data is breached, you have additional assurance that you will not be a secondary victim. I am hopeful that this trend continues, as these protections are essential for reducing the secondary victimisation of a services' users after a data breach.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Qatar World Cup apps prompt digital privacy warnings from regulators ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369537/qatar-world-cup-apps-prompt-digital-privacy-warnings</link>
                                                                            <description>
                            <![CDATA[ European regulators have voiced serious concerns over the permissions required by apps Ehteraz and Hayya ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e4WrSqgqsaoCLF3HRV6JVh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nehfdzE8g792vWuZZDbiQP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Nov 2022 12:58:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nehfdzE8g792vWuZZDbiQP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a decorative fixture outside one of the stadiums hosting the 2022 football World Cup in Qatar]]></media:description>                                                            <media:text><![CDATA[Image of a decorative fixture outside one of the stadiums hosting the 2022 football World Cup in Qatar]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a decorative fixture outside one of the stadiums hosting the 2022 football World Cup in Qatar]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nehfdzE8g792vWuZZDbiQP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two apps described as 'mandatory' for attending the Qatar World Cup have been the subject of privacy complaints by multiple European data regulators, amidst claims they collect sensitive data outside of their remit.</p><p>‘Ehteraz’ and ‘Hayya’ are both apps released by Qatar’s Ministry of Interior and its Supreme Committee for Delivery & Legacy, respectively. The former is listed on Google Play as a <a href="https://www.itpro.com/security/privacy/359597/ico-fines-contact-tracing-service-for-using-personal-data-for-marketing" data-original-url="https://www.itpro.com/security/privacy/359597/ico-fines-contact-tracing-service-for-using-personal-data-for-marketing">contact tracing</a> app for the tournament, while the latter is listed as a portal through which to book tickets, manage accommodation, and enter stadiums, but experts have argued that the permissions required by both apps go far beyond these basic functions.</p><p>In a <a href="https://www.bfdi.bund.de/SharedDocs/Kurzmeldungen/DE/2022/22_Etheraz-Hayya.html">statement</a>, Germany’s BfDI (The Federal Commissioner for Data Protection and Freedom of Information) urged football fans looking to download the app only to do so if “absolutely necessary”.</p><p>The regulator also suggested that users should put the apps on a spare phone that contains no other personal data or contact information, and wipe the phone's storage and operating after use.</p><p>It alleged that the permissions and data processing of both apps goes beyond that described on their app store listings, that one of the apps tracks the number of phone calls made, and that data used by the apps is “transmitted to a central server” in addition to remaining on the device.</p><p>Datatilsynet, Norway's data protection authority, likewise <a href="https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2022/rad-til-deg-som-reiser-til-qatar-vm">stated</a> that it does not know “what these apps actually do,” but that Ehteraz is required for seeking any medical treatment whilst in Qatar.</p><p>It recommended not giving the Hayya app permission to use device location and urged all businesses planing to send employees to the Qatar World Cup to carry out proper risk assessments.</p><p>“We are alarmed by the extensive access the apps require. There is a real possibility that visitors to Qatar, and especially vulnerable groups, will be monitored by the Qatari authorities.”</p><p>Google Play <a href="https://play.google.com/store/apps/datasafety?id=com.pl.qatar&hl=en_GB&gl=US">notes</a> that Hayya’s security practices do not include <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">data encryption</a>, and the developer has neglected to provide a way for users to delete their data. The official FIFA guidance on Hayya <a href="https://hospitality.fifa.com/2022/en/faqs/travel-organization/hayya-card-fan-id/q-what-is-a-hayya-card-fan-id-and-why-do-i-need-one">explains</a> that a Hayya card is “required to access the stadium on match day”.</p><p>The UK government's <a href="https://www.gov.uk/foreign-travel-advice/qatar/qatar-world-cup-2022">travel advice</a> for Qatar states that visitors will not be required to register with Ehteraz prior to arrival, but that Hayya is a mandatory ID required not only for entering stadiums during the event, but also for entering Qatar in general.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/data-centres/368950/microsoft-opens-first-data-centre-region-in-qatar" data-original-url="/server-storage/data-centres/368950/microsoft-opens-first-data-centre-region-in-qatar">Microsoft opens first data centre region in Qatar</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw" data-original-url="/security/362010/ioc-defends-olympics-app-devastating-flaw">IOC defends China Olympics app after 'devastating flaw' revealed</a></p></div></div><p>“We are aware of media reports on this matter and we will consider the potential impact on the privacy rights of UK citizens,” an ICO spokesperson told <em>IT Pro</em>.</p><p>“If anyone is concerned about how their data has been handled, they can make a complaint to the ICO. We’d also always advise travellers who may be heading to Qatar to refer to our Your Data Matters page to ensure they are aware of their data rights."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bm3sqi3QzVYhu44sQY925L" name="bm3sqi3QzVYhu44sQY925L.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/bm3sqi3QzVYhu44sQY925L.png" mos="https://cdn.mos.cms.futurecdn.net/bm3sqi3QzVYhu44sQY925L.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Database and big data security</strong></p><p class="fancy-box__body-text">KuppingerCole 2021 Leadership Compass Report</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369389/database-and-big-data-security" data-original-url="/security/369389/database-and-big-data-security">FREE DOWNLOAD</a></p></div></div><p>The ICO declined to comment on the suggestion of using spare phones for app use.</p><p>Apps released for the promotion of, or to interface directly with, sports events have a history of security concerns. At the start of 2022, a <a href="https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw" data-original-url="https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw">‘devastating flaw’ was discovered in China’s Beijing Olympics app</a> that allowed threat actors to circumvent encryption intended to protect users’ files and voice recordings. </p><p>The MY2022 app, the use of which was mandatory for both international and domestic visitors to the games, was also found to transmit some metadata without any SSL encryption and lacked transparency over the extent to which it shared user medical data with third-party organisations. </p><p>In response, the Federal Bureau of Investigation (FBI) <a href="https://www.itpro.com/security/362110/fbi-urges-olympic-athletes-to-leave-personal-devices-at-home" data-original-url="https://www.itpro.com/security/362110/fbi-urges-olympic-athletes-to-leave-personal-devices-at-home">urged</a> athletes to use temporary phones throughout the Beijing Winter Olympics, and advised participants and spectators not to download apps required to attend the event for fear of personal data theft, tracking, or <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Office 365's encryption feature can be easily hacked, warns WithSecure ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/369344/office-365-encryption-easily-hacked-withsecure</link>
                                                                            <description>
                            <![CDATA[ Researchers advise enterprises to move away from Office 365 Message Encryption, claiming its messages can be decrypted without a key ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6Zg76oiiXZgoLX81mr6Rj2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m2M2qEAJmJeCSH7mPuavok-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Oct 2022 10:43:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m2M2qEAJmJeCSH7mPuavok-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand pressing a phone with the Office 365 logo shown on it, with the Office 365 logo on an orange wall in the background]]></media:description>                                                            <media:text><![CDATA[A hand pressing a phone with the Office 365 logo shown on it, with the Office 365 logo on an orange wall in the background]]></media:text>
                                <media:title type="plain"><![CDATA[A hand pressing a phone with the Office 365 logo shown on it, with the Office 365 logo on an orange wall in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m2M2qEAJmJeCSH7mPuavok-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers at cyber security firm WithSecure have issued an advisory, warning that the method used to generate encrypted messages in Microsoft Office 365 can be cracked relatively easily.</p><p>Microsoft Office 365 Message Encryption (OME), a feature offered within the <a href="https://www.itpro.com/desktop-software/19337/office-365-review" data-original-url="https://www.itpro.com/desktop-software/19337/office-365-review">Office 365 suite</a>, allows enterprise users to send <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encrypted</a> messages as an <a href="https://www.itpro.com/business-strategy/careers-training/358369/front-end-developer-career-guide-7-skills-a-front-end" data-original-url="https://www.itpro.com/business-strategy/careers-training/358369/front-end-developer-career-guide-7-skills-a-front-end">HTML</a> attachment via email.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="moQ7m7Ygm4UQiwkmvgFG3m" name="moQ7m7Ygm4UQiwkmvgFG3m.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/moQ7m7Ygm4UQiwkmvgFG3m.png" mos="https://cdn.mos.cms.futurecdn.net/moQ7m7Ygm4UQiwkmvgFG3m.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to trust your inbox with Cloudflare Area 1</strong></p><p class="fancy-box__body-text">Why your current email security may not be enough</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369345/how-to-trust-your-inbox-with-cloudflare-area-1" data-original-url="/security/369345/how-to-trust-your-inbox-with-cloudflare-area-1">FREE DOWNLOAD</a></p></div></div><p>Microsoft says the function is useful for sending <a href="https://www.itpro.com/security/32397/four-ways-to-secure-sensitive-data" data-original-url="https://www.itpro.com/security/32397/four-ways-to-secure-sensitive-data">sensitive data</a> such as medical records, but WithSecure contends the service uses an insecure method of operation for encryption, allowing threat actors to infer the structure of encrypted messages.</p><p>OME messages are generated using Electronic Codebook (ECB), in which the text of the message is broken down into cipher blocks that are individually encrypted using a key stored and managed by Microsoft, through <a href="https://www.itpro.com/cloud/amazon-web-services-aws/366973/microsoft-azure-leads-aws-in-cloud-market" data-original-url="https://www.itpro.com/cloud/amazon-web-services-aws/366973/microsoft-azure-leads-aws-in-cloud-market">Azure</a> Rights Management (Azure RMS). Each character within the plaintext is directly substituted for a cipher text character, according to the key.</p><p>However, through this method identical blocks of plaintext will return identical blocks of encrypted text, allowing patterns within the content to be identified. This is particularly the case with emails, which have structures that are more easily predicted than other types of messages typically sent through <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encrypted (E2EE)</a> apps, such as <a href="https://www.itpro.com/business/business-operations/368997/signal-hires-former-google-manager-meredith-whittaker-as-first-president" data-original-url="https://www.itpro.com/business/business-operations/368997/signal-hires-former-google-manager-meredith-whittaker-as-first-president">Signal</a> or <a href="https://www.itpro.com/marketing-comms/business-communications/368514/ico-calls-for-gov-review-into-use-of-whatsapp-and-others" data-original-url="https://www.itpro.com/marketing-comms/business-communications/368514/ico-calls-for-gov-review-into-use-of-whatsapp-and-others">WhatsApp</a>.</p><p>Emails within organisations, which are likely to contain repeating headers or footers, might be especially vulnerable to this kind of malicious decryption, as patterns reveal the encrypted substitutions for plaintext. If a message from an organisation always signed off in the same way, an attacker with access to a database of such messages would be able to partially decrypt each one.</p><p>WithSecure has <a href="https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation">advised</a> organisations to consider alternative channels of communication for sensitive company information.</p><p>Recipients are required to access messages through a one-time passcode, valid Microsoft account, or work account in order to decrypt messages, and <a href="https://www.itpro.com/security/encryption/355608/microsoft-will-let-end-users-revoke-encrypted-emails-in-office-365" data-original-url="https://www.itpro.com/security/encryption/355608/microsoft-will-let-end-users-revoke-encrypted-emails-in-office-365">end-users can revoke access</a> to sent emails at any time.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday" data-original-url="/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday">Microsoft still searching for zero-day fixes following Patch Tuesday</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" data-original-url="/network-internet/email-providers/358887/the-most-secure-email-services">The most secure email services of 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369042/new-ransomware-encryption-threatens-cyber-security-strategy" data-original-url="/security/ransomware/369042/new-ransomware-encryption-threatens-cyber-security-strategy">New approach to ransomware encryption threatens to undermine cyber security strategies</a></p></div></div><p>However, OME imposes no usage limitations on the attachment itself. It's possible, therefore, that threat actors could intercept the attachments, <a href="https://www.itpro.com/hardware/367538/best-all-in-one-printers" data-original-url="https://www.itpro.com/hardware/367538/best-all-in-one-printers">print</a> them, or be forwarded them by the original recipient with little remediation possible on the sender’s end.</p><p>WithSecure reported the issue, which it classifies as a vulnerability, to Microsoft on 11 January. However, after several repeated attempts to contact the tech giant, and a notice that it would go public with the disclosure, WithSecure claims it received the following message from Microsoft on 21 September:</p><p>"The report was not considered meeting the bar for security servicing, nor is it considered a breach. No code change was made and so no CVE was issued for this report."</p><p>Researchers cite Microsoft compliance documentation to posit that ECB is used to maintain backwards compatibility with legacy versions of Office, which only support <a href="https://www.itpro.com/security/29671/what-is-aes-encryption" data-original-url="https://www.itpro.com/security/29671/what-is-aes-encryption">Advanced Encryption Standard (AES)</a> 128-bit ECB.</p><p>In addition to OME, enterprise users can use two other encryption services within Office 365. These are Information Rights Management (IRM), and S/MIME, which both offer greater control over the access rights of sent messages. Messages sent through these alternatives are also encrypted using different methods of operation, but come with their own accessibility benefits and drawbacks.</p><p>“The rights management feature is intended as a tool to prevent accidental misuse and is not a security boundary," a Microsoft spokesperson told <em>IT Pro.</em></p><p>"To help prevent abuse we recommend customers follow best security practices, including keeping systems up to date, enabling multi-factor authentication, and using a real time anti-malware product.”</p><p>Microsoft also stated that its use of ECB encryption supports legacy applications, and that it is working on alternative encryption protocols for future product versions.</p><p><em>This article has been updated to include a statement from Microsoft.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The best TeamViewer alternatives ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/remote-access/368061/8-best-teamviewer-alternatives</link>
                                                                            <description>
                            <![CDATA[ Exploring TeamViewer alternatives? These eight remote desktop software tools are feature-packed and could help you save money ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bdZnZud1tQA7sGQevgeiDE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/R3Z2Y26xow9hGrjRLvdLAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Oct 2022 10:16:31 +0000</pubDate>                                                                                                                                <updated>Mon, 30 Jun 2025 08:36:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ nik@nikrawlinson.com (Nik Rawlinson) ]]></author>                    <dc:creator><![CDATA[ Nik Rawlinson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ &lt;p&gt;Nik Rawlinson is a journalist with over 20 years of experience writing for and editing some of the UK’s biggest technology magazines. He spent seven years as editor of MacUser magazine and has written for titles as diverse as Good Housekeeping, Men&#039;s Fitness, and PC Pro.&lt;/p&gt;
&lt;p&gt;Over the years Nik has written numerous reviews and guides for ITPro, particularly on Linux distros, Windows, and other operating systems. His expertise also includes best practices for cloud apps, communications systems, and migrating between software and services.&lt;/p&gt;
&lt;p&gt;Nik is also a prolific writer of books — both fact and fiction — almost all of which you can find on Amazon. In most cases, he produces not only the words and pictures but the layouts, too.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/R3Z2Y26xow9hGrjRLvdLAF-1280-80.jpg">
                                                            <media:credit><![CDATA[TeamViewer]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TeamViewer demonstrated on a monitor, smartphone and tablet]]></media:description>                                                            <media:text><![CDATA[TeamViewer demonstrated on a monitor, smartphone and tablet]]></media:text>
                                <media:title type="plain"><![CDATA[TeamViewer demonstrated on a monitor, smartphone and tablet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/R3Z2Y26xow9hGrjRLvdLAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Celebrating its 20th year in 2025, it's little surprise that <a href="https://www.itpro.com/mobile/remote-access/368053/what-is-teamviewer">TeamViewer</a> is one of the first names to come to mind when looking for a remote access solution. Built for Windows, Windows Server, macOS, and common Linux distros, it lets you administer a whole fleet of remote machines from a single keyboard and mouse – or from an Android or iOS client.</p><p>It's primarily used by IT technicians who need to access clients' or employees' devices, and by employees who need to access office computers from home or while travelling. As well as facilitating remote control of a distant machine, much like VNC, some tiers allow for file transfer, video conferencing, and collaboration.</p><p>Pricing varies, based on features and use case, with single-user access to three managed devices starting at £15.90 a month, billed annually. A single business licence, at £35.90, adds Google Meet integration, mobile device support, the ability to record and play back sessions, and a 200-device limit. Team plans run from £67.90 for 15 users and 300 devices, and enterprise pricing is fully customised, so quoted on request.</p><p>Non-profit and education users get a 30% discount, and there's a free tier for personal use, although that drops support for file transfers, Wake on LAN, and remote printing.</p><p>However, TeamViewer isn't your only option. A wide range of alternatives offers a similar set of core tools plus a range of specific features tailored to particular use cases. Here, we'll take a look at six alternatives you may want to consider alongside TeamViewer.</p><h2 id="the-best-teamviewer-alternatives-available">The best TeamViewer alternatives available</h2><h3 class="article-body__section" id="section-chrome-remote-desktop"><span>Chrome Remote Desktop</span></h3><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oNMVg8jduedWn3553eLcg9" name="ChromeRemoteDesktop" alt="The Chrome Remote Desktop logo on the ITPro background" src="https://cdn.mos.cms.futurecdn.net/oNMVg8jduedWn3553eLcg9.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Google/Future)</span></figcaption></figure><p><a href="http://remotedesktop.google.com">Chrome Remote Desktop</a> uses a proprietary protocol to connect computers over the web. It's entirely browser-based, as you might expect from Google, and guests don't need to install anything, so long as their browser supports WebRTC. Most modern browsers will satisfy these requirements.</p><p>Host machines will need to be running <a href="https://www.itpro.com/web-browsers/24796/best-browser-chrome-vs-edge-vs-firefox">Firefox or Chrome</a>, plus the necessary host utility, which you can download for free from remotedesktop.google.com. Once installed, set a six digit pin to protect your machine and grant the necessary access rights at the OS level – and you're done. The connection is saved to your Google Account, so all you need to do to use it is log in to the same account on a second machine, and click the name of the device you want to access.</p><p>Once connected, you can set up clipboard synchronisation so that anything copied on one machine can be pasted on the other, and you can transfer files between machines by opening the hidden sidebar (look for the tab on the right of the browser window).</p><p>If you won't need to return to the remote machine several times, you can instead set up an ad-hoc connection by generating a one-time code on the host and typing it in on the guest. This function is hived off in a separate Remote Support section, and although it's for short-term use, so isn't the option you'd use if you regularly want to work with your own machine remotely, it still allows keyboard and mouse control of the host.</p><p><a href="https://www.itpro.com/mobile/remote-access/368056/what-is-chrome-remote-desktop">Chrome Remote Desktop</a> is a neat, free solution for accessing remote machines, on either a one-off or ongoing basis. For many smaller businesses, it offers everything they're likely to need, without the associated price tag.</p><p><em>Read more on </em><a href="https://www.itpro.com/mobile/remote-access/368055/how-to-set-up-chrome-remote-desktop"><em>Chrome Remote Desktop </em></a><em>for more information.</em></p><h3 class="article-body__section" id="section-idrive-remotepc"><span>IDrive RemotePC</span></h3><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eVdtiGQGhvCwF3ZiLX4wNH" name="iDrive_logo.jpg" alt="The IDrive logo on the ITPro background" src="https://cdn.mos.cms.futurecdn.net/eVdtiGQGhvCwF3ZiLX4wNH.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>RemotePC, from cloud-backup specialist <a href="https://www.itpro.com/cloud/cloud-storage/367988/idrive-vs-onedrive">IDrive</a>, is another through-the-browser solution that doesn't require dedicated software on the guest machine. However, it does offer a connector for RDP should you need it, and there are apps for Android and iOS.</p><p>Setup is refreshingly simple. Install the host utility on the remote machine and log in to your RemotePC account on both devices. You'll see a list of all enrolled machines on your guest device, where a Connect button lets you initiate an in-browser or app-based connection. Once up and running, you can collaborate with remote users using chat or whiteboard (the latter allowing you to draw directly on their screen), blank their terminal while you work, and exchange files using the integrated file browser.</p><p>RemotePC's flexible pricing is both feature- and seat-based. Soho pricing starts at $79.50 for five computers (discounted in the first year) and offers file transfer, remote printing, session recording, remote chat, and support for <a href="https://www.itpro.com/technology/how-to-work-on-windows-macos-and-linux-at-the-same-time">Windows, macOS, and Linux</a>. There's even a package for Raspberry Pi.</p><p>The Team tier (from $299.50 for 50 computers) rolls in Active Directory / SSO and on-demand remote support, and Enterprise plans, for which pricing is advertised up front (starting at $599.60 for 100 computers) allow you to organise computers into groups, and set roles and access permissions for users. As you'd expect, each tier includes every feature of the tiers below, and there are two consumer plans for home use.</p><p>We were impressed by both how easy this was to set up and use. The up-front Enterprise pricing, which is often hidden elsewhere, was likewise welcome. The fact that there's a free seven-day trial for all plans that don't require card details means there's nothing to be lost in giving it a go.</p><p><em>Read our full </em><a href="https://www.itpro.com/software/idrive-remotepc-team-2023-review-affordable-cloud-hosted-remote-support"><em>IDrive review</em></a><em> for more information.</em></p><h3 class="article-body__section" id="section-logmein-pro"><span>LogMeIn Pro</span></h3><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1903px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="MZQbjH4oKS3hkuubKyRAyC" name="logmein_rescue_copy.jpg" alt="The LogMeIn Rescue dashboard" src="https://cdn.mos.cms.futurecdn.net/MZQbjH4oKS3hkuubKyRAyC.jpg" mos="" align="middle" fullscreen="" width="1903" height="1070" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>LogMeIn Pro is part of a varied portfolio of remote control and access platforms from GoTo, where it sits alongside training, webinar, and communications products. It's aimed primarily at small businesses and offers both browser- and app-based access. The browser-based screen viewer is still in beta at the time of writing.</p><p>We performed our tests using the <a href="https://www.itpro.com/software/logmein-rescue-review-for-those-who-want-the-strictest-access-security-for-their-remote-support-services">LogMeIn</a> client on a Mac, from which we connected to a Windows PC. This initially asked for our Windows password, as it doesn't support PIN-based login (which we use to access Windows). Entering our Microsoft account credentials did the trick, and it's possible to set up an access code as an alternative inside LogMeIn itself.</p><p>Once up and running, you can chat between machines, exchange files, draw on the remote display, and use an on-screen laser pointer. If you have a PC at both ends of the connection, you can drag and drop files between them, but if either is a Mac, you'll need to use the file browser instead</p><p>Upon clicking to end the remote connection, the client warned us that the host wasn't "completely protected from modern cyber threats" and prompted us to install LogMeIn's own antivirus software powered by Bitdefender. We opted not to do this as the host was already running Windows Security virus and threat protection.</p><p>The recommended Power Users plan starts at £69.99 a month (£839 a year), discounted to £699 if you opt for an annual payment. This lets an unlimited number of users access to five computers. The small business plan, at £108 per month when paid annually, ups the computer count to 10. These might not be impulse-purchase prices, but there's no need to commit right away: LogMeIn offers a generous 14 day free trial for which there's no need to enter any card details.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nkJY2faZ4P9fjuCkSx3EiA" name="nkJY2faZ4P9fjuCkSx3EiA.jpg" caption="" alt="Whitepaper on unified endpoint management and security,with image of female working remotely at a laptop on her sofa" src="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere"><em>Find out why companies are using XDR as a supplement to existing EDR solutions</em></a></p></div></div><p><em>Read our full </em><a href="https://www.itpro.com/software/business-software/360917/logmein-gotoassist-remote-support-5-review-a-great-support"><em>LogMeIn Pro review </em></a><em>for more information.</em></p><h3 class="article-body__section" id="section-realvnc-connect-8"><span>RealVNC Connect 8</span></h3><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SHbuHeYxUzUawuMse4wkJo" name="SHbuHeYxUzUawuMse4wkJo.jpg" alt="RealVNC logo" src="https://cdn.mos.cms.futurecdn.net/SHbuHeYxUzUawuMse4wkJo.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: RealVNC)</span></figcaption></figure><p><a href="https://www.itpro.com/mobile/remote-access/368067/vnc-connect-review">RealVNC</a> claims that more than a billion devices run its software. Connect 8 offers both code-based temporary control of remote machines, as well as longer term device enrollment for ongoing management. It's app-based rather than browser-based, with a unified server/client utility that handles both ends of the connection.</p><p>New in this version is a redesigned toolbar that you can move around the screen, and a reworked file transfer tool with a side-by-side view of local and remote files. These include in-session chat, session recording, and support for multiple monitors. At the time of writing, session handover and annotations were listed as upcoming features.</p><p>VNC passwords are set per-machine and are distinct from both your Windows login and your RealVNC account password (unless you set them to match). Devices are organised in the client app, optionally with a thumbnail of the last-known state, which can help you identify several similar machines if you only check in periodically.</p><p>Team plans start with the Plus tier, at £12.50 per active connection per month, which allows an unlimited number of users to connect to 50 devices. The Premium plan, at £20.75 per active connection per month, raises the device limit to 150 and adds support for audit logs of key events, MFA for sessions, and on-demand connections over LAN that don't traverse the cloud. There's also an Essentials plan (single user and three device limit) for £7.25 a month, and enterprise pricing is available on demand. Although prices are quoted per-month, billing is annual. RealVNC offers a 14-day free trial with no need to provide your card details up front.</p><p>Connect 8 works with Windows, macOS, and Linux. Essentials tier users can also connect to Raspberry Pi OS, which is perhaps not surprising given that both Raspberry Pi and RealVNC are based in Cambridge, UK, and RealVNC was <a href="https://www.itpro.com/software/operating-systems/362160/raspberry-pi-os-launches-first-stable-64-bit-release">Raspberry Pi's</a> default mode of remote access on launch.</p><p><em>Read our full </em><a href="https://www.itpro.com/mobile/remote-access/368067/vnc-connect-review"><em>RealVNC Connect review</em></a><em> for more information.</em></p><h3 class="article-body__section" id="section-splashtop-remote-access"><span>Splashtop Remote Access</span></h3><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="y4SAxrocawSrfvc5UfNzV4" name="y4SAxrocawSrfvc5UfNzV4.jpg" alt="Splashtop logo" src="https://cdn.mos.cms.futurecdn.net/y4SAxrocawSrfvc5UfNzV4.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Splashtop)</span></figcaption></figure><p><a href="https://www.itpro.com/mobile/remote-access/368071/splashtop-business-review">Splashtop</a> supports remote Windows, macOS and <a href="https://www.itpro.com/operating-systems/25139/linux-mint-vs-ubuntu-which-one-is-better">Linux</a> machines, accessed from Windows, Mac, iOS, Android, and Chromebook. You can also access virtual machines on a range of common cloud platforms, and it's even possible for two remote users to access the same host machine simultaneously. It requires a host app, known as a streamer, to be running on the remote computer, but clients can connect using either the accompanying business app or via the browser. We took this latter option and authenticated ourselves using our Microsoft Account credentials.</p><p>The cheapest business plan – Pro – is keenly priced at £7 per user, per month. Aimed at individuals and small teams that need to work remotely, it supports multiple monitors, and chat, and session recording. The Performance plan, at £10 per user per month, builds on this with 240FPS compatibility, high-fidelity audio, USB pass-through, and both remote stylus and Wacom Bridge, with support for pressure, orientation, tilt, and size of stylus during the session. This will likely make Splashtop Remote Access an appealing proposition for hybrid design teams.</p><p>Enterprise pricing is available as a quote, and at the opposite end of the scale, there's a Solo tier for individual users at £5 a month. This allows unattended remote access, file transfer, and remote printing. Although prices are quoted per-month, billing is annual.</p><p><em>Read our full </em><a href="https://www.itpro.com/mobile/remote-access/368071/splashtop-business-review"><em>Splashtop review</em></a><em> for more information.</em></p><h3 class="article-body__section" id="section-zoho-assist"><span>Zoho Assist</span></h3><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XKo2AwrJbjDsH3YcJyr8Zo" name="XKo2AwrJbjDsH3YcJyr8Zo.jpg" alt="Zoho Assist logo" src="https://cdn.mos.cms.futurecdn.net/XKo2AwrJbjDsH3YcJyr8Zo.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zoho)</span></figcaption></figure><p>Zoho has separate plans for remote support and unattended access, each starting at £10 a month (reduced to an equivalent £8 per month if you pay for a year up front). They require a host application on the remote machine for access through the browser at the local end. This enables clipboard sharing, instant chat, video and voice chat, file transfer, and multi-monitor navigation. There's also a free plan, but this drops support for file transfers and remote screen blanking, as well as limiting the number of enrolled technicians to one (this is unlimited on all other plans).</p><p>Windows, macOS, and Linux are supported at all levels, but you'll need to upgrade to at least the Professional tier (£14 / £12 per month for monthly or annual access respectively) if you need to support ChromeOS, iOS, Android, or IoT devices.</p><p>As well as being interactive with the remote display, you can perform a lot of powerful admin tasks through the browser, without affecting the remote user's screen. For example, the browser-based Task Manager displays all running services and applications, which you can shut down from a distance. You can access the Device Manager, add and remove users, edit the Registry, and more. You can also enable Wake on LAN, where supported, so that you can activate and log into machines that have gone to sleep.</p><p>Assist is a flexible platform that's easy to get up and running – and, like the others featured here, you can try it yourself, for 15 days, without providing card details.</p><p><em>Read our full </em><a href="https://www.itpro.com/networking/29443/zoho-assist-review"><em>Zoho Assist review</em></a><em> for more information.</em></p><h2 id="further-reading-on-remote-desktops">Further reading on remote desktops</h2><p>If you'd like to learn more about remote desktop technology and platforms, we've got a wide range of content available for your reference. </p><p>Learn more about protocols such as <a href="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp">RDP</a>, <a href="https://www.itpro.com/mobile/remote-access/368057/what-is-xrdp">XRDP</a> or <a href="https://www.itpro.com/mobile/remote-access/368108/what-is-vnc">VNC</a> and <a href="https://www.itpro.com/mobile/remote-access/368053/what-is-teamviewer">what TeamViewer offers</a>; find out <a href="https://www.itpro.com/mobile/remote-access/368101/how-to-use-microsoft-remote-desktop-connection">how to use Microsoft Remote Desktop</a> and <a href="https://www.itpro.com/mobile/remote-access/368070/how-to-use-remote-desktop-on-windows-10">how to use remote desktop on Windows 10</a>.</p><p>If you need walkthroughs for setting up remote access via Microsoft or Apple OS', see <a href="https://www.itpro.com/mobile/remote-access/368069/how-to-use-remote-desktop-on-mac" target="_blank">how to use remote desktop on Mac</a>, <a href="https://www.itpro.com/mobile/remote-access/368055/how-to-set-up-chrome-remote-desktop" target="_blank">how to set up Chrome Remote Desktop</a>; and <a href="https://www.itpro.com/mobile/remote-access/368068/how-to-remote-desktop-from-mac-to-windows" target="_blank">how to remote desktop from Mac to Windows</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GSMA partners with IBM, Vodafone on Post-Quantum Telco Network Taskforce ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/network-internet/369208/gsma-ibm-vodafone-quantum-telco-network-taskforce</link>
                                                                            <description>
                            <![CDATA[ The three organisations will work together to create a roadmap to implement quantum-safe networking ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j7TEshPQk8CmhDedwn7KNa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Bat2UBH5PpLBjZ6V8ZMbhC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Sep 2022 09:56:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Bat2UBH5PpLBjZ6V8ZMbhC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract fractal render of glowing neon purple shapes with a glowing padlock symbol overlaid]]></media:description>                                                            <media:text><![CDATA[Abstract fractal render of glowing neon purple shapes with a glowing padlock symbol overlaid]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract fractal render of glowing neon purple shapes with a glowing padlock symbol overlaid]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Bat2UBH5PpLBjZ6V8ZMbhC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The GSMA has teamed up with IBM and Vodafone to form the GSMA Post-Quantum Telco Network Taskforce, which the trio say will support the roadmap for post-quantum cryptology.</p><p>Their aim is to help define policy, regulation, and operator business processes for the enhanced protection of telecommunications as <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing" data-original-url="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> takes on a more prominent role.</p><p>Instead of relying on bits for calculation like today’s computers, quantum machines leverage the exponential power of quantum bits, called qubits. That involves a simultaneous mix of 0s and 1s and opens up the possibility of solving complex of problems that today’s supercomputers struggle with.</p><p>The Taskforce has been set up to help navigate these new waters. The team will help define requirements, identify dependencies, as well as create the roadmap to implement <a href="https://www.itpro.com/security/cyber-security/356584/quantum-security-the-end-of-security-as-we-know-it" data-original-url="https://www.itpro.com/security/cyber-security/356584/quantum-security-the-end-of-security-as-we-know-it">quantum-safe networking</a>, to help mitigate potential risks.</p><p>“The GSMA Taskforce’s goal is to bring together leading global communication services providers with experts from IBM, Vodafone, and other operators and ecosystem partners to understand and implement quantum-safe technology,” said Alex Sinclair, Chief Technology Officer at the GSMA.</p><p>These future quantum-safe controls will aim to protect sensitive business information and consumer data from attackers that harvest present-day data for later decryption.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LSdLhNv8ZDJAzbBQMKxLSa" name="LSdLhNv8ZDJAzbBQMKxLSa.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/LSdLhNv8ZDJAzbBQMKxLSa.png" mos="https://cdn.mos.cms.futurecdn.net/LSdLhNv8ZDJAzbBQMKxLSa.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The future of work is already here. Now’s the time to secure it.</strong></p><p class="fancy-box__body-text">Robust security to protect and enable your business</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369060/the-future-of-work-is-already-here-nows-the-time-to-secure-it" data-original-url="/security/369060/the-future-of-work-is-already-here-nows-the-time-to-secure-it">FREE DOWNLOAD</a></p></div></div><p>That will be no small feat, either. In its announcement, the GSMA noted the World Economic Forum’s recent estimation that more than 20 billion devices will need to be upgraded or replaced in the next 10-20 years in order to use the new forms of quantum-safe <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encrypted communication</a>.</p><p>“By working together to establish consistent policies, we can define quantum-safe approaches that protect critical infrastructure and customer data, complementing our ongoing security efforts to increase resiliency in future networks,” Sinclair added.</p><p>Back in July 2022, the U.S. National Institute of Standards and Technology (NIST) announced it had chosen the first four post-quantum cryptography algorithms to be standardised for cyber security in the quantum computing era.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/369135/ses-esa-and-european-commission-partner-on-satellite-based-quantum" data-original-url="/security/encryption/369135/ses-esa-and-european-commission-partner-on-satellite-based-quantum">SES, ESA and European Commission partner on satellite-based quantum cryptography system</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/368889/chinas-internet-giant-baidu-unveils-first-quantum-computer" data-original-url="/hardware/368889/chinas-internet-giant-baidu-unveils-first-quantum-computer">China’s internet giant Baidu unveils first quantum computer</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/368915/how-quantum-computing-could-change-cyber-security" data-original-url="/security/encryption/368915/how-quantum-computing-could-change-cyber-security">How quantum computing could change cyber security</a></p></div></div><p>These were designed to rely on the computational difficulty of problems from the mathematical areas such as lattices, isogenies, hash functions, and multivariate equations, and protect current systems from future quantum machines.</p><p>Taskforce member IBM, which boasts the world’s largest fleet of cloud-accessible quantum computers, contributed to the development of three of these four chosen algorithms.</p><p>“Given the accelerated advancements of quantum computing, data and systems secured with today’s encryption could become insecure in a matter of years,” warned Scott Crowder, Vice President of IBM Quantum Adoption and Business Development.</p><p>“IBM is pleased to work with the GSMA Post-Quantum Telco Network Taskforce members to prioritize the telco industry’s move to adopt quantum-safe technology.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SES, ESA and European Commission partner on satellite-based quantum cryptography system  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/369135/ses-esa-and-european-commission-partner-on-satellite-based-quantum</link>
                                                                            <description>
                            <![CDATA[ The project will determine the course of EAGLE-1, which may launch as early as 2024 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tEieNoDcjFfrC2yLRG2nKa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mAv2fWK3jZwaTLTNRCUkKR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Sep 2022 11:25:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mAv2fWK3jZwaTLTNRCUkKR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Satellite orbiting Earth]]></media:description>                                                            <media:text><![CDATA[Satellite orbiting Earth]]></media:text>
                                <media:title type="plain"><![CDATA[Satellite orbiting Earth]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mAv2fWK3jZwaTLTNRCUkKR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A consortium of 20 European companies led by the federal government’s Senior Executive Service (SES) is set to build Europe’s first sovereign Quantum Key Distribution (QKD) system.</p><p>The move is anticipated to facilitate secure cryptographic key transmission to bolster cyber security among European nations.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9exnyaj6XxZMJPE3sGkDPB" name="9exnyaj6XxZMJPE3sGkDPB.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9exnyaj6XxZMJPE3sGkDPB.png" mos="https://cdn.mos.cms.futurecdn.net/9exnyaj6XxZMJPE3sGkDPB.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Go ahead, dream big: The Dell EMC PowerVault ME4 platform</strong></p><p class="fancy-box__body-text">Delivering fast, affordable storage, optimised for the big plans of growing businesses</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/368833/go-ahead-dream-big-the-dell-emc-powervault-me4-platform" data-original-url="/infrastructure/server-storage/368833/go-ahead-dream-big-the-dell-emc-powervault-me4-platform">FREE DOWNLOAD</a></p></div></div><p>Per reports, the EAGLE-1 satellite-based QKD system will be developed in partnership with the European Space Agency (ESA) and European Commission. An operations centre is also underway in Luxembourg, in addition to a dedicated low earth orbit satellite.</p><p>On a related note, it is anticipated that the EAGLE-1 satellite will launch in 2024 and will be in orbit for three years with support from the European Commission.</p><p>A QKD demonstration and validation from low earth orbit to the ground will be completed by ESA and EU Member States through EAGLE-1, which will aid next-generation quantum communication infrastructures (QCIs) using valuable space mission data.</p><p>Most importantly, the breakthrough in in-orbit technologies will pave the way for sovereign and autonomous cross-border quantum communications networks. Furthermore, the consortium will work towards developing a QKD payload, terrestrial optical station, scalable quantum operational networks, and key management system to facilitate EAGLE-1’s ultra-secure cryptographic key exchange system.</p><p>Josef Aschbacher, ESA director general, said: “European space innovation has gained strong momentum both from a technology perspective and in terms of commercialisation. It allows us to develop and implement next-generation, future-proof projects in space across critical domains like secure communication, next-generation networks and cybersecurity.”</p><p>“Led by ESA, partially financed by the European Commission and implemented by SES, EAGLE-1 is a major step towards making the secure and scalable European Quantum Communications Infrastructure a reality,” added Aschbacher.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Signal hires former Google manager Meredith Whittaker as first president ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-operations/368997/signal-hires-former-google-manager-meredith-whittaker-as-first-president</link>
                                                                            <description>
                            <![CDATA[ An outspoken critic of the dangers of AI, Whittaker promises to keep Signal users out of tech giants' "surveillant gaze" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vDQ54oBXrUmBeGY2S7qGiy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mwMPSgPKWjWjoKQdka7tQQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Sep 2022 12:47:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mwMPSgPKWjWjoKQdka7tQQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Signal]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A headshot of Meredith Whittaker, against a light grey background]]></media:description>                                                            <media:text><![CDATA[A headshot of Meredith Whittaker, against a light grey background]]></media:text>
                                <media:title type="plain"><![CDATA[A headshot of Meredith Whittaker, against a light grey background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mwMPSgPKWjWjoKQdka7tQQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Signal has appointed Meredith Whittaker, co-founder of the AI Now Institute and founder of Google’s Open Research Group, as its first-ever president.</p><p>As president, effective September 12, Whittaker will be responsible for company strategy. <a href="https://www.washingtonpost.com/technology/2022/09/06/signal-meredith-whittaker">Speaking</a> to <em>The Washington Post</em>, she outlined her priority as sustaining the firm’s funding, noting that it “costs tens of millions of dollars per year to develop and maintain an app like Signal.”</p><p>The encrypted messaging service Signal is primarily known for its app, which provides users with <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption (E2EE)</a> on all messages by default and has been <a href="https://www.itpro.com/security/encryption/355956/signal-app-use-surges-as-protests-spread" data-original-url="https://www.itpro.com/security/encryption/355956/signal-app-use-surges-as-protests-spread">widely used by protesters</a> seeking to avoid surveillance.</p><p>A former Google manager, Whittaker was one of the main organisers of the 2018 walkout that saw 20,000 employees leave their desks to protest the company’s handling of sexual harassment cases and forced arbitration. After drawn out action, the movement <a href="https://www.itpro.com/policy-legislation/33064/google-employees-win-class-action-rights-after-long-fought-fight" data-original-url="https://www.itpro.com/policy-legislation/33064/google-employees-win-class-action-rights-after-long-fought-fight">secured Google employees' class action rights and an end to the forced arbitration practice</a>.</p><p>Further protests in which Whittaker was involved centred around Google’s involvement in the Pentagon’s ‘Project Maven’, which would have seen AI used to enhance the capabilities of military drones. Employee pressure eventually <a href="https://www.itpro.com/machine-learning/30891/google-publishes-ethical-code-for-ai-following-project-maven-fallout" data-original-url="https://www.itpro.com/machine-learning/30891/google-publishes-ethical-code-for-ai-following-project-maven-fallout">forced Google to withdraw from the project altogether, and publish an AI ethics code</a>.</p><p>Since leaving the company, Whittaker has been a prominent critic of <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" data-original-url="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai">artificial intelligence (AI)</a> and <a href="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology" data-original-url="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology">facial recognition technology</a>, testifying before congress that both carry the risk of entrenching existing <a href="https://www.itpro.com/technology/artificial-intelligence-ai/361824/how-biased-is-your-app" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/361824/how-biased-is-your-app">biases</a> against minorities. She has also advised the Federal Trade Commission on AI in the role of senior advisor.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368815/signal-confirms-1900-users-impacted-by-twilio-breach" data-original-url="/security/cyber-attacks/368815/signal-confirms-1900-users-impacted-by-twilio-breach">Signal confirms 1,900 of its users were hit by Twilio breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms" data-original-url="/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms">Zoom adds end-to-end encryption to Zoom Phone and Breakout Rooms</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/business-management/368531/red-hat-appoints-matt-hicks-as-ceo" data-original-url="/business-operations/business-management/368531/red-hat-appoints-matt-hicks-as-ceo">Red Hat appoints Matt Hicks as CEO</a></p></div></div><p>“Signal is not made for pristine academic speculation, it is made to be used by real people, all over the world,” stated Whittaker, in a <a href="https://signal.org/blog/announcing-signal-president">blog post</a> announcing her appointment to the role.</p><p>“And many millions do use it, turning to Signal for a safe and pleasant space where intimate, experimental, and private communication can happen outside of the surveillant gaze of dominant tech companies and states who can and do subpoena their data.</p><p>“I believe that Signal is core infrastructure whose growth and stability is imperative for a livable future. And as Signal’s President I will do everything I can to build on Signal’s firm foundation and vision, and to create a rich soil where Signal can continue to grow and thrive. </p><p>“I’m honored to be taking this role, and I’m grateful to the team whose careful work makes Signal possible, and to the community beyond who contribute labor and intelligence that helps us maintain our rigorous standards. Onward!”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="X45j9iJmNPhLBRNurdifFT" name="X45j9iJmNPhLBRNurdifFT.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" mos="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cyber resiliency and end-user performance</strong></p><p class="fancy-box__body-text">Reduce risk and deliver greater business success with cyber-resilience capabilities</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368832/cyber-resiliency-and-end-user-performance" data-original-url="/security/368832/cyber-resiliency-and-end-user-performance">FREE DOWNLOAD</a></p></div></div><p>Whittaker assumes her position amidst growing government hostility towards the use of E2EE in messaging apps. The <a href="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn" data-original-url="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn">currently stalled</a> Online Safety Bill <a href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" data-original-url="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">received an amendment in July that would compel companies operating messaging apps to scan for child sexual exploitation</a> and abuse (CSEA) content and remove it from their platform or be fined up to 10% of their worldwide revenue. Firms would be required to use “best endeavours to develop or source” technology to do the same, effectively mandating backdoors into messaging apps that security services could use. </p><p>Last year, <a href="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls" data-original-url="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls">Meta continued with its roll out of encryption</a> as default across the direct messaging of its apps Messenger and Instagram, facing harsh criticism from the UK government. Despite this, <a href="https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it" data-original-url="https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it">experts have argued that E2EE is a necessary technology</a> and that restricting the technology would have a detrimental effect on the tech landscape.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How quantum computing could change cyber security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/368915/how-quantum-computing-could-change-cyber-security</link>
                                                                            <description>
                            <![CDATA[ The huge leap in computing performance from quantum computing poses a threat to traditional security, but there are steps you can take to guard against the quantum future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vwTenmU9V9Anp7yWmX5Z3F</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Sep 2022 16:23:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image representing the digital quantum world]]></media:description>                                                            <media:text><![CDATA[An image representing the digital quantum world]]></media:text>
                                <media:title type="plain"><![CDATA[An image representing the digital quantum world]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Quantum computing still sounds like the realm of science fiction. The promise is that quantum computing can perform calculations over a hundred million times quicker than the fastest current supercomputer. This will have hugely positive implications for solving the big problems in science.</p><p>But it has a darker side effect: encryption that would have taken thousands of years to crack with conventional computers could be dispatched in a matter of minutes – or even seconds. The implication today is that adversaries are currently able to hoover up and store data, which they can attack with a quantum computer in years to come. Some commercial and personal data will remain sensitive far into the future. So, it's worth future-proofing data to withstand quantum computing attacks.</p><h3 class="article-body__section" id="section-how-quantum-computing-works"><span>How quantum computing works</span></h3><p>The increased performance of quantum computing compared to existing 'Von Neumann' machines is such a massive leap that one could easily be forgiven for not believing it's real. But the speed is a by-product of how quantum computing works, which is markedly different. Traditional computer chips are still based around the computing concept devised by John Von Neumann and published in 1945. In this system, each operation is performed sequentially, by being read from the input device, worked on logically, and then output again back to storage.</p><p>Even massively parallel supercomputers function in this way. If they are performing thousands of operations at the same time, each one is still executed sequentially by the CPU core. GPUs are simpler than CPUs, but they contain sequential units too, albeit with much greater parallelisation of lots more units. Traditional computing also works with bits, which have two states - usually represented as 0 and 1. The input will be one state, and after operation the output will be the same or the other state. As problems get more complex, with more possibilities to calculate, breaking these into individual sequential calculations can mean they go well beyond the capabilities of current architectures.</p><p>This is not how quantum computers work. Rather than containing lots of individual computing cores to run sequential operations on single bits in parallel, a quantum computer works on the probability of an object’s state before it is measured. Known as a qubit, these states are undefined properties of an object prior to detection, such as the polarisation of a photon or spin of an electron. Because these quantum states don’t have a clear position before measurement, they mix many different possible positions at once, rather than just two.</p><p>However, despite being undefined until measured, these mixed states can be 'entangled' with those of other objects in a mathematically related way. By applying the mathematics of this entanglement to an algorithm, complex problems can be solved in essentially one operation. On the one hand, this can be used for very difficult science such as predicting multiple particle interactions in a chemical reaction or creating security codes that are much more difficult to break than current ones. But conversely, they can also be used to crack existing codes that would have been impossible to breach with current computer technology, because they can run through lots of possible solutions at once.</p><p>Putting this in perspective, a conventional computer would take around 300 trillion years – 22,000 times the age of the universe – to crack the ubiquitous 2,048-bit RSA encryption. But a quantum computer with 4,099 qubits would require just 10 seconds, using Shor’s Algorithm, which is designed to find the prime factors of an integer used in encryption keys. It’s clear that there is a danger looming for many forms of cryptography. For example, the ubiquitous SSL and TLS used for encrypting web connections employ 2,048-bit RSA keys and would therefore be vulnerable to being breached by a quantum computer.</p><h3 class="article-body__section" id="section-how-fast-are-current-quantum-computers"><span>How fast are current quantum computers?</span></h3><p>The good news is that we were not at this stage just yet. While 4,099 qubits don’t sound like a lot when we now have 64-core processors executing more than 3 billion operations per second per core, it’s still more than the most potent current quantum computer. IBM’s Eagle, unveiled at the end of 2021, only has 127 qubits. Google’s Sycamore only has 53 qubits, the University of Science and Technology of China’s Jiuzhang has 76 cubits, and most quantum processors (QPUs) have fewer than 50 qubits. There are ‘quantum annealing’ processors from D-Wave with up to 5,760 qubits, but these require a limited set of possible outcomes, and can’t run the Shor’s Algorithm required to break encryption.</p><p>Development is moving forward, however. Xanadu plans to launch a 216-qubit QPU called Borealis in 2022, and IBM aims to hit 433 qubits in 2022 with Osprey, followed by 1,121 qubits with Condor in 2023. So while traditional encryption remains safe for now, it will not be the case for much longer. IBM’s roadmap, for example, is aiming for 4,158 qubits by 2025, making it likely that cracking 2,048-bit RSA virtually in real time will be possible before 2030, which is the final year when NIST originally reckoned it would still be secure. You may not be able to go out and buy a quantum computing desktop computer by 2030 – D-Wave’s first commercially available quantum computer cost $15 million when it shipped in 2017. Prices will fall, but it is only likely to be large companies and countries that have QPUs for years to come. However, not all those countries will have our best interests at heart, so the danger is looming.</p><h3 class="article-body__section" id="section-hardening-cyber-security-against-quantum-computing"><span>Hardening cyber security against quantum computing</span></h3><p>Fortunately, there is time to get ready for the threat; for example, by using security products based on post-quantum cryptography. These products can protect your sensitive data today and future-proof it against attacks from quantum computers.</p><p>Current encryption algorithms use either integer factorisation, discrete logarithms, or elliptic-curve discrete logarithms, all of which Shor’s Algorithm can defeat using a quantum computer. Post-quantum cryptography switches to alternative approaches that are not vulnerable to quantum computing. Research is still in its infancy based around six primary methods, but there are already products appearing that employ the technology. One example is <a href="https://www.qstvpn.com" rel="nofollow" target="_blank">QST-VPN</a>, based on the OpenVPN library but with post-quantum secure algorithms protecting user data. The server software is provided via the AWS cloud, with clients for Windows, MacOS and a wide range of Linux distributions, and offers an opportunity for businesses to begin bolstering their security now, rather than after the quantum horse has bolted.</p><p>Quantum computing has massive potential to revolutionise how fast we can perform calculations. Like every new technological development, this has both good and bad implications. But now that we know what’s in store for cyber security – in the not-too-distant future – we can at least prepare, so that the beneficial potential of quantum computing prevails over the more nefarious possibilities.</p><p><a href="https://www.qstvpn.com" rel="nofollow" target="_blank"><strong><em>Learn more about how QST-VPN can help protect your business</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How will the Online Safety Bill change the tech industry? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/368807/how-will-the-online-safety-bill-change-the-tech-industry</link>
                                                                            <description>
                            <![CDATA[ The landmark legislation will affect 25,000 companies, and is among the first laws directly regulating the business practices of tech giants ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nEYTcUrXxTLMqfswA8Bt8q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tUGnwHKCa2wdDmKtYW3qS7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Aug 2022 09:01:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tUGnwHKCa2wdDmKtYW3qS7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouette of a child using a tablet in a dark room with blue lighting]]></media:description>                                                            <media:text><![CDATA[Silhouette of a child using a tablet in a dark room with blue lighting]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouette of a child using a tablet in a dark room with blue lighting]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tUGnwHKCa2wdDmKtYW3qS7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Rumbling in the wings of the government’s policy programme for the last few years has been the widely anticipated Online Safety Bill.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368763/what-will-it-take-2022-uk-digital-strategy" data-original-url="/business/policy-legislation/368763/what-will-it-take-2022-uk-digital-strategy">What will it take to make the UK's 2022 Digital Strategy a success?</a></p></div></div><p>This major piece of legislation will be among the first laws directly regulating tech companies and the way they operate, with 25,000 businesses falling under the scope of this complex framework. The overarching ambition is to make the internet a safer place to be – given it’s reportedly rife with terrorism, hate speech and exploitative content – although critics say it infringes on free speech. </p><p>Nevertheless, it still represents a marked change in the way business is conducted online, with those affected expected to adapt, or face huge financial penalties, when it eventually comes into force. </p><h2 id="what-is-the-online-safety-bill">What is the Online Safety Bill?</h2><p>First proposed formally in March 2021, the Online Safety Bill effectively regulates the content that any “user-to-user service” makes available online. It seeks to make <a href="https://www.itpro.com/data-insights/big-data/358795/pros-and-cons-of-breaking-up-big-tech" target="_blank" data-original-url="https://www.itpro.com/data-insights/big-data/358795/pros-and-cons-of-breaking-up-big-tech">big tech companies</a> more responsible for the material they host on their platforms in order to protect their users. </p><p>The Bill applies to search engines, internet services that host user generated content and those that publish or display pornographic content. It’s been designed to make the UK “the safest place in the world to be online” while defending free expression. It also aims to improve law enforcement’s capacity to tackle harmful content online, improve users’ ability to keep themselves safe, and improve society’s understanding of the harms landscape.</p><p>The legislation proposes a shift away from self regulation, which has arguably failed, to one that promotes accountability and a safety-first mindset. Under this model, tech companies will need to be able to demonstrate they have evaluated key risks. This includes misinformation, predatory behaviour, and cyber bullying. They need to have proven there are suitable protections and safeguarding mechanisms in place on their platforms, with those falling short of these expectations facing massive fines. These will either be up to 10% of annual turnover, or £18 million, which are similar levels to fines under the General Data Protection Regulation (GDPR).</p><h2 id="how-has-the-online-safety-bill-evolved">How has the Online Safety Bill evolved?</h2><p>In the many months <a href="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official">since this legislation was introduced</a>, the government has amended its terms to reflect more regulatory requirements. Initially, Ofcom was granted a statutory duty of care to enforce the terms of the <a href="https://www.itpro.com/marketing-comms/social-media/358129/tech-firms-face-billions-of-pounds-in-fines-for-failing-to" target="_blank" data-original-url="https://www.itpro.com/marketing-comms/social-media/358129/tech-firms-face-billions-of-pounds-in-fines-for-failing-to">Online Harms white paper</a>, which was produced as a result of a two-year consultation.</p><p>In February this year, for example, the government introduced an amendment <a href="https://www.itpro.com/business/policy-legislation/362182/porn-sites-uk-age-verification-online-safety-bill" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/362182/porn-sites-uk-age-verification-online-safety-bill">compelling websites containing pornographic content</a> to use secure age verification technology on their platforms. The following month, the scope of the legislation expanded from the purest sense of ‘online harms’ to also <a href="https://www.itpro.com/security/scams/365805/online-safety-bill-harmful-ads-scams" target="_blank" data-original-url="https://www.itpro.com/security/scams/365805/online-safety-bill-harmful-ads-scams">include fraudulent and misleading adverts</a>, which social media sites and search engines would have to do more to protect UK users from.</p><p>The government then changed a key provision in the Online Safety Bill in July, with an <a href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">amendment forcing companies to identify child sexual exploitation and abuse (CSEA) content</a> and take it down. Previous iterations of the law only required companies to use “accredited technology” to detect CSEA and terrorism content, but the amendment goes further in stating companeis should further seek to use “best endeavours to develop or source technology” to automatically detect and take such material offline.</p><p>Then, less than a week later, the government <a href="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn">inadvertently put the Online Safety Bill on ice</a> after failing to include its third reading in the parliamentary schedule before the summer recess. This means the legislation will be delayed, and possibly subject to change when a new prime minister is appointed by the Conservative Party in September.</p><h2 id="why-do-some-feel-the-online-safety-bill-doesn-t-go-far-enough">Why do some feel the Online Safety Bill doesn’t go far enough?</h2><p>Charlotte Aynsley, safeguarding advisor at Impero Software, says the Bill needs clearer directives around reporting and referrals. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rNAQoa9nwMcMG72HQokQfh" name="rNAQoa9nwMcMG72HQokQfh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" mos="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Storage's role in addressing the challenges of ensuring cyber resilience</strong></p><p class="fancy-box__body-text">Understanding the role of data storage in cyber resiliency</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber" data-original-url="/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber">FREE DOWNLOAD</a></p></div></div><p>“There is currently no centralised system to make referrals, nor is there clear guidance or clarification on who these referrals go to and how they will be progressed,” she tells <em>IT Pro</em>. “If they do go to the police, how will this then be managed? It is vital that victims feel reassured by knowing their incident will be addressed – if people don’t think any action will be taken, or there isn’t a timely response, there is a risk that harmful incidents will continue to go unreported,” she says.</p><p>Dr Bill Mitchell, director of policy at BCS, the Chartered Institute for IT, says the Bill leaves a lot of abstract definitions, and much of the concrete expectations for what platforms will be asked to do will be set out in secondary legislation and codes of practice. He adds that this means “it’s currently very difficult to assess what exactly platforms will be asked to do to reduce harms and protect rights, and whether it will be sufficient”.</p><p>“For instance, platforms will need to take into account the importance of ‘democratically important content’ – the definition of which is extremely unclear,” he explains.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a></p></div></div><p>For Robin Wilton, meanwhile, a director at the Internet Society, one omission in the legislation is highly significant – <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encryption</a>. “The Bill only mentions encryption twice, and not in a meaningful way: it says that if a service provider gets a law enforcement request for access to data and, in providing that <a href="https://www.itpro.com/strategy/28185/what-is-data-mining" target="_blank" data-original-url="https://www.itpro.com/strategy/28185/what-is-data-mining">data</a>, encrypts it so that it is unusable by law enforcement, it’s committing an offence. Fine. I wonder how many times that has ever happened in the past. I suspect it’s none.”</p><h2 id="how-will-the-online-safety-bill-affect-big-tech">How will the Online Safety Bill affect big tech?</h2><p>Hand in hand with the raft of new obligations are new costs that companies falling in syncope will have to absorb, according to Luke Jackson, a director at Yorkshire-based law firm Walker Morris LLP.</p><p>“As well as the mooted Ofcom regulator fee, many will need to commission specialist support to ensure compliance – be that with subscriptions for policing and age-gating software or legal fees to interpret the act and understand risk exposure,” he says.</p><p>Worryingly, there’s also scope in the legislation to compel companies to develop flawed <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">security</a> in their products, critics allege. Wilton says that, until now, the Bill stopped short of allowing the government to compel the tech industry to design their products in such a way that might not be feasible. However, the latest amendments removed any doubt. The July update, instructing tech companies to implement technology <a href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">automatically scanning messages</a>, is an example. </p><p>“This is “scope creep” of the worst kind, and in all probability, it won’t work,” he adds. “Consider this: today, Apple announced a $10m research fund to “harden” devices against spyware probes like Pegasus. By contrast, the UK Government’s “Safety Tech Challenge Fund”, to develop <a href="https://www.itpro.com/business-strategy/business-transformation/368712/uk-safety-tech-sees-another-year-of-growth" target="_blank" data-original-url="https://www.itpro.com/business-strategy/business-transformation/368712/uk-safety-tech-sees-another-year-of-growth">“safe” tools for backdoor access</a> has distributed £85,000 each to a handful of start-ups. The Online Safety Bill will not prevent secure communication technology from reaching the mass consumer market, but it could prevent UK users from being lawfully allowed to use it. That represents significant harm for no visible benefit.”</p><h2 id="how-will-the-online-safety-bill-change-the-wider-industry">How will the Online Safety Bill change the wider industry?</h2><p>The Bill sets out to take on the big tech companies, but it has the potential to impact any business that is operating in the digital space. Jackson says that the legislation could well require a mindset shift for all enterprises with an online presence, requiring them to prevent online harm as a driving principle in the way their web presences are delivered. </p><p>Jackson adds that, for consumers, the idea of an Online Safety Bill should, in theory, be a good thing. “A reduction in the spread of misinformation, online abuse and inappropriate content for children would undoubtedly make the Internet a better place,” he says. “However, as some have pointed out, there is a very delicate balance to be struck between shielding users from harmful content whilst protecting freedom of speech.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill" data-original-url="/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill">Why does the UK government want to replace GDPR with the Data Reform Bill?</a></p></div></div><p>When, or if, enacted, the Online Safety Bill is likely to cause much controversy in the form of projected weakened security in products and services. Wilton says that the bill not only enables scope creep, but in the context of technology, it also allows societal scope creep, as this is also built into the Bill. Wilton explains that it allows the secretary of state for Digital, Culture, Media and Sport (DCMS) to add new categories to the list of banned content through secondary legislation.</p><p>“That means no parliamentary scrutiny, and it’s a licence for the minister to ban whatever he or she chooses,” he explains. “That could be ‘communicating about an anti-Government protest; it could be ‘saying rude things about the minister’; it could be ‘demanding information about secret donations to political parties’; it could be ‘publishing information about access to abortion’,” he says. “We live in an information society, with a data-driven economy, and a population of digital natives. We cannot allow the government to weaponise digital technology against its citizens."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK safety tech sees another year of growth, amidst backlash ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/business-transformation/368712/uk-safety-tech-sees-another-year-of-growth</link>
                                                                            <description>
                            <![CDATA[ Record investment in the sector has led to widespread implementation of safety measures, but rights groups and some experts still aren't convinced ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uZybb1spqWvMeZaGwnMcZ5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eMQuoqqyAsijwMr7Mrh6pM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Aug 2022 14:55:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eMQuoqqyAsijwMr7Mrh6pM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI padlock with many two-dimensional projections of itself projecting out from it towards the camera, with code streaming across their surfaces]]></media:description>                                                            <media:text><![CDATA[A CGI padlock with many two-dimensional projections of itself projecting out from it towards the camera, with code streaming across their surfaces]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI padlock with many two-dimensional projections of itself projecting out from it towards the camera, with code streaming across their surfaces]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eMQuoqqyAsijwMr7Mrh6pM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK safety tech sector revenues hit £381 million last year, the government has announced, an increase of 21% across the ‘world-leading’ industry. </p><p>This was matched by the creation of jobs within the sector, with a total number of 2,850 now available marking a 30% increase from the previous year.</p><p>Additionally, 57% of safety tech firms <a href="https://www.itpro.com/business-strategy/34625/the-best-uk-cities-to-live-and-work-in" data-original-url="https://www.itpro.com/business-strategy/34625/the-best-uk-cities-to-live-and-work-in">were based outside of London and the South East</a>, a sizeable increase from the 48% based outside of these regions just two years prior. In total, 117 firms have been identified as currently offering safety tech solutions.</p><p>In a blog post, the government specifically championed safety tech such as tools used to detect and remove child sexual exploitation and abuse (CSEA) content. These systems have been put in the spotlight by the government’s <a href="https://www.itpro.com/marketing-comms/social-media/362045/online-safety-bill-missed-opportunity-child-abuse-dcms" data-original-url="https://www.itpro.com/marketing-comms/social-media/362045/online-safety-bill-missed-opportunity-child-abuse-dcms">Online Safety Bill</a>, which seeks to <a href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" data-original-url="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">compel companies to use or develop such tools</a> to even work on messages currently protected by <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption (E2EE)</a>.</p><p>The bill has drawn criticism from rights organisations such as The Open Rights Group, which <a href="https://www.openrightsgroup.org/press-releases/governments-online-safety-bill-is-an-orwellian-censorship-machine">has described</a> the measures as “an Orwellian censorship machine.” A recent survey of industry experts also revealed that <a href="https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it" data-original-url="https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it">66% thought ending E2EE would have a negative impact on protecting society</a>, while Meta <a href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023" data-original-url="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">plans rollout of E2EE across Messenger and Instagram</a> in 2023.</p><p>Last year, the government set up the <a href="https://www.gov.uk/government/news/government-funds-new-tech-in-the-fight-against-online-child-abuse">Safety Tech Challenge Fund</a>, a £555,000 competition to find novel solutions for combatting CSEA content without impacting people’s rights to privacy. These include artificial intelligence (AI) and facial recognition solutions for detecting child abuse images before upload.</p><p>At the time, it was announced that the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> would offer advice to the winners, to protect privacy throughout the development process.</p><p>However, doubts have been raised over the feasibility of regulation of direct messaging that also retains privacy measures. Last year several rights organisations signed <a href="https://bigbrotherwatch.org.uk/2021/06/big-brother-watch-signs-joint-letter-to-mps-to-protect-end-to-end-encryption">an open letter to MPs</a>, stating that the tech being sought by the government would be bad for business as well as individual privacy.</p><p>“End-to-end encryption means that your constituents’ family photographs, messages to friends and family, financial information, and the commercially sensitive data of businesses up and down the country, can all be kept safe from harm’s way,” the letter stated.</p><p>“It also keeps us safer in a world where connected devices have physical effect: end-to-end encryption secures connected homes, cars and children’s toys. The government should not be making those more vulnerable to attack.”</p><p>At the time of writing, the Online Safety Bill <a href="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn" data-original-url="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn">has been put ‘on ice’</a> amidst Conservative Party restructuring, leaving the timeline for when these changes can be expected to be passed into law unclear.</p><p>When the house returns in September the bill could be redrafted, or scrapped entirely under the leadership of either Liz Truss or Rishi Sunak.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech" data-original-url="/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech">Why the UK is dragging its feet on regulating big tech</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms" data-original-url="/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms">Zoom adds end-to-end encryption to Zoom Phone and Breakout Rooms</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28115/the-pros-and-cons-of-net-neutrality" data-original-url="/strategy/28115/the-pros-and-cons-of-net-neutrality">The pros and cons of net neutrality</a></p></div></div><p>For now, safety tech sees no signs of slowing, as <a href="https://www.gov.uk/government/publications/safer-technology-safer-users-the-uk-as-a-world-leader-in-safety-tech/uk-safety-tech-sector-2022-analysis#supporting-the-safety-tech-sector">67% of firms within the sector</a> predict a customer base increase of 50% or more within the next 12 months. </p><p>“Making the online world safer is not only the right thing to do, it’s good for business,” said digital minister Damien Collins</p><p>“UK tech firms are at the cutting-edge developing practical solutions to the risks posed by the internet so that it continues to be a benefit not a detriment to people’s lives.</p><p>“They have blazed a trail of growth, innovation and job creation to become world leaders in their field and we are committed to maintaining their upward trajectory.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom adds end-to-end encryption to Zoom Phone and Breakout Rooms ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/368624/zoom-adds-end-to-end-encryption-to-zoom-phone-and-breakout-rooms</link>
                                                                            <description>
                            <![CDATA[ Users will need to be on the same Zoom account for E2EE for Zoom Calls to work ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qH4LYafWrW8KC7cg3uz4Jy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8mxV7rogumbJtMhEsnf9m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Jul 2022 09:56:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8mxV7rogumbJtMhEsnf9m-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Zoom logo on a mobile phone]]></media:description>                                                            <media:text><![CDATA[The Zoom logo on a mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[The Zoom logo on a mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8mxV7rogumbJtMhEsnf9m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zoom is expanding its privacy and security capabilities by adding end-to-end encryption (E2EE) settings to more of its services.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" data-original-url="/software/355486/zoom-review-are-we-alone-now">Zoom review: Are we alone now?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/video-conferencing/360877/zoom-the-pandemic-powered-tech-giant" data-original-url="/software/video-conferencing/360877/zoom-the-pandemic-powered-tech-giant">Zoom: From pandemic upstart to hybrid work giant</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a></p></div></div><p>In the coming months, <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end to end encryption</a> will be available on its cloud-based Zoom Phone and in meeting Breakout Rooms.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8ywDr2ijNoUdeD3qsTehn4" name="8ywDr2ijNoUdeD3qsTehn4.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/8ywDr2ijNoUdeD3qsTehn4.jpg" mos="https://cdn.mos.cms.futurecdn.net/8ywDr2ijNoUdeD3qsTehn4.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The challenge of securing the remote working employee</strong></p><p class="fancy-box__body-text">The IT Pro Guide to Sase and successful digital transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/361930/the-challenge-of-securing-the-remote-working" data-original-url="/business-strategy/digital-transformation/361930/the-challenge-of-securing-the-remote-working">FREE DOWNLOAD</a></p></div></div><p>Breakout Rooms lets an admin divide the participants in a meeting into smaller groups that come together in their own mini-meeting within the larger one.</p><p>For Zoom Phone calls, users can add <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">E2EE</a> during a call by selecting "more" and hitting the option for the higher level of encryption. When enabled, the call will be encrypted using cryptographic keys known only to the devices that belong to the caller and the receiver. This can also be verified with special E2EE status in the form of a security code the participants can share with one another.</p><p>However, to enable E2EE users will have to have a few things in place first. Their account will need to have E2EE turned on in the web portal and both callers will need to be on the same Zoom account. Both callers will also have to use the Zoom Phone desktop or mobile client and neither caller can record the call - automatic call recording will also have to be turned off. What's more, E2EE is only available for one-to-one calls.</p><p>Although other Zoom services previously had end to end encryption options, these protections did not extend to Breakout Rooms. Before today's change, creating a meeting and attempting to set it to E2EE would automatically disable the Breakout Rooms feature.</p><p>To extend the encryption to Breakout Rooms, each breakout will have its own unique encryption key. The feature is not live yet, though Zoom says it is coming "soon".</p><p>E2EE on Zoom was something of a <a href="https://www.itpro.com/security/cyber-security/356104/mozilla-urges-zoom-to-encrypt-free-video-calls" data-original-url="https://www.itpro.com/security/cyber-security/356104/mozilla-urges-zoom-to-encrypt-free-video-calls">PR disaster</a> in the early days of the pandemic when the video conferencing platform <a href="https://www.itpro.com/software/video-conferencing/360877/zoom-the-pandemic-powered-tech-giant" target="_blank" data-original-url="https://www.itpro.com/software/video-conferencing/360877/zoom-the-pandemic-powered-tech-giant">quickly grew in popularity</a>. It only began <a href="https://www.itpro.com/security/357551/zoom-starts-rolling-out-end-to-end-encryption-for-all-users" target="_blank" data-original-url="https://www.itpro.com/security/357551/zoom-starts-rolling-out-end-to-end-encryption-for-all-users">rolling out E2EE for meetings in October 2020</a>, after months of various security problems, such as <a href="https://www.itpro.com/security/357785/zoom-adds-three-new-ways-to-stop-call-disruption" target="_blank" data-original-url="https://www.itpro.com/security/357785/zoom-adds-three-new-ways-to-stop-call-disruption">Zoomboming</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta begins encrypting Facebook URLs, nullifying tracking countermeasures ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368588/meta-begins-encrypting-facebook-urls-nullifying-tracking-countermeasures</link>
                                                                            <description>
                            <![CDATA[ The move has made URL stripping impossible but will improve analytics ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5y7N7wqU3nJgtaiv6kA9Ps</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e2GMzvNcdoRzqxaorTmQJ7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Jul 2022 10:39:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e2GMzvNcdoRzqxaorTmQJ7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screen with a stylised M logo and the word Meta sits on a reflective surface]]></media:description>                                                            <media:text><![CDATA[A screen with a stylised M logo and the word Meta sits on a reflective surface]]></media:text>
                                <media:title type="plain"><![CDATA[A screen with a stylised M logo and the word Meta sits on a reflective surface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e2GMzvNcdoRzqxaorTmQJ7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has doubled down on its inclusion of tracking parameters in URLs posted to Facebook, by encrypting URLs to include parameters within required portions of the address itself.</p><p>When a user clicks a link shared through Facebook, all kinds of parameters are added to the URL. Some of these, such as utm_source and utm_medium are used by analytics sites such as <a href="https://www.itpro.com/data-insights/big-data/361469/15-best-google-analytics-courses" data-original-url="https://www.itpro.com/data-insights/big-data/361469/15-best-google-analytics-courses">Google Analytics</a> to measure where traffic is coming from, and how much of it there is.</p><p>Facebook has historically used the parameter <a href="https://developers.facebook.com/docs/marketing-api/conversions-api/parameters/fbp-and-fbc">fbclid</a> to measure what sites its users visit and which links they click, whether or not those sites support Facebook’s tracking script Meta Pixel. These are then used to tailor users’ ad profiles, to target them more effectively.</p><p>URLs under the new system lack clearly defined parameter names, appearing instead as a long string of letters and numbers in which all the address and tracking information is included in an encrypted format.</p><p>It is normally possible to strip certain parameters from URLs, removing the tracking element and increasing link privacy. Some browsers even offer URL stripping as a built-in choice, for privacy-minded users.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/367545/eu-rules-against-meta-in-data-privacy-row" data-original-url="/policy-legislation/data-protection/367545/eu-rules-against-meta-in-data-privacy-row">EU rules against Meta in data privacy row</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" data-original-url="/data-protection/34415/how-to-maintain-your-privacy-on-social-media">How to maintain your privacy on social media</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn" data-original-url="/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn">UK government puts Online Safety Bill 'on ice'</a></p></div></div><p>These include Firefox, which last month introduced a feature called ‘Query Parameter Stripping’ that automatically removes tracking parameters from URLs to improve the privacy profile of its users. This can be activated in the browser's configuration settings. The browser <a href="https://www.itpro.com/network-internet/web-browser/357356/privacy-leaders-release-one-click-method-to-handle-online" data-original-url="https://www.itpro.com/network-internet/web-browser/357356/privacy-leaders-release-one-click-method-to-handle-online">Brave</a> also supports a URL stripping feature. With its move to encrypt the URL parameters, Meta has greatly impacted the ability of such tools to effectively strip the tracking elements.</p><p>In binding tracking elements with the URLs in such a way that it is impossible to tell where the web address ends and the parameters begin, Meta has found a way to track data for advertising almost unavoidably. This is a boost for its analytics operation, as well as for the tech giant's advertising partners whose interests include targeted data on as many users as possible.</p><p>With <a href="https://backlinko.com/browser-market-share">153 million users</a>, Firefox represents a not insignificant pool of users to Meta, which enjoyed just under <a href="https://www.statista.com/statistics/271258/facebooks-advertising-revenue-worldwide">$115 billion in revenue</a> last year largely through advertising.</p><p><em>It Pro</em> has reached out to Meta for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK government puts Online Safety Bill 'on ice' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/368547/uk-government-delays-online-safety-bill-until-autumn</link>
                                                                            <description>
                            <![CDATA[ Delaying the third reading until the autumn gives the next prime minister and digital secretary a chance to revise, or throw out, the legislation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7iQ2Wm25x83KfrkXMjyoUY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kxZQEquVYmYZ83js5dGjm3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jul 2022 12:07:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kxZQEquVYmYZ83js5dGjm3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of the Houses of Parliament by the Thames on a sunny day]]></media:description>                                                            <media:text><![CDATA[An image of the Houses of Parliament by the Thames on a sunny day]]></media:text>
                                <media:title type="plain"><![CDATA[An image of the Houses of Parliament by the Thames on a sunny day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kxZQEquVYmYZ83js5dGjm3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The contentious Online Safety Bill has been delayed by the government as a result of the inner turmoil in the Conservative party.</p><p>Its third reading in the House of Commons was due to take place next Wednesday, but this crucial stage has been pushed back to at least the autumn. The leader of the House of Commons Mark Spencer published next week’s schedule ahead of parliament's summer recess without a mention of the bill. Instead of debating the Online Safety Bill, the government has tabled a motion of no confidence in itself, alongside a debate around the Northern Ireland protocol bill.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" data-original-url="/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">Online Safety Bill: Messaging apps 'forced to scan messages' for child abuse content in fresh amendment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/scams/365805/online-safety-bill-harmful-ads-scams" data-original-url="/security/scams/365805/online-safety-bill-harmful-ads-scams">Harmful ads and scams to be included in Online Safety Bill</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/362182/porn-sites-uk-age-verification-online-safety-bill" data-original-url="/business/policy-legislation/362182/porn-sites-uk-age-verification-online-safety-bill">Online Safety Bill will require porn sites to verify age of UK users</a></p></div></div><p>This could potentially kill off the legislation, as its passage through parliament will be overseen by a new prime minister and perhaps a new secretary of state for digital, culture, media and sport (DCMS), both of whom may not support the bill in its current form.</p><p>The legislation is highly contentious not only because it raises the prospect of banning legal, albeit harmful, content, but also because it compels prominent players in the tech industry to implement sweeping changes across their platforms. The most recent amendment, for example, compels tech companies and messaging services to either develop or acquire technology <a href="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages">that automatically scans messages for content that's deemed harmful</a>.</p><p>Potential Tory leader candidate Kemi Badenoch commented on the matter on Twitter, calling it the right move and underlining that the bill is in no fit state to become law.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1547344817671311360"></a></p></blockquote><div class="see-more__filter"></div></div><p>“If I’m elected Prime Minister I will ensure the bill doesn’t overreach. We should not be legislating for hurt feelings,” she <a href="https://twitter.com/NadineDorries/status/1547320086318485505" target="_blank">said</a>.</p><p>In response, Nadine Dorries, the current DCMS secretary replied: “Which part of the bill legislates for hurt feelings, Kemi?” on Twitter.</p><p>“The Online Safety Bill is fundamentally misconceived. It holds out the threat that our social media posts will be removed and censored, and goes to the heart of our basic right to express our opinions online, and to hear the opinions of others,” said Monica Horten, free expression policy manager of the Open Rights Group. </p><p>Horten added the campaign website belonging to Penny Mordaunt, another Tory leader candidate, is being listed as <a href="https://www.itpro.com/strategy/28709/what-is-e-safety" target="_blank" data-original-url="https://www.itpro.com/strategy/28709/what-is-e-safety">unsafe for children</a> and blocked by customers of some broadband providers, using their filters, which shows what can and will go wrong.</p><p>“As it stands, the bill would mean everyone’s social media posts are monitored in case they are ‘harmful’ or illegal, and even private messages could be scanned,” explained Horten. “What is ‘harmful’ will be decided by government ministers behind closed doors. While the motivations may be good, the result is bad for free speech. MPs now have a chance for a rethink, which is long overdue, if we want to protect our free society from arbitrary censorship and <a href="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-storage/366617/why-video-surveillance-is-about-more-than-just-security">mass surveillance</a>.”</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1547525635555336192"></a></p></blockquote><div class="see-more__filter"></div></div><p>In January, a DCMS <a href="https://www.itpro.com/marketing-comms/social-media/362045/online-safety-bill-missed-opportunity-child-abuse-dcms" target="_blank" data-original-url="https://www.itpro.com/marketing-comms/social-media/362045/online-safety-bill-missed-opportunity-child-abuse-dcms">committee report outlined</a> that the Online Safety Bill fails to tackle child abuse and violence against women and girls. The committee called on MPs to address the issues in the bill, and described the draft legislation in its form as a “missed opportunity”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The psychology of secure passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368438/the-psychology-of-secure-passwords</link>
                                                                            <description>
                            <![CDATA[ The tricks for overcoming poor security hygiene like weak passwords and password reuse ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wSzCPqW5iisPy12vbVrToS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HNidZTvZznte3bL5tD3wGA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jul 2022 11:49:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HNidZTvZznte3bL5tD3wGA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wooden head silhouette mounted on planks with cogs inside it. A magnifying glass shows details of the cogs.]]></media:description>                                                            <media:text><![CDATA[Wooden head silhouette mounted on planks with cogs inside it. A magnifying glass shows details of the cogs.]]></media:text>
                                <media:title type="plain"><![CDATA[Wooden head silhouette mounted on planks with cogs inside it. A magnifying glass shows details of the cogs.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HNidZTvZznte3bL5tD3wGA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Passwords, in recent months, have been the source of much contention in cyber security, with the viability of conventional authentication methods under fire. Although a string of companies are bidding to remove passwords from the information security scene altogether, the reality is they’re still widely prevalent and likely to remain so. Most people lean on passwords to log into anything from personal email accounts to business-critical apps and services, so keeping them secure remains a paramount concern.</p><p>The threat of hackers cracking weak passwords, meanwhile, has only escalated in recent years. Not only has the spotlight been shone onto poor cyber security hygiene practices like password reuse, but a string of historic data breaches mean many credentials are in circulation around the web. Although it’s difficult to avoid a cyber security horror story in today’s age, the unfortunate truth is the majority of people are prone to reverting to easy solutions when devising passwords. Astoundingly, for example, the <a href="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed">most common password of 2021</a> was ‘123456’, which was used by more than 100 million individuals.</p><p>Insecure passwords have long been an issue, with cyber security expert Troy Hunt <a href="https://www.troyhunt.com/science-of-password-selection" rel="nofollow" target="_blank">expressing alarm in 2011</a> that passwords generally tend to follow a similar trend. They’re relatively short (between six and ten characters), simple (less than 1% had a non-alphanumeric character) and predictable (more than a third were in a common password dictionary). In the 11 years since, how much has actually changed? Not an awful lot, it seems, and businesses can’t risk their employees using short, simple and common passwords to access critical business systems. That’s where a password management tool, like Synology C2 Password, comes in to help us safeguard data with stronger access protections and password generation.</p><h3 class="article-body__section" id="section-guess-my-password"><span>Guess my password</span></h3><p>The state of password hygiene across society is poor – thanks, in a large part, to the way our brains work and the limitations of our memory. Beyond ‘123456’, the most common passwords in the top five are ‘password’, ‘1234578’, ‘qwerty’ and ‘123456789’, <a href="https://wpengine.com/resources/passwords-unmasked-infographic" rel="nofollow" target="_blank">according to WPengine</a>. Examining the top 50 most-used passwords suggests number sequences are incredibly common. Whole words such as ‘dragon’, ‘football’, ‘monkey’ and ‘master’ are also leant on heavily.</p><p>It confirms what many of us may have assumed; that people often instinctively choose passwords that might be easier to recall off the top of their head, rather than methodically choosing strong and complex passwords. There’s also the issue of password reuse. With so many passwords to remember, many people tend to just use the same one, or handful, across several user accounts. As a result, hackers wouldn’t need to employ sophisticated brute-force cracking tools often warned about to break into user accounts; they can simply reach for a handful of short and simple go-to words or number sequences.</p><p>Another trick many people lean on to complexify a weak password is to tack a number onto the end of it. Of the ten million passwords WPengine analysed, 8.4% ended with a number between 0 and 99; with people perhaps thinking it was easier to remember than using a more complicated letter and number combination. Of those, more than 20% of people used ‘1’ suggesting convenience is the key priority.</p><p>When choosing whole words as passwords, many people rather predictably tend to pick words from categories such as colours, animals, or fruits, in addition to first names, superheroes or even days of the week. This, of course, makes the job that much simpler for cyber criminals hoping to break into user accounts that aren’t protected with a password management tool. Poor password hygiene, indeed, does most of the heavy lifting. </p><h3 class="article-body__section" id="section-a-modern-remedy-to-age-old-problems"><span>A modern remedy to age-old problems</span></h3><p>How do we, collectively, move past the limits of our password-creating psychology? There are various methods to overcome poor password hygiene, including the National Cyber Security Centre (NCSC) recommendation to use three random words. Although the ‘three random word’ strategy is suited for use at both home and work, it might not be so simple for users to remember a few dozen different three-word combinations for the various apps, services and user accounts they’ll log in and out of on a daily basis.</p><p>Password reuse is, by far, the greatest risk with this strategy. Whild sensible on paper, most people will likely default to a handful of combinations and rotate as they see fit. Meanwhile, although two-factor authentication (2FA) might provide another barrier for cyber criminals, this isn’t entirely infallible and not all organisations offer such protective measures on every internal system.</p><p>Password managers are, by far, the most effective and simplest protective measure anyone can take when safeguarding their account credentials. The Synology C2 Password platform, in particular, is a shining example of a robust and free password management tool fitted with a litany of capabilities that collectively serve as a modern remedy to age-old problems associated with passwords.</p><p>Synology C2 Password allows users to store their passwords in a bank alongside other sensitive material like banking information, addresses and passport details, while keeping everything organised using categories, favourites and tags. The platform is also accessible across a multitude of devices, so you can add an item on your primary work machine and access it from your tablet, for example. Saved credentials, too, are also automatically filled in at login screens. </p><p>The most important feature, however, is the password generation tool. Synology C2 Password automatically generates and securely stores passwords for your essential apps and services, so you don’t have to generate and remember a complex and uncrackable password for each one you access. The use of AES-256 encryption to safeguard all data also ensures the password data cannot be remotely accessed or intercepted; items are encrypted before they leave your device to be stored on C2 servers. The decryption key, moreover, is stored on your devices and never shared with Synology C2 servers.</p><p>Poor password hygiene is a growing spectre in the security world, with the most common habits people lean on when devising passwords a huge factor. However, using a free password management tool like Synology C2 Password could be the most effective way to counter the shortcomings of human psychology, and completely wipe out the prevalence of bad habits like using number sequences or common words when setting passwords, or reusing passwords across multiple accounts.</p><p><a href="https://c2.synology.com/en-us/password/overview" rel="nofollow" target="_blank"><strong><em>Learn more about Synology C2 Password</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US unveils next-gen encryption tools to withstand quantum computing attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368469/us-unveils-encryption-tools-to-withstand-quantum-computer-attack</link>
                                                                            <description>
                            <![CDATA[ The National Institute of Standards and Technology (NIST) hopes to offer a variety of tools for quantum-proof encryption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jrtAQQBLGkwJJk3nW6qiKC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Jul 2022 10:10:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image representing the digital quantum world]]></media:description>                                                            <media:text><![CDATA[An image representing the digital quantum world]]></media:text>
                                <media:title type="plain"><![CDATA[An image representing the digital quantum world]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Commerce’s National Institute of Standards and Technology (NIST) has revealed the first four encryption tools that are designed to withstand future cyber attacks powered by quantum computing.</p><p>The four selected <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encryption</a> algorithms will become part of NIST’s post-quantum cryptographic standard, which is expected to be finalised in two years. They’ll be used to withstand potential future assaults by hackers using quantum computers, which may have the ability to crack the security used to protect privacy in digital systems, including in online banking and email software.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/high-performance-computing-hpc/361542/ibm-launches-most-powerful-quantum-chip" data-original-url="/server-storage/high-performance-computing-hpc/361542/ibm-launches-most-powerful-quantum-chip">IBM launches its 'most powerful' quantum processor</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/358966/the-quantum-internet-is-on-its-way" data-original-url="/infrastructure/network-internet/358966/the-quantum-internet-is-on-its-way">The quantum internet is on its way</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368351/quantum-is-the-future-of-aws-system-security-amazon-claims" data-original-url="/infrastructure/network-internet/368351/quantum-is-the-future-of-aws-system-security-amazon-claims">Quantum is 'the future of AWS system security', Amazon claims</a></p></div></div><p>The announcement is part of a six-year effort pushed by NIST when, in 2016, it called on the world’s cryptographers to devise and vet <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> methods that could resist an attack from a future <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing" target="_blank" data-original-url="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computer</a> that would be more powerful than today's most advanced hardware. NIST said the selection of these encryption tools marks the beginning of the finale of the agency’s post-quantum cryptography standardisation project.</p><p>Four additional <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" target="_blank" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithms</a> are under consideration for inclusion in the standard, and NIST plans to announce the finalists from that round in the near future. It said it’s announcing its choices in two stages because of the need for a robust variety of defence tools. The agency also said there are different systems and tasks that use encryption, and a useful standard would offer solutions designed for different situations, use varied approaches for encryption, and offer more than one algorithm for each use case in the event one proves vulnerable.</p><p>“NIST constantly looks to the future to anticipate the needs of US industry and society as a whole, and when they are built, quantum computers powerful enough to break present-day encryption will pose a serious threat to our information systems,” said under secretary of commerce for standards and technology, and NIST director, Laurie E Locascio. “Our post-quantum cryptography programme has leveraged the top minds in cryptography — worldwide — to produce this first group of quantum-resistant algorithms that will lead to a standard and significantly increase the security of our digital information.”</p><h2 id="which-encryption-tools-can-withstand-a-quantum-computer-attack">Which encryption tools can withstand a quantum computer attack?</h2><p>The four quantum-resistant algorithms rely on maths problems that both conventional and quantum computers should have difficulty solving, thereby defending <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">privacy</a> both now and down the road, added the agency.</p><p>The algorithms are designed for two main tasks for which encryption is typically used, general encryption, used to protect information exchanged across a public network, and digital signatures, used for <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy" target="_blank" data-original-url="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity authentication</a>. All four of the algorithms were created by experts collaborating from multiple countries and institutions. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R2jbpb4nBynt6hb5iyJKaD" name="R2jbpb4nBynt6hb5iyJKaD.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" mos="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing IBM Security QRadar XDR</strong></p><p class="fancy-box__body-text">A comprehensive open solution in a crowded and confusing space</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368459/introducing-ibm-security-qradar-xdr" data-original-url="/security/cyber-security/368459/introducing-ibm-security-qradar-xdr">FREE DOWNLOAD</a></p></div></div><p>For general encryption, used when users access secure websites, NIST has selected the CRYSTALS-Kyber algorithm. Its advantages include comparatively small encryption keys that two parties can exchange easily, as well as its speed of operation. </p><p>For digital signatures, often used when users need to verify identities during a digital transaction or to sign a document remotely, NIST has selected the three algorithms CRYSTALS-Dilithium, FALCON and SPHINCS+. Reviewers noted the high efficiency of the first two, and NIST recommends CRYSTALS-Dilithium as the primary algorithm, with FALCON for applications that need smaller signatures than Dilithium can provide. The third, SPHINCS+, is larger and slower than the other two, but is valuable as a backup for one key reason: It’s based on a different maths approach than all three of NIST’s other selections.</p><p>Three of the selected algorithms are based on a family of maths problems called structured lattices, while SPHINCS+ uses hash functions. The additional four algorithms still under consideration are designed for general encryption and do not use structured lattices or hash functions in their approaches. </p><p>While the standard is in development, NIST has encouraged <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> experts to explore the new algorithms and consider how their applications will use them, but not to deploy them into their systems yet, as the algorithms could change slightly before the standard is finalised.</p><p>To prepare, NIST said that users can inventory their systems for applications that use public-key cryptography, which will need to be replaced before cryptographically relevant quantum computers appear. They can also alert their IT departments and vendors about the upcoming change.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Online Safety Bill: Messaging apps 'forced to scan messages' for child abuse content in fresh amendment ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/368449/online-safety-bill-amendment-forced-to-scan-messages</link>
                                                                            <description>
                            <![CDATA[ Apps utilising end-to-end encryption would require backdoors or new mechanisms to allow user data to be scanned and passed on to authorities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aZrS7JABRRno2HtGLutCMq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3Cp2NjEUCP4hERMDna8cgH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Jul 2022 10:26:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3Cp2NjEUCP4hERMDna8cgH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand reaching out to touch a holographic padlock, which floats above a phone screen displaying green code]]></media:description>                                                            <media:text><![CDATA[A hand reaching out to touch a holographic padlock, which floats above a phone screen displaying green code]]></media:text>
                                <media:title type="plain"><![CDATA[A hand reaching out to touch a holographic padlock, which floats above a phone screen displaying green code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3Cp2NjEUCP4hERMDna8cgH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new amendment tabled for the upcoming Online Safety Bill would compel companies to identify child sexual exploitation and abuse (CSEA) content and take it down.</p><p>Previous versions of the bill have only compelled companies to use “accredited technology” to detect CSEA and terrorism content, but the <a href="https://publications.parliament.uk/pa/bills/cbill/58-03/0121/amend/onlinesafety_rm_rep_0706.pdf">July 6 amendment</a> goes further in stating that companies should further seek to use “best endeavours to develop or source technology” to detect and remove CSEA content.</p><p>It is unclear whether the government has undertaken research into what form this technology could take, or whether the expectation is companies will fall back on “accredited technology” such as encryption backdoors. </p><p>The clarification within the bill that the requirement applies to messages “communicated publicly or privately” seeks to extend oversight to messages currently protected by <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption</a> messaging, in which messages are encrypted before being transmitted and thus are accessible only by the sender and recipient.</p><p>Under powers already established in earlier drafts of the bill, Ofcom would have the power to fine non-compliant companies up to £18 million or 10% of their worldwide revenue in the most recent complete accounting period.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs" data-original-url="/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs">The government’s anti-encryption campaign shows it’s learned nothing from the war on drugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/scams/365805/online-safety-bill-harmful-ads-scams" data-original-url="/security/scams/365805/online-safety-bill-harmful-ads-scams">Harmful ads and scams to be included in Online Safety Bill</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps" data-original-url="/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps">What should we do about encrypted messaging apps?</a></p></div></div><p>The government argues that giving security and law enforcement services unfettered access to encrypted messages will improve safety at home and abroad, but critics have argued that once ways around message encryption are established, no messages can properly be considered private.</p><p>Companies such as Meta have committed to not only keeping WhatsApp direct messages encrypted but to eventually <a href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023" data-original-url="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">roll out end-to-end encryption</a> to Messenger and Instagram, a move which has increasingly put them at odds with government ideology.</p><p>The last few cabinets have been particularly vocal in their opposition to encryption. Last year, Home Secretary Priti Patel responded to Meta’s commitment to providing end-to-end encryption across its messaging platforms in harsh terms, stating:</p><p>"The offending will continue, the images of children being abused will proliferate - but the company intends to blind itself to this problem through end-to-end encryption which prevents all access to messaging content.” </p><p>The bill was first published as a draft in May 2021, and since then has been subject to much criticism for providing the government with what is seen as overreaching powers over privacy. The digital rights and freedoms organisation The Open Rights Group has been a particularly vociferous critic of the bill, which is described on its website as “an Orwellian censorship machine.” </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="d25pnmHteqMFEXehyV5g2n" name="d25pnmHteqMFEXehyV5g2n.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" mos="https://cdn.mos.cms.futurecdn.net/d25pnmHteqMFEXehyV5g2n.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Securing endpoints amid new threats</strong></p><p class="fancy-box__body-text">Ensuring employees have the flexibility and security to work remotely</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/367650/securing-endpoints-amid-new-threats" data-original-url="/technology/367650/securing-endpoints-amid-new-threats">FREE DOWNLOAD</a></p></div></div><p>“Dropping powers to ban encryption would be a major step forward if confirmed in the Bill. Ukrainians and Russian dissidents today are relying on encryption to protect themselves from real-world harm.</p><p>“We have repeatedly warned the Government that attacks on encryption would only help blackmailers, scammers and other criminals,” stated the Executive Director of the Open Rights Group, Jim Killock, in a <a href="https://www.openrightsgroup.org/press-releases/governments-online-safety-bill-is-an-orwellian-censorship-machine">blog post</a>.</p><p>WhatsApp was first released in 2009, but it wasn’t until two years after Facebook’s (now Meta) 2014 acquisition of the company that end-to-end encryption was fully implemented across the app. The WhatsApp <a href="https://www.whatsapp.com/security">product page on security</a> currently promises “only you and the person you're communicating with can read or listen to what is sent, and nobody in between, not even WhatsApp.”</p><p><em>IT Pro</em> has approached Meta for comment on the bill.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ QuSecure launches industry-first 'quantum security as a service' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/367756/qusecure-launches-industry-first-quantum-security-as-a-service</link>
                                                                            <description>
                            <![CDATA[ The post-quantum cyber security solution is targeted at enterprises and ‌government entities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">icWho9mkidfJk5FYUMtDmi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 May 2022 15:32:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image representing the digital quantum world]]></media:description>                                                            <media:text><![CDATA[An image representing the digital quantum world]]></media:text>
                                <media:title type="plain"><![CDATA[An image representing the digital quantum world]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sLegwVUXgYqkRs8Ay9Coxf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Post-quantum cryptography (PQC) expert QuSecure has unveiled its end-to-end quantum resilient orchestration platform, considered an industry-first.</p><p>Dubbed QuProtect, the new platform pairs PQC algorithms with a <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing" data-original-url="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum secure</a> channel to offer steadfast security for <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encrypted communications</a> and data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/amazon-web-services-aws/367746/aws-joins-argonne-led-quantum-research-center" data-original-url="/cloud/amazon-web-services-aws/367746/aws-joins-argonne-led-quantum-research-center">AWS joins Argonne-led quantum research center</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/367326/ibms-new-z16-mainframe-brings-two-industry-firsts-and-quantum-proof-data-encryption" data-original-url="/hardware/367326/ibms-new-z16-mainframe-brings-two-industry-firsts-and-quantum-proof-data-encryption">IBM's new z16 mainframe brings two industry-firsts and quantum-proof data encryption</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vEyW6wxoJVbEL6nagWmrdn" name="vEyW6wxoJVbEL6nagWmrdn.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/vEyW6wxoJVbEL6nagWmrdn.png" mos="https://cdn.mos.cms.futurecdn.net/vEyW6wxoJVbEL6nagWmrdn.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Achieving resiliency with Everything-as-a-Service (XAAS)</strong></p><p class="fancy-box__body-text">Transforming the enterprise IT landscape</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/367581/achieving-resiliency-with-everything-as-a-service-xaas" data-original-url="/cloud/367581/achieving-resiliency-with-everything-as-a-service-xaas">FREE DOWNLOAD</a></p></div></div><p>The cyber solution, designed to work round-the-clock on any device, is targeted at enterprises and government agencies.</p><p>The platform, sold as a service under the 'quantum security as a service (QSaaS)' moniker, can protect against <a href="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing" data-original-url="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing">present-day cyber attacks</a> and future quantum computing threats, according to QuSecure.</p><p>“QuSecure’s mission is to provide enterprises and government organizations with a comprehensive cryptographic orchestration platform that addresses today’s classical and future quantum threats,” said Dave Krauthamer, QuSecure CEO.</p><p>“Our QuProtect solution secures networks from current vulnerabilities using zero trust, next-generation standardized encryption, active monitoring, and attack remediation – all cloud-delivered in software to existing devices, over existing infrastructure.”</p><p>“We are creating an exceptionally secure future using a unique and comprehensive approach to cybersecurity that gives organizations a practical encryption solution for resilience to cyberattacks. Early customers tell us that a SaaS end-to-end PQC approach is optimal to address their critical needs for a practical post-quantum cybersecurity solution. QuProtect is the ‘easy button’ for this critical PQC upgrade,” added Krauthamer.</p><p>To support its work, QuSecure has created an advisory team compromised of leading experts in quantum cryptography. The team includes ARM CEO Rene Haas, Paul Touw, former Chief Strategist for the US Department of State and founder of Ariba Networks, Dr. Sarah McCarthy, postdoctoral researcher at the University of Waterloo and specialist in post-quantum cryptography, and Louie Gasparini, former CTO & VP of Product Management at RSA.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BT and Toshiba address QKD concerns with new trial ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/367508/bt-and-toshiba-address-qkd-concerns-with-new-trial</link>
                                                                            <description>
                            <![CDATA[ The National Cyber Security Centre (NCSC) previously raised concernsof potential attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mmYP2bfvo74GnkGKaMPjya</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xu5SFqdUJS2NAMtrahUruE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 Apr 2022 10:19:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xu5SFqdUJS2NAMtrahUruE-1280-80.jpg">
                                                            <media:credit><![CDATA[BT]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Map of BT and Toshiba&amp;#039;s QKD trial]]></media:description>                                                            <media:text><![CDATA[Map of BT and Toshiba&amp;#039;s QKD trial]]></media:text>
                                <media:title type="plain"><![CDATA[Map of BT and Toshiba&amp;#039;s QKD trial]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xu5SFqdUJS2NAMtrahUruE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>BT and Toshiba have officially launched the trial of their quantum-secured metro network which will protect the transmission of valuable data between multiple physical locations around London using quantum key distribution (QKD).</p><p>Although QKD offers <a href="https://www.itpro.com/infrastructure/357306/bt-toshiba-uks-first-unhackable-quantum-network" data-original-url="https://www.itpro.com/infrastructure/357306/bt-toshiba-uks-first-unhackable-quantum-network">“unhackable”</a> encryption that is powerful enough to protect organisations from the rising threat of quantum cyber attacks, it’s still susceptible to <a href="https://www.itpro.com/security/hacking/354435/xss-the-most-widely-used-attack-method-of-2019" data-original-url="https://www.itpro.com/security/hacking/354435/xss-the-most-widely-used-attack-method-of-2019">man-in-the-middle (MITM) attacks</a>, in which an exchange between two computer systems is breached by a third party.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/367492/aws-launches-quantum-random-number-generator" data-original-url="/cloud/cloud-computing/367492/aws-launches-quantum-random-number-generator">AWS launches quantum random number generator</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/367238/hsbc-and-ibm-partner-on-financial-quantum-computing-applications" data-original-url="/cloud/cloud-computing/367238/hsbc-and-ibm-partner-on-financial-quantum-computing-applications">HSBC and IBM partner on financial quantum computing applications</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/366315/bt-selects-google-cloud-digital-transformation" data-original-url="/business-strategy/digital-transformation/366315/bt-selects-google-cloud-digital-transformation">BT selects Google Cloud to support group-wide digital transformation</a></p></div></div><p>However, Andrew Shields, head of the Quantum Technology Division at Toshiba told <em>IT Pro</em> that BT and Toshiba’s network is protected from man-in-the-middle attacks through quantum-safe conventional cryptography authentication:</p><p>“When the other side receives a communication, they have to know where it's coming from and that hasn't been changed in transit and we use conventional cryptography to do that authentication,” said Shields. </p><p>The cryptography is quantum-safe, meaning that it “can’t be broken by a quantum computer”, he added.</p><p>BT's managing director for applied research Tim Whitley told <em>IT Pro</em> that BT had been in touch with the National Cyber Security Centre (NCSC), which previously <a href="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution" data-original-url="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution">raised the concerns</a> of potential man-in-the-middle attacks.</p><p>“They're fully aware of what we're doing in this trial and I think they’re actually very supportive of the research,” he said. The NCSC wasn’t immediately available to comment.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NeFDhiupASoeoyipbhF9uf" name="NeFDhiupASoeoyipbhF9uf.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NeFDhiupASoeoyipbhF9uf.jpg" mos="https://cdn.mos.cms.futurecdn.net/NeFDhiupASoeoyipbhF9uf.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of brand protection 2021</strong></p><p class="fancy-box__body-text">A new front opens up in the war for brand safety</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360246/the-state-of-brand-protection-2021" data-original-url="/security/cyber-security/360246/the-state-of-brand-protection-2021">FREE DOWNLOAD</a></p></div></div><p><a href="https://www.itpro.com/infrastructure/network-internet/361115/bt-toshiba-quantum-secured-network-london" data-original-url="https://www.itpro.com/infrastructure/network-internet/361115/bt-toshiba-quantum-secured-network-london">First announced in October 2021</a> and scheduled to last for three years, the trail follows a smaller-scale experiment <a href="https://www.itpro.com/infrastructure/network-internet/360861/bt-trials-quantum-secure-comms-worlds-first" data-original-url="https://www.itpro.com/infrastructure/network-internet/360861/bt-trials-quantum-secure-comms-worlds-first">successfully conducted last year</a> at BT’s research and engineering campus in Adastral Park, Ipswich, where researchers used a six-metre-long hollow, air-filled cable.</p><p>This time around, the fibre ring connecting the three BT core nodes has a total length of approximately 76 km, stretching from Slough to London’s West End and City, with a trial catchment area of 20km in radial distance.</p><p>Commenting on the official launch, Minister for Science, Research and Innovation George Freeman said that the trial “represents significant progress towards achieving our ambition to make the UK a quantum-enabled economy”. </p><p>“This is the kind of innovation that helps cement the UK as a global innovation economy in the vanguard of discovering, developing and commercially adopting transformational technology with real societal benefits," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Encryption battle plays out in Australian Parliament ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/367445/encryption-battle-plays-out-in-australian-parliament</link>
                                                                            <description>
                            <![CDATA[ The opposition said that the government is “addicted to secrecy” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">71Be512gwjS3QsyEZkFaYE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RAY34UxMVj7EGX4oe3GWVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Apr 2022 10:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RAY34UxMVj7EGX4oe3GWVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man holding smart phone with data security on display at office]]></media:description>                                                            <media:text><![CDATA[Man holding smart phone with data security on display at office]]></media:text>
                                <media:title type="plain"><![CDATA[Man holding smart phone with data security on display at office]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RAY34UxMVj7EGX4oe3GWVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An Australian committee report has outlined that public servants should retain records about government decisions, including messages sent via encrypted messaging or social media apps.</p><p>The report was published by the Parliamentary Joint Committee on Public Accounts and Audit this month. Although there are calls to strengthen existing legislation, the report didn’t support any changes or recommendations to the way the government keeps records of its communications.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" data-original-url="/security/privacy/361191/is-australia-becoming-a-surveillance-state">Is Australia becoming a surveillance state?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361348/australia-federal-police-plots-aggressive-cyber-division" data-original-url="/security/encryption/361348/australia-federal-police-plots-aggressive-cyber-division">Australian Federal Police plots "aggressive" cyber division following law change</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359249/facebook-might-jeopardise-childrens-safety-warns-home-secretary" data-original-url="/security/encryption/359249/facebook-might-jeopardise-childrens-safety-warns-home-secretary">UK gov warns Facebook's encryption plan could harm child safety</a></p></div></div><p>David Fricker, the National Archives of Australia (NAA) director-general, explained in the inquiry that the Archive Act defines a “Commonwealth record” as being “a record that is the property of the Commonwealth.” He noted, however, that WhatsApp and Facebook are not the property of the Commonwealth. Fricker underlined that the increasing use of third party non-government, non-Australian platforms for the conduct of official business is a pressing issue for the NAA.</p><p>“I would like to see our legislation modernised, first and foremost, to embrace a more 21st-century definition of a Commonwealth record, one that incorporates a message sent on WhatsApp, for example,” he said at the inquiry in April last year.</p><p>NAA guidance explains that public servants should keep a record of what they’ve done. If <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encrypted</a> messages are sent through WhatsApp, Signal, or Telegram, then the responsibility is on the user to make sure a copy is saved without encryption and put into the Commonwealth record-keeping system.</p><p>However, Fricker underlined that no transfers of <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">social media</a> records from Commonwealth government agencies or ministerial offices have been received by the NAA yet. He added that initial planning discussions are underway with some agencies over this topic.</p><p>The director general was asked if there were any penalties in place for entities, public servants, or ministers who failed to supply encrypted messages and keep a record as required. Fricker said that under the Archives Act, the only breach is to engage in conduct that leads to the deterioration, loss, or alteration of a Commonwealth record. If the record is never made in the first place then there isn’t any penalty available through the Archives Act.</p><p>Fricker confirmed that advice has been sought on the definition of the Commonwealth record, as in the act the powers in his office are limited to records that are the property of the Commonwealth. NAA has provided advice to the Attorney-General’s department on this matter and is in active discussion to bring the law into the 21st century, he added.</p><p>The committee has failed to acknowledge in its findings the evidence received that the Archives has received few or no records of social media or encrypted messages from public servants or ministers, said Julian Hill, Labour minister and deputy chair of the committee.</p><p>“Dancing around this evidence and failing to make a finding doesn’t change the fact this is a Government addicted to secrecy, and that the definition of Commonwealth record requires updating to ensure government records made or transmitted via modern forms of communication are captured,” added Hill.</p><p>Hill said the committee could have gone further by providing recommendations to the government like providing a more modern definition of “Commonwealth Record” and addressing gaps in rules and policy guidance to make sure <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encrypted</a> messages and social media that relate to government decision making are retained.</p><h2 id="how-does-this-compare-to-the-uk">How does this compare to the UK?</h2><p>Overall, the UK government has supported the <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">use of encryption</a> but has attempted to implement measures that would allow it to bypass barriers to accessing secured data if it needed to. The government has said that end-to-end encryption inhibits law enforcement’s ability to gather data that could lead to the protection of vulnerable individuals.</p><p>In April 2021, Priti Patel said that <a href="https://www.itpro.com/security/encryption/359249/facebook-might-jeopardise-childrens-safety-warns-home-secretary" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359249/facebook-might-jeopardise-childrens-safety-warns-home-secretary">Facebook’s plan to implement end-to-end encryption</a> is likely to jeopardise the progress in fighting online child abuse. The same fears were raised, that the technology could hinder law enforcement efforts to track down and arrest child abusers.</p><p>Despite the Australian parliament calling for more transparency when it comes to ministers’ communications, the country also passed a controversial surveillance bill last year. It granted the authorities <a href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state">extensive new powers</a>, more than any of its allies like the UK or US has, which is said to take surveillance of citizens to the next level. Citizens are said to have their communications listened to, data on their computers altered, copied, added, or deleted, and their social media accounts closed and their identities impersonated.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Breaking end-to-end encryption would do more harm than good, warn IT professionals ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/367240/attacking-end-to-end-encryption-would-do-more-harm-than-good-warn-it</link>
                                                                            <description>
                            <![CDATA[ Two-thirds of IT specialists said restricting the use of this technology would have a negative impact on protecting society ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8UNsYCPgdipyJ17GFMicKh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sNWkFLG4xLCzSEKeKityo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Mar 2022 11:24:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sNWkFLG4xLCzSEKeKityo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image of a key made up of binary code on a blue background]]></media:description>                                                            <media:text><![CDATA[An abstract image of a key made up of binary code on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image of a key made up of binary code on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sNWkFLG4xLCzSEKeKityo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT experts have warned against limiting end-to-end encryption, underlining it wouldn’t make the world safer and is likely to do more harm than good.</p><p>78% of industry professionals don’t believe restricting the use of <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> in messaging would protect users, according to a survey of 1,062 respondents carried out by BCS.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs" data-original-url="/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs">The government’s anti-encryption campaign shows it’s learned nothing from the war on drugs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/365510/encryption-software-market-to-hit-221-billion-by-2026" data-original-url="/security/encryption/365510/encryption-software-market-to-hit-221-billion-by-2026">Encryption software market to hit $22.1 billion by 2026</a></p></div></div><p>66% of specialists also said restricting end-to-end encryption would have a negative impact on protecting society at large. </p><p>The poll was carried out following the UK government-backed No Place to Hide campaign, warning against the further rollout of end-to-end encryption.</p><p>“We are not opposed to end-to-encryption in principle and fully support the importance of strong user privacy,” the campaign said. “Instead, our campaign is calling for social media companies to work with us to find a solution that protects privacy, without putting children at even greater risk.” </p><p>BCS said that <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encrypted messaging</a> has since become increasingly important to the people of Ukraine, with a large rise in usage being reported, including by journalists.</p><p>70% of IT professionals were not confident it is possible to have secure encryption as well as the ability to check encrypted messages for criminal material.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="D8uSnGDuWzpgKVikuNfnbb" name="D8uSnGDuWzpgKVikuNfnbb.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/D8uSnGDuWzpgKVikuNfnbb.png" mos="https://cdn.mos.cms.futurecdn.net/D8uSnGDuWzpgKVikuNfnbb.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Successful WAN and security transformation powers the digital enterprise</strong></p><p class="fancy-box__body-text">Applications are delivered in the cloud - security should be too</p><p class="fancy-box__body-text">FREE DOWNLOAD</p></div></div><p>Many industry experts said they were worried about the possibility of increased surveillance from government, police, and technology companies, added the BCS. Other concerns revolved around the protection of, for example, financial data from <a href="https://www.itpro.com/security/hacking/361206/the-4-most-notorious-hackers" target="_blank" data-original-url="https://www.itpro.com/security/hacking/361206/the-4-most-notorious-hackers">hackers</a> if encryption was undermined.</p><p>There were also concerns that wider sharing of ‘secret keys’ or centralised management of encryption processes would also significantly increase the risk of compromising the confidentiality they are meant to preserve.</p><p>“Now is not the time to weaken technology that is so fundamentally important to our security,” said Bill Mitchellm director of policy at BCS. “There should be more exploration of the alternatives before we go down the road of rolling back E2EE, especially in this time of war, when secure messaging is a vital tool for truth telling across the world.”</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/afvj2E-OOcw" allowfullscreen></iframe></div></div><p>“It’s odd that so much focus has been on a magical backdoor when other investigative tools aren’t being talked about,” he added. “Alternatives should be looked at before limiting the basic security that underpins everyone’s privacy and global free speech.”</p><p>This isn’t the first time the government has faced criticism over its encryption campaign, as in January the Information Commissioner’s Office argued that the technology strengthens online safety. It said that end-to-end encryption helped keep children safe online by not allowing criminals or abusers to send them harmful content or access their pictures or location.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Avast to acquire identity services provider SecureKey ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/367204/avast-to-acquire-identity-services-provider-securekey</link>
                                                                            <description>
                            <![CDATA[ The acquisition will add to Avast’s privacy-focused identity product and services portfolio ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">smDft6jNZRBuRYErVcT79n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ws2XRT2emsZjVjQgNVAMkP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Mar 2022 12:35:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ws2XRT2emsZjVjQgNVAMkP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Avast CEO Ondrej Vlcek]]></media:description>                                                            <media:text><![CDATA[The Avast logo on top of an office building in broad daylight]]></media:text>
                                <media:title type="plain"><![CDATA[The Avast logo on top of an office building in broad daylight]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ws2XRT2emsZjVjQgNVAMkP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Avast has announced it intends to acquire digital identity and authentication provider SecureKey Technologies for an undisclosed sum.</p><p>SecureKey's privacy-enhancing products are designed to streamline access to online services while also ensuring users’ data is only ever shared with prior explicit consent.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">Avast Antivirus Free review: Our free favourite for older Windows PCs <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/366994/nortonlifelock-avast-merger-could-reduce-competition-cma" data-original-url="/business-strategy/mergers-and-acquisitions/366994/nortonlifelock-avast-merger-could-reduce-competition-cma">NortonLifeLock and Avast merger could reduce competition, CMA warns</a></p></div></div><p>A case in point is Verified.Me, SecureKey’s distributed <a href="https://www.itpro.com/business/policy-legislation/366629/digital-identity-scheme-unveiled-uk-government" data-original-url="https://www.itpro.com/business/policy-legislation/366629/digital-identity-scheme-unveiled-uk-government">digital identity</a> verification network that employs banking-grade security measures to prevent identity theft and fraud. User banking information is not accessible through Verified.Me, nor are credentials used for online banking.</p><p>Additionally, Government Sign-In by Verified.Me, tailored for government applications, allows for simplified access to <a href="https://www.itpro.com/strategy/29868/estonias-rise-into-a-digital-nation" data-original-url="https://www.itpro.com/strategy/29868/estonias-rise-into-a-digital-nation">e-government services</a> and applications. So-called 'Triple Blind' capabilities are built into the tool, ensuring nobody, including financial institutions, government agencies, or network operators, can discern the origin of registrations.</p><p>Both Verified.Me and Government Sign-In by Verified.Me are provided by interbank network expert Interac under an exclusive Canadian licensing agreement.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HTov4yTAH35XsuCFKbzXTQ" name="" alt="A close up photo of Ondrej Vlcek, chief executive officer of Avast, speaking on stage" src="https://cdn.mos.cms.futurecdn.net/HTov4yTAH35XsuCFKbzXTQ.jpg" mos="https://cdn.mos.cms.futurecdn.net/HTov4yTAH35XsuCFKbzXTQ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Avast CEO Ondrej Vlcek </span></figcaption></figure><p>"We envisage a global and reusable digital identity framework which will underpin a new trust layer for the internet. It's clear that digital identity is the critical enabler for many digital services and SecureKey's success reflects the growing demand for this from consumers, " said Ondrej Vlcek, Avast CEO.</p><p>“SecureKey is highly complementary to Avast's prior work in Identity and together we will take our offer to the next level, accelerating innovation and working to establish a user-focused, global approach that aligns user, business, and government propositions. We are committed to developing offerings that will be fully inclusive for everyone, regardless of their own circumstances."</p><p>The Avast-SecureKey deal is anticipated to close by April and the general availability of SecureKey-based products is scheduled for Q2 2022.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CDQu52uLq6czv2whmKosyA" name="CDQu52uLq6czv2whmKosyA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/CDQu52uLq6czv2whmKosyA.jpg" mos="https://cdn.mos.cms.futurecdn.net/CDQu52uLq6czv2whmKosyA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Decoding Customer IAM (CIAM) vs. IAM</strong></p><p class="fancy-box__body-text">What’s the difference between CIAM and IAM?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/366355/decoding-customer-iam-ciam-vs-iam" data-original-url="/security/identity-and-access-management-iam/366355/decoding-customer-iam-ciam-vs-iam">FREE DOWNLOAD</a></p></div></div><p>"The maturity of the SecureKey hybrid federation, bank ID, and decentralized technology suite, and history of strong operational delivery in Canada for discerning financial services and government customers & partners, positions Avast for geographic expansion," said Charles Walton, general manager and SVP of identity at Avast.</p><p>"As the European community is investing in public-private sector digital identity infrastructure in 2022 and beyond, we see Avast well positioned as a collaborative provider of digital trust services for people, digital businesses and government."</p><p>"Success for us is where digital identity becomes simple, user-centric and portable, and can enable a more trustworthy digital experience and deeper online engagement benefiting both people and business," added Walton.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/LuqAVA1jiPI" allowfullscreen></iframe></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM launches multi-cloud key management service ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/367195/ibm-launches-multi-cloud-key-management-service</link>
                                                                            <description>
                            <![CDATA[ Unified Key Orchestrator will control keys on cloud and on-premises environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rN5nCmhSu3LGEyjyCR9LG6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sNWkFLG4xLCzSEKeKityo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Mar 2022 08:40:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sNWkFLG4xLCzSEKeKityo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image of a key made up of binary code on a blue background]]></media:description>                                                            <media:text><![CDATA[An abstract image of a key made up of binary code on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image of a key made up of binary code on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sNWkFLG4xLCzSEKeKityo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM has launched a service to help manage digital security keys across multicloud environments.</p><p>The Unified Key Orchestrator supports what IBM calls 'bring your own key' functionality by enabling customers to manage their own data <a href="https://www.itpro.com/security/29889/what-is-ibm-z" data-original-url="https://www.itpro.com/security/29889/what-is-ibm-z">encryption keys</a> across cloud environments including IBM Cloud, Amazon Web Services, and Microsoft's Azure.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/359011/ibm-targets-hybrid-cloud-environments-with-expanded-security-services-for" data-original-url="/cloud/hybrid-cloud/359011/ibm-targets-hybrid-cloud-environments-with-expanded-security-services-for">IBM targets hybrid cloud environments with expanded Security Services for Cloud</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/363044/ibm-launches-security-hub-to-help-apac-firms-prepare-for-cyber" data-original-url="/security/cyber-security/363044/ibm-launches-security-hub-to-help-apac-firms-prepare-for-cyber">IBM launches security hub to help APAC firms prepare for cyber attacks</a></p></div></div><p>It also lets them manage keys on their own premises, the company revealed this week.</p><p>The Orchestrator product allows administrators to manage their keys through a single user interface. Customers can also use an API to integrate digital keys into their <a href="https://www.itpro.com/devops/28097/what-is-devops" data-original-url="https://www.itpro.com/devops/28097/what-is-devops">DevOps process</a>, making it easier to deploy workloads in the cloud, it added.</p><p>The service stores digital keys in its own hardware security module, protected by the customer's master key. It transfers those keys to key stores in different cloud services and manages them via an API.</p><p>Administrators can also redistribute keys that are lost or corrupted in the field, effectively making the Unified Key Orchestrator <a href="https://www.itpro.com/security/29065/ibms-z-mainframe-can-encrypt-all-your-data-and-applications" data-original-url="https://www.itpro.com/security/29065/ibms-z-mainframe-can-encrypt-all-your-data-and-applications">a backup service for digital keys</a>, according to the company.</p><p>IBM has made the key orchestration system part of its existing IBM Cloud Hyper Crypto Services offering, which is a key management and HSM service. It will offer the new service under a tiered pricing model, it said.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/iEFMuuXpmTs" allowfullscreen></iframe></div></div><p>The announcement comes at a time when around 79% of respondents are incorporating multiple public clouds, while 60% said that they're using more than one private cloud, according to <a href="https://www.flexera.com/blog/cloud/cloud-computing-trends-2022-state-of-the-cloud-report">a report</a> from Flexera this month.</p><p>A third of all organizations said that they were using security tools designed for multiple clouds, making it the front runner for the first time, ahead of multi-cloud cost management and governance tools.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Encryption software market to hit $22.1 billion by 2026 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/365510/encryption-software-market-to-hit-221-billion-by-2026</link>
                                                                            <description>
                            <![CDATA[ The IT and telecommunications industries are expected to drive the demand ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">knydnx1Z3moLo3bMHXJxjH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RFpg7dgKN6R5WUGWMHk6BD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Mar 2022 13:37:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RFpg7dgKN6R5WUGWMHk6BD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock on a motherboard]]></media:description>                                                            <media:text><![CDATA[A padlock on a motherboard]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock on a motherboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RFpg7dgKN6R5WUGWMHk6BD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The global <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> software market is projected to exceed $22.1 billion by 2026, according to a new report by MarketsandMarkets.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/364195/top-5-myths-around-encryption-and-data-protection" data-original-url="/security/encryption/364195/top-5-myths-around-encryption-and-data-protection">Top 5 myths around encryption and data protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023" data-original-url="/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">Meta delays product-wide end-to-end encryption rollout until 2023</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NhMQzdZrFWPUNLGH4vbCi8" name="NhMQzdZrFWPUNLGH4vbCi8.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NhMQzdZrFWPUNLGH4vbCi8.png" mos="https://cdn.mos.cms.futurecdn.net/NhMQzdZrFWPUNLGH4vbCi8.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The state of SD-WAN, SASE and zero trust security architectures</strong></p><p class="fancy-box__body-text">Be a leader in the deployment of zero trust, SD-WAN and SASE</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/365560/the-state-of-sd-wan-sase-and-zero-trust-security-architectures" data-original-url="/security/365560/the-state-of-sd-wan-sase-and-zero-trust-security-architectures">FREE DOWNLOAD</a></p></div></div><p>A compound annual growth rate (CAGR) of 15.2% is anticipated for the market between 2021 and 2026, with the IT and telecommunications industries driving the demand for encryption software. </p><p>Regulations for data protection, growing concerns over loss of critical data, and an exponential increase in the adoption of <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/tags/cloud">cloud</a> and virtualization technologies will also propel the market.</p><p>Major players in the global encryption software market include IBM, Microsoft, and Broadcom.</p><p>Within the market forecast period, the <a href="https://www.itpro.com/infrastructure/server-storage/356955/it-pro-live-why-on-premise-isnt-a-dirty-word" data-original-url="https://www.itpro.com/infrastructure/server-storage/356955/it-pro-live-why-on-premise-isnt-a-dirty-word">on-premises</a> segment is forecast to account for the greatest market share of all software deployment models. </p><p>“The on-premises deployment mode is majorly used by critical information industries due to the high security associated with managing sensitive data in-house. Organizations that manage large volumes of sensitive data, especially government agencies, financial companies, and healthcare, still rely on-premises solutions - due to concerns around data security and privacy,” according to MarketsandMarkets’ report.</p><p>Furthermore, telecom and IT markets are expected to grow at the highest CAGR over the forecast period. The use of encryption software will help the industries comply with regulations, such as AES, PCI DSS, and GDPR.</p><p>By region, APAC is slated to grow at the highest CAGR during the forecast period. The increasing threat of spear <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, ransomware, and business email compromise can be attributed to the growth in the region.</p><p>A study by threat intelligence provider FireEye revealed that Asia Pacific countries are more susceptible to cyberattacks than their western counterparts. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 100 million Samsung Galaxy devices vulnerable to cryptographic key hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/362957/samsung-galaxy-devices-vulnerable-cryptographic-key-hack</link>
                                                                            <description>
                            <![CDATA[ Widespread flaws in hardware-backed key management could enable hackers to bypass FIDO2 authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kzoy8kqAETF1KkNm3Tmdbi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3agbH5JePnSnga7zou9MCE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Feb 2022 11:07:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3agbH5JePnSnga7zou9MCE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Samsung Galaxy S21 Ultra smartphone in Phantom Silver at the Samsung Unpacked product launch event]]></media:description>                                                            <media:text><![CDATA[Samsung Galaxy S21 Ultra smartphone in Phantom Silver at the Samsung Unpacked product launch event]]></media:text>
                                <media:title type="plain"><![CDATA[Samsung Galaxy S21 Ultra smartphone in Phantom Silver at the Samsung Unpacked product launch event]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3agbH5JePnSnga7zou9MCE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have found “severe” security flaws in a long line of flagship smartphones made by Samsung whereby attackers can lift cryptographic keys.</p><p>Potentially affecting around 100 million Samsung devices including the <a href="https://www.itpro.com/mobile/mobile-phones/360209/samsung-galaxy-s21-5g-review-a-rose-tinted-experience" data-original-url="https://www.itpro.com/mobile/mobile-phones/360209/samsung-galaxy-s21-5g-review-a-rose-tinted-experience">Galaxy S21</a>, Galaxy S20, and others dating back to the Galaxy S8, attackers can remotely lift cryptographic keys to bypass security authentication standards such as <a href="https://www.itpro.com/security/359512/github-now-supports-security-keys-in-a-move-away-from-passwords" data-original-url="https://www.itpro.com/security/359512/github-now-supports-security-keys-in-a-move-away-from-passwords">FIDO2</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="/security/innovation-at-work/24460/what-is-data-encryption">A complete guide to data encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29671/what-is-aes-encryption" data-original-url="/security/29671/what-is-aes-encryption">What is AES encryption?</a></p></div></div><p>Real-world applications of the vulnerabilities could see attackers extracting keys used for secure payments such as those made through <a href="https://www.itpro.com/security/cyber-security/354855/flaw-in-paypals-google-pay-integration-leading-to-suspected-fraud" data-original-url="https://www.itpro.com/security/cyber-security/354855/flaw-in-paypals-google-pay-integration-leading-to-suspected-fraud">Google Pay</a>, and bypassing FIDO2 authentication which is often used in place of account <a href="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure" data-original-url="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure">passwords</a>.</p><p>The researchers from Tel-Aviv University <a href="https://eprint.iacr.org/2022/208.pdf">demonstrated</a> how two feasible real-world attacks can be performed on even the latest Samsung devices. Said attacks allowed the researchers to extract <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">cryptographic keys</a> from hardware-protected elements of the device, and downgrade devices so that they’re vulnerable to these attacks, known as IV reuse attacks.</p><p>They explained how ARM devices use TrustZone technology which essentially splits a device into two parts: the ‘Normal World’ where normal applications on an operating system (OS) like Android can run; and the ‘Secure World’ which is essentially an isolated environment in which only trusted applications, like those critical to device security, are supposedly able to run.</p><p>The Android Keystore provides hardware-backed cryptographic key management via the Keymaster Hardware Abstraction Layer (HAL) and this is implemented in the Secure World of the TrustZone, where processes are not supposed to be accessed from the outside.</p><p>Cryptographic keys are protected here using the AES-GCM encryption standard, but Samsung’s implementation of Keystore, which allows keys to be retrieved and stored (while wrapped by an encrypted layer) from the Secure World by apps operating in the Normal World, is flawed.</p><p>This allows an attacker to predictably obtain the cryptographic keys if they know the contents of one plaintext sample encrypted using AES-GCM. The encryption standard protects items using the same key and relies on unique initialization vectors (IVs) never being reused. </p><p>The researchers were able to show how Samsung devices were vulnerable to the IV reuse attack, allowing attackers to assign IVs as part of the key parameters.</p><p>In approaching the research, the academics assumed an attacker could fully compromise the Normal World through mechanisms such as malware granting root privileges. The attacker would not need to be able to run code in the Android kernel, just be able to execute code in the Android user mode.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/len6Br8ci3Y" allowfullscreen></iframe></div></div><p>The researchers disclosed their findings to Samsung in August 2021 and the manufacturer addressed the issues by publishing the flaws to the Common Vulnerabilities and Exposures (CVE) register.</p><p>The initial IV reuse attack is tracked as CVE-2021-25444 with a ‘high’ severity rating, and patched in August 2021. </p><p>The downgrade attack which allowed newer devices, such as the Samsung Galaxy S20 and S21, to become vulnerable to the IV reuse attack, was patched in October 2021 after its CVE (CVE-2021-25490) addressed the issue for all devices running Android 9 or later.</p><p>Although Samsung's latest <a href="https://www.itpro.com/mobile/mobile-phones/362199/samsung-unveils-s22-ultra-with-a-note-of-sadness" target="_blank" data-original-url="https://www.itpro.com/mobile/mobile-phones/362199/samsung-unveils-s22-ultra-with-a-note-of-sadness">Galaxy S22</a> devices are also based on ARM architecture, they will not ship with OS versions before Android 9 as standard and as such will theoretically not be vulnerable to the researcher's attack.</p><p>"Samsung takes the security of Galaxy devices seriously. We are constantly looking for ways to enhance the security of our products and welcome any input from research communities," the company told <em>IT Pro</em>.</p><p>"The reported issue was acknowledged and has been addressed through security updates since August 2021. We recommend our users to keep their devices updated with the latest software to enjoy safe and convenient Galaxy mobile experiences."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI urges Olympic athletes to leave personal devices at home due to cyber risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/362110/fbi-urges-olympic-athletes-to-leave-personal-devices-at-home</link>
                                                                            <description>
                            <![CDATA[ The organisation has warned that threat actors could use a broad range of cyber activities, including DDoS or ransomware attacks, to disrupt the event ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6uiVDm4ne1HjisWdkshSzV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/odXzaq87teCWmTNFDtx2qE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Feb 2022 11:06:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/odXzaq87teCWmTNFDtx2qE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI headquarters on Pennsylvania avenue sign with traffic reflections at night]]></media:description>                                                            <media:text><![CDATA[FBI headquarters on Pennsylvania avenue sign with traffic reflections at night]]></media:text>
                                <media:title type="plain"><![CDATA[FBI headquarters on Pennsylvania avenue sign with traffic reflections at night]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/odXzaq87teCWmTNFDtx2qE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has urged all athletes to keep their personal smartphones at home and instead use a temporary phone while at the Olympic Games.</p><p>The organisation published a notice in which it warns entities associated with the February 2022 Beijing Winter Olympics and March 2022 Paralympics that cyber actors could use a broad range of cyber activities, including DDoS or <a href="https://www.itpro.com/tag/ransomware" target="_blank" data-original-url="https://www.itpro.com/search/ransomware">ransomware</a> attacks, to disrupt the events.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw" data-original-url="/security/362010/ioc-defends-olympics-app-devastating-flaw">IOC defends China Olympics app after 'devastating flaw' revealed</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361900/china-introduce-cyber-security-reviews-for-companies-listing-overseas" data-original-url="/security/361900/china-introduce-cyber-security-reviews-for-companies-listing-overseas">China to introduce cyber security reviews for companies listing overseas</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/357033/china-to-launch-global-data-security-initiative" data-original-url="/business/policy-legislation/357033/china-to-launch-global-data-security-initiative">China to launch global data security initiative</a></p></div></div><p>Additionally, the FBI warned Olympic participants and travellers of potential threats associated with mobile applications developed by untrusted vendors.</p><p>“The download and use of applications, including those required to participate or stay in the country, could increase the opportunity for cyber actors to steal personal information or install tracking tools, malicious code, or <a href="https://www.itpro.com/security/malware" target="_blank" data-original-url="https://www.itpro.com/search/malware">malware</a>,” said the FBI.</p><p>The organisation recommends all athletes to use a temporary phone, highlighting that the National Olympic Committees in some Western countries are also advising athletes to leave personal devices at home due to cyber security concerns at the Games. </p><p>However, it added that it isn’t aware of any specific cyber threat against the Olympics, but encourages partners to remain vigilant and maintain best practices in their network and digital environments.</p><p>It pointed to the 2020 Tokyo Olympics and Paralympics, where there were over 450 million attempted cyber-related incidents during the event, although none were successful due to the cyber security measures in place, according to the NTT Corporation which was in charge of IT <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security</a>. The most popular attack methods used were malware, email spoofing, <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, and the use of fake websites and streaming services designed to look like official Olympic service providers.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=44556716&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>The FBI added that the use of new digital <a href="https://www.itpro.com/infrastructure" target="_blank" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a> and mobile applications, like digital wallets or applications that track COVID testing or vaccination status, could also increase the opportunity for cyber actors to inflict damage. This could allow them to steal personal information or install tracking tools, malicious code, or malware. The FBI underlined that athletes will be required to use the MY2022 smartphone app to track their health and travel data.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>The <a href="https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw" target="_blank" data-original-url="https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw">MY2022 app was analysed by Citizen Lab researchers who said they had found it contained a “devastating” encryption flaw</a>, which it said allowed users’ audio and file transfer encryption to be sidestepped. The researchers also said it fails to validate SSL certificates and can be deceived into connecting to a malicious host.</p><p>There also appears to have been some misinformation surrounding the privacy of the Chinese app, with one researcher, Jonathan Scott, claiming that athletes’ audio is being collected, analysed, and saved on servers belonging to a Chinese AI firm with human rights concerns called iFlytek. This claim has been shared by US senators and a prominent podcaster on Twitter.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1488153247814758400"></a></p></blockquote><div class="see-more__filter"></div></div><p>However, members of the infosec community have said the researcher’s claim is unsubstantiated by any of the evidence provided, even though it has already been shared widely.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1486976676965715968"></a></p></blockquote><div class="see-more__filter"></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ White House issues memorandum to bolster national security systems ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/362020/white-house-issues-memorandum-to-bolster-national-security-systems</link>
                                                                            <description>
                            <![CDATA[ Agencies must now implement multi-factor authentication within 180 days, along with encryption for data at rest and in transit ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nbPU1gPQxhZHa1BCxqm9bK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4JNPJ8yJiU2C6vw6WUnvuL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jan 2022 10:12:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4JNPJ8yJiU2C6vw6WUnvuL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US president Joe Biden speaking to press at the White House while sat in front of the US flag]]></media:description>                                                            <media:text><![CDATA[US president Joe Biden speaking to press at the White House while sat in front of the US flag]]></media:text>
                                <media:title type="plain"><![CDATA[US president Joe Biden speaking to press at the White House while sat in front of the US flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4JNPJ8yJiU2C6vw6WUnvuL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The White House issued a memorandum on Wednesday detailing new cyber security requirements and timelines to protect national security systems.</p><p>The Memorandum on Improving the Cybersecurity of National Security, Department of Defense, and Intelligence Community Systems, builds on an Executive Order issued last May to bolster cyber security across the federal government. It identifies more requirements for national security systems that go beyond those in the original document.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360684/white-house-to-call-on-techs-big-guns-for-security-summit" data-original-url="/security/ransomware/360684/white-house-to-call-on-techs-big-guns-for-security-summit">White House turns to big tech CEOs to boost cyber security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/359591/biden-calls-for-22-billion-in-cyber-security-funding" data-original-url="/security/359591/biden-calls-for-22-billion-in-cyber-security-funding">Biden calls for $22 billion in cyber security funding</a></p></div></div><p>The memorandum requires agencies to inventory all systems affecting national security within 90 days. It also calls for an incident reporting and response program with clear reporting deadlines.</p><p>It also addresses systems that span different security domains, such as those designed for sharing information between different agencies.</p><p>The head of the National Security Agency will act as a national manager and advise on their security, the memorandum says. The national manager is responsible for advising on and enforcing most of the requirements in the memorandum.</p><p>The Executive Order last May requested the implementation of <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero-trust</a> architectures, but today's memorandum puts a timeline on it. It calls on the head of each agency to create an implementation plan within 60 days, incorporating the National Institute of Standards and Technology's (NIST) zero-trust guidance documents.</p><p>Agencies must also implement <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication</a> within 180 days, along with <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">encryption for data at rest and in transit</a>, the memorandum said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XEodomHb9jn7VwXYzAFsXa" name="XEodomHb9jn7VwXYzAFsXa.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/XEodomHb9jn7VwXYzAFsXa.jpg" mos="https://cdn.mos.cms.futurecdn.net/XEodomHb9jn7VwXYzAFsXa.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Identity-focussed security for your zero trust journey</strong></p><p class="fancy-box__body-text">Steps to protect your business from identity-driven threats</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/361566/identity-focussed-security-for-your-zero-trust" data-original-url="/security/identity-and-access-management-iam/361566/identity-focussed-security-for-your-zero-trust">FREE DOWNLOAD</a></p></div></div><p>The memorandum also accounts for <a href="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution" data-original-url="https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution">quantum-proof encryption</a>, which researchers are designing to ensure that encrypted data is protected against quantum computers. Quantum systems will eventually be able to unlock data encrypted by conventional asymmetric encryption algorithms when they become powerful enough, fear experts.</p><p>The memorandum calls for agencies to identify any encryption that isn't compliant with an NSA-approved list of quantum-proof encryption algorithms within 180 days. They must also provide a timeline to swap out these algorithms, it adds.</p><p>Other mandatory measures include a program for collaboration between defense and intelligence agency participants on cyber security incident response and cloud security.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IOC defends China Olympics app after 'devastating flaw' revealed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/362010/ioc-defends-olympics-app-devastating-flaw</link>
                                                                            <description>
                            <![CDATA[ The app may even be breaking Google and Apple’s app store policies when it comes to privacy, according to Citizen Lab ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qY3HijT9e4QGnXqMqC4pbd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iafzHCJwHR6JsGfafYSG9c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Jan 2022 11:01:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iafzHCJwHR6JsGfafYSG9c-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a health worker standing in front of a Beijing 2022 sign]]></media:description>                                                            <media:text><![CDATA[An image of a health worker standing in front of a Beijing 2022 sign]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a health worker standing in front of a Beijing 2022 sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iafzHCJwHR6JsGfafYSG9c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The International Olympic Committee (IOC) has defender China’s MY2022 app for the Olympic Games in Beijing after researchers found it contained a "devastating" encryption flaw. </p><p>Due to the pandemic, China has decided to implement a “closed-loop” management system and daily testing. All international and domestic attendees are mandated to download MY2022 14 days prior to their departure for China and to start monitoring and submitting their health status to the app on a daily basis.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361900/china-introduce-cyber-security-reviews-for-companies-listing-overseas" data-original-url="/security/361900/china-introduce-cyber-security-reviews-for-companies-listing-overseas">China to introduce cyber security reviews for companies listing overseas</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/361408/what-is-chinas-personal-data-protection-law-pipl" data-original-url="/business/policy-legislation/361408/what-is-chinas-personal-data-protection-law-pipl">What is China’s Personal Information Protection Law (PIPL)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs" data-original-url="/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs">The government’s anti-encryption campaign shows it’s learned nothing from the war on drugs</a></p></div></div><p>However, the flaw allows encryption protecting users’ voice audio and file transfer to be trivially sidestepped, according to new research from <a href="https://citizenlab.ca/2022/01/cross-country-exposure-analysis-my2022-olympics-app" target="_blank">Citizen Lab</a>. The app fails to validate SSL certificates, allowing an attacker to spoof trusted servers by interfering with the communication between the app and servers. This means it can be deceived into connecting to a malicious host, allowing information it transmits to be intercepted and enabling the app to display spoofed content that appears to originate from trusted servers.</p><p>The researchers also found that some sensitive data is transmitted without any SSL <a href="https://www.itpro.com/security/encryption" target="_blank" data-original-url="https://www.itpro.com/search/encryption">encryption</a> or any security at all. It transmits non-encrypted data to “tmail.beijing2022.cn” on port 8099 which contain sensitive metadata relating to messages, such as the names of messages’ senders and receivers, and their user account identifiers. This data can be read by any passive eavesdropper, such as someone operating an unsecured WiFi access point or an Internet Service Provider.</p><p>The report said the app collects a range of highly sensitive medical information and it is unclear with whom or which organisations it shares this information. It also contains features that allow users to report politically sensitive content, and contains a censorship keyword list which is presently inactive. The keywords target political topics such as Xinjiang and Tibet as well as reference to Chinese government agencies.</p><p>Citizen Lab stated that the app’s security deficits may not only violate <a href="https://www.itpro.com/software/google" target="_blank" data-original-url="https://www.itpro.com/search/google">Google’s</a> Unwanted Software Policy and <a href="https://www.itpro.com/software/apple" target="_blank" data-original-url="https://www.itpro.com/search/apple">Apple’s</a> App Store guidelines but also China’s own laws and national standards pertaining to privacy protection, providing potential avenues for future redress.</p><p>The IOC told <em>IT Pro</em> that the user is in control over what the app can access on their device, as the settings can be changed to configure access to specific features like Files and Media, Camera, Contacts, Microphone, and more.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TpQGJuV8JLJg48R7p8QdfN" name="TpQGJuV8JLJg48R7p8QdfN.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TpQGJuV8JLJg48R7p8QdfN.jpg" mos="https://cdn.mos.cms.futurecdn.net/TpQGJuV8JLJg48R7p8QdfN.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The top three IT pains of the new reality and how to solve them</strong></p><p class="fancy-box__body-text">Driving more resiliency with unified operations and service management</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/it-infrastructure/360224/the-top-three-it-pains-of-the-new-reality-and-how-to" data-original-url="/business-strategy/it-infrastructure/360224/the-top-three-it-pains-of-the-new-reality-and-how-to">FREE DOWNLOAD</a></p></div></div><p>“The app has received approval of the Google Play store (Android/HarmonyOS) and the App Store (iOS) too and is available for download,” said the spokesperson. “It is not compulsory to install 'My 2022' on cell phones, as accredited personnel can log on to the health monitoring system on the web page instead.”</p><p>The IOC added that it has conducted independent third-party assessments on the application from two <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/search/cyber%20security">cyber security</a> testing organisations, with the reports confirming that there are no critical vulnerabilities. It said that many of the app’s features are used for local Beijing 2022 workforce for time-keeping, task management, and instant messaging, as the app is not only for international users.</p><p>The IOC has requested the report from Citizen Lab to understand its concerns better. <em>IT Pro</em> has contacted Google and Apple for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The government’s anti-encryption campaign shows it’s learned nothing from the war on drugs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/361996/uk-anti-encryption-campaign-war-on-drugs</link>
                                                                            <description>
                            <![CDATA[ Criminalisation has almost always backfired through history, pushing illicit materials further into the hands of criminals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wpD9twfwxbozZAXE7SA2LA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/W6TTUZZBrQmxZNRDbU67dE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Jan 2022 09:46:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/W6TTUZZBrQmxZNRDbU67dE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A solider standing in a field of flowers]]></media:description>                                                            <media:text><![CDATA[A solider standing in a field of flowers]]></media:text>
                                <media:title type="plain"><![CDATA[A solider standing in a field of flowers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/W6TTUZZBrQmxZNRDbU67dE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK has waged a war on <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption</a> for years, with the government boomeranging between scaremongering tactics to manipulate public opinion on the divisive technology. Its latest attempt to convince the public that surrendering its basic human right to privacy is, actually, a good idea, however, fails to address the core issue it’s ignoring; that criminalisation almost never works.</p><p>Revelations published by <a href="https://www.rollingstone.com/culture/culture-news/revealed-uk-government-publicity-blitz-to-undermine-privacy-encryption-1285453" target="_blank"><em>Rolling Stone</em></a> shows the government isn’t backing down on encryption, despite a litany of more pressing fires it needs to put out. The Home Office has commissioned M&C Saatchi, a high-end advertising agency, to run an anti-encryption campaign centred on the role of encryption in child exploitation, including an insidious “visual PR stunt” involving a child and an adult. This aims to mobilise public opinion against <a href="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023" data-original-url="https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023">Meta's decision</a> to add encryption to Messenger, for instance, among other uses of the technology.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a></p></div></div><p>The events of recent weeks have shown the contempt the government holds towards its citizens, and the lengths it will go to hide self-servitude. It now believes using child exploitation as the main argument against encryption should be enough to turn the tide.</p><p>It should be under no illusion, however, that banning the technology will do little to curb the online abuse of children, although according to the former head of the NCSC Ciaran Martin, the government <a href="https://twitter.com/ciaranmartinoxf/status/1463136207127429123" target="_blank">may not actually know what it’s talking about</a>. </p><p>Banning <a href="https://www.itpro.com/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps" target="_blank" data-original-url="https://www.itpro.com/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps">encrypted messaging</a> will remove the benefits and freedoms it affords the public, while ramping up the levels of already-hyperactive <a href="https://www.itpro.com/policy-legislation/33407/what-is-the-investigatory-powers-act-2016" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/33407/what-is-the-investigatory-powers-act-2016">state-wide surveillance</a>. The 1920s prohibition era serves as a historical example, as well as today’s so-called war on drugs; it’s very much a losing battle. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="A6JkNoAuvUffjedBwKi84B" name="A6JkNoAuvUffjedBwKi84B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/A6JkNoAuvUffjedBwKi84B.png" mos="https://cdn.mos.cms.futurecdn.net/A6JkNoAuvUffjedBwKi84B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Global security insights report 2021</strong></p><p class="fancy-box__body-text">Extended enterprise under threat</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360947/global-security-insights-report-2021" data-original-url="/security/360947/global-security-insights-report-2021">FREE DOWNLOAD</a></p></div></div><p>Has the lack of easy-access cannabis, like we can find in some states in the US, led to a drop in use? Well, cannabis is still the most misused illicit drug in the UK, <a href="https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/articles/drugmisuseinenglandandwales/yearendingmarch2020" target="_blank">ONS figures</a> show, with usage rising since 2013. Cocaine use, too, was up 37% against 2013, and more people also misused ketamine now than a decade ago. The Children’s Society, meanwhile, <a href="https://www.childrenssociety.org.uk/what-we-do/our-work/child-criminal-exploitation-and-county-lines/what-is-county-lines">says</a> 90% of police forces in England have observed county lines activity, with violence escalating.</p><p>It suggests what we know to be true; that outlawing things of value will only push them into the hands of outlaws. In the case of encryption, only those intent on harm will gain access to encrypted messaging services through technologies like <a href="https://www.itpro.com/encryption/30380/what-is-pgp" target="_blank" data-original-url="https://www.itpro.com/encryption/30380/what-is-pgp">Pretty Good Privacy</a> (PGP), deep underground with little chance of government tracking.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/1WXUN1KUe5V2E7TmxznXwU"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps" data-original-url="/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps">What should we do about encrypted messaging apps?</a></p></div></div><p>Take Messenger, WhatsApp, and <a href="https://www.itpro.com/security/encryption/355956/signal-app-use-surges-as-protests-spread" target="_blank" data-original-url="https://www.itpro.com/security/encryption/355956/signal-app-use-surges-as-protests-spread">Signal</a> away from Joe Public and what are you left with? The vast majority of the population will be exposed to the government of the day, whether it’s Boris Johnson, or an untimely successor. Criminals, meanwhile, will have already burrowed themselves deeper into the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" target="_blank" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>, using PGP-signed messages over which the government has no oversight. Nobody can ban cryptography.</p><p>It’s here from which whiffs of incompetence emanate. Revoking end-to-end encryption will allow dark web communities to flourish, making life even more difficult for law enforcement. We’ve seen how <a href="https://www.itpro.com/security/34521/bulletproof-dark-web-data-centre-seized-by-german-police" data-original-url="https://www.itpro.com/security/34521/bulletproof-dark-web-data-centre-seized-by-german-police">dark web marketplaces</a> have thrived despite attempts to stop the illegal trade of guns, drugs, and other illicit goods. After all, it takes months to infiltrate a marketplace and shut it down, and minutes for an alternative to begin accepting patrons.</p><p>This campaign is yet another thinly-veiled attempt to achieve the government’s ambition of scaling up the apparatus of the surveillance state, first through the <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">Investigatory Powers Act</a>, recently in its <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/985033/Draft_Online_Safety_Bill_Bookmarked.pdf" target="_blank">Online Safety Bill</a>, alongside <a href="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28378/amber-rudd-demands-spy-agency-access-to-whatsapps-encrypted-messages">years of public gesticulations</a>. </p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/iEFMuuXpmTs&t" allowfullscreen></iframe></div></div><p>To complicate matters, though, the government’s argument is somewhat valid, and one that even I, an avid proponent of end-to-end encryption, often struggle to internally justify. When you consider the lives lost through terrorist plots organised over encrypted messaging platforms, or the countless lives ruined through exploitation, it’s a difficult stance to hold.</p><p>When you see through the flagrant technical illiteracy and untruths running through this prospective campaign, however, you have to call into question the motives. This is especially true when you factor in attempts to undermine our rights and access to privacy, alongside the lengths to which government ministers go to hide their own activities from the public by using, you guessed it, WhatsApp. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to build a zero trust model ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model</link>
                                                                            <description>
                            <![CDATA[ Threats are becoming greater and more diverse, but having a zero trust architecture could help your business defend its infrastructure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hzBSKZTrRnD5CbwHdRExub</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZUHvccG7dhVxKAtQP5bmUX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jan 2022 13:19:54 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 12:48:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZUHvccG7dhVxKAtQP5bmUX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security represented by a digital screen with encryption data background]]></media:description>                                                            <media:text><![CDATA[Cyber security represented by a digital screen with encryption data background]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security represented by a digital screen with encryption data background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZUHvccG7dhVxKAtQP5bmUX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the early days of computer networking, <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> was predominantly focused on the perimeter because it was thought you needed to keep the bad guys out. Within the perimeters was thought to be safe and trusted, while outside the enterprise firewalls danger lurked.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/361951/log4shell-nearly-half-of-all-log4j-downloads-remain-vulnerable" data-original-url="/security/vulnerability/361951/log4shell-nearly-half-of-all-log4j-downloads-remain-vulnerable">Nearly half of all Log4j downloads remain critically vulnerable</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/361944/cyber-attacks-on-corporate-networks-increased-50-in-2021" data-original-url="/security/cyber-attacks/361944/cyber-attacks-on-corporate-networks-increased-50-in-2021">Cyber attacks on corporate networks increased 50% in 2021</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/network-attached-storage-nas/361938/qnap-warns-ransomware-targeting-nas-devices" data-original-url="/server-storage/network-attached-storage-nas/361938/qnap-warns-ransomware-targeting-nas-devices">QNAP warns of ransomware targeting internet-facing NAS products</a></p></div></div><p>However, this assumes that hackers haven’t already got into the network and started doing damage. Cyber criminals can get a grip within a businesses' infrastructure by exploiting a vulnerable system, <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">stolen credentials</a>, or by exploiting poorly configured wireless connections. To counteract this scenario, many modern enterprises are adopting a zero trust model.</p><h2 id="what-is-a-zero-trust-model">What is a zero trust model?</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kxVpxFJ7B6cp5Fs3CYkpBN" name="kxVpxFJ7B6cp5Fs3CYkpBN.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/kxVpxFJ7B6cp5Fs3CYkpBN.jpg" mos="https://cdn.mos.cms.futurecdn.net/kxVpxFJ7B6cp5Fs3CYkpBN.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Identity is key to stopping these five cyber security attacks</strong></p><p class="fancy-box__body-text">Many attacks begin with the same weakness: user accounts</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/366339/identity-is-key-to-stopping-these-five-cyber-security-attacks" data-original-url="/security/366339/identity-is-key-to-stopping-these-five-cyber-security-attacks">FREE DOWNLOAD</a></p></div></div><p><a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">Zero trust</a> is a relatively new and evolving approach to network design. It means “never trust, always verify”. By default, devices on a network are not trusted, even when connected to a corporate network and even if previously verified.</p><p>This model protects the environment by using methods and processes such as network segmentation, strong authentication, preventing lateral network movement, and simplifying “least access” policies.</p><p>So how does an organisation go about building, running, and using a zero trust model in the <a href="https://www.itpro.com/infrastructure" data-original-url="https://www.itpro.com/infrastructure">infrastructure</a>?</p><h3 class="article-body__section" id="section-network-segmentation"><span>Network segmentation</span></h3><p>The foundation of a zero trust architecture is network segmentation. Systems and devices must be segregated according to the types of data they process and the access they permit. This can then limit the reach of a hacker once they get into the network.</p><p>To segment a network, organisations should create a comprehensive roadmap based on business and security aims. They should then map application dependencies so that organisations know how apps communicate to endpoints within the infrastructure. Finally, a network should not be over-segmented as this can lead to over complexity and may prevent employees from doing their jobs properly if they can’t access the systems they need to.</p><h3 class="article-body__section" id="section-identity-and-access-management-improvement"><span>Identity and access management improvement</span></h3><p>A strong identity and access management infrastructure is another precondition of a zero-trust model. <a href="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution" data-original-url="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution">Multi-factor authentication</a> offers additional reassurance of identity and defends against credential stealing. Implementing role-based access control permits applications to limit access in a way that implements the principle of least privilege.</p><h3 class="article-body__section" id="section-deploying-least-privilege-at-the-firewall"><span>Deploying least privilege at the firewall</span></h3><p><a href="https://www.itpro.com/security/cyber-security/357381/why-you-should-prioritise-privileged-access-management" data-original-url="https://www.itpro.com/security/cyber-security/357381/why-you-should-prioritise-privileged-access-management">Least privilege</a> not only applies to users, but it also applies to networks. After network segmentation, access between networks should be locked down to only allow traffic between them according to business needs.</p><p>Using a next-generation firewall (NGFW) can help organisations to implement what <a href="https://www.gartner.com/en/information-technology/glossary/next-generation-firewalls-ngfws#:~:text=Next%2Dgeneration%20firewalls%20(NGFWs)%20are%20deep%2Dpacket%20inspection,intelligence%20from%20outside%20the%20firewall.">Gartner</a> defines as a “deep-packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and bringing intelligence from outside the firewall.”</p><h3 class="article-body__section" id="section-monitoring-using-ai-and-machine-learning"><span>Monitoring using AI and machine learning</span></h3><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kxVpxFJ7B6cp5Fs3CYkpBN" name="kxVpxFJ7B6cp5Fs3CYkpBN.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/kxVpxFJ7B6cp5Fs3CYkpBN.jpg" mos="https://cdn.mos.cms.futurecdn.net/kxVpxFJ7B6cp5Fs3CYkpBN.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Identity is key to stopping these five cyber security attacks</strong></p><p class="fancy-box__body-text">Many attacks begin with the same weakness: user accounts</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/366339/identity-is-key-to-stopping-these-five-cyber-security-attacks" data-original-url="/security/366339/identity-is-key-to-stopping-these-five-cyber-security-attacks">FREE DOWNLOAD</a></p></div></div><p>Machine learning can be used by organisations to speed up the work of detecting and mitigating threats. Usually, security analysts would use security information and event management (SIEM) solutions to gain a comprehensive understanding of security events collected from systems, devices, and applications across an organisation’s network and clouds. <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">Machine learning</a> and artificial intelligence (AI) can help to surface threat indicators that would otherwise be lost in reams of data.</p><p>This gives security teams a better way of recognising what activity is taking place and if it is normal activity that machine learning has been trained to identify. If this activity falls outside normal usage patterns, AI can flag this up as suspicious and help enterprises improve their defences from both internal and external threats and deploy a more full-bodied zero trust security model.</p><h3 class="article-body__section" id="section-ongoing-management-and-issues"><span>Ongoing management and issues</span></h3><p>A zero trust model should be thought of as part of an organisation’s overall digital transformation strategy. It should be by design and not simply retrofitted. This means implementing technology to achieve zero trust as more systems move to the cloud and legacy systems are replaced.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/pzAeJFCAexg" allowfullscreen></iframe></div></div><p>Moving to zero trust should involve an ongoing conversation between security and the rest of the organisation to prioritise what moves to a zero-trust model and what can wait.</p><p>When up and running, managing zero trust should involve security teams developing and maintaining zero trust models, while network teams manage networks. The security team should also carry out regular audits to ensure that the network adheres to the policies and protocols of zero trust. Critical workloads will need more analysis of users and devices compared to other, less important, workloads.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US adds dozen Chinese tech companies to trade blacklist ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/361653/us-adds-dozen-chinese-tech-companies-to-trade-blacklist</link>
                                                                            <description>
                            <![CDATA[ Decision was made due to concerns China could use the enterprises to break US encryption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ttvdhpc8cotcmwPefsAiQK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqUUxDWXcJ3DMHRgexch9o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Nov 2021 10:46:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqUUxDWXcJ3DMHRgexch9o-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Department of Commerce sign on the Herbert Clark Hoover Building]]></media:description>                                                            <media:text><![CDATA[Department of Commerce sign on the Herbert Clark Hoover Building]]></media:text>
                                <media:title type="plain"><![CDATA[Department of Commerce sign on the Herbert Clark Hoover Building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqUUxDWXcJ3DMHRgexch9o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Department of Commerce has added a dozen Chinese tech companies to its <a href="https://www.itpro.com/business/policy-legislation/361527/biden-further-us-restrictions-china-huawei-zte" data-original-url="https://www.itpro.com/business/policy-legislation/361527/biden-further-us-restrictions-china-huawei-zte">trade blacklist</a> to prevent the Chinese army from gaining access to critical US technologies.</p><p>Among the newly-banned Chinese companies, eight specialise in <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing" data-original-url="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> technologies and had sparked concerns that the country could leverage them in breaking US encryption or developing unbreakable encryption for the Chinese army.</p><p>Hangzhou Zhongke Microelectronics, Hunan Goke Microelectronics, New H3C Semiconductor Technologies, Xi'an Aerospace Huaxun Technology, and Yunchip Microelectronics have been added to the blacklist due to their "support of the military modernisation of the People's Liberation Army [PRC]”.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/361536/china-cyber-security-review-hong-kong-ipo" data-original-url="/business/policy-legislation/361536/china-cyber-security-review-hong-kong-ipo">China plots tougher cyber scrutiny for tech firms in Hong Kong IPOs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/361408/what-is-chinas-personal-data-protection-law-pipl" data-original-url="/business/policy-legislation/361408/what-is-chinas-personal-data-protection-law-pipl">What is China’s Personal Information Protection Law (PIPL)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361231/russia-missing-from-us-organized-international-ransomware-event" data-original-url="/security/ransomware/361231/russia-missing-from-us-organized-international-ransomware-event">Russia missing from US-organized international ransomware event</a></p></div></div><p>Meanwhile, Hefei National Laboratory for Physical Sciences at Microscale, QuantumCTek, and Shanghai QuantumCTeck had been banned for "acquiring and attempting to acquire US-origin items in support of military applications”.</p><p>Commenting on the decision, US Secretary of Commerce Gina Raimondo <a href="https://www.commerce.gov/news/press-releases/2021/11/commerce-lists-entities-involved-support-prc-military-quantum-computing">said</a> that “global trade and commerce should support peace, prosperity, and good-paying jobs, not <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/361541/uk-order-phase-two-investigation-nvidia-arm-deal" data-original-url="https://www.itpro.com/business-strategy/mergers-and-acquisitions/361541/uk-order-phase-two-investigation-nvidia-arm-deal">national security</a> risks”. </p><p>“The Department of Commerce is committed to effectively using export controls to protect our national security,” she added. </p><p>Apart from the dozen Chinese companies, the governmental body also blacklisted 15 tech businesses from Japan, Pakistan, and <a href="https://www.itpro.com/business-strategy/careers-training/361182/singapore-launches-new-cyber-security-framework" data-original-url="https://www.itpro.com/business-strategy/careers-training/361182/singapore-launches-new-cyber-security-framework">Singapore</a>, as well as determined that Russia’s Moscow Institute of Physics and Technology produces military products for the Russian army.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BcvzLcjfiVEs4Ce5gSZ2YS" name="BcvzLcjfiVEs4Ce5gSZ2YS.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/BcvzLcjfiVEs4Ce5gSZ2YS.png" mos="https://cdn.mos.cms.futurecdn.net/BcvzLcjfiVEs4Ce5gSZ2YS.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>What to consider when choosing a next-generation firewall</strong></p><p class="fancy-box__body-text">How to choose a NGFW solution</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361543/what-to-consider-when-choosing-a-next-generation-firewall" data-original-url="/security/firewalls/361543/what-to-consider-when-choosing-a-next-generation-firewall">FREE DOWNLOAD</a></p></div></div><p>“Today’s actions will help prevent the diversion of US technologies to the PRC’s and Russia’s military advancement and activities of non-proliferation concern like Pakistan’s unsafeguarded nuclear activities or ballistic missile programme,” said Raimondo.</p><p>Hours after the announcement, the Chinese Embassy in Washington released a statement saying that the US "uses the catch-all concept of national security and abuses state power to suppress and restrict Chinese enterprises in all possible means”.</p><p>"China is firmly opposed to that," the embassy’s spokesperson, Liu Pengyu, told <a href="https://www.reuters.com/business/us-restricts-exports-dozen-more-chinese-companies-2021-11-24"><em>Reuters</em></a>.</p><p>The news comes weeks after the Federal Communications Commission (FCC) <a href="https://www.itpro.com/infrastructure/network-internet/361369/fcc-expels-china-telecom-from-the-us" data-original-url="https://www.itpro.com/infrastructure/network-internet/361369/fcc-expels-china-telecom-from-the-us">expelled China Telecom from the US</a>, ordering the US subsidiary of a Chinese state-owned enterprise to stop providing domestic interstate and international communication services within its borders. This is due to the company reportedly being subject to exploitation, influence, and control by the Chinese government. China Telecom has until 27 December to comply with the FCC’s orders.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta delays product-wide end-to-end encryption rollout until 2023 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/361615/meta-delays-product-wide-encryption-rollout-until-2023</link>
                                                                            <description>
                            <![CDATA[ The company wants to 'take its time' to implement the technology in a way that both protects privacy and prevents exposure to online harms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">udvGB23TBQa2NUWwhDmH28</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CBbuvq9jYN85Qvh6ZTxivT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Nov 2021 11:36:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CBbuvq9jYN85Qvh6ZTxivT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image which shows Messenger, Instagram, WhatsApp, and Facebook apps on a smartphone&amp;#039;s home screen]]></media:description>                                                            <media:text><![CDATA[An image which shows Messenger, Instagram, WhatsApp, and Facebook apps on a smartphone&amp;#039;s home screen]]></media:text>
                                <media:title type="plain"><![CDATA[An image which shows Messenger, Instagram, WhatsApp, and Facebook apps on a smartphone&amp;#039;s home screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CBbuvq9jYN85Qvh6ZTxivT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has announced plans to delay the global rollout of end-to-end encryption (E2EE) across its messaging applications to 2023.</p><p>The company previously said it would have <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">E2EE</a> across all its products by 2022 at the earliest.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official" data-original-url="/business/policy-legislation/359502/online-safety-bill-official">Social media firms face fines and shutdowns under draft UK law</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="/security/innovation-at-work/24460/what-is-data-encryption">A complete guide to data encryption</a></p></div></div><p>Meta said it would be taking additional time to ensure the implementation across Facebook Messenger and Instagram is done correctly, protecting privacy while also mitigating the risk of online harms.</p><p>WhatsApp is currently the only app in Meta's product portfolio that enables E2EE by default, although it has previously been <a href="https://www.propublica.org/article/how-facebook-undermines-privacy-protections-for-its-2-billion-whatsapp-users">criticised</a> for allowing moderators to access the contents of any messages flagged by users as potentially abusive.</p><p>“We’re taking our time to get this right and we don’t plan to finish the global rollout of end-to-end encryption by default across all our messaging services until sometime in 2023,” said Antigone Davis, head of safety at Meta, the <a href="https://www.telegraph.co.uk/business/2021/11/20/people-shouldnt-have-choose-privacy-safety-says-facebook-safety"><em>Sunday Telegraph</em></a>.</p><p>“As a company that connects billions of people around the world and has built industry-leading technology, we’re determined to protect people’s private communications and keep people safe online,” she added.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/iEFMuuXpmTs" allowfullscreen></iframe></div></div><p>E2EE has created an ongoing debate around the divide between <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">privacy</a> and personal safety. Meta said it's taking time to implement E2EE in a way that upholds both, but how that happens is unclear.</p><p>If E2EE is deployed in its proper form, with unique on-device encryption, it should be impossible to facilitate any third-party oversight of what is communicated through the technology without breaking its fundamental principles.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BvaxdVesrBPpDZeCYx49S" name="BvaxdVesrBPpDZeCYx49S.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S.jpg" mos="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Multi-factor authentication deployment guide</strong></p><p class="fancy-box__body-text">A complete guide to selecting and deploying your MFA authentication guide</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide" data-original-url="/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide">FREE DOWNLOAD</a></p></div></div><p>"Encryption is an absolute. You either have it or you don’t. There is no 'getting it right'," said Andy Yen, founder and CEO at Proton. "The best way to protect privacy and user data is to not have the data in the first place. </p><p>"Of course we need to ensure tech is not misused, but there are many ways to combat criminal behaviour," he added. "Back doors and similar methods of undermining privacy are an ineffective way of preventing crime. If Meta cared as much about user privacy as it claims, it would have implemented end to end encryption a long time ago."</p><p>From a cyber security perspective, Jim Killock, executive director at Open Rights Group, said there is a clear argument that E2EE offers protections for the everyday consumer and calls for its removal would be welcomed by cyber criminals all over.</p><p>"There are many ways of tackling crime. Storing all communications in the clear is just one; the focus on E2EE is narrow and misleading," he told <em>IT Pro</em>. "What is certain is that E2EE provides security from cybercriminals and hacking.</p><p>"Government campaigning against security technologies is a gift to cybercriminals," he added.</p><p>However, <a href="https://www.itpro.com/security/28381/the-government-needs-to-abandon-its-war-on-whatsapp" data-original-url="https://www.itpro.com/security/28381/the-government-needs-to-abandon-its-war-on-whatsapp">repeated calls</a> for a proposed 'backdoor' in E2EE-enabled messaging services have been made by governments across the world.</p><p>The main opposing arguments are those related to the protection of children online and safeguarding national security from terror events, for example.</p><p>Home Secretary Priti Patel labelled Facebook's encryption plans "simply not acceptable" earlier this year at an event run by the National Society for the Prevention of Cruelty to Children (NSPCC). Patel said tech companies have a duty to protect children from online harms.</p><p>"Facebook is right not to proceed with end-to-end encryption until it has a proper plan to prevent child abuse going undetected on its platforms," said Andy Burrows, head of child safety online policy at the NSPCC, to <a href="https://www.theguardian.com/technology/2021/nov/21/meta-delays-encrypted-messages-on-facebook-and-instagram-to-2023"><em>the Guardian</em></a>.</p><p>"But they should only go ahead with these measures when they can demonstrate they have the technology in place that will ensure children will be at no greater risk of abuse," he added.</p><p>Coinciding with Meta's new 2023 encryption deadline is the enactment of the UK's <a href="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official" data-original-url="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official">Online Safety Bill</a>, which will force online platforms to implement protections for users, including children, from harm and address abusive content.</p><p>The domestic legislation may stifle Meta's ability to enable E2EE across its products, but to what extent the Online Safety Bill will impede consumer privacy through encrypted messaging remains to be seen.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the NCSC and telecoms firms are at loggerheads over quantum key distribution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/361581/ncsc-telecoms-quantum-key-distribution</link>
                                                                            <description>
                            <![CDATA[ In the face of mixed messages between the public and private sector, should businesses be wary of jumping on the bandwagon? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">da8C2ypUYargBkurC91mYB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KWDoBJf29Q2JRofZTQVKec-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Nov 2021 08:00:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KWDoBJf29Q2JRofZTQVKec-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image depicting the security quantum key distribution claims to provide]]></media:description>                                                            <media:text><![CDATA[Image depicting the security quantum key distribution claims to provide]]></media:text>
                                <media:title type="plain"><![CDATA[Image depicting the security quantum key distribution claims to provide]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KWDoBJf29Q2JRofZTQVKec-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The shift to remote working, the increase in ransomware attacks (and <a href="https://www.itpro.com/security/ransomware/360512/average-ransomware-payouts-nearly-double-in-a-year" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/360512/average-ransomware-payouts-nearly-double-in-a-year">ransom costs</a>), and the looming threat of <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber warfare</a> have all unquestionably contributed to elevating the urgency of cyber security. By offering newfound levels of <a href="https://www.itpro.com/infrastructure/357306/bt-toshiba-uks-first-unhackable-quantum-network" target="_blank" data-original-url="https://www.itpro.com/infrastructure/357306/bt-toshiba-uks-first-unhackable-quantum-network">“unhackable”</a> encryption, quantum key distribution (QKD) is turning heads in the cyber security and telecommunications industries alike. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356584/quantum-security-the-end-of-security-as-we-know-it" data-original-url="/security/cyber-security/356584/quantum-security-the-end-of-security-as-we-know-it">Quantum security: The end of security as we know it?</a></p></div></div><p>QKD advocates claim this technology is an ultra-secure communication method that serves as the antidote to the rise of powerful quantum machines. It allows the parties involved in sharing confidential information to generate a shared random key, known only to them, in order to encrypt and decrypt messages distributed between them. Its purported necessity is driven by the fear that quantum computers may one day be powerful enough to <a href="https://www.itpro.com/security/cyber-security/356584/quantum-security-the-end-of-security-as-we-know-it" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/356584/quantum-security-the-end-of-security-as-we-know-it">bypass most cyber security defences</a> by being able to rapidly identify the prime factors of numbers used in RSA encryption. Indeed, theoretically, anybody with access to a powerful enough quantum computer would be able to crack much of <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">today’s encryption</a>, which safeguards messages as well as sensitive medical information and military secrets.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/iEFMuuXpmTs" allowfullscreen></iframe></div></div><p>It’s been a formative year for QKD research; from <a href="https://www.itpro.com/policy-legislation/data-protection/359853/researchers-send-unhackable-quantum-data-over-370-mile" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359853/researchers-send-unhackable-quantum-data-over-370-mile">breaking records in long-distance quantum-secured information transfer</a>, to the <a href="https://www.itpro.com/infrastructure/network-internet/360861/bt-trials-quantum-secure-comms-worlds-first" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/360861/bt-trials-quantum-secure-comms-worlds-first">world’s first trial of QKD over hollow-core fibre cable</a>, the technology is maturing at pace. Earlier this month, meanwhile, we learned London will receive the <a href="https://www.itpro.com/infrastructure/network-internet/361115/bt-toshiba-quantum-secured-network-london" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/361115/bt-toshiba-quantum-secured-network-london">world’s first commercially available quantum-secured metro network</a> connecting the Docklands with the City and M4 Corridor.</p><p>BT is among a number of companies that have, <a href="https://www.itpro.com/strategy/25441/uk-could-lead-world-in-quantum-tech-says-bt" target="_blank" data-original-url="https://www.itpro.com/strategy/25441/uk-could-lead-world-in-quantum-tech-says-bt">for years</a>, advocated for the potential of QKD, with the firm behind the majority of recent developments. The National Cyber Security Centre (NCSC), however, hasn’t subscribed to this view, believing the technology is still a considerable distance from maturity.</p><h3 class="article-body__section" id="section-qkd-hackable-or-not"><span>QKD: Hackable or not?</span></h3><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BcvzLcjfiVEs4Ce5gSZ2YS" name="BcvzLcjfiVEs4Ce5gSZ2YS.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/BcvzLcjfiVEs4Ce5gSZ2YS.png" mos="https://cdn.mos.cms.futurecdn.net/BcvzLcjfiVEs4Ce5gSZ2YS.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>What to consider when choosing a next-generation firewall</strong></p><p class="fancy-box__body-text">How to choose a NGFW solution</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361543/what-to-consider-when-choosing-a-next-generation-firewall" data-original-url="/security/firewalls/361543/what-to-consider-when-choosing-a-next-generation-firewall">FREE DOWNLOAD</a></p></div></div><p>In a whitepaper published in March 2020, the NCSC stated it doesn’t endorse the use of QKD, and cautioned against relying on the technology to protect networks. Although the technology has evolved considerably since the start of the pandemic, the NCSC’s position hasn’t. “While the NCSC welcomes continuing research into QKD,” a spokesperson tells <em>IT Pro</em>, “it does not endorse its use in government or military systems and cautions against its sole reliance on networks used by critical infrastructure.</p><p>“Developments in quantum computing present challenges to cyber security in the long term that must be managed, and the UK is preparing new technologies to mitigate the threat and protect our digital lives. The NCSC considers quantum-safe cryptography to be the most effective mitigation to adopt, and advice to help organisations prepare for the transition has been published <a href="https://www.ncsc.gov.uk/whitepaper/preparing-for-quantum-safe-cryptography" target="_blank">on our website</a>.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a></p></div></div><p>Although QKD promises a secure way of communication that’s “unhackable” by quantum computers, it’s still susceptible to <a href="https://www.itpro.com/security/hacking/354435/xss-the-most-widely-used-attack-method-of-2019" data-original-url="https://www.itpro.com/security/hacking/354435/xss-the-most-widely-used-attack-method-of-2019">man-in-the-middle (MITM) attacks</a>, in which an exchange between two computer systems is breached by a third party. This is because QKD doesn’t have adequate authentication protocols in place, meaning that a threat actor could pose as person B to person A, and as person A to person B, leading them to believe that they are communicating with each other. Apart from that, the technology is also limited by specific hardware requirements, as well as the assumption the code used won’t contain any exploitable bugs which could sabotage the efforts of ultra-secure communication.</p><h3 class="article-body__section" id="section-today-39-s-problem-for-tomorrow-s-security"><span>Today's problem for tomorrow’s security</span></h3><p>Duncan Jones, head of cyber security of the quantum computing company Cambridge Quantum, tells <em>IT Pro</em> he wholeheartedly agrees with the NCSC’s position, adding that QKD won’t be suitable for production use for “a while” – potentially five years. In this respect, QKD is similar to <a href="https://www.itpro.com/infrastructure/network-internet/357153/what-is-6g-and-how-far-are-we-from-rollout" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/357153/what-is-6g-and-how-far-are-we-from-rollout">6G</a>; at the moment, the technology is far from maturity, let alone there being any smartphones capable of supporting it. That shouldn’t, however, stop networking firms from exploring 6G, in the same way companies like BT shouldn’t refrain from continuing to research QKD.</p><p>“[QKD] is going to have a big impact on communications and telecommunications. And so, they are completely right to be investing in this now,” Jones says. The “average enterprise”, on the other hand, might want to sit it out for another few years. So what makes telecom companies exceptional? The answer lies in fibre optic cables, says Jones, and the telecommunication industry’s “responsibility for moving things around securely”. </p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/3eBmL2VD2a8MbfF0GMLq2O"></iframe><p>“So, definitely, they should be exploring it, and a lot of this builds towards this idea in the future of a <a href="https://www.itpro.com/infrastructure/network-internet/358966/the-quantum-internet-is-on-its-way" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/358966/the-quantum-internet-is-on-its-way">quantum internet</a>, so the ability to share quantum data between distributed quantum computers – and that's something else that I know BT and others are thinking about and building towards,” he says.</p><p>Although innovation might seem to be moving at an overwhelmingly fast pace, to some it’s not fast enough. According to BT’s director of Government Relations, Simon Godfrey, the government doesn’t see QKD as a matter of urgency. “Quantum for me is something that I've woken up to only recently, but it is critically important to embrace it and understand it,” he tells <em>IT Pro</em>. “My fear is that our political classes are looking for it to be tomorrow's problem rather than today's problem, and it really is today's problem.”</p><h3 class="article-body__section" id="section-full-steam-ahead"><span>Full steam ahead</span></h3><p>Despite the private and public sector being at loggerheads over the readiness of QKD, Jones believes the technology’s “in a good place” thanks to the multiple grants, funds, and innovation projects that encourage research in the technology. One such initiative is a £10 million partnership between the UK and Singapore to build and fly a satellite QKD test bed. After three years of work, the satellite is set to become operational by the end of 2021. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/357019/what-will-quantum-computing-mean-for-business" data-original-url="/technology/357019/what-will-quantum-computing-mean-for-business">What will quantum computing mean for business?</a></p></div></div><p>Research and development of QKD can be described in one way: full steam ahead. Although this might seem at odds with the NCSC’s position, it’s thanks to its guidance that researchers can pinpoint the areas of development that need to be addressed. QKD might not come into play for most businesses at least for the next five years. With the encryption-breaking prospect of quantum computing coming leaps and bounds, however, UK enterprises might want to keep the technology on their radar as they aspire to future-proof their cyber security defences.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What should we do about encrypted messaging apps? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/361313/what-should-we-do-about-encrypted-messaging-apps</link>
                                                                            <description>
                            <![CDATA[ From WhatsApp to Telegram to Signal, the growth in use of end-to-end encryption messaging apps is soaring. But do their positives outweigh the risks of them being used by 'bad actors'? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kZP3K6gGCPGWNFn5rstFaS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dFTB22UBkUWKAbv6whMk5a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Nov 2021 08:00:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jonathan Weinberg ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dFTB22UBkUWKAbv6whMk5a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Privacy settings on WhatsApp which uses end-to-end encryption]]></media:description>                                                            <media:text><![CDATA[Privacy settings on WhatsApp which uses end-to-end encryption]]></media:text>
                                <media:title type="plain"><![CDATA[Privacy settings on WhatsApp which uses end-to-end encryption]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dFTB22UBkUWKAbv6whMk5a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When WhatsApp, Instagram and Facebook – along with its Messenger – <a href="https://www.itpro.com/infrastructure/network-internet/361114/facebook-whatsapp-instagram-outage-faulty-configuration-change" data-original-url="https://www.itpro.com/infrastructure/network-internet/361114/facebook-whatsapp-instagram-outage-faulty-configuration-change">all went down in October</a>, it became apparent just how ingrained messaging apps have become in people’s everyday lives. </p><p>Many immediately took to Twitter (where else?) to express their frustrations at not being able to contact friends and family as normal. Others cited how critical such channels were to those in countries where free speech is undermined, or where communication infrastructure is lacking.</p><p>Late last year, on an earnings call, Facebook founder Mark Zuckerberg revealed how WhatsApp now delivers more than 100 billion messages a day across the globe, clearly demonstrating how free messaging platforms have left SMS and the simple phone call trailing in their wake.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/361114/facebook-whatsapp-instagram-outage-faulty-configuration-change" data-original-url="/infrastructure/network-internet/361114/facebook-whatsapp-instagram-outage-faulty-configuration-change">Facebook blames faulty configuration change for hours-long outage</a></p></div></div><p>This most recent outage, however, was also used by others to highlight the belief that some messaging routes might be more private and secure than others. Privacy advocate <a href="https://twitter.com/Snowden/status/1445090556388859904">Edward Snowden, for example, suggested</a> on Twitter that it was a “reminder that you and your friends should probably be using a more private, non-profit alternative”. </p><p>Snowdon cited Signal as one example. Describing the eponymous app on its website, Signal says: “We can’t read your messages or listen to your calls, and no one else can either. Privacy isn’t an optional mode — it’s just the way that Signal works.” Competitor Telegram is growing in popularity for similar reasons.</p><p>Andrew Whaley, senior technical director at Norwegian app security company Promon suggests the growth over time in the use of encrypted messaging apps has been determined by the richer functionality and privacy they offer to consumers and company teams. </p><p><strong>“</strong>Apps like WhatsApp, Signal and Telegram all offer end-to-end encryption, which, for the many people wanting privacy, is a big bonus,” he says. “In some cases, this could be privacy from advertisers, while, for others, this might be privacy from the state. Either way, simple SMS or email is typically the less secure option.”</p><h3 class="article-body__section" id="section-from-regulation-to-whistleblowing"><span>From regulation to whistleblowing</span></h3><p>The shift to using end-to-end encrypted messaging apps has thrown up a broad range of controversies, as well as highlighted a range of benefits.</p><p>In some quarters, they are seen as having a negative impact on society with governments around the world regularly raising the idea of regulation. Most often states say there’s a dangerous lack of oversight on the private conversations being had; security services have long expressed concerns about those who may push hate speech or plan terror attacks via these channels.</p><p>Such apps have also recently been in the news amid claims they were used to spread anti-COVID-19 vaccine content or, in the case of the German elections, <a href="https://www.politico.eu/article/german-telegram-election-misinformation">conspiracy theories</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/communications/358347/should-it-departments-to-call-time-on-whatsapp" data-original-url="/marketing-comms/communications/358347/should-it-departments-to-call-time-on-whatsapp">Should IT departments call time on WhatsApp?</a></p></div></div><p>On the opposite side of the argument, the strict privacy of these apps has been heralded as a way for whistle-blowers and journalists to communicate safely, ensuring important stories and scandals are uncovered. In countries where democracy is curtailed, they also offer a route for private and unmonitored discussions.</p><p>Others believe the encryption is also a much-needed tool to stop companies mining data from unencrypted message platforms, which is often then used, or sold, to influence advertising.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RERrhUka2FHhAPqKhQcUZC" name="RERrhUka2FHhAPqKhQcUZC.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/RERrhUka2FHhAPqKhQcUZC.jpg" mos="https://cdn.mos.cms.futurecdn.net/RERrhUka2FHhAPqKhQcUZC.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Build mobile and web apps faster</strong></p><p class="fancy-box__body-text">Three proven tips to accelerate modern app development</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/business-apps/361278/build-mobile-and-web-apps-faster" data-original-url="/software/business-apps/361278/build-mobile-and-web-apps-faster">FREE DOWNLOAD</a></p></div></div><p>Robin Wilton, director of internet trust at the global non-profit Internet Society, says: “One of the main reasons these apps have grown in popularity comes down to the fact consumers have become savvier towards how their data is managed, and are therefore more aware of end-to-end encryption and its benefits. </p><p>“In addition, these apps are often free of charge and are as simple as SMS to use, while delivering enhanced privacy. Therefore, not only do users feel safer, but they also do not have to deal with the inconvenience of having to configure encryption into their applications.”</p><h3 class="article-body__section" id="section-building-the-future-of-encrypted-messaging"><span>Building the future of encrypted messaging</span></h3><p>Not everyone feels so positive towards these sorts of services, though. For Andersen Cheng, CEO at Post-Quantum, a firm of UK cryptographers, the risks related to such heavily encrypted apps actually led to him closing down a previous creation in 2014, described as “the world’s first and only ‘quantum-safe’ instant messaging system”.</p><p>He explains: “In the age of privacy, it was a much-needed win in a period where the misuse and monetisation of user data was widely agreed to be out of control. However, the reality proved vastly more complex when our application subsequently appeared on an Islamic State recommended technical tools list.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/361070/telegram-bots-are-out-to-steal-your-one-time-passwords" data-original-url="/security/hacking/361070/telegram-bots-are-out-to-steal-your-one-time-passwords">Telegram bots are out to steal your one-time passwords</a></p></div></div><p>“We were getting healthy daily downloads as well, but the eventual decision to switch it off was relatively easy — we would not put profit before human lives.”</p><p>Cheng adds: “I firmly believe these privacy-preserving apps have a future but a middle ground must be reached between the two sides of the debate. On the one hand, we have privacy advocates arguing for full and unquestionable privacy for users. However, this makes it extremely difficult for the police and tech firms to monitor communications, detect child grooming and intercept child abuse imagery. It also makes it easier for terrorist organisations to operate undetected.”</p><p>On the other hand, Cheng argues government-sanctioned ‘backdoors’ in encryption aren’t the answer either, warning: “A backdoor for one is a backdoor for all, and anyone can walk through it, whether the intended government agency, a hacker, or a malicious nation.”</p><p>His suggestion is to have a pre-agreed ‘side door’, adding: “That allows you to split control and responsibility, and one you can only access if multiple parties like governments, private companies, privacy groups and preferably courts each provide their section of the key.”</p><p>Amandine Le Pape, co-founder of secure messaging app Element, which claims to be trusted by French, US and UK governments, is also against backdoors. Her aim was to create an open standard for communication that brought benefits to both sides, leading to Matrix – an open standard for decentralised, end-to-end encrypted communication. Element is a Matrix-based app, one of hundreds that now exist, with 38 million users in the network. </p><p>Le Pape states end-to-end encryption is “absolutely vital” to secure the modern digital world. “We need end-to-end encryption to protect the 99.9% of the population that are perfectly law-abiding people from the bad actors,” she adds.</p><p>However, from the technology providers’ side, she believes there is a need for responsible management and explains that by building a “first-class infrastructure … users (and room/community moderators and server admins) make up their own mind about who to trust, and what content to allow”.</p><p>She believes the future is “incredibly bright” but warns: “Backdoors are an absolute disaster. Don’t forget, ‘bad people’ have free and easy access to create their own end-to-end encrypted systems. They will not be using an encrypted system with a wide open backdoor. It only impacts the ‘good people’.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multi-factor authentication deployment guide ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide</link>
                                                                            <description>
                            <![CDATA[ A complete guide to selecting and deploying your MFA authentication guide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tMhF4RS7qewjA5bUziYQor</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Nov 2021 16:51:37 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Mar 2022 16:51:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The whitepaper title on a strip of swirling blue and purple diagonal across the page]]></media:description>                                                            <media:text><![CDATA[The whitepaper title on a strip of swirling blue and purple diagonal across the page]]></media:text>
                                <media:title type="plain"><![CDATA[The whitepaper title on a strip of swirling blue and purple diagonal across the page]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Multi-factor authentication (MFA) has been increasingly adopted in recent years, in line with the threats to password security.</p><p>Web and mobile products primarily use this, but approaches can differ.</p><p>Download this guide to learn why MFA is an essential tool in online security as well as the best practices for deployment.</p><p><em>Provided by </em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aVingsbZaxsFEzjgWucZgF" name="" alt="Okta logo" src="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" mos="https://cdn.mos.cms.futurecdn.net/aVingsbZaxsFEzjgWucZgF.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49540/form-9526?locale=1&p=false&wp=8437"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK gov must act now to regulate Facebook, says whistleblower  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/361355/uk-gov-must-act-now-to-regulate-facebook-says-whistleblower</link>
                                                                            <description>
                            <![CDATA[ Frances Haugen told members of the Online Safety Bill committee that the social network "is closing the door on us being able to act” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gPGapZdbHU3XaDcrqRULQG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DbFdo6zwAEFtpWvLkuEJF9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Oct 2021 10:04:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DbFdo6zwAEFtpWvLkuEJF9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A finger reaching to delete Facebook app from smartphone]]></media:description>                                                            <media:text><![CDATA[A finger reaching to delete Facebook app from smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[A finger reaching to delete Facebook app from smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DbFdo6zwAEFtpWvLkuEJF9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government must act now to regulate Facebook, whistleblower Frances Haugen told MPs on Monday.</p><p>The data engineer and scientist, who worked for Facebook for two years prior to sounding the alarm about the tech giant’s practices, testified before the <a href="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official" data-original-url="https://www.itpro.com/business/policy-legislation/359502/online-safety-bill-official">Online Safety Bill</a> committee on Monday about the dangers created by the social media platform.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/361328/facebooks-oversight-board-demands-more-transparency" data-original-url="/marketing-comms/social-media/361328/facebooks-oversight-board-demands-more-transparency">Facebook's Oversight Board demands more transparency</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/business-management/361308/facebook-change-name-to-suit-new-metaverse-focus" data-original-url="/business-operations/business-management/361308/facebook-change-name-to-suit-new-metaverse-focus">Facebook is reportedly planning to change its name</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/business-management/361132/us-senators-demand-zuckerberg-answer-whistleblowers" data-original-url="/business-operations/business-management/361132/us-senators-demand-zuckerberg-answer-whistleblowers">US senators demand Zuckerberg answers Facebook whistleblower's claims</a></p></div></div><p>Haugen warned MPs that “Facebook is closing the door on us being able to act”.</p><p>“We have a slight window of time to regain people[‘s] control over AI,” she told members of the committee, who are working on new legislation that could see social media companies fined up to 10% of their annual turnover, or £18 million, for failing to quash <a href="https://www.itpro.com/marketing-comms/social-media/360190/bcs-calls-for-social-media-platforms-to-verify-users" data-original-url="https://www.itpro.com/marketing-comms/social-media/360190/bcs-calls-for-social-media-platforms-to-verify-users">online abuse</a>.</p><p>Haugen said that work on the Online Safety Bill ​​has been largely ignored by Facebook CEO Mark Zuckerberg, yet the legislation could have the potential to set a precedent for other countries. </p><p>"The UK has a tradition of leading policy in ways that are followed around the world,” she told Parliament, adding that she was "incredibly proud of the UK for taking such a world-leading stance".</p><p>Haugen told MPs that, due to shortages of moderators, Facebook had been unable to police harmful content in multiple languages around the world, leading to civil unrest in Ethiopia and Myanmar. However, the issue also impacts the UK, she added, due to Facebook’s AI’s inability to detect online abuse in British English.</p><p>"UK English is sufficiently different that I would be unsurprised if the safety systems that they developed primarily for American English were actually under-enforcing in the UK,” she told the committee. </p><p>The hearing comes days after Facebook claimed that its AI managed to <a href="https://www.itpro.com/marketing-comms/social-media/361272/facebook-ai-reduces-hate-speech-50-percent" data-original-url="https://www.itpro.com/marketing-comms/social-media/361272/facebook-ai-reduces-hate-speech-50-percent">reduce the prevalence of hate speech by 50%</a>.</p><p>Haugen also hit back at claims made by <a href="https://www.telegraph.co.uk/news/2021/10/24/facebook-whistleblower-warns-dangerous-encryption-will-aid-espionage"><em>the Telegraph</em></a> on her stance on <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encryption (e2ee)</a>, saying that she had been ‘misrepresented’ by the publication.</p><p>She said that, contrary to <em>the Telegraph</em>’s report published on Sunday, she fully supports “e2e open source encryption software”, using it herself on a daily basis.</p><p>“I want to be very, very clear. I was mischaracterised in <em>the Telegraph</em> yesterday on my opinions around end-to-end encryption,” Haugen told MPs, adding that she is “a strong supporter of access to open source end-to-end encryption software”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TpQGJuV8JLJg48R7p8QdfN" name="TpQGJuV8JLJg48R7p8QdfN.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TpQGJuV8JLJg48R7p8QdfN.jpg" mos="https://cdn.mos.cms.futurecdn.net/TpQGJuV8JLJg48R7p8QdfN.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The top three IT pains of the new reality and how to solve them</strong></p><p class="fancy-box__body-text">Driving more resiliency with unified operations and service management</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/it-infrastructure/360224/the-top-three-it-pains-of-the-new-reality-and-how-to" data-original-url="/business-strategy/it-infrastructure/360224/the-top-three-it-pains-of-the-new-reality-and-how-to">FREE DOWNLOAD</a></p></div></div><p>“Part of why I am such an advocate for open source software, in this case, is that if you’re an activist, if you’re someone who has a sensitive need, a journalist, a whistleblower — my primary form of social software is an open source, end-to-end encryption chat platform,” she said.</p><p>However, Haugen said she was sceptical about the legitimacy of Facebook’s e2ee.</p><p>In August, Facebook <a href="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls" data-original-url="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls">added the option of e2ee for voice and video calls</a> on its Messenger communications platform, defying warnings from the UK government about the technology’s risk to <a href="https://www.itpro.com/strategy/28709/what-is-e-safety" data-original-url="https://www.itpro.com/strategy/28709/what-is-e-safety">children’s safety</a>. Weeks later, it also <a href="https://www.itpro.com/security/encryption/360856/whatsapp-end-to-end-encrypted-cloud-backups-official" data-original-url="https://www.itpro.com/security/encryption/360856/whatsapp-end-to-end-encrypted-cloud-backups-official">extended e2ee to WhatsApp backups</a>.</p><p>Despite the negative attention and increased scrutiny from US and UK officials, Facebook managed to generate a profit of $9.2 billion (£6.67 billion) during the third quarter, according to financial earnings results published on Monday.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Australian Federal Police plots "aggressive" cyber division following law change ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/361348/australia-federal-police-plots-aggressive-cyber-division</link>
                                                                            <description>
                            <![CDATA[ New powers allow law enforcement to launch disruptive operations and collect data on suspected criminals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7zDRNa6BSQQNCoh9URfCLA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yJFJgavypp9fVdfpQShr9N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Oct 2021 11:54:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yJFJgavypp9fVdfpQShr9N-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of encrypted data on a screen]]></media:description>                                                            <media:text><![CDATA[An image of encrypted data on a screen]]></media:text>
                                <media:title type="plain"><![CDATA[An image of encrypted data on a screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yJFJgavypp9fVdfpQShr9N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Australian Federal <a href="https://www.itpro.com/tag/police" target="_blank" data-original-url="https://www.itpro.com/search/police">Police</a> (AFP) has suggested it may introduce a "more aggressive" cyber division, after legislation was passed in September granting extensive new <a href="https://www.itpro.com/tag/surveillance" target="_blank" data-original-url="https://www.itpro.com/search/surveillance">surveillance</a> powers to law enforcement agencies in the country.</p><p>During a Senate estimates hearing held on Monday, in which senators typically scrutinise how the government is spending taxpayer money, AFP commissioner Reece Kershaw said that the introduction of Surveillance Legislation Amendment (Identify and Disrupt) Act 2021 means it can now proactively target suspected criminals with disruptive operations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/357390/five-eyes-nations-demand-encryption-backdoors-by-design" data-original-url="/security/encryption/357390/five-eyes-nations-demand-encryption-backdoors-by-design">Five Eyes nations demand encryption 'backdoors' by-design</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" data-original-url="/security/privacy/361191/is-australia-becoming-a-surveillance-state">Is Australia becoming a surveillance state?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359801/us-and-australia-decrypt-communications-app-to-monitor-and-arrest" data-original-url="/security/encryption/359801/us-and-australia-decrypt-communications-app-to-monitor-and-arrest">US and Australia arrest 'hundreds' in encrypted messaging sting</a></p></div></div><p>Kershaw highlighted that the three new powers in the Act will significantly enhance how the AFP investigates serious cyber-enabled crime. The new powers allow police to disrupt data by modifying, copying, adding, or deleting it and allow the AFP and Australian Criminal Intelligence Commission (ACIC) to collect intelligence from devices and networks. Lastly, the powers allow the agencies to take control of an online account to gather information for an investigation.</p><p>The commissioner said that the police’s investigators are already planning how they might use the new powers in active investigations to identify, target, and disrupt offenders, including those relating to terrorism, drug importations, and distribution of child abuse material.</p><p>"At the moment, we're actually going through an internal review of how we can be more aggressive in cyber, and it may mean a mini restructure internally for us to really have what we would call a cyber offensive operation of the AFP, which would actually conduct disruption operations on these individuals," said Kershaw, according to <a href="https://www.zdnet.com/article/afp-is-looking-to-be-more-aggressive-with-new-cyber-offense-arm" target="_blank"><em>ZDNet</em></a>.</p><p>The commissioner said this includes talking with the Five Eyes alliance about the growth of cyber threats, with Kershaw currently being the chair of the organisation’s law enforcement group.</p><p><a href="https://www.itpro.com/security/encryption" target="_blank" data-original-url="https://www.itpro.com/search/encrypted">Encrypted</a> communications platforms are a significant barrier for the AFP, said Kershaw, outlining that transnational serious organised crime offenders rely on encrypted platforms to carry out their criminality.</p><p>“This is the next frontier of crime, and the AFP and our partners will work with governments and global law enforcement networks to ensure the long arm of the AFP reaches criminals no matter where they are in the world,” he added.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>The AFP's plan for a new cyber offensive arm will have a dangerous effect on people's rights and freedoms in Australia and de-stabilise the open, secure internet we all rely on, said Namrata Maheshwari, Asia Pacific policy counsel, and lead on encryption policy at Access Now.</p><p>"This is extremely damaging for privacy and free expression, and undermines digital security for all. The new arm is being built on a <a href="https://www.accessnow.org/surveillance-state-incoming-with-australias-hacking-bill" target="_blank">flawed foundation: the Identify and Disrupt Bill</a>, which violates human rights; and discussions with the Five Eyes surveillance alliance, which has often called for backdoors to encryption, a measure that would render private and secure communication impossible," she said. "We need rights-respecting frameworks to strengthen cybersecurity, and enhanced surveillance and new 'disruption' tools by law enforcement, as is being contemplated, will have the opposite effect."</p><p>Kershaw explained that Operation Ironside was enabled by unique, global law enforcement partnerships, particularly with the FBI, as the AFP provided the agency with the technical ability to decrypt and read encrypted communications in real time.</p><p>The <a href="https://www.itpro.com/security/encryption/359801/us-and-australia-decrypt-communications-app-to-monitor-and-arrest" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359801/us-and-australia-decrypt-communications-app-to-monitor-and-arrest">operation saw the AFP work for almost three years, leading to the arrest of hundreds of suspected criminals</a> that were tricked into using an encrypted messaging app. The app, codenamed “Anom”, was installed on mobile phones stripped of other capabilities that were bought on the black market. They were only able to send messages to another device that had the app installed, and criminals had to know other criminals to acquire a device.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp backups to get end-to-end encryption ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/361253/whatsapp-backups-to-get-end-to-end-encryption</link>
                                                                            <description>
                            <![CDATA[ Facebook says it's the final step towards a full end-to-end encrypted messaging experience on the chat app ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">94oWCEjEcctEgGpr9zKmZm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pyWBHEFrb9UEdnFEuBZW7H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Oct 2021 10:32:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pyWBHEFrb9UEdnFEuBZW7H-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WhatsApp images with its new feature fore end-to-end encryption for backups]]></media:description>                                                            <media:text><![CDATA[WhatsApp images with its new feature fore end-to-end encryption for backups]]></media:text>
                                <media:title type="plain"><![CDATA[WhatsApp images with its new feature fore end-to-end encryption for backups]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pyWBHEFrb9UEdnFEuBZW7H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook has announced plans to roll out end-to-end encryption for WhatsApp chat history on both Android and iOS versions of the app.</p><p>The feature, which is to be slowly rolled out to those using the latest version of the chat app, will allow users to secure backups before they are saved in iCloud or Google Drive storage, where neither WhatsApp or the cloud service provider will be able to access the files.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent" data-original-url="/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent">EU inches closer to ban on end-to-end encryption</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls" data-original-url="/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls">Facebook defies gov pressure with end-to-end encryption expansion</a></p></div></div><p>Users will be able to use a password to encrypt the backup or use a 64-digit encryption key, the has company confirmed.</p><p>WhatsApp has offered secure messaging since 2016 and the company started testing encrypted backups earlier this year. With Wednesday's announcement, Facebook said it had taken the final step towards providing a full <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encrypted</a> messaging experience on WhatsApp.</p><p>In essence, end-to-end encryption lets only the sender and receiver see the contents of a message, and conceals it from the company providing the service. While this is an assurance to users of WhatsApp, it's a concern for governments and security professionals that feel there needs to be a way to access communications under certain circumstances.</p><p>WhatsApp has long been considered at the forefront of the industry when it comes to end-to-end encryption, and has repeatedly drawn the ire of those seeking to ban its use in telecommunications.</p><p>The <a href="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls" target="_blank" data-original-url="https://www.itpro.com/security/privacy/360588/facebook-messenger-end-to-end-encryption-calls">UK's government</a> has repeatedly called for a mechanism that can bypass the safeguards of a service. This would require service providers to be active participants in the interception and acquisition of user data as part of an investigation.</p><p>Charities, such as the NSPCC, and law enforcement agencies like Interpol and GCHQ, have also argued against end-to-end encryption on the grounds that it protects individuals and impedes investigations.</p><p>Even the European Union, which was once in favour of end-to-end encryption, has reportedly proposed regulations to ban it. <a href="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent" target="_blank" data-original-url="https://www.itpro.com/security/357699/leaked-memo-suggests-eu-ban-on-end-to-end-encryption-imminent">A leaked document</a>, dated 6 November, appeared to show that the Council of the European Union had a near-complete resolution to ban the use of end-to-end encryption on off-the-shelf apps, like WhatsApp or Signal. However, there has been no official announcement from the EU regarding the memo.</p><p>However, many cyber security professionals and industry lobbyists maintain that a so-called backdoor in end-to-end encryption would only make users more vulnerable to cyber crime.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp activates end-to-end encrypted cloud backups ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/encryption/360856/whatsapp-end-to-end-encrypted-cloud-backups-official</link>
                                                                            <description>
                            <![CDATA[ The messaging service will grant users a password-protected key when they save their chat histories to the cloud ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2tQpRHEem5Ayq4kGV7vLRk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kkip7hn565CU2WZyuVDiaP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Sep 2021 09:31:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kkip7hn565CU2WZyuVDiaP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WhatsApp&amp;#039;s app in the top corner of a smartphone ]]></media:description>                                                            <media:text><![CDATA[WhatsApp&amp;#039;s app in the top corner of a smartphone ]]></media:text>
                                <media:title type="plain"><![CDATA[WhatsApp&amp;#039;s app in the top corner of a smartphone ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kkip7hn565CU2WZyuVDiaP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook is launching end-to-end encryption protection for WhatsApp users who want to back up their chat histories to the cloud.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">What is end-to-end encryption and why is everyone fighting over it?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">Four quick tips to create an unbreakable password</a> The top 12 password-cracking techniques used by hackers</p></div></div><p>The firm has devised an entirely new system for <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption key storage</a> that means end-to-end encrypted backups will be protected with a randomly generated 64-character encryption key. </p><p>The firm's two billion users will be able to benefit from this optional feature on their primary devices when it launches in the coming days.</p><p>“For years, in order to safeguard the privacy of people’s messages, WhatsApp has provided end-to-end encryption by default ​​so messages can be seen only by the sender and recipient, and no one in between,” said WhatsApp software engineer managers, Slavik Krassovsky and Gabriel Cadden. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MhoDQHbDgtzbg6RyMTEvAn" name="MhoDQHbDgtzbg6RyMTEvAn.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" mos="https://cdn.mos.cms.futurecdn.net/MhoDQHbDgtzbg6RyMTEvAn.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Aberdeen Report: How a platform approach to security monitoring initiatives adds value</strong></p><p class="fancy-box__body-text">Integration, orchestration, analytics, automation, and the need for speed</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds" data-original-url="/security/360172/aberdeen-report-how-a-platform-approach-to-security-monitoring-initiatives-adds">FREE DOWNLOAD</a></p></div></div><p>“Now, we’re planning to give people the option to protect their WhatsApp backups using end-to-end encryption as well.</p><p>“People can already back up their WhatsApp message history via cloud-based services like Google Drive and iCloud. WhatsApp does not have access to these backups, and they are secured by the individual cloud-based storage services. But now, if people choose to enable end-to-end encrypted (E2EE) backups once available, neither WhatsApp nor the backup service provider will be able to access their backup or their backup encryption key.”</p><p>All users can activate this method of backup to secure their accounts either with the key directly, or with a user password. If users choose a password, the key is stored in a Backup Key Vault that’s built on a component called a hardware security module (HSM). </p><p>When the owner needs to access their backup, they can access it with the encryption key, or use their password to retrieve their key from the HSM-based vault. </p><p><a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">The vault enforces password verification</a> and permanently disables the key after a number of failed attempts, however, meaning the backup will be lost forever. WhatsApp itself will only know that a key is being stored in the vault, and not what the key is. </p><p>WhatsApp isn’t the first company to enforce end-to-end encrypted backups, with Apple enforcing encryption on iCloud backups.</p><p>However, the fact Facebook’s messaging service has expanded the level of encryption it uses on its service will likely anger law enforcement agencies across the world which have <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">railed against the technology</a>.</p><p>The Five Eyes nations of English-speaking countries, for example, have time after time asked for tech companies to water down or undermine the application of end-to-end encryption in their services. </p><p>The group, for example, <a href="https://www.itpro.com/encryption/31822/five-eyes-nations-hand-tech-giants-encryption-ultimatum" data-original-url="https://www.itpro.com/encryption/31822/five-eyes-nations-hand-tech-giants-encryption-ultimatum">handed tech giants an ‘ultimatum’ in September 2018</a> to voluntarily insert a backdoor for law enforcement into their platforms. They have followed this up with repeated calls for a backdoor, and in October 2020, again, <a href="https://www.itpro.com/security/encryption/357390/five-eyes-nations-demand-encryption-backdoors-by-design" data-original-url="https://www.itpro.com/security/encryption/357390/five-eyes-nations-demand-encryption-backdoors-by-design">urged companies to implement a backdoor by-design into their services</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ProtonMail criticised for sharing activist's IP address with law enforcement ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/360793/protonmail-criticised-sharing-activists-ip-address-law-enforcement</link>
                                                                            <description>
                            <![CDATA[ The company prides itself on benefitting from Switzerland's strict privacy laws, yet had to follow the “legally binding order" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tdxsufV2x6GHbY2PYdnhW6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GVsr32mAKF8mNLkRrXVpmF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Sep 2021 09:55:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GVsr32mAKF8mNLkRrXVpmF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ProtonMail home page]]></media:description>                                                            <media:text><![CDATA[ProtonMail home page]]></media:text>
                                <media:title type="plain"><![CDATA[ProtonMail home page]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GVsr32mAKF8mNLkRrXVpmF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ProtonMail has been criticised for providing authorities with the <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address" data-original-url="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP address</a> of a French climate activist.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">How to stay anonymous online <a data-analytics-id="inline-link" href="https://www.itpro.com/security/spyware/360682/bahrain-targets-activists-with-nsos-pegasus-spyware" data-original-url="/security/spyware/360682/bahrain-targets-activists-with-nsos-pegasus-spyware">Bahrain targets activists with NSO's Pegasus spyware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/email-providers/360302/duckduckgo-launches-email-privacy-service" data-original-url="/network-internet/email-providers/360302/duckduckgo-launches-email-privacy-service">DuckDuckGo launches email privacy service</a></p></div></div><p>The company, which is one of the world’s largest secure email services, offers <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">end-to-end encrypted</a> emails which can only be decrypted by the recipient. However, it can log users’ IP addresses in the case of serious crimes.</p><p>French authorities, who were denied the request for the activist’s IP address, managed to obtain the information through Swiss law enforcement. ProtonMail, based in Switzerland, prides itself on benefiting from the country’s strict privacy laws, yet was “obligated" to comply with the “legally binding order from Swiss authorities”, according to founder and CEO Andy Yen.</p><p>The case has been extensively criticised, with many disagreeing about the severity of the crime. The activist had been involved in taking over apartments and commercial locations in the Paris neighbourhood of Sainte Marthe, in order to protest the rising gentrification in the area. <a href="https://www.itpro.com/security/spyware/360276/journalists-human-rights-activists-targeted-with-pegasus-spyware" data-original-url="https://www.itpro.com/security/spyware/360276/journalists-human-rights-activists-targeted-with-pegasus-spyware">Amnesty International</a> technologist Etienne Maynier <a href="https://twitter.com/tenacioustek/status/1434604112470056969">stated</a> on Twitter that he has “a hard time seeing how young people squatting buildings in Paris is an extreme criminal case”. </p><p>“In any case, I have an issue with this lack of transparency from ProtonMail, if any police service can ask them to log IP addresses, that is not anonymous,” he added.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2meHeQoSjXz5uLpoSQhCUn" name="2meHeQoSjXz5uLpoSQhCUn.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/2meHeQoSjXz5uLpoSQhCUn.png" mos="https://cdn.mos.cms.futurecdn.net/2meHeQoSjXz5uLpoSQhCUn.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The ultimate law enforcement agency guide to going mobile</strong></p><p class="fancy-box__body-text">Best practices for implementing a mobile device program</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/public-sector/360508/how-to-go-mobile-law-enforcement-agency" data-original-url="/business-strategy/public-sector/360508/how-to-go-mobile-law-enforcement-agency">FREE DOWNLOAD</a></p></div></div><p>In a company statement published on Tuesday, Yen said that “there was no possibility to appeal this particular request [from the Swiss authorities]”.</p><p>However, it has sparked concerns that ProtonMail could be able to give out IP addresses to law enforcement of any country, as long as they file their request through the Swiss authorities.</p><p>Security expert Filippo Valsorda <a href="https://twitter.com/FiloSottile/status/1434823826332962817">said</a> that “the problem with ProtonMail is not that they don't deliver an impossible product (secure email), but that they advertise it”.</p><p>“It's a choice, they know it, they benefit from it, their users believe it, and they are responsible for it,” he added.</p><p>Yen stated that the company “will be making updates to [its] website to better clarify ProtonMail’s obligations in cases of criminal prosecution”.</p><p>“We apologise if this was not clear. As a Swiss company, we must follow Swiss laws,” he said, adding ProtonMail’s privacy policy will also be updated “to make clearer our legal obligations under Swiss law”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>