21581 - SCTE Broadband August2022 COMPLETE v1

17 Vol. 44 No. 3 - September 2022 Issue scte long read inside the Twitter app, your phone will generate a hidden passkey and store it securely on the device. Twitter itself never learns or stores the passkey; instead, it receives a credential from your phone that verifies your identity and lets you log in.” This is welcome news of course. Human behaviour is nothing if not predictable; how many of us have re-used passwords, knowing we should know better? Who hasn’t heard ruinous stories of corporations whose entire IT security system relies on the laughable identifier “Password123”? How many of us have used our children’s birthdays, pet’s names and mother’s maiden names to identity ourselves? Forgetful people the world over will collectively be breathing a sigh of relief. Currently, society is broken down like this. Organised people might have some sort of password system, a prefix and a changing suffix for every website they access, for example. Others write their passwords down. Big tech is helpfully suggesting customers rely on the ‘STRONG PASSWORD’ option, offered up by their handsets to do the work for them. However, there is a worrying number of people who lack sufficient know-how, organisation or awareness and are sleepwalking into a world of well-documented trouble. At best they risk a protracted period of inconvenience and uncertainty while they assess the damage done by using ‘Fluffy100’ for all their website passwords; at worst, they risk data breaches, fraud and identify theft every time they log in. Shikiar laughed ruefully. “The best thing you can do in the short term is use a password manager, and that’s an imperfect technology. Writing down passwords and sticking them in a drawer somewhere in your home is okay, but not the best practice. It’s probably better than leaving it on a sticky note. There’s really no great answer. The only right answer is for us to get past this stage as soon as we can. Passwords are simply not fit for purpose for the way we use the internet today.” In the same way we now laugh at what we had to do to load up rudimentary computer games on the ZX Spectrum, using a tape recorder and a tangled spaghetti of wires into the back of a TV in the 80s, the current entry system into websites in 2022 is ridiculous, tedious and certainly overdue an upgrade, never mind the security implications. We will look back on this period with incredulity. Shikiar elaborated the point. “It is so stunningly easy at the moment to execute a remote attack at scale that we need to raise the bar to a bare minimum. Right now, if you go to the dark web there are phishing tool kits with customer support available for just a couple of hundred dollars. I can get a toolkit that allows someone to create a fake banking website for me in no time. These are phishing websites, phishing tools, giving access to stolen lists of emails and email/password combinations where I can start spraying people. It’s that easy. You’re always trying to stay ahead of the hackers, and I think that will always be an ongoing task. But this development stands to raise the bar dramatically.” These new capabilities are expected to become available across Apple, Google, and Microsoft platforms over the course of the coming year. It is fair to say that while Big Tech are again racing ahead in the name of progress and they are to be congratulated at working collaboratively on a massive scale, there are implications to consider. Broadband Journal talked to award-winning music journalist and broadcaster Pete Paphides, whose father passed away recently. On Twitter Pete recounted a sad story about his own 84-year- old father, whose failed experience trying to pay for parking via an app a few months ago on his phone eventually led to a disproportionate fine. He spent the last weeks of his life unsuccessfully trying to resolve this, a problem his family had to sort out once he had passed away. The post went viral and led to a broader debate about communities being left behind as technology advances at a faster pace year on year. “It’s out of control,” Pete said. “Tech companies can’t or won’t govern, and governments don’t understand the technology.” We have covered the glacial pace of legislation in this area in other Long Reads – the issue is the same here too. All of It’s essentially what you know, like a password, which is knowledge-based. Then there is what you have, which is proven possession, like your date of birth or zip code. Then finally it’s who you are, which is inherent, and that’s your biometric (your fingerprint, your voice, your face)

RkJQdWJsaXNoZXIy OTIxNzg=