It's mind boggling how bad Microsoft have made this.
I just want to install a few apps and manage their settings. But the combination of Windows, Intune, modern Store apps, multiple similar settings, and licensing, make it a full time job full of footguns.
If they just had one team with responsibility for end user experience they could bring this tech together in amazing ways.
But instead there's probably at least one FTE is every IT department in the world just managing Microsoft's bullshit
IP filtering is a valuable factor for security. I know which IPs belong to my organisation and these can be a useful factor in allowing access.
I've written rules which say that access should only be allowed when the client has both password and MFA and comes from a known IP address.
Why shouldn't I do that?
And there are systems which only support single-factor (password) authentication so I've configured IP filtering as a second factor. I'd love them to have more options but pragmatically this works.
Thanks. That wasn't clear from the Mail article above.
But the Times article also says:
> A spokeswoman for Leicestershire police said crimes under Section 127 and Section 1 include “any form of communication” such as phone calls, letters, emails and hoax calls to emergency services.
So I think the categorisation is a mess, and probably not even consistent across forces
And Microsoft own the client, so they are the one company who don't need to do this!
If you really want to check every time someone clicks on a link then you can do this in the client and keep the visible link the same for the end user.
But instead there are different teams working on this in Outlook, Teams, Exchange, Defender and god knows where else.
(I'm one of the people in corporate IT trying to turn this off and often struggling)
One use case might be if you have limited bandwidth, perhaps only a voice call, and want to join a video conference. I could imagine dialling in to a conference with a virtual face as an improvement over no video at all.
I didn't think of 2FA as being protection against password reuse. People should still avoid reusing passwords and change them if they know of a breach.
Are there really attackers who are picking up breach databases and then sim-swapping to get the 2FA as well?
The article conflates two issues that have different security implications.
The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp.
But 2FA codes seem notably less worrying.
They are the second factor and require an attacker to have the password too.
For these cases I'm much more relaxed about the use of SMS and the risks of interception.
I agree that it would be fine to not have phones - we'd all cope.
But when my daughter hasn't got home on time if I can check her GPS and see that she's in the park then I can relax a little.
If she needs to say she's staying out late, using a group chat to let the whole family know is easier than trying to phone mum, then dad, then grandma.
Or she can include a photo showing how much fun she's having.
My life is richer because of communication on things like family group chats.
It would be a shame to throw the baby out with the bathwater and lose that
There is a potential clash here between control and privacy.
A few years ago Apple blocked[1] some parental control apps because "they put users’ privacy and security at risk"
This actually came up with our school. They tried to use an app to control student phones but it was fundamentally limited by these Apple restrictions.
This debate seems to conflate two or three different issues.
1. Use of phones in classrooms
2. Having phones present in schools, but unused
3. The impact of social media on schoolchildren
(1) is undeniably bad and should be banned everywhere.
(2) raises some issues. I don't want (1) but I would like my child to have a phone for the journey to and from school. And a smartphone is much better at this than a dumb phone (group chats are really good!)
(3) is a concern but it seems almost totally unrelated to the other issues.
The children who are banned from having a phone at school will use the same social media when they're at home and schools will still have to deal with bullying.
Our school current bans (1) and is consulting on more bans. But from parent discussions it feels like both the school and parents are mixing up these issues and just coming back with "phones are bad".
It's wild that this sort of bug got through testing.
As a diabetic it feels like our insulin pump software is very conservative and lacking in features especially compared to what some of the "closed loop" things would like to do.
That seems reasonable if the manufacturers are having to do lots of safety testing.
But if bugs like this are getting through then the testing obviously isn't anywhere near as robust as we'd like.
As a slightly more frivolous use of this website - we're approaching conker season!
Last year my kids wanted to go collecting conkers and I used a similar website (https://www.treetalk.co.uk/) to find a local place with lots of horse chestnuts.
It worked brilliantly and the kids thought I was some kind of genius for finding so many.
I have the Awair Element and I'm reasonably happy with it.
The primary interface is through their app and I think you might need to use this to get it up and running initially.
But they have a supported local API feature[1] that has so far worked as I'd expect.
In the end I've been happy with their app so have primarily used that so far. The data seems good.
They're quite expensive new.
But they were involved in some sort of cryptocurrency (!) that failed. So there are a lot of them available as nearly-new on eBay. In the UK I picked one up for about £60, I think.