Over the past couple of decades it has become abundantly clear that human beings can't be trusted to come up with decent passwords. We might combine the name of a childhood pet with a two-digit number and proudly use it across multiple services, imagining that it ranks alongside Fort Knox in terms of its security. But it doesn't. Bad passwords continue to be exploited by criminals, either by using computers to work their way through large databases of breached passwords, or simply by guessing them. Credentials, cash and personal identities are stolen and misused on a daily basis.
The password problem
The battle against bad passwords has been waged in many ways over the years. Services ask us to change them, they force us to litter them with unusual symbols, and they send additional codes to our mobile phones to confirm our identities. But an industry consortium has now made a significant step towards a future in which passwords become obsolete. Recent versions of the Android mobile operating system – currently used by about one billion devices worldwide – are now certified to use a security system called FIDO2.
The result is that developers can allow access to websites and apps with a fingerprint or a USB security key. No longer will we have to think up strings of letters and numbers, remember them and type them out. FIDO2 may finally save us from our failing memories and lack of imagination.
The move can’t come soon enough. A report released at the end of last year by password management company SplashData revealed that, for the fifth consecutive year, the two most popular passwords online are still “123456” and “password”.
The difficulty of remembering multiple passwords causes us to reuse the same ones across several different services, and that's what makes breaches of password data so dangerous – by using a technique called "credential stuffing", criminals can force their way into a series of accounts. In the past few days, for example, accounts with smart home product manufacturer Nest were attacked in this way. But it's not their fault, it's ours.
Can FIDO2 save us?
The burning question is why, despite being told repeatedly that our passwords are terrible, have we been reluctant to change our ways? One reason is that we become emotionally attached to them, not least because they often (unsafely) incorporate the names of people or things we hold dear. Also, because we need so many, we make passwords easy to remember. Even computer experts do that. In 2016, researcher Elizabeth Stobert surveyed several experts and was surprised by their password habits. "It is telling that they have chosen to trade off security for usability in certain situations," she said. "The social and contextual pressures that affect everyone also affect computer security experts."
As our dependence on digital services grows, the password problem grows, too, but FIDO2 shifts the whole idea of authentication over to the device you're using. In other words, instead of your device sending a password to a service for checking, FIDO2 merely asks for proof that you are who you say you are. That can be done with a fingerprint sensor or a USB key, so passwords aren't needed. Some online banking services have used this system for a while, but the certification of Android should help to establish it as the norm.
Per Thorsheim, a self-confessed password obsessive who runs a global conference called PasswordsCon, which addresses the challenges surrounding digital authentication, is optimistic about FIDO2. "At the last conference, everyone in the room, from geeks to police, and intelligence experts to hackers, agreed that nothing came as close as this to improving security beyond the username and password," he says. "We actually think this might work – and we haven't said that about anything for the past 15 years."
What's the practical solution?
But while the technology is sound, he believes that there are practical issues that stand in its way. "If I gave a USB security key to my mother and told her that it replaces her password, she wouldn't be interested in spending even two minutes learning how to use it. And people will obviously lose them or forget to carry them," he says.
Thorsheim also notes that fingerprint logins are easily bypassed on an iPhone, for example, because you can swipe to log in with a PIN instead. "That's not security, it's convenience," he says. "It doesn't remove passwords from the equation, it just hides them. Passwords are not disappearing. They'll be around for at least the rest of my days on Earth."
If Thorsheim is correct, and the death blow to passwords is more than 20 years away, how should we secure ourselves in the interim? The commonly held belief that you should use a mixture of capital letters, lower-case letters and numbers, while changing your password every 90 days, has been rescinded by Bill Burr, the American software engineer who championed the practise in 2003.
Passwords are not disappearing. They'll be around for at least the rest of my days on Earth.
One hacker says any eight-character password can now be cracked by a computer in under three hours, so longer phrases are essential. Two-factor authentication, in which your phone receives additional confirmation codes, is worth adopting, but the critical piece of advice is to use different passwords for each service. And if that becomes a headache, use a password manager such as 1Password, DashLane or LastPass.
When breaches are reported in the media, they're often made out to be cataclysmic events, such as when more than 21 million passwords from a number of sources were dumped online in January. But the truth is, they mainly contain old passwords, which with luck, you will have stopped using by now. However, if you're worried, services such as Google's Password Checkup can tell you if yours is floating around the internet, and if it is, Thorsheim says you are a target for hackers.
"People don't understand the benefit of strong passwords because nobody has been hacked until they've been hacked," he says. "That's the moment when they realise how bad it can actually be."
SHAITTAN
%3Cp%3E%3Cstrong%3EDirector%3A%20%3C%2Fstrong%3EVikas%20Bahl%3Cbr%3E%3Cstrong%3EStarring%3A%20%3C%2Fstrong%3EAjay%20Devgn%2C%20R.%20Madhavan%2C%20Jyothika%2C%20Janaki%20Bodiwala%3Cbr%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E3%2F5%3C%2Fp%3E%0A
5 of the most-popular Airbnb locations in Dubai
Bobby Grudziecki, chief operating officer of Frank Porter, identifies the five most popular areas in Dubai for those looking to make the most out of their properties and the rates owners can secure:
• Dubai Marina
The Marina and Jumeirah Beach Residence are popular locations, says Mr Grudziecki, due to their closeness to the beach, restaurants and hotels.
Frank Porter’s average Airbnb rent:
One bedroom: Dh482 to Dh739
Two bedroom: Dh627 to Dh960
Three bedroom: Dh721 to Dh1,104
• Downtown
Within walking distance of the Dubai Mall, Burj Khalifa and the famous fountains, this location combines business and leisure. “Sure it’s for tourists,” says Mr Grudziecki. “Though Downtown [still caters to business people] because it’s close to Dubai International Financial Centre."
Frank Porter’s average Airbnb rent:
One bedroom: Dh497 to Dh772
Two bedroom: Dh646 to Dh1,003
Three bedroom: Dh743 to Dh1,154
• City Walk
The rising star of the Dubai property market, this area is lined with pristine sidewalks, boutiques and cafes and close to the new entertainment venue Coca Cola Arena. “Downtown and Marina are pretty much the same prices,” Mr Grudziecki says, “but City Walk is higher.”
Frank Porter’s average Airbnb rent:
One bedroom: Dh524 to Dh809
Two bedroom: Dh682 to Dh1,052
Three bedroom: Dh784 to Dh1,210
• Jumeirah Lake Towers
Dubai Marina’s little brother JLT resides on the other side of Sheikh Zayed road but is still close enough to beachside outlets and attractions. The big selling point for Airbnb renters, however, is that “it’s cheaper than Dubai Marina”, Mr Grudziecki says.
Frank Porter’s average Airbnb rent:
One bedroom: Dh422 to Dh629
Two bedroom: Dh549 to Dh818
Three bedroom: Dh631 to Dh941
• Palm Jumeirah
Palm Jumeirah's proximity to luxury resorts is attractive, especially for big families, says Mr Grudziecki, as Airbnb renters can secure competitive rates on one of the world’s most famous tourist destinations.
Frank Porter’s average Airbnb rent:
One bedroom: Dh503 to Dh770
Two bedroom: Dh654 to Dh1,002
Three bedroom: Dh752 to Dh1,152
THREE POSSIBLE REPLACEMENTS
Khalfan Mubarak
The Al Jazira playmaker has for some time been tipped for stardom within UAE football, with Quique Sanchez Flores, his former manager at Al Ahli, once labelling him a “genius”. He was only 17. Now 23, Mubarak has developed into a crafty supplier of chances, evidenced by his seven assists in six league matches this season. Still to display his class at international level, though.
Rayan Yaslam
The Al Ain attacking midfielder has become a regular starter for his club in the past 15 months. Yaslam, 23, is a tidy and intelligent player, technically proficient with an eye for opening up defences. Developed while alongside Abdulrahman in the Al Ain first-team and has progressed well since manager Zoran Mamic’s arrival. However, made his UAE debut only last December.
Ismail Matar
The Al Wahda forward is revered by teammates and a key contributor to the squad. At 35, his best days are behind him, but Matar is incredibly experienced and an example to his colleagues. His ability to cope with tournament football is a concern, though, despite Matar beginning the season well. Not a like-for-like replacement, although the system could be adjusted to suit.
SERIES SCHEDULE
First Test, Galle International Stadium
July 26-30
Second Test, Sinhalese Sports Club Ground
August 3-7
Third Test, Pallekele International Stadium
August 12-16
First ODI, Rangiri Dambulla Stadium
August 20
Second ODI, Pallekele International Stadium
August 24
Third ODI, Pallekele International Stadium
August 27
Fourth ODI, R Premadasa Stadium
August 31
Fifth ODI, R Premadasa Stadium
September 3
T20, R Premadasa Stadium
September 6
Specs
Engine: 51.5kW electric motor
Range: 400km
Power: 134bhp
Torque: 175Nm
Price: From Dh98,800
Available: Now
SPEC%20SHEET
%3Cp%3E%3Cstrong%3EProcessor%3A%3C%2Fstrong%3E%20Apple%20M2%2C%208-core%20GPU%2C%2010-core%20CPU%2C%2016-core%20Neural%20Engine%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EDisplay%3A%3C%2Fstrong%3E%2013.3-inch%20Retina%2C%202560%20x%201600%2C%20227ppi%2C%20500%20nits%2C%20True%20Tone%2C%20wide%20colour%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EMemory%3A%3C%2Fstrong%3E%208%2F16%2F24GB%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStorage%3A%3C%2Fstrong%3E%20256%2F512GB%20%2F%201%2F2TB%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EI%2FO%3A%3C%2Fstrong%3E%20Thunderbolt%203%20(2)%2C%203.5mm%20audio%3B%20Touch%20Bar%20with%20Touch%20ID%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EConnectivity%3A%3C%2Fstrong%3E%20Wi-Fi%206%2C%20Bluetooth%205.0%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EBattery%3A%3C%2Fstrong%3E%2058.2Wh%20lithium-polymer%2C%20up%20to%2020%20hours%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ECamera%3A%3C%2Fstrong%3E%20720p%20FaceTime%20HD%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EVideo%3A%3C%2Fstrong%3E%20Support%20for%20HDR%20with%20Dolby%20Vision%2C%20HDR10%2C%20ProRes%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EAudio%3A%3C%2Fstrong%3E%20Stereo%20speakers%20with%20HDR%2C%20wide%20stereo%2C%20Spatial%20Audio%20support%2C%20Dolby%20support%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EIn%20the%20box%3A%3C%2Fstrong%3E%20MacBook%20Pro%2C%2067W%20power%20adapter%2C%20USB-C%20cable%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EPrice%3A%3C%2Fstrong%3E%20From%20Dh5%2C499%3C%2Fp%3E%0A
Test
Director: S Sashikanth
Cast: Nayanthara, Siddharth, Meera Jasmine, R Madhavan
Star rating: 2/5
Key facilities
- Olympic-size swimming pool with a split bulkhead for multi-use configurations, including water polo and 50m/25m training lanes
- Premier League-standard football pitch
- 400m Olympic running track
- NBA-spec basketball court with auditorium
- 600-seat auditorium
- Spaces for historical and cultural exploration
- An elevated football field that doubles as a helipad
- Specialist robotics and science laboratories
- AR and VR-enabled learning centres
- Disruption Lab and Research Centre for developing entrepreneurial skills
EXPATS
%3Cp%3E%3Cstrong%3EDirector%3A%3C%2Fstrong%3E%20Lulu%20Wang%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%3C%2Fstrong%3E%20Nicole%20Kidman%2C%20Sarayu%20Blue%2C%20Ji-young%20Yoo%2C%20Brian%20Tee%2C%20Jack%20Huston%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%204%2F5%3C%2Fp%3E%0A
COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3ECompany%3A%3C%2Fstrong%3E%20Eco%20Way%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%20December%202023%3Cbr%3E%3Cstrong%3EFounder%3A%3C%2Fstrong%3E%20Ivan%20Kroshnyi%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Dubai%2C%20UAE%3Cbr%3E%3Cstrong%3EIndustry%3A%3C%2Fstrong%3E%20Electric%20vehicles%3Cbr%3E%3Cstrong%3EInvestors%3A%3C%2Fstrong%3E%20Bootstrapped%20with%20undisclosed%20funding.%20Looking%20to%20raise%20funds%20from%20outside%3Cbr%3E%3C%2Fp%3E%0A
Rooney's club record
At Everton Appearances: 77; Goals: 17
At Manchester United Appearances: 559; Goals: 253
UAE currency: the story behind the money in your pockets
SRI LANKS ODI SQUAD
Perera (capt), Mendis, Gunathilaka, de Silva, Nissanka, Shanaka, Bandara, Hasaranga, Udana, Dananjaya, Dickwella, Chameera, Mendis, Fernando, Sandakan, Karunaratne, Fernando, Fernando.