Connect with us

E-Business

30% of Firms to Use Biometric Authentication for Mobile Devices by 2016

Published

on

Chris Onyemenam, director general, National Identity Management Commission (NIMC),
Kindly share this post

The consumerization of IT and business bring your own device (BYOD) programs have resulted in potential security problems for IT leaders, according to Gartner Inc.

User expectations of a clean and simple mobile user experience often outweigh security concerns, and the same valuable data guarded by complex passwords and security measures on PCs can be left vulnerable on mobile devices.

Gartner predicts that, by 2016, 30 percent of organizations will use biometric authentication on mobile devices, up from five percent today.

“Mobile users staunchly resist authentication methods that were tolerable on PCs and are still needed to bolster secure access on mobile devices. Security leaders must manage users’ expectations and take into account the user experience without comprising security,” said Ant Allan, research vice president at Gartner.

Gartner has identified some potential security impacts of the consumerization of IT, and has made some recommendations for IT security leaders.

Advertisement

While most organizations require robust passwords on laptops, smartphones and tablet devices often have access to the same applications and critical data but not the same levels of security.

The increased number of devices in play also exacerbates the exposure of critical information. Implementing standard power-on password policies is made much more complex by the acceptance of BYOD practices, with the inevitable clash over user rights and privacy.

While complex passwords can be especially problematic for users to type on mobile devices, if these devices hold corporate data or provide access to corporate systems such as email without further login, even a default four-digit password is inappropriate.

 However, support for more robust power-on authentication is patchy, with only a few mobile operating systems and devices supporting biometric authentication. Even in cases that do offer this support, the implementation may not be good enough for business use.

“An eight-digit numeric password will require hours to recover, and that will discourage casual hackers with toolkits,” said John Girard, vice president and distinguished analyst at Gartner.

Advertisement

“However, even a six-character lowercase alphanumeric password can provide billions of values. For most practical purposes, hackers are not prepared to pursue this large a set of combinations due to the relatively slow speeds involved in brute force attacks against smartphones and tablets.”

Gartner recommends that a password policy requiring use of at least six alphanumeric characters, and prohibiting dictionary words, is enforced on devices with access to corporate information via mobile device management (MDM) tools.

Some organizations attempt to counter the risks from a lost or stolen device by implementing controls that wipe a device after a limited number of incorrect password entries, or by remote command. “This practice does not wholly mitigate the risk because solid-state memory is nearly impossible to overwrite,” said Mr. Girard.

“The best practice is to use encryption that is not tied to the primary power-on authentication, meaning the key cannot be recovered from the device after a soft wipe operation has been performed.”

In addition, Gartner recommends that a further authentication method — at a minimum, another password — should be used for access to sensitive corporate applications and data.

Advertisement

In this way, even if a hacker breaches the power-on defenses, each additional app or store of data presents an additional challenge that will, collectively, present too much of a hurdle to be worthwhile.

In some cases, higher-assurance authentication is required. In PCs (traditionally), a standalone device may be used to provide a hardware token that might be used to provide additional authentication. “Traditional authentication of this kind is often spurned in mobile use cases, because of the poor user experience with most kinds of hardware tokens,” said Mr. Allan.

“Juggling the token in one hand, the phone in another and a latte in the third is increasingly resisted by mobile device users.”

Software tokens, such as X.509 credentials on the endpoint, provide options in this case, but often need MDM tools to be implemented properly and still require additional controls to provide the higher-assurance authentication necessary in some organizations.

Advertisement

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

E-Business

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.

Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.

The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.

According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.

Advertisement

The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.

It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.

Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.

The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.

The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.

Advertisement

The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.

Kindly share this post
Continue Reading

E-Business

Microsoft to Unveil Next-generation AI Chip in September

Published

on

Kindly share this post

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon ​as next month, The Information reported on Monday, citing ‌people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and ​Amazon in scaling up its in-house chip efforts as ​it seeks to reduce its reliance on Nvidia’s costly ⁠processors.

Google began recognizing revenue from direct sales of its custom ​AI chips, called Tensor Processing Units, in the quarter ended June, ​while Amazon has also seen growing adoption of its processors, including its Trainium chips.

Microsoft has been in talks with chipmaker TSMC to secure manufacturing ​capacity for more than 300,000 units of the chip for ​delivery in 2027, according to the report. It is also looking to significantly ramp up ‌production ⁠and persuade major cloud customers such as Anthropic to adopt the chip.

Microsoft ultimately ​aims to ⁠secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity ​negotiations with TSMC could constrain its plans, according ​to the ⁠report.

Advertisement

It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.

Microsoft packed the chip with a significant amount of ⁠SRAM, ​a type of memory that can provide ​speed advantages for AI systems handling large numbers of user requests.

 

Kindly share this post
Continue Reading

E-Business

X Replaces Revenue Sharing wit New Creator Rewards Programme

Published

on

Kindly share this post

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

X Replaces Revenue Sharing wit New Creator Rewards Programme

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.

“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.

X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.

“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.

Advertisement

According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.

X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.

The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.

Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.

X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.

Advertisement

On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.

To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.

They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.

X said creators must also regularly post original content to remain eligible.

“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.

Advertisement

The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.

It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.

“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.

X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.

It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.

Advertisement

The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.

It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.

“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.

The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.

“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.

Advertisement

Kindly share this post
Continue Reading

Trending