Microsoft Demands Authenticity for Access

Microsoft will retire SMS (text messages) next February as a means of authentication for access to its accounts. I can imagine someone standing up in a meeting and saying: “We’re doing this for your own good.” It’s time to cut the phishing line.

Text messages can work as an authentication method, but the concept has vulnerabilities. It’s based on the assumption that when you get a verification code to authenticate your access, you have your cell phone in your physical possession. That’s true virtually all of the time. However, text messages are subject to SIM swapping, a technique hackers use to temporarily take over your phone number, and they can do it long enough to intercept the text without you ever knowing about it until something goes wrong.

There are also some locations in various cellular networks that are vulnerable to breaches, and it’s possible that a hacker can get access to the cellular network right as the text message is being sent to you.

If a hacker can gain access to a user’s Microsoft account while they’re logging in, they can gain access to contact lists and use them to launch phishing campaigns by email and text.

Authenticator apps bypass the cellular network. They generate a code from your phone, making them impossible to intercept. Many authenticator apps include additional security measures such as passcodes, passwords, or biometric authentication (like fingerprints or facial recognition), making it more difficult for unauthorized users to access your accounts even if they have your password.

This does force an issue, especially for businesses or other organizations that require employees to use their personal cell phones for business. Some employees fear their employers will be able to access their personal phones. That does NOT happen with an authenticator app. Instead, it will provide stronger security for remote logins.

If an employee leaves an organization, the authenticator app for that phone can be blocked by the employer.

To comply, we highly recommend that users have a fairly recent smartphone. Older devices may have problems running the app or require a time-consuming process to get them set up or install a backup process.

We can help any user set up an authenticator app on their phone. In most cases, it’s just a matter of walking someone through the process. Once it’s installed, it can be used independently of the employer for access to any website that offers it as an option to SMS authentication.

Call us – 973-433-6676 – or email us if you have any questions or need help setting up the app.

No Folds Barred with New iPhone?

You don’t need to hold your breath, but Apple is making a big series of announcements at 1 p.m. ET tomorrow. One expected announcement is the new, foldable iPhone 18 Ultra. In our opinion, it’s not for everyone.

According to reports we’ve seen, it will have a book-like design, and it will measure around 5.5 inches when closed and 7.6 inches when open. It will be similar to using an iPad when unfolded. Because it’s expected to be so thin, there will be compromises. It will use Touch ID instead of Face ID, and it won’t have a telephoto camera.

So, if you are looking to combine an iPhone with greater photographic capabilities, you likely will want the Pro or the Max Pro model, neither of which is foldable. The Pro will feature the new A20 Pro chip, a smaller Dynamic Island, and a new dark cherry color option. The Pro Max adds a larger battery and a variable aperture camera.

The iPhone 18 is anticipated to bring significant upgrades in camera technology, particularly with its variable aperture and enhanced AI capabilities, which could lead to even better photography experiences compared to the iPhone 17. Both will have a 48 MP main lens and ultrawide camera, but the Pro Max will have a variable aperture on the main lens. That will give you more control over depth of field and light intake for better pictures. It will also have better AI-based processing. However, it will come at a cost of nearly $2,500.

The expected prices for the Pro and Pro Max are expected to be $1,099 and $1,299, respectively. Apple is expected to introduce a new iPhone 18 and iPhone SE in the spring. The base model for the iPhone 18 is expected to be $799.

The consensus we’ve seen is that it doesn’t make much sense to upgrade from the 17 to 18 unless you really want the better camera or if you want the folding capability and larger workspace of the 18 Ultra.

In addition to the phones, we can expect to hear about:

  • Apple Watch Series 12 and Ultra 4, both featuring a new chip and a number of fitness feature advances, especially for the Ultra 4
  • A smarter, better-connected Apple 4K TV
  • Second-generation HomePod with improved sound quality, device responsiveness and integration with other Apple products

As always, we’ll be available after announcements to answer your questions about the new products and offer selection advice based on your needs. Call us – 973-433-6676 – or email us to set up an appointment.

Avoid BitLocker Recovery Issues

Every business-grade Windows-based computer has a hidden 48-digit BitLocker recovery key. It’s a hidden, unique numerical password that automatically unlocks an encrypted drive when standard authentication methods fail, and it’s essential for regaining access to your data in situations such as hardware changes, forgotten passwords, or system updates. It typically restores access after BIOS updates, but sometimes it fails. Here’s how to avoid BitLocker problems.

First and most important, there is NO WAY to recover your 48-digit BitLocker recovery key. So, Step Number 1 is to write it on a piece of paper or copy it into a note on your smartphone or tablet. If you don’t have it when the “blue screen of death” appears, your data is dead.

The blue screen that appears when there is a failure does have a place for you to enter your 48-digit BitLocker recovery key. Just enter it accurately and you’re good to go. If you bought your business-grade computer from us, we have backed up your 48-digit key, and we can provide it for you.

Regardless, you should have your key readily available, and you can find it before anything happens. Go to account.microsoft.com on any device, sign in to your Microsoft account, click Devices, select your PC, and look for BitLocker data protection. Write down the code and store it safely in several places. This will work from any device that’s connected to the internet, and it’s one way to get your key when the blue screen is present.

While your computer is still functioning, you can go into your profile and click on the BitLocker key for your device. It is buried in your profile, but it can be found. We can walk you through the process or send you detailed instructions. We also keep records of the BitLocker key for each device, but sometimes names of people or devices don’t match our records.

BitLocker keys are good for security, but they are bad if you don’t remember your key or have access to it. There is an option to turn off the BitLocker system altogether, but we don’t recommend it. It’s like leaving a door open to all your data.

Call us – 973-433-6676 – or email us if you have any questions or need assistance in securing your BitLocker recovery key.

New Security Tools and VPN

To boil it down to one word, we were shocked when we looked at the alerts we saw for our Trend Micro customers. While your security is good, it can be a lot better. The same goes for our VPN customers. Start watching for the new tools.

Let’s look at overall security first. Three keys to good security – in our opinion – are: malware detection, phishing detection, and reliability. We have joined our colleagues in IT and security in finding that Trend Micro has fallen to average or below-average performance in these areas. We came to our conclusion by comparing the alerts we saw in your systems to industry-wide reports. The software was getting buggier and less effective in our opinion, and we found better tools from a number of other vendors. A key element for us is making sure we keep your system out of danger 24/7/365.

Our new security tools will be a combination of products instead of relying on one vendor. This will give us the ability to tailor stronger tools to your specific needs. We believe all of us will sleep better at night once we have the new tools installed. They will cost a little more, but they will be well worth the investment.

We’re also rolling out a new VPN. While we like ZTNA (Zero Trust Network Access) as a way of verifying access to a network, VPNs are ubiquitous and usually easier to administer. Our new VPN will be easier to maintain (which can help you keep it more secure), and it will create a more locked-down environment (which also keeps you more secure).

The feature I like most about the new VPN is that it allows me to connect to any Wi-Fi network in the world and trigger software to route traffic through a specific device. I have device called a Raspberry Pi, a computer the size of a credit card with the power to run a desktop. I use mine to route all my internet traffic through my home internet to home/office computer. The VPN removes worries about rerouting and who might see my traffic. That’s an important feature if you’re forced to use a public Wi-Fi network or even hotel network that’s supposed to be password-protected. You really can’t be assured one of those networks has been compromised.

If you travel and want access to all your home-based streaming accounts, our new VPN will see your home or office internet if you have it set up to do so.

While we’ll be contacting all of our clients to offer our new security tools and VPN, you can contact us for more information about how they can work for you. Call us – 973-433-6676 – or email us to discuss your objectives and your needs.

AI: the Good, the Bad, and the Ugly

AI gives you the tools to do a lot of things in a fraction of the time they used to require. But using AI has its privacy costs, and trying to avoid them can lead to some really bad consequences. AI also doesn’t always get things right.

The most important thing you need to know about AI is that it’s not private. As soon as you put something into AI, it’s out in the world. AI makes its living by collecting data from the internet – lots of data at lightning-fast speed and often without permission. That means they frequently gather sensitive information without your knowledge or consent, and that data can be used for purposes you didn’t agree to, raising ethical concerns. AI can also enable unchecked surveillance, and when you combine that with the vast amounts of data stored by AI systems, you could be set up for the heightened risk of unauthorized access and data breaches. That’s bad and ugly.

Protecting your privacy takes some work. Best practices include never sharing sensitive information, actively controlling data settings, and using approved AI tools. Additionally, regularly deleting past chat histories and reading privacy policies can help ensure better data security. To be anonymous, consider using tools that run locally on your device instead of cloud-based services, and utilize a secure browser with privacy features. You can also use a VPN and sign up with a disposable email address to further protect your identity. DO NOT try to use the dark web. I have some good “street smarts” in the internet world, but these streets are populated by some really bad people. You can easily stumble into a really bad place and be ruined. It’s not like a game.

You also need to remember that AI is not always correct or all that smart. AI can provide wrong answers, so it’s up to you to make sure you verify any information you get from it. A wrong answer could create a life-and-death situation, a costly business decision, or a major inconvenience – just to name a few.

But what I find really frustrating is when Copilot puts you into a loop that is not related in any way to what you’re trying to do. I understand how computers work – they’re anal – but you are supposed to be able to use plain English get your work done or get information. I got into some serious verbal tiffs with my AI; it was really ugly.

However, if you check and double-check AI and really stay on top of it, the technology can work wonders. As an example, I was able to create in just a few hours a travel itinerary that combined independent travel and a cruise. It got us down to the minute we would arrive in various locations, and in the next-to-the-last stage, it gave us choices of hotels that met specific criteria. On the downside, it included a hotel that doesn’t exist, but the beauty was that as I continued to feed it information, it kept narrowing down our options to those that were more acceptable. The lesson from this exercise is that you have to verify all the information, but the bottom line is that it saved me days of work.

We can help you peel away the bad and the ugly to get to the good stuff in AI. Call us – 973-433-6676 – or email us to see how you can keep your corporate data safe and prevent employees from leaking sensitive information. We can set up rules for how your system uses AI. Our new security software tools provide safeguards if you choose to use them.

The Useful Lifespan of a Wireless Router

Some people like to run their wireless router until it drops – and some may not even know when it has dropped dead. A wireless router that can’t take the latest software updates is a huge security risk.

Signs that a router has reached the end of its useful service life include unreliable connections, significantly reduced speeds, weak signals or dead zones, and an inability to handle multiple devices effectively. Let’s look at them in a little more depth.

  • Unreliable Connections: Frequent disconnections or dropped signals can indicate that your router is failing, and they may be due to worn-out components or outdated firmware. We’ll have more to say about firmware later in this article.
  • Reduced Speeds: Noticeably slower download and upload speeds can signal that your router is struggling to keep up with current demands.
  • Weak Signal or Dead Zones: If you’ve had good coverage but find it’s diminished, it could be a sign that your router is failing.
  • Inability to Handle Multiple Devices: If your router struggles to maintain connections when multiple devices are online, it may be overloaded. And if you see a sudden drop in connectivity when new devices connect can indicate that your router’s hardware is no longer sufficient.

The average lifespan of a router is between three to five years, and it can be affected by usage intensity, environmental conditions (dust and heat), and technological advancements (new Wi-Fi standards or heavier traffic demands).

You can extend or maximize a router’s life by installing firmware updates as they’re issued. Similar to software updates for your OS and apps, firmware updates keep your hardware (routers, printers, etc.) operating at peak performance. Regardless of how old your router is, you should check for firmware updates right away and then do so regularly.

You should also check to make sure the manufacturer still supports your current router. We see this most commonly with devices such as mobile phones and with app software. At some point, the manufacturer or software publisher stops supporting an older version of its product, and that leaves you vulnerable to failure at some point.

We can help by checking your router for updates or helping you decide on a new router. For home users, we can also check on your mesh network if you have one or install one if it’s needed. Call us – 973-433-6676 – or email us to set up an appointment.

Block That Flow – Device Code Flow in Microsoft Entra ID

As you read this, I’m at the Xchange Security Conference in Dallas, and I learned something yesterday that I must share to protect your data. I will need to work with you to block device code flow in Microsoft Entra ID. In simple terms, it’s disabling a code system that’s similar to how you match a code on two devices when signing into Netflix.

Device code flow is typically used to sign into accounts on devices such as smart TVs or IoT devices. You enter the short code displayed on the device into a separate device, such as your smartphone or computer, to complete the authentication process.

It’s super convenient, but it also poses security risks, particularly related to phishing attacks. Attackers can exploit this flow to gain unauthorized access to accounts without needing to steal credentials directly. It’s especially critical to prevent phishing attacks.

Microsoft advises organizations to block device code flow unless absolutely necessary. This should help mitigate the risk of phishing attacks. At the same time, we will need to help you implement conditional access policies to control and restrict the use of device code flow. This includes specifying when and where it can be used.

We can tailor conditional access policies based on factors such as user location, device status, and risk assessments. This allows you to enforce specific security measures that align with your needs and compliance requirements. This approach enhances security by ensuring that only authorized users can access sensitive information.

Some of things we’ll discuss with you are:

  1. Determining which users or groups need specific access controls based on their roles or functions.
  2. Setting conditions based on the factors mentioned above. For example, you might require MFA for users accessing data from untrusted locations.
  3. Choosing the appropriate access controls, such as blocking access, requiring MFA, or enforcing device compliance.
  4. Testing all of your policies in a report-only mode to assess their impact without affecting users.
  5. Continuously monitoring the effectiveness of the policies and make adjustments as necessary based on user feedback and security incidents.

Call us – 973-433-6676 – or email us to discuss how to block the flow and develop access control policies for your specific needs.

Travel Tip for Getting Email

We found a problem – and a solution – for getting your email without interruption while traveling internationally. The problem has to do with various countries’ rules on blocking IP addresses and how they interact with Starlink systems.

The problem came up during our last cruise when Danit couldn’t access her mail. Then I couldn’t get my email, nor could I access my Cloud PC, which I heavily depend on. Naturally, that raised our response level.

The problems are that countries can block IP addresses, which include your email providers’ addresses, for various reasons related to censorship, copyright infringement, and national security. This blocking can prevent access to specific websites or content deemed inappropriate or harmful according to local laws and cultural norms. This can include blocking sites related to unauthorized gambling, child abuse material, or copyright infringement.

IP address blocking can restrict access to specific websites or online content based on geographic location, often leading to unintended consequences such as blocking legitimate services. While it may seem arbitrary, IP address blocking is a strategic measure aimed at enhancing security and managing online behavior. There are ways to work around these blocks, but they require a lot of steps, all based on the specifics of each country. It’s painful for many users.

In addition to local internet providers in all countries, Starlink provides high-speed, reliable internet access in remote or underserved areas where traditional broadband is unavailable or unreliable, such as on a cruise ship or a remote resort. Starlink does not have the capability to block specific IP addresses. Instead, it uses a system of Carrier Grade Network Address Translation (CGNAT) to manage IP addresses.

For customers needing specific connections, Starlink offers an optional public IP configuration. This is available for certain plans, such as Priority, Mobile Priority, and Maritime services. Again, this is a complicated system for most people.

However, all is not lost. We’ve developed a solution: Starlink exception lists tailored to locations and dates. Using AI and some other tools, we can create Starlink exception lists that have IP address exceptions for specific locations and specific dates. The lists can cover itineraries and help you gain access to your email and websites you need while you travel.

To learn more about how this solution can work for you and to set up lists, call us – 973-433-6676 – or email us to discuss your needs and what you’ll need to know to use your list.

Temperatures and Computer Prices Rising More This Summer

Three factors are contributing to this summer’s rise in computer prices: AI, security, and chip shortages. The times call for cool, calculated thinking about the technology you have and what you need.

AI has upped the ante considerably because it’s so necessary for many business applications. AI is also a necessity to run all the security measures needed to combat the increasingly complex technologies used by hackers to get into any system.

The rapid expansion of AI continues to create a significant demand for memory chips, particularly DRAM chips, and that has led to a supply/demand imbalance that still persists. In turn, prices for memory chips have surged, affecting the overall cost of consumer electronics, including computers. Apple had been trying to hold the line on its prices, but it just raised them.

Your bottom line is that a $3,000 price tag for computers is coming. And if you have computers that are more than three years old, they may not cut it. To provide adequate performance for today’s business environment, an AI-ready computer must be able to perform at least 40 trillion operations per second (TOPS) just for basic operations. That jumps to 80 TOPS for more intensive AI tasks and ensures that a computer can handle advanced applications and workloads for next-generation AI software and features.

We can help you navigate the price/performance balance by looking at your computers and your computing needs. Based on how your business or organization uses computers, we can help you determine which units are most in need of performance upgrades and develop a plan to redeploy your units. This can maximize the efficiency of your total complement of computers while – hopefully – reducing the number of new units you need to purchase. We can combine our assessment with a security audit to shore up weaknesses in your system.

Call us – 973-433-6676 – or email us to set up an appointment to discuss your needs and options, including a plan for the next few years to help your long-term budgeting.

Take Your Seat

I save every client email because when you contact me with a problem, I can see what related problems you’ve had and find a solution faster. I have good rules to file every email, but there are still lots and lots of messages to manage. I’m not a programmer, but I developed a routine using Copilot to make my email searches more efficient.

Admittedly, it took some doing to develop my system, and it took some refining to get it to where I wanted it to be. The key for me – and for just about all users – was knowing the right questions to ask Copilot to get the desired outcome.

I use Outlook just like most of you to manage my email, and I need to manage my messages across several email addresses and services, such as my own domain and providers such as Gmail. Outlook can search every email address you have, but it doesn’t always show you every message – which means the message you need is hiding somewhere.

Using the AI power of Copilot, I was able to write a routine to handle detailed email searches meeting numerous criteria. The beauty of AI is that I could write them in English, not code, and get answers back in English. That helped me refine my search instructions by asking Copilot more questions.

However, there are two caveats.

The first caveat is that you need to understand how computer programming works (just like you understand how your car works but don’t necessarily know how to fix it). Computers are extremely anal, so you must ask exact questions. AI doesn’t do a good job – yet – of reading your mind. If you’re too general, you’ll get vague answers.

In my case, I had to use a combination of AI and some manual steps before being able to tell the software how I wanted my email stored and how to develop new routines for storage going forward. I have been able to cut my search time dramatically to provide you with better service.

The second caveat is that you need to invest in a license (or seat in tech jargon), to get the most out of Copilot – or just about any AI engine. The free versions just have the power to create the routines that can really make a difference. Licensing can run $20 to $30 per seat, so you need to know who in your organization needs the capability of Copilot and has the ability to use it.

Going in, you can be assured that Microsoft is aware of your privacy concerns and doesn’t use your data to train its AI models. Microsoft 365 Copilot complies with privacy regulations such as the General Data Protection Regulation (GDPR), and security measures are in place regardless of whether you have a Pro license.

We can help you with the entire Copilot process. Call us – 973-433-6676 – or email us to discuss what you need Copilot to do, writing instructions for Copilot, determining the number of seats you’ll need and training the people who will occupy those seats.