Microsoft accused of making it harder to ditch Edge in Windows 11


Zach Marzouk

19 Aug, 2021

Microsoft has been accused of making it harder to switch default browsers in Windows 11, prompting complaints from browser competitors like Firefox and Opera.

The tech giant has changed the way users can set default apps on its new operating system, according to The Verge. Similar to Windows 10, a prompt appears when a user installs a new browser or opens a web link for the first time.

The problem lies with a change in the way default browser apps are handled in Windows 11. Where Windows 10 allowed users to change default apps based on a program, Windows 11 requires users to set defaults by file or link type instead, much in the same way that PDFs or image extensions are handled.

For example, in Chrome, this means individually changing the default behaviour for HTM, HTML, PDF, SHTML, SVG, WEBP, XHT, XHTML, FTP, HTTP, and HTTPs, with each having its own drop-down menu.

Rival browsers tend to prompt users to set them as default, forcing them to navigate the default apps part of settings to do this.

Critics have argued that this creates unnecessary complications in what otherwise should be a simple process, causing many users to simply stick with Edge.

“Being able to select your preferred web browser is essential to shaping the internet experience that everyone deserves,” Selena Deckelmann, senior vice president of Firefox said to IT Pro. ”We have been increasingly worried about the trend on Windows. Since Windows 10, users have had to take additional and unnecessary steps to set and retain their default browser settings. These barriers are confusing at best and seem designed to undermine a user’s choice for a non-Microsoft browser.”

Krystian Kolondra, Opera’s EVP and head of desktop browsers, told IT Pro that it is “unfortunate” when a platform vendor is “obscurifying a common use case to improve the standing of their own product”.

“We would like to encourage all platform vendors to respect user choice and allow competition on their platforms. Taking away user choice is a step backwards,” added Kolondra.

IT Pro has contacted Google and Microsoft for comment.

GitHub Discussions is now generally available


Keumars Afifi-Sabet

18 Aug, 2021

GitHub Discussions is officially out of beta, meaning open source developers can access a comprehensive suite of forum discussion tools to stay on top of community management.

Discussions grants open source development teams access to tools and processes to make community engagement more collaborative, the firm said. This includes being able to mark the most helpful answers, upvote responses, customise categories and pin major announcements. 

“Creating open source software today is so much more than the source code,” said GitHub’s Evi Liu.

“It’s about managing the influx of great ideas, developing the next generation of maintainers, helping new developers learn and grow, and establishing the culture and personality of your community.

“Over the past year, thousands of communities of all shapes and sizes have been using the GitHub Discussions beta as the central space for their communities to gather on GitHub in a productive and collaborative manner.”

Labelling discussions, integrating apps and responding through mobile are among the newest features GitHub has introduced as it’s taken the platform out of beta, with the company planning on rolling out further updates in the coming months.

Maintainers can organise and triage discussions with labels to keep forums tidy and help members filter to areas of interest. Power users can also integrate with GitHub Actions or existing workflows using the DiscussionsGraphQL API as well as Webhooks Finally, GitHub Discussions on mobile allows administrators to check in while away from their desktop. 

These new features are part of efforts to improve the overall GitHub user experience (UX) and make the open source coding repository more accessible and intuitive for developers. 

GitHub Discussions was first announced as part of a broader product roadmap in July 2020 as a means for communities to collaborate within a repository alongside issues and pull requests. The platform was then launched in December in its first beta version and has since been iterated upon following testing and feedback.

Private repositories were able to access GitHub Discussions from March this year, with the latest announcement signalling the general availability of the anticipated social feature.

83 million IoT devices at risk of hacking


Sabina Weston

18 Aug, 2021

At least 83 million Internet of Things (IoT) devices around the world could be at risk of hacking, potentially enabling threat actors to listen in on private conversations and watch live video streams from baby monitors and smart cameras.

That’s according to new findings from Mandiant, a cyber security company and subsidiary of FireEye.

Mandiant security researchers Jake Valletta, Erik Barzdukas, and Dillon Franke discovered a vulnerability that affects IoT devices that use the Kalay network platform manufactured by Taiwanese IoT and M2M (machine-to-machine) solutions provider ThroughTek.

Tracked as CVE-2021-28372, the vulnerability affects a core component of the Kalay platform, allowing hackers to “listen to live audio, watch real-time video data, and compromise device credentials for further attacks based on exposed device functionality”, according to the researchers.

Although Mandiant was not able to pinpoint the affected devices, its researchers noted that ThroughTek has at least 83 million active devices as well as an estimated 1.1 billion monthly connections on its Kalay platform, with all of them potentially being exposed to hackers.

Mandiant disclosed the vulnerability to the US’ Cybersecurity and Infrastructure Security Agency (CISA), which has published an advisory report on the issue that recommends that users disconnect their ThroughTek devices from the internet, isolate them from the business networks, and to only connect to devices through virtual private networks (VPN).

A spokesperson for the UK’s National Cyber Security Centre (NCSC) told IT Pro that it is “aware of this vulnerability”, adding that ThroughTek “has released an update to fix the issue”.

“Simply using the platform does not automatically make you vulnerable to real-world impact, as additional information that is hard to guess is needed to exploit the vulnerability in an individual device successfully. To maximise protection, the NCSC recommends individuals keep their software up to date by installing the latest vendor updates as soon as practicable,” said the NCSC spokesperson.

The discovery of CVE-2021-28372 by Mandiant comes two months after Nozomi Networks researchers discovered a similar flaw affecting ThroughTek’s P2P SDK, which is used to provide remote access to audio or video streams over the internet.

The UK government is working on a new law that will force IoT device manufacturers to meet minimum security requirements and banning them from setting easy-to-hack passwords such as ‘admin’ or ‘password’. In April, it was announced that the legislation would also include smartphones.

Cisco acquires Israeli application monitoring startup Epsagon


Keumars Afifi-Sabet

16 Aug, 2021

Cisco has acquired application monitoring firm Epsagon in a multi-million dollar deal that will see the firm’s technology integrated into Cisco’s products and services. 

Joining the company’s Strategy, Incubation and Applications division, the Epsagon acquisition will expand Cisco’s advanced full-stack observability strategy with its expertise and technology. 

The startup, which has offices in New York and Tel Aviv, distributes tracing systems for modern applications and services, including containers and server-free environments. 

The value of the acquisition hasn’t been publicly disclosed, although Globes reports the figure stands at $500 million. Epsagon itself has raised $30 million to date, according to Pitchbook, with Globes estimating its value at between $100 to $200 million.

As the app market’s competitive landscape expands, Cisco’s senior VP and chief strategy office Liz Centoni said, businesses must fast-track their innovation timelines or they’ll be overtaken by their rivals. 

Businesses are doing this by adopting cloud-native technologies, microservices and containerised components on a massive scale. This has led to a rise in the complexity of IT environments, with firms like Epsagon stepping in to track the performance of the components that make up a firm’s digital infrastructure. 

“Cisco’s approach to full-stack observability gives our customers the ability to move beyond just monitoring to a paradigm that delivers shared context across teams and enables our customers to deliver exceptional digital experiences, optimise for cost, security and performance and maximise digital business revenue,” Centoni said.

“Epsagon’s technology and talent align well with Cisco’s vision to enable enterprises to deliver unmatched application experiences through industry-leading solutions with deep business context. By contextualizing and correlating visibility and insights across the full stack, teams can improve collaboration to better understand their systems, solve issues quickly, optimise and secure application experiences and delight their customers.”

Cisco’s core software as a service (SaaS) platforms includes AppDynamics, ThousandEyes and Intersight which all feed into the full-stack observability strategy. This provides observability across the entire stack of apps, network infrastructure and security with real-time insights correlated across domains, and integrated with business context powered by AI and machine learning.

Working from home has created an «overtime epidemic»


Bobby Hellard

16 Aug, 2021

Working from home during the pandemic has caused an «epidemic of hidden overtime», the Autonomy thinktank has warned. 

The organisation’s latest report proposes drafting legislation that would create a «right to disconnect«, which stipulates employees do not have to take calls or respond to emails related to work during their time off. 

Autonomy is calling for amendments to be made to the Employment Rights Act 1996 to ensure workers have the right to fully switch off from all work communications beyond their scheduled hours and to bring employment tribunals for any breach of that stipulation. 

«Modern workplaces and homes are digital spaces,» the report states. «The fact that we are able to send and receive messages, emails, and online content twenty-four hours a day, seven days a week means that it is increasingly hard to disconnect, enjoy our leisure time and develop a healthy work-life balance. 

«This has created an epidemic of ‘hidden overtime’, where workers never quite ‘switch off’ and continue to do bits of work throughout the evening and weekend. Being ‘switched back on’ by an employer after the working day has finished differs from standard overtime, whereby a worker is usually required to ‘stay on’. Instead, a call from an employer – and the response it requires – expands the working day fragment by fragment, meaning the worker is never quite ‘off’.»

The report suggests that this has been a growing problem for a number of years but it has been «exacerbated» by the pandemic and the mass switch to remote working.

It highlights another study by the National Bureau for Economic Research that claims the number of meetings per person has increased by 12.9% over the last 18-months. The length of those meetings had actually gone down, on average, but overall the working day had consistently been extended by an average of 49 minutes, largely attributed to a greater number of emails being sent after standard business hours. 

The enormous rise in overtime has come with the additional burden of poor mental health; by the end of 2020, the prevalence of mental distress among workers was 49% higher compared to 2017-19 and had increased across all major sectors, the report states.

The issue is particularly concerning for women, who are far more likely to shoulder the additional burden of childcare, housework and care for elderly family members, according to the report. 

NCSC simplifies Outlook scam-reporting tool


Sabina Weston

12 Aug, 2021

The National Cyber Security Centre (NCSC) has simplified its cyber scam-reporting with a new add-in for Outlook on Microsoft 365 which makes it even easier to flag phishing emails to its Suspicious Email Reporting Service (SERS).

Launched in April of last year, SERS allows users to report email scams by forwarding them to report@phishing.gov.uk. Within the last 16 months, it has received over 6.5 million reports from the public resulting in the removal of 97,000 online scams, the NCSC said.

However, the organisation has said that this isn’t enough, with NCSC technical director Dr Ian Levy saying that the new tool will make it easier for businesses to “further help combat cyber crime”.

Designed as a simple button, it allows staff to report a suspicious-looking email with just one click, saving the time that it takes to find the SERS email address and forward the message. The more automated approach aims to make reporting easier and faster, allowing users to protect the security of the business without compromising on time and productivity. 

“As more people report more dodgy stuff to us, the safer everyone gets,” said Levy. “The pandemic has shown the cyber criminals will stop at nothing to attack and defraud citizens and businesses. But our Suspicious Email Reporting Service has also shown that the British public can help us fight back against this scourge.»

SMBs have been especially vulnerable to hackers, with almost a third of cyber attacks now involving a small business. According to Federation of Small Businesses national chair Mike Cherry, innovations such as the simplified reporting tool “are crucial to calling time on business crime”. 

“Small achievable steps will go a long way to protect thousands of small firms from cyber attacks. Every year, there are almost four million cases of cyber attacks against small businesses in the UK, and more than 50 per cent of these come from phishing,” he said, adding that “these systems not only help prevent disruption to small firms today but will become increasingly important to help safeguard small businesses for the future”.

Organisations interested in equipping their staff with the Microsoft 365 tool can go to the Microsoft AppSource portal and search for the Report Phishing add-in, click the “Get it now” button, and follow the instructions to complete the installation. 

IBM and Verizon expand Texas lab to test new 5G use cases


Rene Millman

12 Aug, 2021

IBM and Verizon have expanded facilities at their Industry Solution Lab in Coppell, TX to include an environment for developing and testing 5G-enabled use cases for Industry 4.0 applications.

The new capabilities will enable enterprise customers to develop and test how 5G Ultra-Wideband can combine with hybrid cloud, edge, and artificial intelligence (AI) technologies to enhance next-gen use cases like robotics, guided vehicles, manufacturing process automation, visual quality inspection, data analytics, and more.

Verizon has installed 5G ultra-wideband and multi-access edge computing (MEC) to trial use cases, alongside IBM’s hybrid cloud and AI technologies, which run on Red Hat OpenShift.

The lab will offer customers a  pre-commercial, standalone 5G network and all the technical resources needed to test and optimize products. Customers can co-create business-specific use cases and jointly work with IBM Global Business Services and ecosystem partners to leverage these technologies in solving current business challenges and bring new solutions and services to market.

The lab will focus on three priority areas that take advantage of 5G networks. 

The first area is asset monitoring and optimization. IBM and Verizon said major shipping companies with ground and package-handling facilities could use the IBM Maximo Application Suite and IBM Acoustic Insights to trial how they can use ultrasonic technology to anticipate and prevent their package handling machinery from malfunctioning.

The second area is in field worker productivity and safety. By using Maximo Mobile on devices on the Verizon 5G Network, a utility company could trial scenarios where it uses AI, remote human assistance, and real-time data to “improve the on-the-job safety and enhance the quality and efficiency of fieldwork with guided workflows, reducing multiple repeat inspections and repairs of the same equipment.”

The third area is visual inspection. IBM said industrial product manufacturers could leverage IBM’s suite of visual inspection products, including IBM Maximo Visual Inspection.

“Mobile devices running the suite could be mounted on assembly lines, robotic arms, or even held or worn by the user to inspect components and finished goods for defects using near real-time insights to improve manufacturing processes,” said Steve Canepa, global GM & managing director at IBM’s Communications Sector.

He added that the joint 5G test bed with Verizon “serves as a signal of IBM’s ongoing investment in capabilities that include, among others, centers of excellence and labs around the world.”

Just 15% of Londoners returned to the office in July


Bobby Hellard

12 Aug, 2021

Only 15% of workers in central London have returned to the office, according to new figures from the Centre for Cities think tank. 

The figures for the last week of July show that London had the lowest number of workers returning to the office out of all the towns and cities in the UK. 

The research is based on footfall traffic in the week after ‘Freedom Day’ (19 July) when the government lifted all remaining COVID restrictions. It doesn’t specifically state numbers for those returning to offices, but it suggests a rise or fall based on daytime footfall to shops and restaurants in city centres. 

Across the UK, less than one in five (18%) people have returned to their place of work, with day time footfall traffic falling 1% in the last week of July, compared to stats compiled before Freedom Day. People in Brighton were the most likely to have returned, according to the report, but worker footfall there was at 49% of pre-COVID levels and still far from normal.

Just two places have recovered to their pre-pandemic levels of footfall: Blackpool and Bournemouth. However, their popularity with tourists means that visitor numbers are likely to fall once summer ends and offers no indication of appetite to return to the office.  

«It’s a mixed picture as the country takes its next steps back to normality – both for different types of businesses, and for different places,» said Paul Swinney, Centre for Cities director of policy.

«People’s eagerness, particularly in cities in the North and Midlands, to go out and socialise has been a lifeline for many businesses in the night-time economy. But a reluctance to head back to the office in our largest and most economically important cities means that people in the so-called ‘sandwich economy’ that caters to city centre office workers are facing an uncertain future as we get ever closer to the end of the furlough scheme in September.»

The low numbers for London could be perceived as a blow to chancellor Rishi Sunak and his plans to boost the economy by encouraging more people back into the workplace. Sunak recently suggested that platforms like Microsoft Teams and Zoom were no help to people at the start of their careers. 

Salesforce launches a new streaming TV service, Salesforce+


Danny Bradbury

11 Aug, 2021

Salesforce is launching a streaming business TV service called Salesforce+ that will roll out as part of its Dreamforce conference in September. 

The company is designing the service on the digital content models used by companies like Netflix and Peloton but aimed at a business audience. The content will initially be created entirely using its internal team, under the brand name Salesforce Studios. Over time, though, it hopes to encourage more community content.

«The people watching Disney+, the people watching ESPN+, are the same people watching Salesforce content in a business setting, so why wouldn’t we follow that sort of direction? That’s really the genesis of this idea,» explained the company’s senior VP of brand marketing Colin Fleming in an interview about the new service. 

The initial Salesforce+ content features new shows and content the company has already produced and distributes through its YouTube channel. One example is its 70-episode-strong Leading Through Change series, which launched in March 2020. 

Other content on the service will include Connections, which features innovations with marketing executives from different companies, and a career advice series called Boss Talks. Another show, Simply Put, will be a short form program featuring simple explainer videos for complex business topics. 

The initiative will be the conduit for the company’s Dreamforce event next month, which moved online last year due to the pandemic. The event will be mainly online this year, with in-person attendance by invitation only.

Salesforce+ Dreamforce coverage will feature four broadcast channels with a combined 100 hours of initial content: Prime Time, Trailblazer, Customer 360, and Industries. 

Prime Time will feature news announcements and customer case studies. Trailblazer will feature interviews with industry leaders and previews of Salesforce products. The Customer 360 and Industries channels will feature more case studies and innovation stories. 

The company added that viewers would be able to customize their content into collections focusing on different topics, such as artificial intelligence (AI) and financial services. They will also be able to ask questions via the platform and get live answers from presenters during the Dreamforce event.

NSA awards secretive $10bn ‘WildandStormy’ cloud contract to AWS


Zach Marzouk

11 Aug, 2021

The National Security Agency (NSA) has awarded Amazon a cloud computing contract codenamed ‘WildandStormy’ worth up to $10 billion, prompting an appeal from Microsoft.

Although the specific details of the contract are hidden, the NSA is reportedly looking to move away from its on-premise environment as it looks to bring in commercial cloud computing technology, according to Washington Technology. The security agency is reportedly pursuing a “Hybrid Compute Initiative” to see what data can be stored in a commercial cloud infrastructure.

Following the decision, Microsoft filed a protest with the Government Accountability Office (GAO) on 21 July, claiming that the NSA did not conduct a proper evaluation. The decision is expected back by 29 October.

«NSA recently awarded a contract for cloud computing services to support the Agency. The unsuccessful offerer has filed a protest with the Government Accountability Office. The Agency will respond to the protest in accordance with appropriate federal regulations,» an NSA spokesperson told IT Pro.

A Microsoft spokesperson told Nextgov that the company was filing an administrative protest via the GAO. “We are exercising our legal rights and will do so carefully and responsibly,» said the spokesperson.

IT Pro contacted Amazon for comment, which has referred any questions to the NSA.

Last July, the Department of Defense (DoD) cancelled a $10 billion Joint Enterprise Defense Infrastructure (JEDI) project and scrapped its Trump-backed contract with Microsoft. The deal had been challenged by Microsoft’s rival AWS, which alleged that former president Donald Trump had influenced DoD decisions during the bidding process in order to sabotage their chances.

As a replacement for the JEDI project, the DoD announced the Joint Warfighter Cloud Capability (JWCC), which is set to be “a multi-cloud/multi-vendor Indefinite Delivery-Indefinite Quantity (IDIQ) contract” that will consider both AWS and Microsoft. Although there isn’t an estimated value of how much the project would cost, it’s expected the first set of contracts would be awarded by April 2022.