All posts by Paul Stradling

Google Maps Suggests Routes To Navigate More Sustainably

Google has announced the introduction of three new features to Google Maps that will enable users to make greener travel route choices.

Help Cut Transportation CO2 emissions

The new features, which were unveiled at the company’s ‘Sustainable With Google’ event are designed to help tackle the problem of 75 per cent of transportation CO2 emissions being one of the largest contributors of greenhouse gasses worldwide (International Energy Agency).

Three New Features

Based on a new sustainable routing model, the three new Google Maps navigation features are:

Eco-friendly Routing. Google says that AI and insights from the U.S. Department of Energy’s National Renewable Energy Laboratory (NREL) have helped it to design an entirely new routing model for Maps that not only gets users to their destination as quickly as possible, but also optimises for lower fuel consumption.

In addition to showing the fastest route, this new feature (which is already live) will also show the most fuel-efficient route, even if it isn’t the fastest. Eco-friendly routing also gives users an ETA for each option, thereby allowing users to make their own sustainability choices while taking into account their own travel needs.

Google estimates that this feature could prevent over one million tons of carbon emissions per year, which is the equivalent of removing over 200,000 cars from the road!

Lite navigation for cyclists. Based on the statistic that biking directions on Maps has dramatically increased in cities around the world (by up to 98 per cent), this feature is designed to make cycling safer and easier for the growing number of urban bike users. With cyclists citing having to constantly look at a screen-on phone and use turn-by-turn navigation as a problem, Google’s Lite Navigation instead give users an at-a-glance snapshot of the route and includes real-time ETA update and route elevation details. Lite navigation will be live on Android and iOS in the coming months.

Bike and scooter shared information. This expansion of an existing feature now draws upon shared bike and scooter information from over 300 cities around the world and help from Google’s micro-mobility partners including Donkey Republic, Tier and Voi (Europe), and Bird and Spin (US-based).

With this feature, Google Maps users can find nearby stations, pinpoint how many vehicles are available at that moment in any of the cities, and even make sure there’s a place to park before heading to the station.

Criticism

There has, however, been some criticism of another of Google’s travel/traffic related sustainability projects. Google’s use of artificial intelligence to optimise traffic lights in a scheme at four locations in Israel has led to some critics voicing concern that Google may not know enough about traffic engineering to be extending the scheme (as it plans to do).

What Does This Mean For Your Organisation?

With the climate crisis now high on the world agenda, big tech businesses, many of which have been involved in sustainability projects around the world for some time, are now using their tech skills and their communications reach to highlight and compete using sustainability innovations and product features that users can share and understand the value of. AI is a key technology that is driving many of these sustainability features and is now beginning to really prove its value in helping to tackle some of most difficult challenges to businesses, governments, and the world. Some businesses involved in transportation of passengers or goods in city centres e.g., food delivery, couriers, and others, may find these new features from Google useful, and these features along with other sustainability efforts by Google e.g., water stewardship at data centres represent valuable good publicity as well as delivering environmental benefits.

Google Joins Other Tech Giants With ‘Water Stewardship’ Sustainability Pledge

Google has matched water use pledges by Microsoft and Facebook by announcing a ‘water stewardship target’ to replenish more water than it consumes by 2030 and to support water security in communities where it operates.

Stewardship

Google says that through focusing on water stewardship at office campuses and data centres, ecosystems in water-stressed communities, and by sharing prediction technology and tools, it can replenish 120 per cent the water it consumes.

Water For Data Centre Cooling

Data centres have traditionally been big water users as part of cooling process. For example, back in 2019, it was reported (from public records and online legal filings) that Google requested/was granted, more than 2.3 billion gallons of water for data centres in three different states. Also, in 2020 in early 2020 in Red Oak, just south of Dallas, a legal filing indicated that that Google may have needed as much as 1.46 billion gallons of water a year for its data centre by 2021.

Criticism

Google is not the only big tech company that’s needed lots of water for data centre cooling, often in hot locations where others are urged to conserve water. The practice has led to criticism that tech companies may have been taking away critical resources away from water-scarce communities as well as consuming vast amounts of water at a time when there is a strong focus on the environment and climate change.

Office Campuses

Google has stressed that its water stewardship pledge, as part of its broader carbon-neutral plan, is a journey that it has been on for some time. For example, Google’s water stewardship announcement highlights its plans to look at how it can utilise more on-site water sources (collected storm-water and treated wastewater) at its office campuses for landscape irrigation, cooling and toilet flushing, and the company has already developed drip irrigation, using watering systems linked to local conditions for its San Francisco Bay campuses.

Prediction Tech

Google’s latest announcement also highlights how it has already partnered with organisations including United the Nations Environment Programme and the European Commission’s Joint Research Centre (JRC), Global Water Watch, and OpenET to help Communities, policymakers, and planners with need tools to measure and predict water availability and water needs.

Sustainable Water Management at Data Centres

In Google’s 2020 Environmental Report, a year before this latest water stewardship pledge, the company highlighted its work on sustainable water management practices and new cooling options at its datacentres in Finland, Belgium, Ireland, and Douglas County, Georgia.

Facebook and Microsoft

Back in August, Facebook announced its commitment to replenishing more water than it consumes in its global operations by 2030 by improving water efficiency in-house and investing in water restoration projects. Also, in September, Microsoft pledged to replenish more water than it consumes by 2030 on a global basis.

Innovative Solutions

Examples of innovative solutions to data centre cooling that Microsoft has tried in recent years include sinking a data centre to the ocean floor of the coast of Orkney for 2 years (retrieved and hailed a success in 2020) and using liquid immersion cooling at datacentre on the eastern bank of the Columbia River.

What Does This Mean for Your Organisation?

Climate change, a growing world population and increasing industrial development have all contributed to a water crisis that requires innovative moves to reduce the amount of water humans use to operate economies and societies. The huge growth of the Internet, the big move to the cloud, and closer scrutiny, particularly about water requirements in data centres (often in water-scarce communities) have put pressure on the big tech companies to make public pledges and work harder to find more innovative and sustainable solutions to their resource requirements, and to communicate these to stakeholders. Although tackling a growing water crisis is a challenge that requires a global effort and changes at individual as well as enterprise and government level, big tech companies like Google are keen to highlight ways that show they are doing their part and in doing so, maintain a positive brand image, as well as compete effectively on environmental credentials.

Featured Article: “Your call Is Important To Us”

In this featured-article, we look at the traditional frustrations that occur when customers encounter (some) phone systems and how technology is helping to bring better experiences.

Spending Time On Hold

Being put on hold and spending time waiting has long been known to frustrate customers, cause stress, and lead to them hanging up. Even though it costs money and can lead to lost business, many companies continue to do it even though, from a customer’s perspective, it may feel like the company really doesn’t care about them. Despite messages that their call is ‘important,’ many customers feel that these experiences on hold are more for the company’s convenience, rather than that of the customer.

There is also an argument that from the company’s perspective, losing customers (from putting them on hold) means that the business loses opportunities to gain insights from the calls that could feed into creating a better service and a better experience for customers moving forward. It can also lose opportunities to gain information about competitor activity which is often mentioned in customer calls.

60 Seconds … to Lose 60% of Customers

There is large body of research to show that customers h-a-t-e being put on hold, but really like human engagement. Research from Volaro (2012), for example, showed that waiting on hold for 60 seconds results in almost 60 per cent of customers hanging up, and 63 per cent would prefer a call-back option.

A Sense of Progress Is Valued

A 2007 study (Munichor, Nira, Rafaeli, Anat, Journal of Applied Psychology), where one-third of callers were given music, one-third were given music interrupted by messages apologising for the wait, and one-third were given punctuated by status updates (i.e., “You are the fourth caller in line… You are the third caller in line,”) showed that those who received the status updates were the most satisfied. Even though they waited the same amount of time, it was the sense of progress that they valued and found comforting.

Human Engagement Is Important

Even in this virtual age, human engagement is still very much valued by customers. A CGS survey (2019), showed that 86 per cent of consumers prefer interaction with a human agent rather than a bot or a recording.

Also, research by Shell and Buell (Harvard Business Review – 2019) made the point that when people feel anxious, it is human nature to turn to others for help. Many companies, however, funnel nervous customers to self-service technologies. The research, based in the financial service industry, found that when people had the ability to connect with another person (an expert or a peer) the deleterious effects of their anxiety were offset. The researchers concluded that anxious customers left to fend for themselves may be less satisfied with their choices, and less trusting of the company with which they are interacting. The researchers found that simply offering access to talk to a person is enough to restore customer confidence, improve trust in the company, and even strengthen long-term relationships.

Not In Supermarkets?

Interestingly, despite lessons learned in past (e.g., adding human interaction points to please consumers at deli counters, fish counters, meat counters), UK supermarkets now appear to be moving towards favouring shop-floor technology and reducing human interaction (self-service, or even zero checkouts). Although this may bring them in line with some overseas supermarkets, cut overheads, and deliver operational efficiencies, it remains to be seen whether customers will begin to miss human interaction.

Dos and Don’ts

Developing hold systems for the phone that stop customers from hanging up has become a science in itself where there is much research and where technology is now playing a major part.

For example, findings published in “The Psychology of Telephone ‘On Hold’ Programming” by Dr. Jim Will (2005) highlighted certain points to remember when creating an on-hold experience for callers. These include:

– A primary cause of caller discontent involves the concept of “perceived time” on hold and adding music is effective in the lowering of perceived time. The music, however, should be upbeat, should be created differently in type and instrumentation, and should not include songs that don’t evoke negative associations in the mind.

– The length of the overall message-on-a-hold program is also an important factor in reducing potential anxiety. Longer, less repetitive on-hold message program formats are more effective at reducing caller anxiety.

Also, an optimal “message on hold” program consisting of music on hold and verbal presentations should:

– Incorporate a variety of information genres to maximise interest and cognitive functions, placed in a structured manner.

– Have longer message formats to minimize “wearout”.

– Have upbeat and personable verbal information delivery.

– Have information with no background music or interference (which could divert attention).

– Offer lower perceived time and provide structure to the holding period.

Outsourcing To Call Centres Offshore

The outsourcing of call centres offshore by companies may make sense financially and in terms of increasing capacity, but it has been a contentious issue. For example, back in 2018, BT pledged to bring all its call-centres from offshore locations such as India and the Philippines back to the UK and Ireland after the use of foreign customer service staff was identified as a major complaint by BT’s UK customers.

Some of the reasons some customers dislike speaking to call-centres that have been outsourced include:

– A feeling that their problem isn’t important enough to be dealt with by the company directly, and a perception that the only reason for offshore customer service is to save money.

– Feeling uncomfortable about language difficulties and communication problems, and how this can complicate solving their problem.

– A reliance on scripted conversations by some offshore call-centres can frustrate customers.

– Customers want to talk directly to the company, particularly for services that are personal and involving finances (for example), rather than what they perceive to be ‘go-betweens.’

– Customers are looking for quality service more than fast service and consequently, customers are more likely to recommend a brand based on good service experience.

– From the company’s point of view, poor customer call experiences and negative perceptions can damage the marketing efforts that the company has spent time and effort on and could lead to customers switching.

New Technology

Despite the faults from the point of view of some customers, on-hold messaging services are likely to remain an important part of customer service for some time yet. Examples of how technology is being used to improve these services include:

– Tailor-made music to suit specific customer demographics.

– Systems that can update recordings with the latest promotions.

– Auto-attendant and IVR for automatically routing calls.

– AI-powered voice recognition technology (IVR receptionists) that lets callers state the purpose of their call and their expectations in their own words.

– Google’s AI secretary (‘Hold for Me’) that waits on hold for phone users and notifies users when the call is picked up, thereby leaving them free to put the phone down.

– AI call transcription that can transform call recordings into text documents.

– Using AI-driven analytics in VoIP business phone services to gain better insights into call metrics, caller-behaviour, and the performance of individual company agents.

Chatbots

In the wider sphere of customer service and information provision, bots have become a favoured tool. Bots provide a way for businesses and organisations to reduce costs, make better use of resources and communicate with customers and enquirers 24/7. Examples of how bots can make a positive difference include:

– Lancaster University’s ‘Ask L.U.’ chatbot. Built on Amazon Web Services (voice), it delivers a voice interface that interacts with users, and can be accessed via the iLancaster App on mobile phones and tablets, or by asking “Alexa, Ask L.U.” on any Amazon Echo device. The service, based on the most popular 300 student queries gives students a way to get information in a fast, easy, and convenient way, 24/7.

– Marriott International’s chatbot, ChatBotlr, available to users through Facebook Messenger and Slack, enables Marriott Rewards members to research and book travel to more than 4,700 hotels.

– During the pandemic, the World Health Organization’s (WHO) bot on WhatsApp became a trusted information source and alert delivery tool for the coronavirus (COVID-19) spread.

What Does This Mean For Your Business?

The phone is still an important way for customers to make contact with businesses and organisations. How those calls are handled, and the customer’s experience of the interaction is vital to retaining customer trust, and the positive perceptions that have been built-up, with considerable investment, over time. Using a system and a supplier that enables customers to get what they want quickly (without hanging up) and allows the business to get the insights and information it needs to feed into improving its marketing are important considerations. Websites, social media, and technologies such as AI and the use of bots may have reduced the reliance on the phone system, but where customers have to use it, the most important part of a good customer experience is actually having the problem solved effectively in a reasonable amount of time.

Tech Insight : WAP … WEP … What ???

In this tech insight, we take a brief look at the WEP and WAP security protocols, and what happened to them.

What Is WAP?

Developed by Ericsson, Motorola, Nokia, and Unwired Planet, and introduced back in 1999, Wireless Application Protocol (WAP) was a security standard for devices with a wireless Internet connection on a mobile network. It was designed to create interoperability between WAP equipment e.g., mobile phones that used the protocol, and WAP software e.g., WAP-enabled web browsers and network technologies.

Used A Gateway Intermediary

WAP worked in a similar way to the traditional client-server model but had a WAP gateway that sat between the client and server. The WAP gateway:

– Translated the WAP device requests from a mobile browser (micro browser) into an HTTP URL request and sent it to the server over the internet.

– Processed the response by sending the webpage to the WAP mobile device as a WML file that was compatible with micro browsers.

Why WAP?

Some of the benefits of WAP were:

– It gave wireless network and mobile phone operators an opportunity to improve their services while enabling the introduction of new apps that didn’t require phone or infrastructure modifications.

– It created the potential for third-party developers to write apps (in WML).

– End-users had better security when accessing online services like online banking.

What Happened To WAP?

WAP was not widely adopted around the world and by 2013, due to HTML compatibility in mobile phones, it had largely disappeared.

What Is WEP?

Wired Equivalent Privacy (WEP), which was developed in the late 1990s, was a security protocol for wireless networks that encrypted data transmitted over the WLAN using a static key with the RC4 stream encryption algorithm. The idea was to use WEP to give wireless networks the same level of protection as LANs which also benefitted from physical protection.

Protection From Unauthorised Network Access

Whereas wired networks can only be accessed by users with physical access network access points, wireless networks needed protection from threats such as people gaining access to the WLANs via the radio waves that connect to the network.

What WEP Provided

WEP provided privacy by using a data encryption key (128 or 256-bit), an initialisation vector (an arbitrary number used alongside the secret key), data integrity due to the use of a CRC-32 checksum algorithm (a string of letters and numbers acting as a fingerprint file), and authentication. This authentication could be either Open System Authentication (OSA) or Shared Key Authentication (using a multi-step challenge-response algorithm).

WEP Weaknesses

Unfortunately, WEP was found to have had several critical weaknesses such as:

– Weaknesses in the encryption and RC4 algorithms.

– The inability to authenticate individual users because all users shared the same key.

– The use of the protocol was optional and, therefore, it wasn’t always activated when new devices were installed.

What Happened To WEP?

WEP’s weaknesses and the introduction of the better Wi-Fi Protected Access (WPA) protocol meant that WEP was replaced by WPA2 in 2004. WPA2 offered stronger encryption and integrity protection. The current version is WPA3 (introduced in 2018).

What Does This Mean For Your Business?

With most of us now using mobile devices for our work and home life, particularly with the shift to remote and hybrid working over the last year, it is clear to see why security protocols for mobile networks are so important. WAP and WEP represented important steps in the evolution of network security and encryption, and lessons learned over time have led to the much more secure protocols that we use today.

Tech News : Crypto ATM Scammers

An FBI announcement has warned that scammers are now directing victims to use physical cryptocurrency ATMs and digital QR codes to complete payment transactions.

What Are Cryptocurrency ATMs?

A cryptocurrency ATM is a physical kiosk/terminal/device that connects to a cryptocurrency network (e.g. bitcoin) and allows customers to purchase crypto tokens with deposited cash. Cryptocurrency ATMs are connected to the Internet and can use QR codes to send and receive tokens to users’ digital wallets. The UK, for example, already has bitcoin ATMs in many cities, for instance there are 50 in London and 10 in Manchester.

What Scams?

The FBI’s warning relates to scams that are using impersonation schemes, where the scammer falsely identifies as a familiar entity, for example the government, law enforcement, a legal office, or a utility company. Scammers are also using romance schemes (establishing a fake online relationship with a victim), and lottery schemes where scammers falsely convince victims that they have won a prize and need to pay lottery fees.

How Do The Scams Work?

According to the FBI, regardless of the scheme, the methods using cryptocurrency ATMs and QR codes appear similar. The scammer requests payment from the victim and directs the victim to withdraw money from their financial-accounts (e.g. bank or investments). The scammer then provides a QR code associated with the scammer’s cryptocurrency wallet for the victim to use. The scammer directs the victim to a physical cryptocurrency ATM to insert their money, purchase cryptocurrency, and use the provided QR code to auto-send the money. Reports indicate that the scammer is in constant contact online with the victim, providing step-by-step instructions until the payment is completed.

Why Cryptocurrency?

The reasons why the scammers are using cryptocurrency are:

– The decentralised nature of cryptocurrencies makes them very difficult to recover.

– The transfer is immediate. As soon as the victim makes the payment, the recipient instantly owns the cryptocurrency and can immediately transfer the funds to an account overseas (making it even more difficult to trace).

– It creates extra hurdles for the police/law enforcement agencies in trying to recover the funds.

Protection

Ways to protect yourself from falling victim to this type of scam include:

– Never send payments to a person you have only spoken with online.

– Don’t respond to callers claiming to be representatives of a company where you are an account holder, and who request personal information or demand cryptocurrency, or to callers from an unknown telephone number who request cryptocurrency.

– Don’t respond to anyone who says they can only accept cryptocurrency and (for example) identifies as the government, law enforcement, a legal office, or a utility company.

– Avoid anonymous cryptocurrency ATMs as they may be used for money laundering.

– Report any such calls to ‘Action Fraud.’

What Does This Mean For Your Business?

Cryptocurrency ATMs are still uncommon in the UK, but crimes such as romance fraud are quite widespread and for victims in large UK cities it’s only a short step before this type of scam is operated on a bigger scale. The story also illustrates how manipulative and ruthless scammers can be if the return is rewarding enough. Since the big increase in remote working during the pandemic, the UK has seen a huge rise in various scams. In June, for example, Citizens Advice reported that more than two-thirds of UK adults (36 million) have been targeted by a scammer since January, and that 12 per cent were offered a fake investment or ‘get rich quick’ scheme. There was also a very sad report from Citizens Advice Consumer Service of an elderly man who contacted the charity after he sent £240,000 to an account he thought belonged to his bank. Fraudsters prefer vulnerable targets but anyone, if caught off-guard, is a potential victim. It is vitally important, therefore, that experiences of scam calls/texts/emails are shared, and suspected scams are reported to Citizens Advice and Action Fraud so that the nature of the scams can be identified which can lead to the fraudsters being stopped.

Tech News : Microsoft Unveils ‘Loop’ Collaborative App

Microsoft has unveiled the new ‘Loop’ collaborative app which it describes as “a flexible canvas with portable components” designed for assisting with new hybrid working patterns.

Background

Microsoft says that the new app is part of a “reimagining” of Office, and a response to the new opportunities created by new (hybrid) working patterns that can make Office more of a universal, interactive canvas for creators of all kinds. Loop (which incorporates AI) is, therefore, positioned as an enhanced, collaborative, flexible canvas that can be customised to suit any project with portable components that move freely and stay in sync across apps, thereby, Microsoft hopes, enabling teams to improve how they think, plan, and create.

Three Elements

Loop consists of three elements, which are:

1. Loop pages. These are the scalable, “flexible canvases” which are the shared collaborative spaces into which the components and other relevant elements are dropped for each project.

2. Loop components. These are the “units of productivity” which could be anything from lists, tables, notes, and tasks, to a customer sales opportunity from Microsoft Dynamics 365. These components can be used in the Loop page, a chat, email, meeting, or a document. They are synchronised and the idea of being able to arrange and work with different components is to help the team keep a flow to the work, thereby improving productivity and efficiency. As part of its Loop announcement, Microsoft also announced two new Loop components. These are a voting table to make it easier for teams to ideate, drive consensus, and finalise decisions together, and a status tracker to help track the progress of projects.

3. Loop workspaces. These are the shared spaces where teams can see and group together everything that’s important to a project.

Start Rolling Out This Month

Microsoft says that Loop components across Microsoft 365 apps like Teams, Outlook, and OneNote will start rolling out this month, and more details about the availability of the Microsoft Loop app will be made available in the upcoming months.

Like Google’s ‘Smart Canvas’

Loop is a similar idea to Google’s collaborative working ‘Smart Canvas’ tool, announced in May this year, which uses ‘building blocks’ and ‘smart chips’ to connect and share information between apps such as Docs and Sheets.

All-In-One Document Concept

The idea of an all-in-one document concept is not new (other examples include the Airtable platform, the Notion collaborative app, or the Coda doc) but it now represents a logical, competitive move for Microsoft.

What Does This Mean For Your Business?

The shift to hybrid working, whereby employees work part of their time at home and part in the office, is now a pattern that is (after the pandemic) embedded in the working culture of many organisations. Collaborative working platforms are, therefore, very much in demand and although a little late to the party (two years in the making) Microsoft hopes that Loop’s flexible format and, coupled with familiar apps, will prove popular with businesses. Microsoft has seriously turned up the competitive heat (for Apple) over the last year with features and services designed to be compatible with new ways of working (e.g., Teams Connect, the 365 cloud PC, and Windows 11 including Android apps). For businesses, Loop may prove to be a useful, compatible, collaborative tool that could help improve productivity in uncertain times. For Microsoft, Loop is a way of re-imagining how Office programs can be used more flexibly for business customers as part of a system where projects can be customised to maximise workflow.

Tech Tip(s) – 3 Top YouTube Tips

If you use YouTube videos in your website or need to view or share specific parts of YouTube videos quickly, here are 3 top tips:

1. How To Start A YouTube Video At Any Point

If you need to share part of a video rather than making someone watch the whole thing:

– Edit the YouTube URL with &t=MmSSs, replacing M with the minutes, and replacing SS with seconds, OR…

– Obtain a link automatically while you’re watching the YouTube video by right clicking the video and selecting Copy video URL at current time.

2. Create An Infinite YouTube Video Loop

If you’d like to play a video of your music (for example) continuously in the background while working:

– Visit the YouTube video that you’d like to loop, replace YouTube.com in the URL with YouTubeLoop.net and press ENTER, OR…

– Right-click the video you’re watching and select ‘Loop’ from the menu.

3. Disable Related Videos

If you’ve embedded one of your YouTube videos in your website but want to stop the suggested other videos from being displayed when your embedded video finishes playing:

– In the embed code (you got from clicking the ‘Share’ icon under the video in YouTube) Append ?rel=0 at the end of the YouTube URL. This will prevent the suggested videos from showing.

Tech Insight : Smart Doorbells and UK Law

In this insight, we look at ‘smart’ doorbells and how the outcome of a recent legal case has highlighted the legal responsibilities that owner/operators of smart doorbells have under UK law.

Smart Doorbells

Smart doorbells, such as Eufy, Ring, Nest Hello, Arlo, Vuebell, IseeBell, and more are Internet-connected replacements for traditional doorbells. Smart doorbells use a smartphone app to enable the home occupant to see and talk in real-time with a caller using the doorbell’s built-in high-definition (infrared) camera and microphone. Smart doorbells can be activated by motion sensors and/or the pressing of a button, and the pictures and audio conversations can also be recorded.

The Issues

As outlined in a recent legal case in Oxfordshire, a judge ruled that security cameras and a Ring doorbell installed in a house broke data laws and contributed to harassment. Although the background of the case highlighted a long-running neighbourly dispute and one security camera was placed on a shed, the outcome focused on some very real legal issues relating to smart doorbells such as privacy, security, and regulation of increasingly normalised domestic surveillance.

In this particular case, some key issues were that:

– The smart doorbell could capture personal data (audio of conversations and video) from people who were not even aware that the device was there, and that it recorded and processed audio and personal data (there was no consent).

– The capturing of the audio data was found by the judge to be “even more problematic and detrimental than video data”.

– The extent of the range that the doorbell could capture audio was judged to be well beyond the range of video captured and, therefore, not reasonable (in this case).

– The device’s ability to capture conversations at ranges of between 40ft and 68ft away was excessive.

– An update to the doorbell in 2020 meant that it could not be switched off.

– Even if the ‘activation zone’ (motion-activated area) feature of the doorbell cameras was disabled, it could still film the whole area due to movement in one of the other non-disabled activation zones.

Pro Privacy Campaigners

Privacy campaigners such as Hannah Hart of ProPrivacy have highlighted how, using devices such as smart doorbells, “a small number of residents can effectively transform public spaces into surveillance hotbeds, and even share their recordings with police.”

The Laws

The laws that apply to issues around the use of smart doorbells are the UK Data Protection Act 2018 and UK GDPR. Also, a 2014 case (albeit in the Czech Republic) means that domestic surveillance systems are regarded as being within the scope of the data protection legislation where data is captured beyond the boundaries of a homeowner’s property.

The Manufacturer

The doorbell (Ring) manufacturer in the Oxfordshire case mentioned above was Amazon. Amazon may have:

– Built privacy and security features into the smart doorbell e.g., customisable privacy zones, motion zones, and Audio Toggle to turn audio on and off.

– Added end-to-end encryption to its smart doorbell technologies to keep personal data captured secure against misuse by third parties….

BUT the responsibility for HOW the equipment is used (in relation to the law) lies with you, the user.

How Can You Use Your Smart Doorbell Legally?

The important points to remember for using home surveillance devices, including smart doorbells are:

– Use home surveillance equipment in a way that respects the rights of other people, including neighbours.

– Be transparent (e.g., with neighbours) about what the equipment has been installed for and how it operates, thereby retaining your data protection obligation to process data in a lawful and transparent way, and not to collect personal data without a specified or lawful purpose (as required by the Data Protection Act 2018 and the GDPR).

– Ensure that the scope (e.g., the distance) of data capture is reasonable for its purpose.

– Consider putting up a sign that states recording is taking place, and why.

– Follow published guidance, such as ICO guidance for using CCTV: https://ico.org.uk/your-data-matters/domestic-cctv-systems-guidance-for-people-using-cctv/

What Does This Mean For Your Business?

Smart surveillance products may have some particular advantages (e.g., being able to hold real-time conversations with visitors when you’re not at the premises) but despite their in-built privacy and security features, how they are used and operated and contextual factors mean that you, the owner/user still have legal responsibilities. The recent Oxfordshire (Fairhurst Vs Woodward case) shows that simply installing such devices without the correct consideration of transparency about their use, their operating scope, and how they could affect the legal privacy rights of neighbours could land you with a large fine.

Tech News : One Million UK households May Be ‘Brushing’ Scam Victims

A report from Consumer watchdog Which? reveals that as many as 1.1 million people in the UK may have been caught up in a parcel delivery ‘brushing’ scam.

What Is Brushing?

Brushing is where people are sent packages of goods to their address that they didn’t order, apparently purchased on Amazon, by a person not known to them. Which? believes that third-party unscrupulous sellers, or agents acting on behalf of the sellers may be sending the goods. The reason for the scam is so that third-party sellers can log the deliveries as genuine sales, thereby boosting their own rankings on the highly competitive Amazon platform which favours products with high sales volumes and good reviews.

Where Do The Sellers Find The Addresses?

According to Amazon, sellers find the names and addresses from publicly available sources. The Which? website, however, gives an example which suggests that names and addresses can be easily collected and ‘consolidated’ from a variety of sources, such as Amazon itself (via its seller platform for merchants), from a seller’s list of customers that it serves on other marketplaces and platforms, or from previously unconnected website security breaches.

Accounts Set Up In Some Cases

Which? also reports that some unscrupulous sellers take the brushing scam a step further by creating a fake Amazon account linked to the unsuspecting recipient’s address to ‘purchase’ the item themselves and then leave a glowing (fake) review.

What Kind of Items?

A separate Which? survey showed that a wide variety of items have been received by victims of the scam including LED strip lights, books, envelopes, sunglasses, and headphones.

What Is Amazon Doing About Brushing Scam?

Amazon says it has ‘robust’ processes in place to prevent brushing, which it says are carried out by ‘bad actors’ using data from ‘external sources.’

What Happens To The Parcels?

Amazon’s reported position is that customers don’t need to return the items and can choose to keep the parcels or throw them away, whichever they find more convenient.

The Which? research shows that where there was an Amazon parcel not ordered by the recipient, not sent by a known person, and not taken in for a neighbour, 63 per cent said they kept them, 18 per cent said they threw them away, and 16 per cent said they gave the item away.

What Does This Mean For Your Business?

Although it may sound like a positive thing to be the ‘victim’ recipient of lots of goods that you don’t have to give back, there are some serious issues here. Some would argue that it’s not enough for Amazon to simply say that recipients can do what they like with the parcels, and the fact that the scam exists is a sign that that the system of the platform is not working as it should. Which? wants Amazon to do more to increase its scrutiny of seller profiles and monitor for suspicious activity that could suggest product purchases and reviews are not genuine. The apparent fake reviews that result from the fake sales are also something that could adversely affect Amazon customers and create a more unfair situation for the other Amazon sellers who behave honestly. A better position by Amazon could be to encourage those who have received unsolicited packages to report them to customer services so that it can investigate fully and take robust action against sellers that are attempting to mislead consumers. This would benefit other Amazon sellers and customers alike. There is also an argument that laws should be introduced to crack down on brushing and force tech giants to protect people online. It should also be noted that, at a time when environmental issues are high on the world’s priority list, more goods simply being thrown away is not helping (as in the case of 18 per cent of brushing recipients) .

Tech News : Massive Rise In HTTPS Attacks

The latest “ThreatLabz: The State of Encrypted Attacks,” 2021 report has shown a 300 per cent increase in online attackers using HTTPS to cloak their activities and blend in with other traffic.

HTTPS

HTTPS, the encrypted version of the Hypertext Transfer Protocol (HTTP), enables secure communication over a computer network, using Transport Layer Security (formerly, Secure Sockets Layer). HTTPS is particularly important for protecting the kind of personal data that’s submitted in online activities like shopping, banking, and remote work.

Massive Increase

The ThreatLabz report showed that threats inside encrypted traffic have increased 314 per cent as online attackers choose HTTPS to cloak their activities.

How?

Cybercriminals can use HTTPS to hide threats like malware from web security tools that don’t fully inspect encrypted traffic.

Why?

The rise of this type of attack has been driven by factors such as:

– Google making it known that the presence of HTTPS is an important consideration for search-results rankings, and Chrome and Firefox showing warnings about sites without HHTPS, thereby fuelling a general belief that HTTPS is totally safe.

– Attackers (as well as legitimate businesses) can now enable and auto-renew HTTPS for their sites, regardless of whether the content is suspect.

– New types of malware are now being shared behind a lock symbol.

Types of Attack

The types of attack that criminals are using HTTPS to hide include:

– Malware (including ransomware). This type of attack has grown by 212 percent and nine out of ten attacks via HTTP(S) involved malware. Spyware has also shown a 435 per cent increase.

– Phishing has grown by 90 per cent on last year and is being driven by attacks launched through legitimate services. For example, Microsoft 365 was the most common attack vector for phishers.

– Web applications like credential stuffing. For example, the ThreatLabz report shows that attackers interacted with almost 70 per cent of HTTPS-based web-facing applications.

Who Was Attacked The Most?

The report showed that technology companies were attacked the most using HTTPS cloaking (a 2,344 per cent rise) followed by retail and wholesale companies which saw an 841 percent increase in this type of stealth attack. Increased scrutiny by law enforcement on healthcare companies/organisations and government (which have been heavily targeted before) appears to be the reason for a decrease in the numbers of HTTPS-based attacks on these targets.

What To Do?

Ways that businesses can protect themselves against cybercriminals hiding attacks using HTTPs include:

– Not assuming that SSL traffic is automatically secure traffic – the padlock icon of HTTPS does not guarantee security.

– Start from a position of zero trust, where there is no lateral movement, apps are invisible to attackers, and authorised users directly can only access needed resources, not the entire network.

– If possible, use AI-driven quarantine rather than firewall-based passthrough approaches.

– Use a proxy-based architecture and cloud-native performance to decrypt detect and prevent threats from SSL traffic.

– Make sure all company network users have the same high level of security at all times, at all locations (e.g., when working remotely or even when on the go). All traffic on and off-premises needs to be inspected to stop encrypted threats.

What Does This Mean For Your Business?

Even though HTTPS has been designed to provide a valuable layer of encryption, it has also become relatively easy for cybercriminals to create websites with the HTTPS distinction. Also, cybercriminals have been helped by an assumption that HTTPS and a padlock must mean that everything is secure, and by web security tools which don’t fully inspect and check encrypted traffic, on and off-premises. Businesses should not assume the HTTPS is totally secure and one of the key ways that many businesses are now protecting themselves from a wide range of threats, including HTTPS-based attacks, is to adopt a Zero Trust approach to IT Security where the approach is “never trust, always verify.”