“A brilliant specialist with a short attention span.”
Pros
Rights itself and launches from open water every single time
Tracking at 15 mph is steady enough to pass for a chase boat
The Lighthouse wearable handles launch, landing, and following
Onboard screen lets you replay clips on the water with no phone
Dead battery? It lands softly on the surface and floats
Cons
I measured 10 and 13 minutes of flight against an advertised 23
The Lighthouse shows no battery level at all
No obstacle avoidance
The battery is only fully waterproof while it sits in the drone
Quick Take
I spent two weeks on an Oregon river trying to break this thing — off an eFoil, out of a kayak, and by throwing it into the water on purpose. The HoverAir Aqua is the first consumer drone actually built to live on open water, and after two weeks I still stop what I’m doing to watch it launch. Throw it in the river upside down, and it flips upright, shakes the water off its props, pops into a low hover, and waits for you. Strap the Lighthouse beacon to your forearm, and it will follow you across the river at eFoil speed with your hands never touching a controller.
Let me be blunt, because this is the most important thing to know before you buy: there are two battery problems. HoverAir prints 23 minutes on the box. I measured 10 minutes and 13 minutes with the drone actively tracking me. And the wearable never tells you how much charge is left. So this is a drone I love, packed in a dry bag next to a fistful of spare batteries I resent having to carry.
HoverAir Aqua specs: A quick peek at the innards
Weight
Under 249 g, light enough to skip FAA registration for recreational U.S. flight
Waterproofing
IP67; floats and rights itself; battery fully waterproof only while installed
Camera
4K at up to 100 fps through a heated lens that sheds fog and spray
Altitude sensing
Millimeter wave radar that reads wave height for low passes over water
Display and storage
1.6-inch onboard AMOLED; 128GB internal storage, no SD card
Battery
2,013 mAh smart battery; rated 23 min; I measured 10 and 13 min while actively tracking
Charging
About 55 minutes with the battery inside the drone
Controller
Lighthouse waterproof wearable (launch, land, track, auto recall) with no battery readout
Obstacle avoidance
None
Recognition
CES 2026 Innovation Awards honoree; Red Dot Award
Test conditions
Two weeks on an Oregon river; eFoil at about 15 mph plus kayak sessions
HoverAir Aqua design & build: A pool toy with flagship chops
Ian Bell / Digital Trends
The first thing I noticed pulling the Aqua out of the box is the fat ring of safety-orange foam around its body, the same shade as a life vest. It looks like a pool toy. That’s deliberate. The foam keeps the drone buoyant, cushions the props, and makes the aircraft easy to spot from fifty yards out when it sets down on dark green water. The whole package carries an IP67 rating and weighs under 249 g, which keeps recreational pilots in the U.S. under the FAA registration threshold.
Ian Bell / Digital Trends
My favorite piece of hardware here is also the smallest. A 1.6-inch AMOLED screen sits on the drone’s spine, and it stays readable even with glare coming off the water. It’s there to pick flight modes, but I mostly used it to review what I’d just shot — sitting on the board, dripping, thumbing back through a run while the river went past. Two weeks in, I was still reaching for it instead of my phone. Storage is 128GB and internal, so there’s no SD card to lose, forget, or flood.
Ian Bell / Digital Trends
The camera records 4K at up to 100 fps for slow motion through a heated lens, which keeps fog from forming and makes water bead off instead of smearing across the glass. Underneath the airframe is the strangest line I have ever typed about a consumer drone: millimeter wave radar that reads the height of the waves rolling beneath it, so the Aqua can skim low over moving water without clipping a crest.
For those of you unfamiliar with the term, and since the spec sheets never bother explaining it, millimeter wave radar bounces very short-wavelength radio off a surface to measure distance to it — here, a surface that will not hold still. The industry noticed. The Aqua premiered at CES 2026 as an Innovation Awards honoree and collected a Red Dot Award along the way.
HoverAir Aqua water launch: Throw it in, it flies out
Ian Bell / Digital Trends
The water launch is the feature every bystander will ask you to do twice, and I tested it from the kayak with my kids leaning over the side to watch. You toss the drone into the river upside down, carelessly. However, it happens to leave your hand. It bobs for a beat. Then the props bite, it rolls upright, and it climbs into a hover a few feet off the surface to wait for you to start moving. It did that every single time I asked, and I asked a lot. Not once did I have to paddle over and fish it out or reset anything. In a category where water has always meant total loss, that is a bigger deal than a party trick sounds.
HoverAir Aqua subject tracking: A chase boat on your forearm
Most of my testing happened on my eFoil at around 15 miles per hour, with the waterproof Lighthouse strapped to my forearm like a chunky watch. One button sends the drone up. One button brings it home. Everything between those two presses is automatic.
Advertisement
Not the actual resolution captured by the HoverAir Aqua. The image has been resized.Ian Bell / Digital TrendsNot the actual resolution captured by the HoverAir Aqua. The image has been resized.Ian Bell / Digital TrendsNot actual resolution captured by the HoverAir Aqua. The image has been resized.Ian Bell / Digital Trends
The footage surprised me. My wake unspooling behind the board in a long white seam, the tree line sliding by, and me held in the center of the frame for the entire run. The best material came when the drone swung out ahead of the board and shot back at me, spray kicking off the foil, the whole river opening up behind.
It never fell behind, and it never wandered. When I drifted too far, it closed the gap on its own. When I slipped off the board and sat chest-deep in the water beside it, it stayed locked on and waited. The kayak sessions at lazier speeds went the same way: steady framing, no fuss, the family paddling along with a small orange aircraft holding formation off the bow. This is the closest thing to a camera operator you can wear on your wrist.
HoverAir Aqua Battery Life: High on the box, dips in the water
Ian Bell / Digital Trends
Now, the part the box will not tell you. HoverAir advertises 23 minutes of flight from the 2,013mAh smart battery. My first battery, actively tracking me on the foil, gave me 10 minutes before the drone called it quits. I rode back to shore, clicked in a fresh one, and went back out. Thirteen minutes. Doing the exact job you bought it for, you get about half the number on the sticker.
It’s worth noting that drone makers rate flight time in windless conditions with no tracking load, and you should not expect that figure in the real world. Even allowing for that, half is a wide gap. At least the ending is graceful.
When the charge runs out, you get a warning that the drone will land in 15 seconds, and then it sets down on the surface, orange side up, rocking on the chop until you come get it. Nothing dramatic happened in two weeks of testing. Recharging takes about 55 minutes with the battery inside the drone, and because a battery is only fully waterproof while it’s installed, HoverAir includes a dedicated waterproof pouch for hauling spares out on the water. Read that accessory list again. The company is telling you, in its own way, that you will be swapping batteries mid-session.
HoverAir Aqua Lighthouse Wearable: Great controller, no fuel gauge
Ian Bell / Digital Trends
The second problem makes the first one worse. The Lighthouse is otherwise the best thing about this product, and it tells you nothing about the battery. No percentage. No halfway warning. No blinking light as the level sinks. Mid-run, I had no idea whether the drone above me had eight minutes left or thirty seconds.
Ian Bell / Digital Trends
When the entire budget is 10 to 13 minutes, that silence turns every session into a guessing game. Both times a battery died on me, my only notice was the 15-second landing warning, right when I felt like I was getting going.
Should you buy
HoverAir
The good here is genuinely good. The footage is beautiful, the Aqua keeps pace with a foil at speed, it launches itself out of open water, and it runs hands-off enough that you forget it exists until you sit down to replay the clips. As a piece of engineering built for a hostile environment, it is the real deal.
The battery is what makes me hesitate, and I am not going to soften that. Plan a full session around this drone, and you are packing a pocketful of spares and guessing when to burn them.
Advertisement
So here is the fork. If what you want is a quick promo shot or a fast social clip off the water, this is the drone doing that job, and I don’t know of another one built to take the punishment. If you want to shoot an entire session, wait and watch for a firmware update that pushes battery data to the Lighthouse.
That one change would make this an easy recommendation for anyone who makes content on the water. As it stands, the Aqua is a brilliant specialist with a 10-minute attention span, and I keep taking it out anyway.
Why not try?
HOVERAir X1 PROMAX — Priced significantly lower at $700, this one offers hands-free auto-follow tracking and Lighthouse wearable perks, can shoot up to 4K 120fps footage, and stands out with a foldable design. It’s slightly slower and doesn’t offer a waterproof build, but makes up for it with collision-sensing tech.
DJI Mini 4 Pro — Another option that is more affordable as well, DJI’s drone offers impressive aerial capture capabilities with omnidirectional obstacle sensing and a reliable 4K camera that can capture high dynamic range videos. Plus, the battery packs can extend the flight time by up to 45 minutes, while the transmission performance is also fantastic. But an impending ban casts a shadow of skepticism over long-term support and after-sales experience.
Advertisement
FAQs (Frequently Asked Questions)
Who needs the HoverAir Aqua?
It’s a waterproof, self-flying 4K camera drone. If you’re into activities such as kayaking and wakeboarding, it’s an appropriate choice.
Is it capable of taking off and landing directly on water?
Yes, the positive buoyancy engineering allows it to float on water. And yes, it can take off and land from the surface of water. Moreover, it also comes with a Turtle Flip feature that lets it correct its position instantly, even if it’s flipped upside.
Is the build really waterproof?
The HoverAir Aqua has an IP67-certified build, featuring corrosion-resistant components, while the camera sensor is protected by a hydrophobic, anti-fog lens.
Do you need a license to fly it?
It falls under the prescribed FAA weight limit, so you don’t need a license to fly it.
Advertisement
Can it fly and capture without a phone?
Yes, the wearable Lighthouse controller relies on Real-Time Kinematics (RTK) positioning to let the drone track you and capture videos without requiring a cellular link or base stations.
What is the top speed and battery life?
The HoverAir Aqua can fly at a speed of up to 34 miles per hour, and it is claimed to last over 20 minutes on a single charge.
Lesser horseshoe bat. (Credit: Lylambda, Wikimedia)
As great as echolocation is, things can get rather messy once it’s not just you chirping away, but also hundreds of your buddies in roughly the same area. This is the scenario that the typical colonies of bats have to deal with. In a recent study by [Haruhito Matsumoto] et al. in Journal of Comparative Physiologythey investigated how colonies of greater Japanese horseshoe bats deal with this issue.
Echolocation in animals can use a variety of methods, including frequency modulation (FM, varying the pitch) or constant frequency (CF), with both having their uses during hunting as well as obstacle avoidance. One big advantage of CF is that it can be used for Doppler shift, giving very precise information about location and velocity of objects in the environment, but if used in a busy colony the acoustic interference would effectively render them blind.
What researchers have found is that the CF component frequencies differ per bat colonies, with the mixing of wild-caught and resident horseshoe bats in this experiment showing them adjusting the dominant second harmonic (CF2) to match, with bats using a lower frequency CF2 adjusting it upwards. In this way frequency convergence is used as a strategy to avoid acoustic interference using a so-called ‘silent spectral window’.
As this spectral window for effective Doppler tracking is found above the CF2 frequency, it therefore makes sense that the bats at a lower CF2 harmonic would adjust their CF upwards to match that of their neighbors. Although more research is required to fully confirm these findings, it sheds some more light on the use of echolocation by these amazing flying mammals.
In a nutshell: Despite Nvidia losing fans over the last few years as its focus on gamers diminishes (or disappears), the company’s GPUs have dominated the sales charts. But that status quo is starting to change: Amazon’s top 10 best-selling GPU list is an even split between Team Red and Team Green, with the highest position held by a Radeon 9000-series card. Meanwhile, in Germany, AMD is the one that’s dominating sales – at least at one retailer.
The rise of RDNA 4 was highlighted by TechEpiphany on X.
The Amazon best-selling list has changed slightly since the post, but the Radeon RX 9070 XT is still the top GPU. This Gigabyte version is priced at $749, which, of course, is considerably higher than the GPU’s $599 launch MSRP.
The other AMD cards in the chart are an Asus model of the 9070 XT, an Asrock 9070, and an Asus 9060 XT. Nvidia also holds four positions with its RTX 5070, RTX 5060 Ti, and two RTX 5080 models.
Advertisement
Things appear even more favorable for Lisa Su’s firm in Germany. The figures, which come from Mindfactory, show AMD accounting for almost 56% of all GPUs sold over the last week, while Nvidia holds a 40% share. Again, the RX 9070 XT is the most popular card by far, followed by the RX 9060.
It’s worth remembering that Mindfactory has a reputation for favoring AMD, offering promotions, discounts, and bundles featuring its products, which help push up sales figures. The store’s AMD cards have outsold Nvidia’s in the past.
However, these charts do illustrate the impact of the memory crisis on the graphics card market. All GPUs are more expensive, but AMD’s are often cheaper than equivalent Nvidia cards.
The other reason is likely simple availability. The Amazon chart shows three AMD cards in stock, while Nvidia only has one – a Gigabyte RTX 5080 for a colossal $1,599, and that’s with a 6% discount.
Advertisement
Only one company dominates the Steam survey GPU chart
TechEpiphany’s claim of AMD “dominating everywhere” might be a bit of an exaggeration, but there are signs of consumers opting for its cards because of the cheaper prices – or just buying them because there are no Nvidia alternatives. The most valuable company in the world still has GPUs in almost 73% of Steam survey participants’ machines, compared to AMD’s 18.6%, so we’re not seeing a red revolution just yet.
Create a strong password policy by prioritizing length and uniqueness, blocking compromised passwords, allowing password managers and autofill, removing arbitrary complexity and expiration rules, and requiring MFA for important accounts. Deploy the policy with a managed password vault, secure recovery procedures, and tests that confirm the written rules work in every covered system.
Quick Take
Require at least 15 characters when a password is the only authentication factor.
Allow passwords of at least 64 characters, including spaces.
Do not require arbitrary mixtures of uppercase letters, numbers, and symbols.
Replace scheduled password expiration with changes triggered by suspected compromise.
Reject commonly used, predictable, and previously compromised passwords.
Allow password managers, paste, and autofill on login forms.
Protect important accounts and cloud-synchronized vaults with MFA.
Test login, recovery, export, offboarding, and session-revocation controls.
These requirements follow current NIST authenticator guidance. They are a security baseline rather than proof that a particular policy satisfies every law, contract, or industry framework.
Prerequisites and Ownership
Identify the accounts in scope
Inventory the systems that accept passwords before writing the rules. Include workforce accounts, customer accounts, administrator access, cloud services, remote-access tools, shared credentials, and legacy applications. Record which systems use single-factor authentication, MFA, or single sign-on.
Keep machine credentials in a separate category. API keys, database secrets, certificates, service-account tokens, and CI/CD credentials require secrets-management controls rather than an ordinary employee password vault. A dedicated article on business secrets management should cover those systems.
Assign responsibility
Name a policy owner, identity-platform administrator, security reviewer, help-desk recovery owner, and departmental access approver. A policy without named owners tends to fail at exceptions, recovery, and offboarding rather than during ordinary password creation.
Advertisement
Document technical constraints
Record each system’s minimum and maximum length, supported characters, MFA options, password-history rules, breached-password screening, paste and autofill behavior, recovery process, and session controls. Legacy systems that cannot meet the baseline should enter a documented exception process with compensating controls and a retirement or remediation date.
Step-by-Step: Create the Password Policy
Define which accounts the policy covers
State whether the policy applies to employees, contractors, administrators, customers, service providers, and shared accounts. Classify higher-risk accounts such as email, identity-provider, financial, cloud-administrator, source-code, and password-vault accounts.
Where possible, replace shared accounts with individually attributable accounts. If sharing is unavoidable, use a managed vault that records access and lets administrators revoke membership.
Expected result: Every covered account type has an owner, risk classification, authentication method, and exception status.
Set length and input requirements
Require at least 15 characters when a password is the only authentication factor. NIST permits passwords used only as part of an MFA process to be shorter, but they must contain at least 8 characters. Organizations may adopt a longer minimum when users can rely on a password generator.
Permit passwords of at least 64 characters. Accept spaces and broad character sets, process the entire submitted password, and never silently truncate it. Systems that mishandle spaces or long generated values should be corrected or documented as exceptions.
Advertisement
Expected result: Users can create long passphrases or generated passwords without encountering unnecessary input restrictions.
Remove mandatory composition rules
Do not require every password to contain a prescribed mixture of uppercase letters, lowercase letters, numbers, and symbols. Current NIST rules prohibit these composition requirements because users commonly satisfy them with predictable patterns.
Symbols remain acceptable when a generator selects them or a service requires them. The policy should not imply that a short password becomes safe simply because one letter was replaced with a familiar symbol. NIST’s public password creation guidance prioritizes length and recommends long passphrases when a password must be created manually.
Expected result: Users can choose long, usable passwords without following predictable formatting recipes.
Replace scheduled expiration with event-driven changes
Do not force users to change passwords every 30, 60, or 90 days without evidence of risk. Require a change when a password is known or suspected to have been disclosed, appears in relevant breach data, was transmitted insecurely, or may remain known to someone whose access has ended.
A password change must be accompanied by session revocation when an attacker could already be signed in. Changing the secret alone may not invalidate active browser sessions, application tokens, or remembered devices.
Advertisement
Expected result: Password changes respond to compromise and access changes rather than an arbitrary calendar.
Block weak and compromised passwords
Compare new and changed passwords against a blocklist containing commonly used, expected, and compromised values. Include context-specific choices such as the organization’s name, service name, username, and predictable derivatives.
Explain why a proposed password was rejected and ask the user to choose a genuinely different value. Do not reveal whether another person uses that password. Avoid enormous blocklists that create excessive false rejections without meaningfully improving protection against rate-limited online guessing.
Expected result: Users cannot enroll values that attackers are likely to guess early or already possess from breach collections.
Add controls around the password
Require MFA for email, identity-provider, financial, remote-access, cloud-administrator, source-code, and password-manager accounts. Prefer phishing-resistant methods such as passkeys or hardware-backed security keys where the service and user environment support them.
Rate-limit or progressively delay failed attempts. Monitor suspicious logins, protect account recovery, avoid knowledge-based questions as a sole recovery method, and provide a way to revoke sessions after suspected compromise. The OWASP authentication guidance treats password controls, MFA, recovery, session handling, and login monitoring as connected parts of account security.
Advertisement
Expected result: A guessed or disclosed password is harder to convert into persistent account access.
Require password-manager-compatible login forms
Allow users to paste and autofill credentials. Use standard password fields and avoid scripts or form designs that block managers. NIST requires verifiers to allow password managers and autofill and recommends permitting paste when autofill interfaces are unavailable.
Do not interpret clipboard blocking as a security control. It can push users toward shorter passwords they can type manually or toward storing credentials in insecure notes.
Expected result: Users can generate, store, and enter unique credentials without weakening them for convenience.
How to Choose a Password Manager
Select a manager by deployment fit, recovery design, security controls, and usability rather than by the length of its feature list. The NCSC buyers guide emphasizes that an unusable manager will leave insecure workarounds in place.
Advertisement
Comparison of password-manager deployment models
Manager type
Best fit
Principal advantage
Main limitation
Browser or platform manager
People using one primary browser or device ecosystem
Low setup friction and integrated autofill
Potential platform lock-in and fewer team controls
Standalone cloud-sync manager
Mixed-device users and small teams
Cross-platform access and centralized synchronization
Remote account and recovery paths require strong protection
On-device manager
Narrow or offline use cases
Reduced dependence on a cloud service
Limited synchronization and more difficult recovery
Enterprise-managed vault
Organizations requiring governance and offboarding
Managed sharing, audit records, policy enforcement, and provisioning
Greater administrative complexity and recurring cost
Evaluate the following capabilities before deployment:
Protection of credentials and metadata at rest.
Who controls or can recover the vault’s decryption key.
MFA, passkey, and approved-device support.
Recovery options and the people authorized to use them.
Secure sharing without revealing passwords in email or chat.
Role-based administration, audit records, and offboarding controls.
Restrictions or alerts for bulk export.
Supported browsers, operating systems, and mobile devices.
Update delivery and the provider’s vulnerability-disclosure process.
A practical method for leaving the service without permanent lock-in.
Browser and device managers can be appropriate when convenience and ecosystem integration matter most. A reputable standalone manager may fit mixed-device environments or teams requiring advanced sharing and administration. The NCSC’s updated password-manager guidance recommends evaluating reputation, device security, recovery, MFA, and platform needs instead of assuming one type fits everyone.
How to Deploy and Use the Password Manager
1. Protect the vault account
Create a long, unique primary passphrase that is never used elsewhere. Enable the strongest practical MFA and secure every registered device with updates, automatic locking, and a local PIN or biometric unlock.
Store recovery keys or emergency instructions separately from the vault. Avoid circular recovery in which the only way to access the email account is through the vault while the only way to recover the vault is through that email account.
2. Import credentials carefully
Some managers migrate credentials through a CSV file. That export may contain readable usernames and passwords. Create it only on a trusted device, import it immediately, verify that the records arrived, and delete the exported file from the original folder, recycle bin, cloud synchronization, and temporary storage.
Advertisement
Do not perform a vault migration over an unfamiliar hotspot. Review the precautions in this public Wi-Fi security guide before accessing sensitive accounts away from a trusted connection.
3. Replace reused passwords in risk order
Secure the password-manager account and its recovery channels.
Change email and identity-provider credentials.
Change banking, payment, payroll, and financial credentials.
Change administrator, cloud, source-code, and remote-access credentials.
Change shopping, social-media, subscription, and lower-impact accounts.
Do not change dozens of accounts without confirming that each new password was saved. Keep the old session open until the new credential has been tested in a separate private window or another approved device.
4. Configure generation and autofill
Generate a different random password for every compatible service. Match the site’s supported length and character rules while avoiding needless manual edits. If autofill does not appear, check the exact domain before searching the vault and copying the password.
Autofill may help resist phishing because a manager should associate credentials with the legitimate domain. It is not infallible. Users must still inspect unusual addresses, subdomains, redirects, and browser warnings.
5. Configure team sharing and offboarding
Store business credentials in organization-controlled collections rather than personal vaults. Grant access by role, assign an accountable owner, review membership, and remove access promptly when someone changes roles or leaves.
Advertisement
Revoking vault access prevents future retrieval, but it cannot make a password unknown to someone who already viewed or copied it. Rotate credentials when a departing user could retain them. Teams protecting software repositories should connect this process to the controls in the guide to preventing source-code theft.
Verify That the Policy Works
Test the deployed controls instead of assuming a written setting was applied consistently.
Checklist
Confirm that a 15-character single-factor password is accepted.
Confirm that long passphrases, spaces, paste, and autofill work.
Confirm that the application processes the full password without truncation.
Attempt to enroll a known common password and verify that it is rejected with useful guidance.
Confirm that uppercase, number, and symbol mixtures are not mandatory.
Verify that routine expiration is disabled and compromise-driven resets work.
Trigger repeated failed attempts in an approved test account and verify rate limiting or progressive delay.
Test MFA, recovery, session revocation, emergency access, and lost-device procedures.
Remove a test user from a shared collection and verify that access ends.
Verify that export actions are restricted, logged, or both.
Record exceptions and failed tests with an owner and target correction date. Repeat the checks after identity-platform changes, password-manager migrations, or major policy revisions.
Failure Modes and Troubleshooting
Common password policy and manager deployment failures
Failure
Likely cause
Security consequence
Corrective action
Long generated password is rejected
Legacy length or character restriction
User shortens or reuses a password
Correct the restriction or document a temporary exception
Autofill does not appear
Unsupported form, disabled extension, or domain mismatch
User may copy into the wrong page
Verify the domain and manager permissions before manual entry
Credentials fill on an unexpected subdomain
Overly broad saved-domain matching
Password may reach an unintended service
Narrow the saved address and report unsafe matching
Primary passphrase is lost
Recovery was not configured or documented
Vault data may become inaccessible
Use the approved recovery process and reset affected accounts if recovery fails
MFA device is lost
No backup factor or recovery key exists
User is locked out or bypasses policy
Use pre-established recovery and revoke the lost device
Exported CSV remains on disk
Migration cleanup was missed
Passwords remain exposed in plaintext
Delete all copies and rotate credentials if exposure is possible
Former worker retains a shared password
Vault removal occurred without credential rotation
Continued unauthorized access remains possible
Rotate the credential and review account activity
Legacy system requires frequent changes
Obsolete platform rule
Users may create predictable variations
Apply compensating controls and schedule remediation
Vault and email recovery depend on each other
Circular recovery design
One lost factor can lock out both services
Create an independent recovery route and protect it offline
Operational Limits and Edge Cases
Concentrated value: A vault makes unique passwords practical, but a successful vault compromise can expose many accounts. Protect the primary account and registered devices accordingly.
Compromised endpoints: Malware or someone using an unlocked computer may capture credentials after the vault decrypts them. A password manager does not replace device protection. Organizations can evaluate those controls separately in this endpoint protection guide.
Recovery trade-off: Recovery improves availability but creates another path that an attacker may target. Document who can recover a vault and what evidence is required.
Shared accounts: A vault improves sharing, but individual accounts remain preferable because they provide attribution and cleaner revocation.
Offline access: Emergency recovery material needs physical protection, named custodians, and periodic verification.
Phishing: Passwords themselves are not phishing-resistant. Adopt passkeys where appropriate and evaluate the differences in a future passkeys versus passwords guide.
Key Takeaways
Use length, uniqueness, blocklists, and login protections instead of frustrating composition rules.
Require at least 15 characters when a password is the only authentication factor.
Do not force periodic changes without evidence of compromise.
Allow password managers, paste, autofill, and long values.
Protect the password vault, email, identity provider, and administrator accounts with MFA.
Select a manager based on security, recovery, usability, platform support, export, and governance.
Replace reused passwords in risk order and verify each change.
Test recovery, offboarding, exports, and session revocation before an incident.
Frequently Asked Questions
Should contractors use the company password manager?
Contractors should use an organization-controlled vault when they need access to company credentials. Place them in restricted groups, set an access end date where supported, and avoid mixing business credentials with their personal vaults. At contract completion, revoke access and rotate any credential they could have copied.
Should a password manager store the code for its own MFA?
Storing a service’s password and MFA code in one vault is convenient, but storing the vault’s own second factor inside that same locked vault creates a circular dependency. Protect the manager itself with a separate authenticator, passkey, hardware key, or securely stored recovery code.
What happens if the password manager company shuts down?
A usable exit plan should let authorized users export or transfer credentials to another manager. Confirm the export format before deployment and document how migration would work. Because exports may be plaintext, continuity planning should not involve leaving permanent backup exports on ordinary drives.
Advertisement
Can administrators see employees’ passwords in a business vault?
That depends on the manager’s encryption, sharing, recovery, and administrative design. Some administrators can recover accounts or manage shared collections without seeing every private credential. Others may have broader recovery powers. Review the product’s key-ownership and recovery documentation before adoption.
Should personal and work passwords be kept in the same vault?
Separate vaults or clearly separated organization-controlled and personal spaces are preferable. The company must be able to manage, audit, and revoke business access without gaining control over personal credentials. Employees should also retain their personal passwords after leaving without exporting company secrets.
What should happen when a password appears in a data breach?
Change the affected password, revoke active sessions, review account recovery methods, inspect recent activity, and replace the same password anywhere it was reused. Follow a documented data breach response checklist so the reset does not overlook tokens, forwarding rules, or connected applications.
It’s a little more than three months until Grand Theft Auto 6 rocks the video game industry, and other than two trailers, little of the game has been shown by developer Rockstar Games. The first real look at maybe the most hotly anticipated game ever is coming soon, but fans will need a Netflix account to watch it first.
GTA 6 will make its debut on the streaming service on Aug. 27, Rockstar Games announced Thursday, in what’s likely an extended preview of the game. Grand Theft Auto 6: An Extended Look will premiere first on the streaming platform at 12 p.m. PT (3 p.m. ET) and then on a new GTA 6 YouTube channel at 6 p.m. PT (9 p.m. ET) the same day.
The developer didn’t provide any additional details about this GTA 6 preview or how long it will be. There was also no info provided on this partnership between the game company and Netflix, and whether it signalled an ongoing retlationship. It’s an unprecedented move to have the game first shown on a paywalled streaming service.
Rockstar Games didn’t immediately respond to a request for additional comment.
Advertisement
“Grand Theft Auto reveals have become cultural moments in their own right. The anticipation and fandom around Grand Theft Auto 6 is unprecedented, and we’re honored that Rockstar Games has partnered with us to debut the next part of the Grand Theft Auto story with Netflix members first,” Brandon Riegg, Netflix’s vice president of nonfiction series, said in a statement. “It’s a reflection of what we hope Netflix is becoming: a place where the most ambitious storytelling, from any medium, can find the biggest possible audience.”
For astronomy enthusiasts, August 2026 will be a month to remember. Some of the most spectacular celestial phenomena—including ones that are easy to observe without telescopes or other specialized equipment—will all occur during the same week.
It’s a great time to get your viewing plans together and start refreshing your weather app to see whether the skies will be clear where you are to catch all the happenings in the heavens.
Perseid Meteor Shower
The Perseids are among the most spectacular meteor showers of the year, along with the Geminids in December and the Quadrantids in January. Every August, Earth passes through the trail of particles left behind by Comet 109P/Swift-Tuttle. As the fragments enter the atmosphere at high speed, they produce an intense meteor shower.
In 2026, activity will peak during the night of Wednesday, August 12, and extend into the early morning hours of the following day. It will coincide with the new moon. That means the sky will be exceptionally dark, offering prime viewing conditions.
Advertisement
The Perseids appear to radiate from the constellation Perseus. In reality, the meteors can streak across any part of the sky, but locating that constellation with the help of a stargazing app can make it easier to know where to look for the best chance of catching streaks across the night sky.
Solar Eclipse
The main astronomical event of the month will be a total solar eclipse. Not everyone will get a glimpse, though, with the path of totality crossing sliver of Spain, Portugal, Iceland, and Greenland. Areas outside those locations will still be treated to a partial eclipse.
The timing will be particularly dramatic, with totality set to occur at sunset on August 12. The Sun’s low position above the horizon will offer an unusual—and photogenic—scene.
This will be the Iberian Peninsula’s first time seeing a total solar eclipse in more than a century. Madrid is in the path of totality as are regions that include Galicia, Asturias, Castile and León, Madrid, Aragon, Catalonia, Valencia, and the Balearic Islands. In the rest of the country, the eclipse will be partial.
Advertisement
Those outside the eclipse path will also be able to follow the event. Agencies such as NASA and the European Space Agency will broadcast the event live. The main piece of advice for those trying to observe it: Do not under any circumstances stare directly at the sun.
Planetary Alignment
As if the solar eclipse and the meteor shower weren’t enough, in the early morning hours of August 12, an alignment of six planets will also occur. Jupiter, Mercury, Mars, Uranus, Saturn, and Neptune will form an apparent line in the sky.
Observing this alignment is more challenging than watching the meteor shower given the faintness of some of the planets. However, if atmospheric conditions are favorable, it will be possible to see Mercury, Mars, and Saturn with the naked eye near the horizon shortly before sunrise. To observe Uranus and Neptune, you’ll need a telescope.
Lunar Eclipse
August 27 will close out the month with a partial lunar eclipse that will cover up to 96 percent of the moon’s disk. Unlike solar eclipses, which only cuts a very narrow path across the Earth’s surface, lunar eclipses can be seen from much larger regions of the planet. On this occasion, it will be visible across virtually the entirety of the Americas, from Canada to Argentina.
Advertisement
Also unlike this month’s solar eclipse, observing this one will require no special eye protection. Simply find a dark spot, away from light pollution and, if possible, with a clear horizon. The only protection you might need is from the cold, particularly if you’re in the southern hemisphere given the season.
This story originally appeared onWIRED en Españoland has been translated from Spanish.
Bottom line: Uber is moving quickly to put robotaxis on its main app, backed by a large cash pile and new approvals for real-world testing. The company plans to spend about $10 billion over the next few years to deploy 120,000 autonomous vehicles. It expects to run robotaxi services in at least 15 cities this year, putting it in direct competition with Alphabet’s Waymo and Tesla as they all push to turn self-driving technology into a commercial service.
Chief executive Dara Khosrowshahi said the spending is possible because Uber is generating strong cash flow from its core business. In the second quarter, the company produced a record $2.8 billion in free cash flow. Over the past 12 months, free cash flow has reached about $10.1 billion as bookings continue to grow. “We’re investing from a position of strength, as we accelerate our cross-platform strategy at a global scale and build the world’s largest platform for autonomous vehicles,” he said. “Our ambition is clear: to become the world’s leading commercialization platform for autonomous mobility.”
Instead of building a single in-house autonomous driving system, Uber is trying to become the main platform that connects multiple AV technologies to riders. The company shut down its own autonomous vehicle program in 2020 during a cost-cutting push. Over the past year, it has shifted to working as an intermediary for AV startups around the world.
That includes agreeing to invest in vehicle fleets and taking equity stakes in companies such as Zoox, Rivian, and Lucid, a change from its earlier asset-light approach. Uber is also sending out hundreds of sensor-equipped vehicles to collect driving data for its partners, who use that information to train and refine their self-driving systems.
Advertisement
One of the key partnerships is with Wayve, a UK-based autonomous driving company focused on software that can handle complex city streets. On Wednesday, Uber said Wayve had received permits from Transport for London to launch a commercial robotaxi service with a supervising driver behind the wheel. “I believe that it’s the UK’s first license for AV technology to operate and a big step forward for the UK,” Alex Kendall, Wayve’s chief executive, told the Financial Times, adding that the approval should allow the two companies to offer rides to Londoners in “a matter of weeks.” Transport for London said it had cleared 15 of Wayve’s modified Ford Mustang Mach-E vehicles to operate with a safety driver while the technology is tested on public roads.
Uber’s push into robotaxis comes as investors are still debating how autonomous vehicles will affect its core ride-hailing business. The stock is down 13% in 2026 as some shareholders worry that robotaxis could disrupt the existing model that relies on human drivers. Uber is arguing that its base of more than 200 million customers and its ability to route trips across different services will give it an advantage as AVs become more common.
Balaji Krishnamurthy, Uber’s chief financial officer, said the company will keep using its balance sheet to back growth projects, including AVs and international expansion. He pointed to Uber’s €13 billion offer for German delivery group Delivery Hero as part of that strategy. Uber has already paid about $4 billion for a 37% stake ahead of a formal bid, a move that would open access to faster-growing markets in Europe and the Middle East if the deal goes through.
The next test for Uber will be whether its platform-based AV strategy can turn technical progress into dependable services on busy city streets. The Wayve permits in London and robotaxi launches in other cities will bring Uber’s autonomous vehicle partners to more riders and regulators. The industry must still prove that driverless transport can be safe, scalable, and profitable.
Comedian and “Love Isn’t Blind” host Allison Goldberg, center in pink, during the touring live show. (Photo via Love Isn’t Blind)
Can’t a tech bro catch a break?
A live dating show that has made stops in Seattle sheds a little bit of light on how tech workers in the city are received, according to a new report from Axios Seattle.
Allison Goldberg, comedian and host of “Love Isn’t Blind,” says that when she introduces a contestant who is a software engineer, the audience boos.
“I’m sorry, are we booing a man with a job?” Goldberg said in the Axios story. “I live in Los Angeles, where I would love to meet a man with a job and benefits.”
The insight offers unscientific, but at least anecdotal proof that Seattle has never really come to terms with its tech-fueled identity crisis.
Advertisement
Decades into the city’s growth into a tech hub, the tension between Seattle’s blue-collar, artsy roots and the high-earning tech influx remains palpably unresolved. Even as software engineers and Amazonians make up a massive slice of the local population, the cultural friction lingers.
Tech workers are an easy, almost reflexive punchline for local audiences who still harbor a little resentment over skyrocketing rent, gentrification, and shifting city vibes. GeekWire witnessed another version of tech roasting several years ago when the comedy show “Socially Inept” was in town. And we’ve documented anti-tech messaging in graffiti and stickers across the city.
“Love Isn’t Blind” is aimed at singles who are tired of swiping. “F*** the apps,” it says on its website.
Men compete on stage for one “lucky bachelorette” — but the men are not allowed to speak. Instead, Axios reports, “Goldberg searches their phones, calls their moms and rifles through their Notes and AI apps while the audience waves literal green flags to show approval.”
Advertisement
Goldberg, whose show tours the country, also said the contestants and audience members in Seattle skew smarter than average, with more software engineers and Ph.D.s than most cities. Maybe that just means more booing.
Tech workers, or any other brave singles, can apply to be on the show or nominate a friend. “Love Isn’t Blind” returns to Seattle this Friday at the Fremont Abbey Arts Center.
Older ferries like this vessel sailing across Washington’s Puget Sound are scheduled to be upgraded or replaced with electric-hybrid ferries to cut greenhouse emissions. (GeekWire Photo / Kurt Schlosser)
The sun is setting on Washington state’s aging diesel-powered ferry fleet as work begins on new hybrid-electric vessels.
Eastern Shipbuilding Group in Panama City, Fla., has started building the state’s first new ferry since the Suquamish launched in 2018. The hybrid ferries will use batteries and diesel engines to cut emissions, with the first vessel scheduled for delivery in 2030. Eastern will complete the second and third ferries in 2031 and 2032.
Washington State Ferries is the biggest contributor to greenhouse gases among state agencies. In 2018, then-Gov. Jay Inslee signed an executive order to begin electrifying the fleet.
The state has since developed a long-term plan to deploy 16 new hybrid ferries and convert six existing boats into plug-in vessels by 2040.
In 2019, the state struck a deal with Vigor, a Seattle shipyard, to build up to five hybrid-electric ferries, with the first due within three years. Negotiations between Washington State Ferries and Vigor over price and contract terms broke down, and the state ultimately relaunched a competitive bid for the project.
Advertisement
The three 160-car ferries under contract with Eastern will cost $714.5 million to build, plus additional costs for owner-furnished equipment, construction management, crew training, and risk contingencies. All told, the total price tag is $1.15 billion.
The Wenatchee, a 202-car ferry converted to hybrid-electric by Vigor, began sailing the Seattle-Bainbridge route last summer, making it the largest battery-powered ferry in North America. Two additional Jumbo Mark II-class ferries await conversion, but the state’s supplemental transportation budget adopted in March did not fund their upgrades.
The system has 21 vessels, 11 of which are more than 40 years old. State leaders say 26 ferries will eventually be needed. Washington operates the largest ferry system in the U.S., which transported more than 20.1 million passengers last year.
Construction began in Florida with a ceremonial steel-cutting event early Wednesday. Gov. Bob Ferguson did not attend because of Washington’s wildfires but recognized the milestone.
Advertisement
“In the past decade, we lost four ferries to retirement,” Ferguson said in a statement. “Today signifies a critical step in rebuilding our fleet with modern vessels that will allow us to provide more dependable service.”
In the teensy Midwestern town of Braham, homemade pie capital of Minnesota, something unusual in the municipality’s computer systems knocked the city’s entire water supply offline last week.
At least a dozen states have been affected by the attack, which briefly led to a flurry of small-town service disruptions, boil-water notices, and local flooding. Water wells, dams, sewers, and pipelines are some of America’s oldest and creakiest pieces of infrastructure, built long before the internet existed, and certainly long before AI made hacking much easier. While you may assume most hackers are in it for the money or for data, some have targeted critical infrastructure like water systems or energy grids in ploys for control or disruption — or worse still, as acts of war.
And, as last week’s attacks show, the nation’s water system is woefully unprepared. But how worried should you be that the very infrastructure that keeps our water taps running is, apparently, hackable?
Advertisement
When we say the water supply got hacked, what we really mean is that someone, somewhere has broken into the computer that controls a local water treatment plant or reservoir, and is now pulling the levers, like the one that decides how much of a corrosive chemical can safely go into cleaning the water that comes out of your tap.
These levers were once manual buttons and knobs operated in-person by real live humans, meaning that — barring a natural disaster, bomb, or break-in — protecting them was about as simple as building a fence and hiring guards. Increasingly, however, these levers have gone digital, meaning that they are now remotely operable from anywhere in the world.
Those upgrades have been convenient, allowing technicians to monitor and troubleshoot problems in real time. But, in the process, they have exposed at times centuries-old infrastructure to distinctly modern vulnerabilities. Most local water systems are operated by local authorities, don’t have a dedicated IT team, and lack the money or resources to thoroughly protect themselves without some extra help. Hackers know this, which is why they’ve increasingly targeted local agencies in such attacks.
A water treatment plant in Minnesota, where a coordinated cyberattack targeted dozens of municipal water systems last week.Star Tribune via Getty Images
“With great connectivity comes great responsibility,” said Joshua Corman, founder of I Am The Cavalry, a nonprofit focused on helping critical infrastructure withstand hackers. And yet, even when it comes to critical services like water, “our dependence on connected technology is growing faster than our ability to secure it.”
Advertisement
About 97 percent of water systems are small, run by local agencies that often barely lock the proverbial front door. America’s water system is like an expensive heirloom bicycle that’s been left on a busy street, protected by only the flimsiest of padlocks. And that very vulnerability has made tiny towns like Braham prime targets for faraway adversaries. Accessing the computers that operate most water systems — known as programmable logic controllers or PLCs — is often as simple as entering a username and password on a public-facing webpage. Sometimes, there is no real password at all, because PLCs were initially intended to be accessed only within locked, secure facilities, not on the open internet. If the US wants to avoid a far more severe version of what happened last week, then it will need to start taking the security of tiny water systems like Braham’s seriously.
“Any sociopath from anywhere in the world can see these things on the internet,” said Corman. And in the case of last week’s attacks, “these were devices with no password, no firewall or VPN shielding them — they just had to log in” as whoever the intended operator was, and just like that, they were inside a local water plant.
How did this happen at all?
When municipalities began hooking up their old water and wastewater systems to the internet — a trend that accelerated during the pandemic as water operators, like everyone else, adapted to remote work — cybersecurity was rarely front of mind, neither for individual utilities nor for regulators as a whole.
Advertisement
Most of America’s small-town water systems are unusually vulnerable to cyberattacks.Arin Yoon/The Washington Post
“We have more cybersecurity regulations for your credit card than we have for the nation’s water supply,” said Corman. Only recently have some municipalities begun to take steps to decrease the exposure of their water plants to hacks. In March, New York state, for example, launched a set of grants and basic cybersecurity regulations mandating security training for all water operators.
Basic cybersecurity hygiene isn’t always enough. More than half of all credit card holders have been hacked, even with the help of mandatory firewalls and data encryption. You can imagine how vulnerable our water must be without the assistance of such guardrails. In a worst-case scenario, a malicious actor could quite literally open the floodgates, as Russian hackers did to a Norwegian dam last year. They could poison the tap water, as a still unidentified hacker almost did in Florida in 2021, dialing up the levels of sodium hydroxide used at a water treatment plant by over 100 times its normal levels. In a severe scenario, they could indefinitely cut off access to all water entirely.
The good news is, none of this happened last week. Nobody died, nobody lost water for more than a few hours, no fire hydrants ran dry, and no hospitals were forced to cut off their dialysis machines (which can use more than a hundred gallons of water per treatment session). There’s no need to panic, and your drinking water is almost certainly still safe to drink, assuming it was safe before. Even the city of Braham, within a few hours, was able to bring its water tower back online, pumping groundwater back to its 1,800 residents.
How do we avoid cyber-armageddon?
Advertisement
If you’ve watched the Julia Roberts and Mahershala Ali-starring thriller Leave the World Behind, in which a cyberattack apocalyptically spoils a family vacation, then you might have some idea of where this story could go.
Cyberattacks on critical infrastructure can be extraordinarily dangerous, but thankfully, none have directly cost lives or severely disrupted services in this country so far. If the US wants to keep it that way, that will mean doing more to help small cities like Braham adapt and better monitor for potential threats. As it stands, of the roughly 151,000 water facilities in the US, only about 420 participate in voluntary information sharing on their own cybersecurity practices, says Corman, who has been leading his own project that recruits volunteers to give free cybersecurity support to water utilities in the nation’s roughly 6,000 hospital towns, where a disruption could be particularly deadly.
Cybersecurity experts like Corman believe that hackers from other nations like China have already quietly established cyber intrusions in countless local US utilities, water systems, and power grids, lying in wait to attack or act as leverage if a conflict arises.
Unfortunately, the Trump administration has hardly treated last week’s attacks as symptoms of a system in need of much broader strengthening, at least in its public statements. “I think Minnesota is behind it. You know who’s behind it? Minnesota,” the president baselessly claimed during a Cabinet meeting last Friday. “I think the governor is behind it. I don’t think there was an Iranian cyber attack.”
Advertisement
Gov. Tim Walz touring a water treatment plant in Minnesota.Alex Kormann/Star Tribune via Getty Images
Just a few months ago, he proposed $707 million in cuts to the US Cybersecurity and Infrastructure Security Agency (CISA), the agency responsible for protecting the nation’s infrastructure from cyberattacks. He did so, at least in part, out of anger over the agency’s role in confirming the validity of the 2020 election results. If Iran is, indeed, responsible, for the recent water system intrusions, all of this means that Trump has effectively made us more vulnerable to the consequences of a conflict he initiated.
At the end of the day,“nation-state hackers do not respect the jurisdictional lines separating federal, state, and local responsibility,” Jen Easterly, who led CISA under the Biden administration, wrote in the New York Times this week. “They search for the most vulnerable way to disrupt American life, and too often they find it in small communities that lack the resources to defend themselves.” Easterly’s role has remained vacant for the past 18 months.
Kurt Gaudette, a senior vice president at the cybersecurity firm Dragos, told me that water systems have got to get into the habit of monitoring their networks for suspicious activity. Most power utilities have begun doing so in recent years, with some bipartisan backing from Congress.
In some cases, however, the most cost-effective and safest way to avoid a repeat of last week’s mess might be to unplug the most vital controls — like the one that decides the chemical levels in a water treatment plant — from the web entirely.
Advertisement
As Corman puts it, “if you can’t protect it, disconnect it.”
Microsoft is eating humble pie over its unrealistic RAM recommendations
It has deleted articles that pushed 32GB as an ideal or ‘no-worries’ loadout
Apple is also feeling the heat in the RAM crisis, with rumors that it’s struggling to secure an alternative source of memory supply from China
There are some fresh twists with the RAM crisis hitting some big tech companies, as Microsoft has backtracked on its previous memory recommendations, and even Apple is apparently finding it difficult to cope with the scarcity of memory.
Let’s discuss Microsoft first, and as Windows Latest pointed out, the company has been busy backpedalling on previous memory recommendations now that the RAM crisis – which just keeps getting worse – has made those suggestions look foolish.
Microsoft previously had support documents in its Windows Learning Center which have now been removed, and Windows Latest highlights two of them. One was about optimizing your gaming PC, and it advised that “32GB is ideal for serious players who run the most demanding titles” (albeit the article also said 16GB was “plenty” for most games).
Latest Videos FromTechRadar
Advertisement
Another piece said that 32GB of RAM was the “no-worries zone”, and that article was also quietly deleted as there was some backlash against this, given that it was published when the price of system memory had become ridiculous. (And buying a 32GB kit was very much a worry for your wallet).
The links to those articles now redirect to the home page of the Learning Center, and Microsoft is evidently trying to forget about pushing 32GB of RAM as an ‘ideal’ or ‘worry-free’ target for memory on your PC.
More broadly, since Copilot+ PCs were launched and the AI features for these devices made them require 16GB, Microsoft has obviously been keen to have that as a baseline memory configuration. Except now, a change of stance is necessary, as with the RAM crisis reaching alarming new heights, Microsoft has been forced to enact huge price hikes with its Surface devices.
Advertisement
And of course, the latest twist with that Surface hardware is that Microsoft has brought back 8GB models with last year’s Surface Pro and Surface Laptop. Which makes it kind of difficult to push 16GB as a minimum, let alone make suggestions that 32GB is where it’s really at for properly smooth performance.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
The abandonment of these Learning Center articles is hardly surprising, then, and Microsoft is also addressing how speedily Windows 11 runs with 8GB of memory (not quickly enough currently). One of its promises with fixing the OS was better performance with a leaner RAM loadout, and Microsoft just made it clear that the company is now actively working to make Windows 11 run better with 8GB before the end of the year.
This has become a vital goal, really, when you consider that Apple has pulled off a commendable showing of performance with its MacBook Neo that packs 8GB of RAM. That was effectively a gauntlet thrown down for Microsoft – something of a declaration that macOS is coming to try to take Windows 11’s market share – and one that the Windows maker had to respond to (which became clear enough when Microsoft went on the attack against the Neo).
Advertisement
Apple turnover: China play rumored to end in a fumble
(Image credit: Future)
Speaking of Apple, Microsoft isn’t the only tech giant being buffeted by the rising costs caused by the RAM storm. While it has had a big success with the Neo, the challenge for Tim Cook‘s firm – soon to be John Ternus’s, of course – is to maintain that momentum, and by all accounts, that’s proving a tricky task.
The latest speculation, however, is that according to a report from Digital Daily (a Korean tech site, via Wccftech), Apple has floundered in negotiations with Chinese memory giant CXMT.
Apparently CXMT has strong enough domestic demand that it doesn’t have to offer more attractive pricing to Apple. Essentially, CXMT is holding the line and has “insisted on prices that were higher or similar to those offered by Samsung or SK Hynix” (bear in mind there may be nuances lost with the translation of the article).
You get the message, though: Apple is failing to obtain better deals on mobile DRAM, which includes LPDDR5X, for its iPhones (and that RAM is also used in its MacBooks, of course). And CXMT was supposed to be an escape route from the difficulties of getting enough RAM inventory from Samsung and SK Hynix (and also Micron, a key supplier for Apple), but it seems like a dead-end for now.
At least if this report is correct, but analyst Tim Culpan has also written a short post which backs up the notion that Apple is in trouble here. Culpan writes: “Apple and its suppliers are scrambling to get enough memory chips for its upcoming release of new iPhone models.”
Advertisement
‘Scrambling’ is a word that evokes quite a sense of panic, and indeed with the iPhone 18 models – and the foldable offering – not much more than a month away from launch now (in theory), I’d bet there are some heated words flying here and there. Culpan notes: “Assemblers are working with Apple to rush shipments of DRAM used in mobile devices.”
That report is specifically about smartphones, mind, but this same situation applies to mobile RAM that’s also used in MacBooks.
The overall theme is more RAM misery all round, which is hardly a surprise given all the negative news we’ve been hearing on the grapevine of late. GPU pricing has been the latest round of doom and gloom over the past week or two, and I don’t think the pessimistic news is going to stop flowing for the foreseeable.
It’s not bad news for everyone, though. A source in the semiconductor industry told Digital Daily that: “With the general-purpose DRAM floor remaining unbroken and Samsung and SK Hynix monopolizing the lead in high-value AI memory such as HBM4, the operating profit margins and global market control of the domestic semiconductor sector are expected to rise even more steeply in the second half of the year.”
Advertisement
So, it’s a familiar story: profits will be on the up and up for memory makers, while consumers will be suffering the pain of the hikes. Apple’s purported rush for RAM supplies as the clock runs down on the iPhone launch window is a particularly worrying sounding story, one that doesn’t bode well in terms of avoiding more Mac (and iPhone) price rises in the future. Neither can we rule out more Surface price rises, or other laptops for that matter.
You must be logged in to post a comment Login