Connect with us

Tech

Strong Password Policy and Password Manager Guide

Published

on

Create a strong password policy by prioritizing length and uniqueness, blocking compromised passwords, allowing password managers and autofill, removing arbitrary complexity and expiration rules, and requiring MFA for important accounts. Deploy the policy with a managed password vault, secure recovery procedures, and tests that confirm the written rules work in every covered system.

Quick Take

  • Require at least 15 characters when a password is the only authentication factor.
  • Allow passwords of at least 64 characters, including spaces.
  • Do not require arbitrary mixtures of uppercase letters, numbers, and symbols.
  • Replace scheduled password expiration with changes triggered by suspected compromise.
  • Reject commonly used, predictable, and previously compromised passwords.
  • Allow password managers, paste, and autofill on login forms.
  • Protect important accounts and cloud-synchronized vaults with MFA.
  • Test login, recovery, export, offboarding, and session-revocation controls.

These requirements follow current NIST authenticator guidance. They are a security baseline rather than proof that a particular policy satisfies every law, contract, or industry framework.

how-to-create-a-strong-password-po-policy-comparison-cards

Prerequisites and Ownership

Identify the accounts in scope

Inventory the systems that accept passwords before writing the rules. Include workforce accounts, customer accounts, administrator access, cloud services, remote-access tools, shared credentials, and legacy applications. Record which systems use single-factor authentication, MFA, or single sign-on.

Keep machine credentials in a separate category. API keys, database secrets, certificates, service-account tokens, and CI/CD credentials require secrets-management controls rather than an ordinary employee password vault. A dedicated article on business secrets management should cover those systems.

Assign responsibility

Name a policy owner, identity-platform administrator, security reviewer, help-desk recovery owner, and departmental access approver. A policy without named owners tends to fail at exceptions, recovery, and offboarding rather than during ordinary password creation.

Advertisement

Document technical constraints

Record each system’s minimum and maximum length, supported characters, MFA options, password-history rules, breached-password screening, paste and autofill behavior, recovery process, and session controls. Legacy systems that cannot meet the baseline should enter a documented exception process with compensating controls and a retirement or remediation date.

Step-by-Step: Create the Password Policy

  1. Define which accounts the policy covers

    State whether the policy applies to employees, contractors, administrators, customers, service providers, and shared accounts. Classify higher-risk accounts such as email, identity-provider, financial, cloud-administrator, source-code, and password-vault accounts.

    Where possible, replace shared accounts with individually attributable accounts. If sharing is unavoidable, use a managed vault that records access and lets administrators revoke membership.

    Expected result: Every covered account type has an owner, risk classification, authentication method, and exception status.

  2. Set length and input requirements

    Require at least 15 characters when a password is the only authentication factor. NIST permits passwords used only as part of an MFA process to be shorter, but they must contain at least 8 characters. Organizations may adopt a longer minimum when users can rely on a password generator.

    Permit passwords of at least 64 characters. Accept spaces and broad character sets, process the entire submitted password, and never silently truncate it. Systems that mishandle spaces or long generated values should be corrected or documented as exceptions.

    Advertisement

    Expected result: Users can create long passphrases or generated passwords without encountering unnecessary input restrictions.

  3. Remove mandatory composition rules

    Do not require every password to contain a prescribed mixture of uppercase letters, lowercase letters, numbers, and symbols. Current NIST rules prohibit these composition requirements because users commonly satisfy them with predictable patterns.

    Symbols remain acceptable when a generator selects them or a service requires them. The policy should not imply that a short password becomes safe simply because one letter was replaced with a familiar symbol. NIST’s public password creation guidance prioritizes length and recommends long passphrases when a password must be created manually.

    Expected result: Users can choose long, usable passwords without following predictable formatting recipes.

  4. Replace scheduled expiration with event-driven changes

    Do not force users to change passwords every 30, 60, or 90 days without evidence of risk. Require a change when a password is known or suspected to have been disclosed, appears in relevant breach data, was transmitted insecurely, or may remain known to someone whose access has ended.

    A password change must be accompanied by session revocation when an attacker could already be signed in. Changing the secret alone may not invalidate active browser sessions, application tokens, or remembered devices.

    Advertisement

    Expected result: Password changes respond to compromise and access changes rather than an arbitrary calendar.

  5. Block weak and compromised passwords

    Compare new and changed passwords against a blocklist containing commonly used, expected, and compromised values. Include context-specific choices such as the organization’s name, service name, username, and predictable derivatives.

    Explain why a proposed password was rejected and ask the user to choose a genuinely different value. Do not reveal whether another person uses that password. Avoid enormous blocklists that create excessive false rejections without meaningfully improving protection against rate-limited online guessing.

    Expected result: Users cannot enroll values that attackers are likely to guess early or already possess from breach collections.

  6. Add controls around the password

    Require MFA for email, identity-provider, financial, remote-access, cloud-administrator, source-code, and password-manager accounts. Prefer phishing-resistant methods such as passkeys or hardware-backed security keys where the service and user environment support them.

    Rate-limit or progressively delay failed attempts. Monitor suspicious logins, protect account recovery, avoid knowledge-based questions as a sole recovery method, and provide a way to revoke sessions after suspected compromise. The OWASP authentication guidance treats password controls, MFA, recovery, session handling, and login monitoring as connected parts of account security.

    Advertisement

    Expected result: A guessed or disclosed password is harder to convert into persistent account access.

  7. Require password-manager-compatible login forms

    Allow users to paste and autofill credentials. Use standard password fields and avoid scripts or form designs that block managers. NIST requires verifiers to allow password managers and autofill and recommends permitting paste when autofill interfaces are unavailable.

    Do not interpret clipboard blocking as a security control. It can push users toward shorter passwords they can type manually or toward storing credentials in insecure notes.

    Expected result: Users can generate, store, and enter unique credentials without weakening them for convenience.

how-to-create-a-strong-password-po-seven-policy-steps

How to Choose a Password Manager

Select a manager by deployment fit, recovery design, security controls, and usability rather than by the length of its feature list. The NCSC buyers guide emphasizes that an unusable manager will leave insecure workarounds in place.

Advertisement
Comparison of password-manager deployment models
Manager type Best fit Principal advantage Main limitation
Browser or platform manager People using one primary browser or device ecosystem Low setup friction and integrated autofill Potential platform lock-in and fewer team controls
Standalone cloud-sync manager Mixed-device users and small teams Cross-platform access and centralized synchronization Remote account and recovery paths require strong protection
On-device manager Narrow or offline use cases Reduced dependence on a cloud service Limited synchronization and more difficult recovery
Enterprise-managed vault Organizations requiring governance and offboarding Managed sharing, audit records, policy enforcement, and provisioning Greater administrative complexity and recurring cost

Evaluate the following capabilities before deployment:

  • Protection of credentials and metadata at rest.
  • Who controls or can recover the vault’s decryption key.
  • MFA, passkey, and approved-device support.
  • Recovery options and the people authorized to use them.
  • Secure sharing without revealing passwords in email or chat.
  • Role-based administration, audit records, and offboarding controls.
  • Restrictions or alerts for bulk export.
  • Supported browsers, operating systems, and mobile devices.
  • Update delivery and the provider’s vulnerability-disclosure process.
  • A practical method for leaving the service without permanent lock-in.

Browser and device managers can be appropriate when convenience and ecosystem integration matter most. A reputable standalone manager may fit mixed-device environments or teams requiring advanced sharing and administration. The NCSC’s updated password-manager guidance recommends evaluating reputation, device security, recovery, MFA, and platform needs instead of assuming one type fits everyone.

How to Deploy and Use the Password Manager

1. Protect the vault account

Create a long, unique primary passphrase that is never used elsewhere. Enable the strongest practical MFA and secure every registered device with updates, automatic locking, and a local PIN or biometric unlock.

Store recovery keys or emergency instructions separately from the vault. Avoid circular recovery in which the only way to access the email account is through the vault while the only way to recover the vault is through that email account.

2. Import credentials carefully

Some managers migrate credentials through a CSV file. That export may contain readable usernames and passwords. Create it only on a trusted device, import it immediately, verify that the records arrived, and delete the exported file from the original folder, recycle bin, cloud synchronization, and temporary storage.

Advertisement

Do not perform a vault migration over an unfamiliar hotspot. Review the precautions in this public Wi-Fi security guide before accessing sensitive accounts away from a trusted connection.

3. Replace reused passwords in risk order

  1. Secure the password-manager account and its recovery channels.
  2. Change email and identity-provider credentials.
  3. Change banking, payment, payroll, and financial credentials.
  4. Change administrator, cloud, source-code, and remote-access credentials.
  5. Change shopping, social-media, subscription, and lower-impact accounts.

Do not change dozens of accounts without confirming that each new password was saved. Keep the old session open until the new credential has been tested in a separate private window or another approved device.

4. Configure generation and autofill

Generate a different random password for every compatible service. Match the site’s supported length and character rules while avoiding needless manual edits. If autofill does not appear, check the exact domain before searching the vault and copying the password.

Autofill may help resist phishing because a manager should associate credentials with the legitimate domain. It is not infallible. Users must still inspect unusual addresses, subdomains, redirects, and browser warnings.

5. Configure team sharing and offboarding

Store business credentials in organization-controlled collections rather than personal vaults. Grant access by role, assign an accountable owner, review membership, and remove access promptly when someone changes roles or leaves.

Advertisement

Revoking vault access prevents future retrieval, but it cannot make a password unknown to someone who already viewed or copied it. Rotate credentials when a departing user could retain them. Teams protecting software repositories should connect this process to the controls in the guide to preventing source-code theft.

Password Vault laptop connects to Primary Passphrase, MFA Key, Secure Import, Shared Vault, and Recovery Kit.

Verify That the Policy Works

Test the deployed controls instead of assuming a written setting was applied consistently.

Checklist

  • Confirm that a 15-character single-factor password is accepted.
  • Confirm that long passphrases, spaces, paste, and autofill work.
  • Confirm that the application processes the full password without truncation.
  • Attempt to enroll a known common password and verify that it is rejected with useful guidance.
  • Confirm that uppercase, number, and symbol mixtures are not mandatory.
  • Verify that routine expiration is disabled and compromise-driven resets work.
  • Trigger repeated failed attempts in an approved test account and verify rate limiting or progressive delay.
  • Test MFA, recovery, session revocation, emergency access, and lost-device procedures.
  • Remove a test user from a shared collection and verify that access ends.
  • Verify that export actions are restricted, logged, or both.

Record exceptions and failed tests with an owner and target correction date. Repeat the checks after identity-platform changes, password-manager migrations, or major policy revisions.

Failure Modes and Troubleshooting

Common password policy and manager deployment failures
Failure Likely cause Security consequence Corrective action
Long generated password is rejected Legacy length or character restriction User shortens or reuses a password Correct the restriction or document a temporary exception
Autofill does not appear Unsupported form, disabled extension, or domain mismatch User may copy into the wrong page Verify the domain and manager permissions before manual entry
Credentials fill on an unexpected subdomain Overly broad saved-domain matching Password may reach an unintended service Narrow the saved address and report unsafe matching
Primary passphrase is lost Recovery was not configured or documented Vault data may become inaccessible Use the approved recovery process and reset affected accounts if recovery fails
MFA device is lost No backup factor or recovery key exists User is locked out or bypasses policy Use pre-established recovery and revoke the lost device
Exported CSV remains on disk Migration cleanup was missed Passwords remain exposed in plaintext Delete all copies and rotate credentials if exposure is possible
Former worker retains a shared password Vault removal occurred without credential rotation Continued unauthorized access remains possible Rotate the credential and review account activity
Legacy system requires frequent changes Obsolete platform rule Users may create predictable variations Apply compensating controls and schedule remediation
Vault and email recovery depend on each other Circular recovery design One lost factor can lock out both services Create an independent recovery route and protect it offline

Operational Limits and Edge Cases

  • Concentrated value: A vault makes unique passwords practical, but a successful vault compromise can expose many accounts. Protect the primary account and registered devices accordingly.
  • Compromised endpoints: Malware or someone using an unlocked computer may capture credentials after the vault decrypts them. A password manager does not replace device protection. Organizations can evaluate those controls separately in this endpoint protection guide.
  • Recovery trade-off: Recovery improves availability but creates another path that an attacker may target. Document who can recover a vault and what evidence is required.
  • Shared accounts: A vault improves sharing, but individual accounts remain preferable because they provide attribution and cleaner revocation.
  • Offline access: Emergency recovery material needs physical protection, named custodians, and periodic verification.
  • Phishing: Passwords themselves are not phishing-resistant. Adopt passkeys where appropriate and evaluate the differences in a future passkeys versus passwords guide.

Key Takeaways

  • Use length, uniqueness, blocklists, and login protections instead of frustrating composition rules.
  • Require at least 15 characters when a password is the only authentication factor.
  • Do not force periodic changes without evidence of compromise.
  • Allow password managers, paste, autofill, and long values.
  • Protect the password vault, email, identity provider, and administrator accounts with MFA.
  • Select a manager based on security, recovery, usability, platform support, export, and governance.
  • Replace reused passwords in risk order and verify each change.
  • Test recovery, offboarding, exports, and session revocation before an incident.

Frequently Asked Questions

Should contractors use the company password manager?

Contractors should use an organization-controlled vault when they need access to company credentials. Place them in restricted groups, set an access end date where supported, and avoid mixing business credentials with their personal vaults. At contract completion, revoke access and rotate any credential they could have copied.

Should a password manager store the code for its own MFA?

Storing a service’s password and MFA code in one vault is convenient, but storing the vault’s own second factor inside that same locked vault creates a circular dependency. Protect the manager itself with a separate authenticator, passkey, hardware key, or securely stored recovery code.

What happens if the password manager company shuts down?

A usable exit plan should let authorized users export or transfer credentials to another manager. Confirm the export format before deployment and document how migration would work. Because exports may be plaintext, continuity planning should not involve leaving permanent backup exports on ordinary drives.

Advertisement
Can administrators see employees’ passwords in a business vault?

That depends on the manager’s encryption, sharing, recovery, and administrative design. Some administrators can recover accounts or manage shared collections without seeing every private credential. Others may have broader recovery powers. Review the product’s key-ownership and recovery documentation before adoption.

Should personal and work passwords be kept in the same vault?

Separate vaults or clearly separated organization-controlled and personal spaces are preferable. The company must be able to manage, audit, and revoke business access without gaining control over personal credentials. Employees should also retain their personal passwords after leaving without exporting company secrets.

What should happen when a password appears in a data breach?

Change the affected password, revoke active sessions, review account recovery methods, inspect recent activity, and replace the same password anywhere it was reused. Follow a documented data breach response checklist so the reset does not overlook tokens, forwarding rules, or connected applications.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Apple TV may be planning a ‘Silo’ spinoff

Published

on

A rumored “Silo” spinoff could keep Apple TV’s dystopian franchise alive beyond its planned finale, but the books’ author is pushing back on the claim.

“Silo” is a dystopian science-fiction drama about a society living underground after humanity has been driven from the surface. The Apple TV series is based on the bestselling “Silo” trilogy, “Wool,” “Shift,” and “Dust,” by Hugh Howey.

While it was well liked, Apple TV had told the creators that the series would end after the fourth season. The third season just returned to the small screen in July, with the fourth season anticipated to release in Summer 2027.

Even though the series is facing down its inevitable end, it may not be time to say goodbye just yet.

Advertisement

Allegedly, there’s a chance “Silo” may be getting its own spinoff, set to begin pre-production in late 2026. It is expected to tie into Hugh Howey’s upcoming “Silo 40” trilogy, which is set to release in 2027.

This tantalizing tidbit was shared by Apple TV enthusiast Sigmund Judge on Threads.

One minute later, however, a very significant figure refuted the claim. Speaking up was the “Silo” author, Hugh Howey.

“Yo, this is news to me,” Howey says in the replies. “So probably not true.”

Advertisement

“I appreciate you wanting to keep a surprise,” Judge says in response. “Love everything you do.”

Judge says that he’s got some further evidence in response to “a denial,” presumably Howey’s. Judge says that hires for the upcoming project have begun, and that the main sets used for “Silo” have remained, even after production on the fourth season wrapped in March.

Source link

Advertisement
Continue Reading

Tech

How Bats Prevent Doppler Acoustic Interference

Published

on

https://commons.wikimedia.org/wiki/File:Bat(20070605).jpg
Lesser horseshoe bat. (Credit: Lylambda, Wikimedia)

As great as echolocation is, things can get rather messy once it’s not just you chirping away, but also hundreds of your buddies in roughly the same area. This is the scenario that the typical colonies of bats have to deal with. In a recent study by [Haruhito Matsumoto] et al. in Journal of Comparative Physiology they investigated how colonies of greater Japanese horseshoe bats deal with this issue.

Echolocation in animals can use a variety of methods, including frequency modulation (FM, varying the pitch) or constant frequency (CF), with both having their uses during hunting as well as obstacle avoidance. One big advantage of CF is that it can be used for Doppler shift, giving very precise information about location and velocity of objects in the environment, but if used in a busy colony the acoustic interference would effectively render them blind.

What researchers have found is that the CF component frequencies differ per bat colonies, with the mixing of wild-caught and resident horseshoe bats in this experiment showing them adjusting the dominant second harmonic (CF2) to match, with bats using a lower frequency CF2 adjusting it upwards. In this way frequency convergence is used as a strategy to avoid acoustic interference using a so-called ‘silent spectral window’.

As this spectral window for effective Doppler tracking is found above the CF2 frequency, it therefore makes sense that the bats at a lower CF2 harmonic would adjust their CF upwards to match that of their neighbors. Although more research is required to fully confirm these findings, it sheds some more light on the use of echolocation by these amazing flying mammals.

Advertisement

Source link

Advertisement
Continue Reading

Tech

HoverAir Aqua review: I spent two weeks trying to drown this drone

Published

on

HoverAir Aqua

MSRP $1,299.00

Advertisement

“A brilliant specialist with a short attention span.”

Pros

  • Rights itself and launches from open water every single time
  • Tracking at 15 mph is steady enough to pass for a chase boat
  • The Lighthouse wearable handles launch, landing, and following
  • Onboard screen lets you replay clips on the water with no phone
  • Dead battery? It lands softly on the surface and floats

Cons

  • I measured 10 and 13 minutes of flight against an advertised 23
  • The Lighthouse shows no battery level at all
  • No obstacle avoidance
  • The battery is only fully waterproof while it sits in the drone

Quick Take

I spent two weeks on an Oregon river trying to break this thing — off an eFoil, out of a kayak, and by throwing it into the water on purpose. The HoverAir Aqua is the first consumer drone actually built to live on open water, and after two weeks I still stop what I’m doing to watch it launch. Throw it in the river upside down, and it flips upright, shakes the water off its props, pops into a low hover, and waits for you. Strap the Lighthouse beacon to your forearm, and it will follow you across the river at eFoil speed with your hands never touching a controller.

Let me be blunt, because this is the most important thing to know before you buy: there are two battery problems. HoverAir prints 23 minutes on the box. I measured 10 minutes and 13 minutes with the drone actively tracking me. And the wearable never tells you how much charge is left. So this is a drone I love, packed in a dry bag next to a fistful of spare batteries I resent having to carry.

HoverAir Aqua specs: A quick peek at the innards

Weight Under 249 g, light enough to skip FAA registration for recreational U.S. flight
Waterproofing IP67; floats and rights itself; battery fully waterproof only while installed
Camera 4K at up to 100 fps through a heated lens that sheds fog and spray
Altitude sensing Millimeter wave radar that reads wave height for low passes over water
Display and storage 1.6-inch onboard AMOLED; 128GB internal storage, no SD card
Battery 2,013 mAh smart battery; rated 23 min; I measured 10 and 13 min while actively tracking
Charging About 55 minutes with the battery inside the drone
Controller Lighthouse waterproof wearable (launch, land, track, auto recall) with no battery readout
Obstacle avoidance None
Recognition CES 2026 Innovation Awards honoree; Red Dot Award
Test conditions Two weeks on an Oregon river; eFoil at about 15 mph plus kayak sessions

HoverAir Aqua design & build: A pool toy with flagship chops

The first thing I noticed pulling the Aqua out of the box is the fat ring of safety-orange foam around its body, the same shade as a life vest. It looks like a pool toy. That’s deliberate. The foam keeps the drone buoyant, cushions the props, and makes the aircraft easy to spot from fifty yards out when it sets down on dark green water. The whole package carries an IP67 rating and weighs under 249 g, which keeps recreational pilots in the U.S. under the FAA registration threshold.

My favorite piece of hardware here is also the smallest. A 1.6-inch AMOLED screen sits on the drone’s spine, and it stays readable even with glare coming off the water. It’s there to pick flight modes, but I mostly used it to review what I’d just shot — sitting on the board, dripping, thumbing back through a run while the river went past. Two weeks in, I was still reaching for it instead of my phone. Storage is 128GB and internal, so there’s no SD card to lose, forget, or flood.

The camera records 4K at up to 100 fps for slow motion through a heated lens, which keeps fog from forming and makes water bead off instead of smearing across the glass. Underneath the airframe is the strangest line I have ever typed about a consumer drone: millimeter wave radar that reads the height of the waves rolling beneath it, so the Aqua can skim low over moving water without clipping a crest.

For those of you unfamiliar with the term, and since the spec sheets never bother explaining it, millimeter wave radar bounces very short-wavelength radio off a surface to measure distance to it — here, a surface that will not hold still. The industry noticed. The Aqua premiered at CES 2026 as an Innovation Awards honoree and collected a Red Dot Award along the way.

HoverAir Aqua water launch: Throw it in, it flies out

The water launch is the feature every bystander will ask you to do twice, and I tested it from the kayak with my kids leaning over the side to watch. You toss the drone into the river upside down, carelessly. However, it happens to leave your hand. It bobs for a beat. Then the props bite, it rolls upright, and it climbs into a hover a few feet off the surface to wait for you to start moving. It did that every single time I asked, and I asked a lot. Not once did I have to paddle over and fish it out or reset anything. In a category where water has always meant total loss, that is a bigger deal than a party trick sounds.

HoverAir Aqua subject tracking: A chase boat on your forearm

Most of my testing happened on my eFoil at around 15 miles per hour, with the waterproof Lighthouse strapped to my forearm like a chunky watch. One button sends the drone up. One button brings it home. Everything between those two presses is automatic.

Advertisement

The footage surprised me. My wake unspooling behind the board in a long white seam, the tree line sliding by, and me held in the center of the frame for the entire run. The best material came when the drone swung out ahead of the board and shot back at me, spray kicking off the foil, the whole river opening up behind.

It never fell behind, and it never wandered. When I drifted too far, it closed the gap on its own. When I slipped off the board and sat chest-deep in the water beside it, it stayed locked on and waited. The kayak sessions at lazier speeds went the same way: steady framing, no fuss, the family paddling along with a small orange aircraft holding formation off the bow. This is the closest thing to a camera operator you can wear on your wrist.

HoverAir Aqua Battery Life: High on the box, dips in the water

Now, the part the box will not tell you. HoverAir advertises 23 minutes of flight from the 2,013mAh smart battery. My first battery, actively tracking me on the foil, gave me 10 minutes before the drone called it quits. I rode back to shore, clicked in a fresh one, and went back out. Thirteen minutes. Doing the exact job you bought it for, you get about half the number on the sticker.

It’s worth noting that drone makers rate flight time in windless conditions with no tracking load, and you should not expect that figure in the real world. Even allowing for that, half is a wide gap. At least the ending is graceful.

When the charge runs out, you get a warning that the drone will land in 15 seconds, and then it sets down on the surface, orange side up, rocking on the chop until you come get it. Nothing dramatic happened in two weeks of testing. Recharging takes about 55 minutes with the battery inside the drone, and because a battery is only fully waterproof while it’s installed, HoverAir includes a dedicated waterproof pouch for hauling spares out on the water. Read that accessory list again. The company is telling you, in its own way, that you will be swapping batteries mid-session.

HoverAir Aqua Lighthouse Wearable: Great controller, no fuel gauge

The second problem makes the first one worse. The Lighthouse is otherwise the best thing about this product, and it tells you nothing about the battery. No percentage. No halfway warning. No blinking light as the level sinks. Mid-run, I had no idea whether the drone above me had eight minutes left or thirty seconds.

When the entire budget is 10 to 13 minutes, that silence turns every session into a guessing game. Both times a battery died on me, my only notice was the 15-second landing warning, right when I felt like I was getting going.

Should you buy

The good here is genuinely good. The footage is beautiful, the Aqua keeps pace with a foil at speed, it launches itself out of open water, and it runs hands-off enough that you forget it exists until you sit down to replay the clips. As a piece of engineering built for a hostile environment, it is the real deal.

The battery is what makes me hesitate, and I am not going to soften that. Plan a full session around this drone, and you are packing a pocketful of spares and guessing when to burn them.

Advertisement

So here is the fork. If what you want is a quick promo shot or a fast social clip off the water, this is the drone doing that job, and I don’t know of another one built to take the punishment. If you want to shoot an entire session, wait and watch for a firmware update that pushes battery data to the Lighthouse.

That one change would make this an easy recommendation for anyone who makes content on the water. As it stands, the Aqua is a brilliant specialist with a 10-minute attention span, and I keep taking it out anyway.

Why not try?

HOVERAir X1 PROMAX — Priced significantly lower at $700, this one offers hands-free auto-follow tracking and Lighthouse wearable perks, can shoot up to 4K 120fps footage, and stands out with a foldable design. It’s slightly slower and doesn’t offer a waterproof build, but makes up for it with collision-sensing tech.

DJI Mini 4 Pro — Another option that is more affordable as well, DJI’s drone offers impressive aerial capture capabilities with omnidirectional obstacle sensing and a reliable 4K camera that can capture high dynamic range videos. Plus, the battery packs can extend the flight time by up to 45 minutes, while the transmission performance is also fantastic. But an impending ban casts a shadow of skepticism over long-term support and after-sales experience.

Advertisement

FAQs (Frequently Asked Questions)

Who needs the HoverAir Aqua?

It’s a waterproof, self-flying 4K camera drone. If you’re into activities such as kayaking and wakeboarding, it’s an appropriate choice.

Is it capable of taking off and landing directly on water?

Yes, the positive buoyancy engineering allows it to float on water. And yes, it can take off and land from the surface of water. Moreover, it also comes with a Turtle Flip feature that lets it correct its position instantly, even if it’s flipped upside.

Is the build really waterproof?

The HoverAir Aqua has an IP67-certified build, featuring corrosion-resistant components, while the camera sensor is protected by a hydrophobic, anti-fog lens.

Do you need a license to fly it?

It falls under the prescribed FAA weight limit, so you don’t need a license to fly it.

Advertisement

Can it fly and capture without a phone?

Yes, the wearable Lighthouse controller relies on Real-Time Kinematics (RTK) positioning to let the drone track you and capture videos without requiring a cellular link or base stations.

What is the top speed and battery life?

The HoverAir Aqua can fly at a speed of up to 34 miles per hour, and it is claimed to last over 20 minutes on a single charge.

Can you fly it manually?

Yes, using the Beacon & JoySticks accessory.

Advertisement

Source link

Continue Reading

Tech

AMD GPUs are climbing the sales charts as Radeon beats Nvidia on Amazon and in Germany

Published

on

In a nutshell: Despite Nvidia losing fans over the last few years as its focus on gamers diminishes (or disappears), the company’s GPUs have dominated the sales charts. But that status quo is starting to change: Amazon’s top 10 best-selling GPU list is an even split between Team Red and Team Green, with the highest position held by a Radeon 9000-series card. Meanwhile, in Germany, AMD is the one that’s dominating sales – at least at one retailer.

The rise of RDNA 4 was highlighted by TechEpiphany on X.

The Amazon best-selling list has changed slightly since the post, but the Radeon RX 9070 XT is still the top GPU. This Gigabyte version is priced at $749, which, of course, is considerably higher than the GPU’s $599 launch MSRP.

The other AMD cards in the chart are an Asus model of the 9070 XT, an Asrock 9070, and an Asus 9060 XT. Nvidia also holds four positions with its RTX 5070, RTX 5060 Ti, and two RTX 5080 models.

Advertisement

Things appear even more favorable for Lisa Su’s firm in Germany. The figures, which come from Mindfactory, show AMD accounting for almost 56% of all GPUs sold over the last week, while Nvidia holds a 40% share. Again, the RX 9070 XT is the most popular card by far, followed by the RX 9060.

It’s worth remembering that Mindfactory has a reputation for favoring AMD, offering promotions, discounts, and bundles featuring its products, which help push up sales figures. The store’s AMD cards have outsold Nvidia’s in the past.

However, these charts do illustrate the impact of the memory crisis on the graphics card market. All GPUs are more expensive, but AMD’s are often cheaper than equivalent Nvidia cards.

The other reason is likely simple availability. The Amazon chart shows three AMD cards in stock, while Nvidia only has one – a Gigabyte RTX 5080 for a colossal $1,599, and that’s with a 6% discount.

Advertisement

Only one company dominates the Steam survey GPU chart

TechEpiphany’s claim of AMD “dominating everywhere” might be a bit of an exaggeration, but there are signs of consumers opting for its cards because of the cheaper prices – or just buying them because there are no Nvidia alternatives. The most valuable company in the world still has GPUs in almost 73% of Steam survey participants’ machines, compared to AMD’s 18.6%, so we’re not seeing a red revolution just yet.

Source link

Advertisement
Continue Reading

Tech

Ted Lasso season 4 is coming soon with these two major changes

Published

on

After a three-year wait, Ted Lasso is finally returning to Apple TV+, but season four isn’t simply picking up where the last season ended. Instead, Apple is relaunching one of its biggest original series with a fresh premise, a revamped cast, and notable behind-the-scenes changes that could determine whether the Emmy-winning comedy can rediscover the charm that made it a global phenomenon.

The new season premieres on August 4, with Jason Sudeikis returning as Ted Lasso. However, this time he won’t be leading AFC Richmond’s men’s team. Instead, Ted takes charge of the Lady Greyhounds, shifting the show’s focus to women’s football while introducing several new faces to the franchise. It’s easily the biggest narrative shake-up since the series debuted in 2020.

For Apple, the stakes are higher than they appear. Ted Lasso remains one of Apple TV+’s defining originals, and a successful fourth season would reinforce the company’s ability to extend its flagship franchises without losing what made them successful in the first place.

The Lady Greyhounds become the story

Season four retains familiar characters including Ted, Rebecca, Keeley, Roy Kent and Coach Beard, but several regulars from AFC Richmond’s men’s squad are no longer part of the main cast. According to 9to5Mac, Jamie Tartt, Dani Rojas, Sam Obisanya, Isaac McAdoo and Colin Hughes will not return as series regulars, although some may make cameo appearances. The future of Nick Mohammed’s Nate Shelley also remains uncertain, with reports suggesting he could appear in some capacity.

Advertisement

The new women’s team brings a fresh lineup of characters, including Tanya Reynolds as assistant coach Alice Chilton, alongside players Gemma, Boots, Lizzie, Niamh and Siobhan. Rather than simply continuing AFC Richmond’s story, Apple appears to be using the new team to reset the series while keeping its familiar emotional core intact.

It’s a sensible move. Extending a beloved series without changing anything often leads to diminishing returns, particularly after a divisive third season. By introducing a new squad instead of recycling old storylines, Ted Lasso has a chance to evolve while remaining recognizably itself.

Apple has also changed what happens behind the camera

The creative overhaul extends beyond the cast. During the first two seasons, Bill Lawrence played a central role in shaping Ted Lasso alongside Jason Sudeikis. His involvement was significantly reduced during season three, a change many critics and fans linked to the show’s uneven storytelling.

For season four, Apple has brought in veteran television producer Jack Burditt, whose credits include 30 Rock and Modern Family, to work alongside Sudeikis. According to The Hollywood Reporter, Burditt helped oversee production and the writers’ room while Sudeikis continued leading the show’s creative vision. Early reactions suggest the partnership may have restored some of the focus that viewers felt was missing in the previous season.

Ultimately, Ted Lasso doesn’t need to reinvent television. It simply needs to remind audiences why they fell in love with its optimism, humor, and emotional storytelling in the first place. Apple has changed both the players on the pitch and some of the people calling the shots behind the scenes. Whether those changes deliver another championship-worthy season will become clear when the series returns next week.

Advertisement

Source link

Continue Reading

Tech

How iTools became iCloud

Published

on

Before iCloud became the backbone of the Apple ecosystem, it spent more than a decade evolving through three distinct services: iTools, .Mac, and MobileMe.

If you’ve got an iPhone, you’ve got an iCloud account. Sure, you might only have the base account, but you’re still signed up for it.

And for most of us, we probably actively engage with iCloud to some degree. After all, iCloud is what Apple uses to store your Messages, Photos, Notes, Contacts, and software backups, and it powers Find My.

But how did Apple get here? While iCloud launched in late 2011, Apple actually began taking its first big steps into subscriptions as a service, or SaaS, eleven years prior.

Advertisement

So here’s the story of how iCloud became iCloud, and the shoulders of the three prior giants it stood upon.

The year was 2000, and Apple was looking for ways to convert Windows users to loyal Mac fanatics. And what is one of the best ways to lure people in?

That’s right: free stuff.

On January 5, Apple launched iTools. It was a collection of services available to those who were using Mac OS 9.

Advertisement

The first was iCards, which was electronic greeting card software. It lets you create greeting cards that you could send via email to friends and family.

It may not sound like it, but this was pretty big. In the early 2000s, sending greeting cards via email was a huge deal.

A collection of tools found within iTools

Image credit: BasicAppleGuy on Threads

It also included iReview, which gave dedicated reviews of internet content. Unfortunately for iReview, it would be the first of the iTools products to go under; it was cancelled in 2001 after failing to attract traffic.

Advertisement

KidSafe was essentially Apple’s take on Bess or Net Nanny, services that would only allow children to visit pre-approved “safe” websites. KidSafe was discontinued in mid-2001, one month after iReview was killed off.

HomePage was another offering, and allowed users to create a personal website without any sort of backend coding. Even more interesting, as Phil Schiller pointed out in 2000, it was available for free.

HomePage gave users templates, free images, and allowed for drag-and-drop customization. It also featured integration with Apple’s iDisk.

And if you’re curious about iDisk, it was yet another iTool. Effectively, iDisk walked so iCloud could run.

Advertisement

Users were granted 20MB of free personal internet storage, but they were able to purchase up to 400MB as part of an annual subscription. If you wanted that whole 400MB of storage, you’d need to fork over $400.

Those with a HomePage could use a file sharing template to publish the contents of an iDisk folder to the web, enabling sharing with anyone who came across your HomePage.

And last but not least, we had mac.com. While it certainly sounds like it was a place to buy a Macintosh computer, it actually was an email hosting account.

Users who utilized mac.com addresses got an @mac.com email address. Not only was it a great way to show your allegiance in the PC-Mac battle, but it worked as free advertising for Apple, too.

Advertisement

And then there was .Mac

iTools existed, more or less, in its initial state, for a little over two years. However, when July 2002 rolled around, Apple rebranded it to .Mac.

This brought a lot of changes, but perhaps the most significant was that it was no longer free. As you could imagine, that didn’t go over particularly well.

The service offered a few new features to make up for its sudden price tag. Notably, Backup launched with the service, allowing users to archive their data to iDisk, CD, or DVD.

Users also got McAfee Vriex, an antivirus program, for free. Well, it was free until 2005, at least.

Advertisement

In 2007, .Mac got a few notable upgrades.

The first was that anyone who had a .Mac account got 10GB of “free” storage that could be split between their email account and iDisk. Users had the option to purchase additional storage up to 30GB.

Finally, and fatally, MobileMe

MobileMe wouldn’t launch until 2008, when Apple acquired me.com. MobileMe would lay the groundwork for the deep ecosystem integration that we know and love about Apple products today.

“Think of MobileMe as ‘Exchange for the rest of us,’” then-CEO Steve Jobs said.

Advertisement

“Now users who are not part of an enterprise that runs Exchange can get the same push email, push calendars and push contacts that the big guys get.”

Logo with the word mobileme in lowercase, mobile in dark gray sans serif and me in light blue script on a plain white background

And then there was MobileMe

At launch, MobileMe allowed users to sync emails, folders, and messages across platforms, the way that iCloud does now. And, it even allowed you to check many of these apps from the web.

Users could still choose to create a @mac.com email address, or if they wanted, one emblazoned with @me.com.

Advertisement

At this point, Apple was still charging for the service. The base MobileMe platform cost $99 per year and came with 20GB of storage. Users could also upgrade to a “Family Pack” for $149 per year, which included one master account with 20GB of storage and four Family Member accounts with 5GB of storage each.

MobileMe also saw the launch of Find My iPhone in 2009. This precursor to Find My allowed users to use the web to locate a missing iPhone on a map, play a sound, change the password, or remotely erase content.

MobileMe survived for four years after launch, eventually being discontinued on June 30, 2012. Apple had announced iCloud in 2011, so it didn’t exactly come as a surprise, but many users were sad to see it go.

iCloud

As stated above, iCloud was announced in October 2011. Jobs made the announcement at WWDC 11, saying that it would replace MobileMe, which had been considered a failure.

Advertisement

Unlike MobileMe, iCloud would launch as a free service as part of iOS 5 and OS X Lion. No longer would users be expected to fork over at least $100 a year.

“iCloud is the easiest way to manage your content, because iCloud does it all for you and goes far beyond anything available today,” said Eddy Cue, Apple’s senior vice president of Internet Software and Services.

Middleaged man in a bright blue shirt speaking on stage, holding a small device, with a microphone clipped to his collar against a dark background.

Apple’s Eddy Cue was instrumental in helping to launch iCloud

“You don’t have to think about syncing your devices, because it happens automatically, and it is free.”

Advertisement

This alone ensured that people would use the service. But it also refined features that its predecessors never seemed to get right.

Photo Stream, which would eventually get rolled into Photos, allowed users to take a picture on iPhone and see it on other devices, including Apple TV. Documents in the Cloud gave users an easy way to manage, edit, and save iWork documents across all devices.

iTunes in the Cloud allowed users to download new music purchases to all devices, meaning users could purchase music on their Mac and find it on their iPhone later.

Other features introduced included Find my Friends and improved cross-device management of Contacts, calendar, and Mail.

Advertisement

It may have taken eleven years to get to iCloud, but it’s interesting to see how Apple got there in the end. And, it’s just as impressive that Apple’s managed to expand upon iCloud in the nearly 15 years after its launch.

Source link

Advertisement
Continue Reading

Tech

Hosepipe ban in your area? Don’t worry, tech can keep your garden looking fresh, legally

Published

on

When they’re not discharging sewage into rivers and the sea, or failing to fix leaks, the water companies seem poised to launch a hosepipe ban. To be fair, it’s been an extremely hot and dry summer for most of the country.

If you’re one of the millions of affected households, then you don’t have to sit back and watch your garden die, as there are some legal ways to keep your plants fresh and watered.

For this article, I’m focusing on established gardens; most water companies allow hosepipe watering of food crops and new plants and lawns under certain conditions. For example, Thames Water has this rule for new lawns and plants: “You can only use a hose or sprinkler if the laying, sowing or planting was completed by a business as a service. In this case, hose use is allowed for the first 28 days from the day of planting, sowing or turf laying. The hosepipe must only be used on the new planting, and not elsewhere.”

Of course, before you do anything, it’s worth checking with your specific water company if an activity is allowed or not.

Advertisement

Drip watering system

You can’t spray wildly, but drip irrigation systems, such as those sold by Hozelock, are typically allowed during most hosepipe bans. Rather than spraying water, these systems drip water exactly where it’s needed. Even outside of a hosepipe ban, these systems are more efficient and will save you money.

Hozelock Cloud Controller Kit watering kit onHozelock Cloud Controller Kit watering kit on

Advertisement

You’ll need to check compatibility with your water company, but to stay compliant with a hosepipe ban, most systems need to have a pressure-reducing valve and a timer. Be careful of the adaptors that you use: you can’t use ones that use a jet or mist, and the system must drip water directly onto or beneath the surface.

You’ll also need a timer, which can be a smart one, such as the Eve Aqua.

Use a cordless pressure washer with a water butt

In most hosepipe ban areas, you can still use buckets and watering cans for the garden, but this can be a faff. However, if you have a water butt, then a cordless pressure washer could help make the job easier.

Advertisement

Provided your cordless pressure washer, such as the Stihl RCA 20, can work with alternative water sources, such as water butts, you can use this to draw the water directly out, and spray it where you want.

With the RCA 20, the end of the hose can be dropped into a water butt, with a filter used to prevent any bits of debris being sucked up.

Advertisement

Stihl RCA 20 Cordless Pressure Washer with wandStihl RCA 20 Cordless Pressure Washer with wand
Image Credit (Trusted Reviews)

As you haven’t connected the pressure washer to the mains water, you’re not breaking any rules. Just remember, you can’t use mains water to top up your water source, and have to rely on either rain water or grey water harvesting.

Turn down the pressure, so that you’re lightly sprinkling water, rather than jetting it out, and target the roots of your plants to make the most of this method.

Advertisement

Source link

Continue Reading

Tech

Securities firm Rosenblatt raises its AAPL price target following earnings call

Published

on

Securities firm Rosenblatt is still bearish on Apple’s future, seeing short term supply problems as well as difficulties matching the iPhone 17 range’s success. Just the same, it has raised its price target to a still-underwater $300.

Following Apple’s latest earnings call, the company’s shares took their usual inexplicable dip, but investment and securities firms are looking further ahead. Rosenblatt, which remains amongst the most bearish on Apple, has told investors that it is raising its price target by $24 to $300.

In an note to investors seen by AppleInsider, the company says that it has decided to do this by focusing on how it believes Apple will be faring in a year’s time. Even then, it says the reason for only raising the target by what it calls a modest amount, is down to the volatile financial environment.

That includes economic factors that affect all firms, such as tariffs and inflation. But with Apple, it notes what Tim Cook has said about supply constraints across the company’s product ranges.

Advertisement

Beyond that, Rosenblatt also believes that Apple is going to have difficulty with the iPhone 18 range simply because the iPhone 17 range was such a huge success. Calling it a big test, the company speculates that Apple will have a tough comparison as it tries to continue growing.

As a result of that, the securities firm thinks that iPhone sales will slow substantially. It also says that European Union-drive legislation and regulation could decrease Apple’s value.

All of this means that Rosenblatt has raised its target price but kept a neutral rating for the company. Even as it does so, though, it notes that there is a possibility that the new Apple Intelligence will drive more sales than it expects.

JP Morgan, has been bullish overall, and has the same short term questions. But that investment firm trimmed its Apple price target to $340 after earnings.

Advertisement

They’re above water, at least. Apple stock got hammered after earnings, falling to $307.80 on Thursday, despite record-breaking results again.

AAPL has been on a tear as of late. It’s been above $300 since July 2. It touched the $5 trillion valuation mark on on July 28.

Separately, in April 2026, Rosenblatt was one of the analyst firms praising the appointment of John Ternus as the new Apple CEO. It described that as Apple continuing what already works, but also “leaning into its hardware successes.”

Advertisement

Source link

Continue Reading

Tech

$300 iPhone 18 Pro price hike rumored as chip shortage bites

Published

on

Following price hikes across the rest of Apple’s product lineup, one analyst believes that the upcoming iPhone 18 Pro could be hit with a massive $300 increase, a bump that might not be out of the question considering other recent price changes.

Apple increased the price of its Macs, iPads, and other products in June 2025 as a result of increasing RAM and storage costs. Some Mac models saw four-digit price hikes, although the iPhone lineup was left unscathed.

That has long been rumored to change when the iPhone 18 Pro and iPhone 18 Pro models launch this fall. A report from July 2026 hinted that a price increase of up to 10% was in the cards.

But analyst Jeff Pu has blown that prediction out of the water. According to a post on the X social network, Pu believes iPhone 18 Pro buyers could pay $250 to $300 more than the iPhone 17 Pro price at debut in 2026.

Advertisement

If Pu turns out to be right, the iPhone 18 Pro could start at $1,399. Buyers of the iPhone 18 Pro Max could expect to fork out at least $1,499 for their new handset.

Simply passing on the costs

While some will no doubt accuse Apple of increasing prices to boost its balance sheet, Pu doesn’t expect that to be the case. He cites the increased costs of components like RAM and NAND storage as key reasons behind the price increase.

The use of TSMC’s 2nm manufacturing process for the iPhone 18 Pro’s A20-series chip is also thought to be a factor in the price bump.

Pu believes that while recent Apple earnings show the iPhone to still be a key driver of growth, iPhone 18 Pro demand could be hampered by the price increases.

Advertisement

However, it’s also important to remember that Pu’s track record is far from impeccable, with plenty of misses in recent years. While a price increase seems likely, $300 is more than has been previously rumored.

Dire expectations

Price hikes on the iPhone 18 Pro versus the iPhone 17 Pro are inevitable. It’s just a question of how much.

Pu isn’t the only one to have dire pricing concerns. Analysts at Counterpoint Research suggested the iPhone 18 Pro Max could cost on average $200 more than its predecessor.

While not quite the same, we can use Apple’s previous price increases as a guide. The 11-inch iPad Pro increased from $999 to $1,099, a $100 bump. But the 13-inch iPad Pro saw a $200 price increase to $1,499.

Advertisement

With that in mind, maybe a $250-$300 iPhone price increase isn’t out of the question after all.

Those hoping for a silver lining should note that the 13-inch iPad Pro saw a 15% price increase. A $300 price hike on the iPhone 18 Pro Max would represent a 25% increase depending on the storage configuration.

There’s even more promising news to be found in a July 2026 report that Apple has sought to lessen the impact of increasing costs. It was reported that Apple had pushed display manufacturers for lower prices in an attempt to offset the higher costs of RAM and storage.

Advertisement

Source link

Continue Reading

Tech

Leasing your iPhone, the new China problem, & Apple’s future

Published

on

The Apple Upgrade program has been revealed, so it’s time to discuss what leasing your Apple products actually means. Plus, your hosts discuss Apple’s plan to combat the chip shortage on the AppleInsider Podcast.

Apple Upgrade is no longer a rumor and the details match up with what was expected. While Apple won’t be remotely locking iPhones when people miss payments, the lease terms are straightforward about where fees might appear.

AI-driven RAM shortages have pushed Apple to look to Chinese suppliers for China-made products. However, the US government isn’t excited by the prospect and expect it’ll create a slippery slope to more problems in the future.

Your hosts also discuss how Apple might handle smart glasses and privacy. Plus, they share more thoughts on Home Hub, Apple TV, and a new game called Character Limit.

Advertisement

BONUS: Subscribe via Patreon or Apple Podcasts to hear AppleInsider+, the extended edition. This time, it’s the near future and your hosts have been chosen to decide how Apple needs to be broken up to comply with government regulation.

More AppleInsider podcasts

Tune in to our Smart Home Insider podcast covering the latest news, products, apps, and everything HomeKit related. Subscribe in Apple Podcasts, Overcast, or just search for HomeKit Insider wherever you get your podcasts.

Podcast artwork from Basic Apple Guy. Download the free wallpaper pack here.

Those interested in sponsoring the show can reach out to us at: [email protected].

Advertisement

Subscribe to AppleInsider on:

Keep up with everything Apple in the weekly AppleInsider Podcast. Just say, “Hey, Siri,” to your HomePod mini and ask for these podcasts, and our latest HomeKit Insider episode too. If you want an ad-free main AppleInsider Podcast experience, you can support the AppleInsider podcast by subscribing for $5 per month through Apple’s Podcasts app, or via Patreon if you prefer any other podcast player.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025