Friday, March 11, 2016

The Church Collection Plate Goes Digital (BusinessWeek)

There really is an app for everything

Dylan Ciamacco, 25, first went to the Los Angeles outpost of international megachurch C3 as a teen. His mom thought a lot of the young people there—in skinny jeans, chunky sweaters, and leather jackets—dressed like him. He’d emerged recently from a “sick” (as in awesome) atheist phase, he says, mocking himself, and was looking to go back to church.

A typical service, Ciamacco says, opens with a band that would fit in at the Coachella festival, were it not for the Jesus lyrics: “What a savior, my Redeemer/Friend of sinners, one like me.” (In one podcast, a pastor, sermonizing about society’s obsession with markers of achievement, uses an Internet-approved term of endearment to channel his audience, asking, “When am I going to get my own bae?”) At the end, a member of the “worship team” will call on parishioners to tithe and pass the collection plate. But not all people reach into their wallet. Many take out their phone instead.

Ciamacco gives each week, using the Tithe.ly app. It takes fewer than five taps, and built-in geolocation means he can contribute at any of the 1,000 churches that subscribe—a feature that’s especially useful around holidays like Easter, when many people travel. Tithe.ly lets worshipers set up automatic recurring payments, but because Ciamacco’s paycheck fluctuates with his work as a freelance video producer, he tithes on demand—usually about 10 percent of whatever he’s brought in.

“We see people giving all times of day and night”

Although churches are saying a collective hallelujah that a new generation of devotees is filling pews, a youthful congregation has its limitations. Twentysomethings might find religion, but not a lot of them have found that six-figure job. They don’t carry cash—and what, exactly, is a personal check? Still, about a quarter of them use mobile payment apps such as PayPal and Venmo regularly, according to a recent Accenture survey. And enormously popular services such as Seamless, Uber, and Amazon.com have normalized one-tap payments—91 percent of millennials use their phone to buy something at least once a month, market-research firm Statista says.

Tithe.ly is one of a handful of apps leveraging that spending behavior for the good of the church. Pushpay, which about 3,000 congregations employ, works similarly; worshipers decide whether to donate to a general budget or a specific program the institution designates. Another, EasyTithe, features a text-to-give option. It also provides technology for a Square-like credit card reader to await the faithful in church lobbies. Regardless of which app a congregation chooses, the point is convenience. “We call it frictionless giving,” says Dean Sweetman, Tithe.ly’s co-founder and a former minister at C3 Atlanta. He designed the app with C3’s wallet-light clientele in mind: “We see people giving all times of day and night. Nothing stands in the way.”

Apparently not. Churches using tithing apps report they see more donations, more often, from more people. (Subscribing establishments either pay a monthly fee or allow the app to collect a cut of each gift. Tithe.ly lets donators cover this; Pushpay promises churches a 5 percent spike in donations or their money back.) But getting parishes with pastors and members older than 40 to sign on has been more Job-like. Tradition is hard to overcome. “In some churches, if you let the plate go by and you don’t put something in, you feel a little guilty,” says Brad Hill, who works in platform services at EasyTithe. To combat that, some congregations print out cards that say, “I gave online.”

Ciamacco’s friend James Crocker, also 25, says it’s much more awkward to donate the old way: “Putting your personal credit card details on a piece of paper and leaving it there? For millennials, there’s no way.” Ciamacco agrees, if for different reasons. “I was so anti writing my name on an envelope—it was a holier-than-thou thing,” he says. “When Tithe.ly came out, I was like, ‘Hell, yeah.’ ”

Thursday, March 10, 2016

Descubra si califica para un beneficio tributario por sus ingresos laborales

El “Crédito por ingreso del trabajo” (EITC, sigla en inglés) es un beneficio tributario para los trabajadores de ingresos bajos o moderados. También beneficia a los trabajadores y trabajadoras con hijos.  

El EITC podría reducir la cantidad de impuesto que adeuda, y beneficiarlo con un reembolso. Obtenga más detalles sobre este beneficio.

Este servicio es proporcionado en forma gratuita por GobiernoUSA.gov, el sitio web oficial del Gobierno de Estados Unidos en español.

¿Tiene preguntas? Contáctenos.
Conéctese con GobiernoUSA.gov: 

Facebook  Twitter  YouTube Medios y colaboradores  


Tuesday, March 8, 2016

Google prepares to test Project Loon in India

in partnership with telecom providers


Google’s managing director for South East Asia and India Rajan Anandan told The Economic Times in an interview that the company is in talks with local telecom service providers to pilot Project Loon, its program to beam internet access from balloons floating thousands of feet up in the air.

We’ve known for a couple of years now that Google planned to bring its moonshot initiative to the country. In December 2014, the company met with government authorities to address potential issues concerning Loon transmissions interfering with cellular networks and to look into ways to work with existing telecom firms.

Last December, Sundar Pichai reiterated how important the Indian market was for Google and cited Project Loon as well as a program to bring free Wi-Fi to 400 railway stations across the country. The first of these went online in January and 99 more are expected to get connected by the end of 2016.

It’s worth noting that Google hasn’t claimed that Loon will provide internet access for free. However, it will solve the problem of bringing connectivity to rural populations and those who live in far-flung areas, where installing terrestrial networks proves difficult.

Anandan said that the government has been “very supportive” of Project Loon. That’s not surprising, given that India still has 1 billion who are yet to be connected to the Web, according to McKinsey & Co. However, he declined to name the telecom companies that Google is in talks with concerning the trial program.

It’ll be interesting to see how soon Google can begin to offer its balloon-powered internet across the nation and how it will monetize its offering. Zero-rating services that favor select sites and content are not an option, as the Telecom Regulatory Authority of India banned them last month and effectively forced Facebook to shutter its Free Basics initiative in the country.

Google will have to figure out ways to educate millions of Indians who have never been online about its new service and also offer it at an affordable price. Local partnerships could help in those respects, but it will no doubt face a challenge in communicating the value of internet access to people who haven’t tried it before.

The company began technical trials of Project Loon balloons in Sri Lanka last month and is set to launch tests in Indonesia this year too.

Monday, March 7, 2016

Who Needs Apple When the FBI Could Hack Terrorist iPhone Itself (BusinessWeek)


  • Experts say Feds could access data without going to court
  • A kiosk in a Chinese mall holds a potential solution

The Federal Bureau of Investigation has put the onus on Apple Inc. to break into the iPhone 5c carried by San Bernardino terrorist Syed Rizwan Farook. In fact, the feds almost certainly could do it themselves.

Security experts say there are many ways the FBI could hack the iPhone now at the center of a standoff between Apple and the U.S. government. They argue that doing so would be faster than waiting for the courts to decide whether Apple should be forced to create software that would let investigators try multiple passcodes without erasing the device. No one is saying a government hack would be easy, but the experts interviewed for this story have concluded the Feds aren’t even trying because they’d rather win a legal precedent that gives agents the power to access phone data with a warrant.

Jonathan Zdziarski, a cybersecurity researcher who consults with law enforcement, says the FBI could learn something from back-alley techies in China who break into iPhones all the time. He describes a kiosk in a Shenzhen mall that charges $60 to upgrade a 16-gigabyte phone to 128 gigabytes. Using a PC, tweezers and screwdrivers, he says, the kiosk operator copies the contents of the iPhone onto a chip with more capacity then swaps it in.

Zdziarski says the FBI could use a similar workaround: copy the phone’s contents onto a chip so there’s a backup file when password attempts erase the device. The trick is figuring out a way of doing this hundreds of times without destroying the chip. He says the problem could be solved with research and that typically investigators can crack a passcode with fewer that 200 attempts because people usually choose easy ones.

That’s just one of multiple ways the FBI could extract data by messing with iPhone hardware, Zdziarski says. Other potential solutions include finding and exploiting cracks in the software. All systems contain flaws and they continue to be found every month in Apple’s software, according to Jason Syversen, a former manager at the Defense Advanced Research Projects Agency (DARPA) and now chief executive officer of cyber security firm Siege Technologies. In fact, Apple publicly lists the security vulnerabilities that researchers have found. There’s no shortage of cyber experts within the FBI, contractors that work on-site, or third parties and academic organizations that law enforcement could enlist to try and use those cracks to extract the data, Syversen says.

Some experts have argued that the FBI should ask the National Security Agency for help. They note that the NSA is the best-funded spy agency on Earth, employs legions of hackers and almost certainly can break into secure computer systems. But in testimony before Congress on Tuesday, Worcester Polytechnic Institute cybersecurity professor Susan Landau said the NSA may be reluctant to help the FBI, since the secretive agency’s hacking abilities could become public should it be hauled into court.

In written testimony for the congressional hearing, Landau said the FBI needs to build its own investigative center employing agents with deep technical understanding so surveillance can keep up with advances at Apple and other tech companies. The cost to maintain this would be in the hundreds of millions, but a worthy investment and probably the only long-term solution, she wrote.

“The FBI must learn to investigate smarter; you, Congress, can provide it with the resources and guidance to help it do so,” Landau wrote in her testimony. “Bring FBI investigative capabilities into the twenty-first century.”

In the meantime, the FBI will continue to use the courts to force Apple to build back doors into its devices -- which Apple says would risk exposing customers’ private information to hackers and authoritarian regimes. FBI Director James Comey said at the congressional hearing that “we have engaged all parts of the U.S. government to see, does anybody have a way, short of asking Apple, to do it, with a 5C running iOS9, and we do not.”

Jay Edelson, a class-action lawyer at Edelson PC that specializes in suing technology companies (going after tech giants including Apple and Google), is on Silicon Valley’s side this time. He says the FBI chose this case to score political points -- not because hacking iPhones is too hard.

“The government’s take is even if we have experts in the government, we don’t have an obligation to enlist their help,” Edelson says. “They’re just trying to establish precedent. 

They think they have a decent argument where they can force companies to change their business systems to help them.”

Friday, March 4, 2016

Rise of the CISO: Why the C suite needs a security chief

The CISO role is growing in popularity, but what does it actually mean for your business? 
Here's what the role is responsible for and why CISOs are multiplying in the enterprise.


The latest c-suite executive role to step into the spotlight is the chief information security officer, or CISO. Even more focus was put on the CISO role when, in February, President Obama announced that the US government was planning to hire its first ever Federal CISO.

Obama's announcement further justified what many organizations were already doing, which was assigning a specialized executive over security issues, instead of leaving them to be handled by the CIO or CTO, whose top priorities are typically a mix of innovation and operations. And, while the CISO is not a new role, it is still gaining popularity in the enterprise.

So, we're going to break down what it is and why you might need one. Let's start with defining the role.

What is a CISO?

Simply put, the goal of the CISO is to protect the business at all costs against present and future digital security threats.

Andrew Hay, CISO at DataGravity, said, "The CISO role is a true hybrid role that is responsible for implementing, defending, measuring, and communicating the security and privacy strategy of the organization to all of its stakeholders."

And that "all stakeholders" bit is key—the CISO isn't going to hold court with the executive team only. True CISOs will be working with employees, customers, and other partners as well, Hay said.

Additionally, the CISO role isn't the typical "vision caster" most people associate with a CXO title. The CISO role is a mixture of strategy/big picture thinking and tactical skills. Most CISOs are coming from an IT security background, so they know how to directly implement and work with the systems they are recommending.

In terms of who they report to, Entertainment Partners CISO John Tooley said that he believes the majority report to specific executives, and not just the CEO. In his tenure, he said he has reported to the CIO and CTO. Other CISOs may report to the COO or the CFO.

What does a CISO do?

In a broad sense, the CISO's functions revolve around risk—identifying risk, assessing risk, presenting risk, and implementing programs to combat it. The difficulty in the role, Tooley said, is doing these things in a way that makes sense to the business, but is also effective in driving real change.

Identifying and assessing risk are skills that are typically developed as a combination of the training a CISO has received throughout his or her career and the sense of intuition that develops over a long time spent in the industry. Presenting the risk becomes a bigger challenge in that it requires specific communications and sales skills to get other leaders on board with a solution.

"As opposed to other C-level executives, I think there is more of a communication challenge, taking highly technical language and translating it into business value and need. There is also the balance that needs to be struck between empowering employees and securing the enterprise, since insider threats represent one of the biggest security concerns," said Ari Lightman, director of the CISO Program at Carnegie Mellon University's Heinz College.

The CISO must champion the organization's security in all that he or she does, setting security goals and milestones to help measure the success of that strategy. Lightman said some of the day to day functions that comprise the role may include the following:

Secure the enterprise's digital assets

Educate and train employees and the extended ecosystem on security best practices and procedures
Define and monitor access and permissions
Hire and train security personnel
Define budgets for security equipment and training
Work with other C-level executives to ensure compliance with security procedures
And, that above list is not exhaustive. Ultimately, a CISO's role will also be shaped, in part, by the needs of the industry they operate in and the needs of their employer.

The rise of the CISO

So, why are we seeing the CISO rise to prominence now? For starters, security is no longer purely a technological issue, and can no longer be constrained solely to IT.

"So there is awareness among senior management now that information security is really a risk issue, and risk is a business challenge that needs broader solutions.," Tooley said.

Another big issue is growth—there's just more technology in the workplace than there has ever been before and it's affecting organizations in new and interesting ways. The addition of DevOps, cloud, IoT, BYOD, and big data mean that the attackable surface is growing as well, and it needs a guardian.

"As a result, industry guidance, regulatory compliance standards, and the realization that security is a key component in business continuity and operational excellence, has led to the realization that the safety, security, and compliance of a company's IT and information assets require an advocate at the highest level," Hay said.



Thursday, March 3, 2016

A security expert said he could hack into San Francisco's $35,000 police drones from a mile away

SkyRanger Drone

Think drones are scary? Then you might not like the notion of hackable $35,000 police drones flying in your airspace.

Unfortunately, that notion is something of a reality — at least according to one hacker who says he’s capable of commandeering a very expensive, very high-tech quadcopter from over a mile away.

On Wednesday’s RSA security conference in San Francisco, security researcher Nils Rodday revealed a number of rather alarming flaws in the city’s advanced, police-grade unmanned aerial vehicles (UAVs) that make it possible for him “to take full control over the quadcopter with just a laptop and a cheap radio chip connected via USB.”

Due to the absence of any sort of encryption technology between the drone and its controller (called a “telemetry box,”), taking over one of these UAVs isn’t a particularly complicated process. In fact, if you’re able to reverse engineer the flight software, you’re able to completely hijack the quadcopter, sending your own controls while blocking all signals from the legitimate operator.

“You can inject packets and alter waypoints, change data on the flight computer, set a different coming home position,” Rodday says. “Everything the original operator can do, you can do as well.”

So what’s leading to this massive security flaw? Rodday has narrowed it down to two primary culprits — the weak “WEP” or “wired-equivalent privacy” encryption used to connect the telemetry module and a user’s tablet, and even worse, the incredibly insecure encryption (or lack thereof) that connects the telemetry model to the UAV itself.

Rodday, who now works at IBM, has since informed drone manufacturers to the breaches he’s uncovered, and tells Wired that the company plans to address the issue when it updates its line of drones. But that means that the UAVs already on the market are fair game for hacking, and from quite a distance at that.

This is by no means the first time that the security of such drones has been called into question. A few years ago in 2013, Samy Kamkar, a hacker in his own right, showed how his homemade Raspberry Pi equipped drone could be used to hack into other drones mid-flight. The vast majority of the problems he discovered, he said, were contingent on insecure Wi-Fi connections. “It’s all the same story: really poor authentication or no authentication,” Kamkar told Wired.

So before drones can be used by police, they need to be secured. Because nothing could be worse than a gun-equipped UAV that has been taken over by malicious hackers.


Tuesday, March 1, 2016

The Most Important Passages From Apple's Challenge to the FBI (BusinessWeek)

"GovtOS" may make us all part of a police state, and other stark warnings from Apple.

GovtOS. That's what Apple Inc. calls the newest product in its pipeline. It's not the brainchild of the gadget masters in Cupertino but rather an iPhone operating system conceived by some buttoned-down folks in Washington, D.C. Unlike the latest iPhone or iPad, it wasn't revealed on a stage before thousands of the faithful. Instead, it was unveiled in a stark response to the Obama administration's attempt to force the computer maker to assist in a terrorism probe. And, Apple has warned, it may someday lead to every American being made an unwilling assistant to law enforcement.

In a 65-page federal court filing on Thursday in Riverside, Calif., Apple said making it override the encryption of an iPhone belonging to one of the San Bernardino shooters was wild overreach. As a legal matter, Apple's lawyers swiftly disassembled the government's use of an 18th century law (the All Writs Act) to justify its demand and described in minute detail how forced compliance would play out, both for Apple's technicians and whoever else is next. 

Although Apple has a growing number of lawyers in this fight, it may have telegraphed its intent to make a First Amendment argument a pillar of the case. Forcing someone to write code is like forcing them to speak, Apple suggested, and that's usually a constitutional no-no. The brief's main author, Ted Boutrous of Gibson Dunn & Crutcher LLP, is one of the nation's premier media lawyers. Here are some highlights:

A Broader Threat

"Under the same legal theories advocated by the government here, the government could argue that it should be permitted to force citizens to do all manner of things 'necessary' to assist it in enforcing the laws, like compelling a pharmaceutical company against its will to produce drugs needed to carry out a lethal injection in furtherance of a lawfully issued death warrant, or requiring a journalist to plant a false story in order to help lure out a fugitive, or forcing a software company to insert malicious code in its autoupdate process that makes it easier for the government to conduct court-ordered surveillance. " 

A Threat to Privacy on a Global Scale

"This is not a case about one isolated iPhone. Rather, this case is about the Department of Justice and the FBI seeking through the courts a dangerous power that Congress and the American people have withheld: the ability to force companies like Apple to undermine the basic security and privacy interests of hundreds of millions of individuals around the globe."

A Trifecta of Illegality

"No court has ever authorized what the government now seeks, no law supports such unlimited and sweeping use of the judicial process, and the Constitution forbids it."

Christmas for Criminals and Spies

"The government wants to compel Apple to create a crippled and insecure product. Once the process is created, it provides an avenue for criminals and foreign agents to access millions of iPhones. And once developed for our government, it is only a matter of time before foreign governments demand the same tool."

The Internet of Big Brother's Things

"If Apple can be forced to write code in this case to bypass security features and create new accessibility, what is to stop the government from demanding that Apple write code to turn on the microphone in aid of government surveillance, activate the video camera, surreptitiously record conversations, or turn on location services to track the phone’s user? Nothing."

"Compelling Apple to create software in this case will set a dangerous precedent for conscripting Apple and other technology companies to develop technology to do the government’s bidding in untold future criminal investigations."

Forgot to Call Tech Support

"Unfortunately, the FBI, without consulting Apple or reviewing its public guidance regarding iOS, changed the iCloud password associated with one of the attacker’s accounts, foreclosing the possibility of the phone initiating an automatic iCloud back-up of its data to a known Wi-Fi network, which could have obviated the need to unlock the phone and thus for the extraordinary order the government now seeks. Had the FBI consulted Apple first, this litigation may not have been necessary."

Congress Already Said No

"Congress has never authorized judges to compel innocent third parties to provide decryption services to the FBI. Indeed, Congress has expressly withheld that authority in other contexts, and this issue is currently the subject of a raging national policy debate among members of Congress, the President, the FBI Director, and state and local prosecutors. Moreover, federal courts themselves have never recognized an inherent authority to order non-parties to become de facto government agents in ongoing criminal investigations."

We Just Made It, We Don't Own It

"Apple is no more connected to this phone than General Motors is to a company car used by a fraudster on his daily commute." 

"Nothing connects Apple to this case such that it can be drafted into government service to write software that permits the government to defeat the security features on Apple’s standard operating system. Apple is a private company that does not own or possess the phone at issue, has no connection to the data that may or may not exist on the phone, and is not related in any way to the events giving rise to the investigation."

Thin End of the Wedge

"The government’s flawed suggestion to delete the program and erase every trace of the activity would not lessen the burden, it would actually increase it since there are hundreds of demands to create and utilize the software waiting in the wings. If Apple creates new software to open a back door, other federal and state prosecutors—and other governments and agencies—will repeatedly seek orders compelling Apple to use the software to open the back door for tens of thousands of iPhones."

"This enormously intrusive burden—building everything up and tearing it down for each demand by law enforcement—lacks any support in the cases relied on by the government, nor do such cases exist."

"The alternative—keeping and maintaining the compromised operating system and everything related to it—imposes a different but no less significant burden, i.e., forcing Apple to take on the task of unfailingly securing against disclosure or misappropriation the development and testing environments, equipment, codebase, documentation, and any other materials relating to the compromised operating system."

It Cannot Be Destroyed

In an affidavit attached to the court filing (formally called "Apple Inc.'s Motion to Vacate Order Compelling Apple Inc. to Assist Agents in Search, and Opposition to Government's Motion to Compel Assistance"), Apple's manager of user privacy, Erik Neuenschwander, summed up the government's "use and destroy" idea this way: "The virtual world is not like the physical world. When you destroy something in the physical world, the effort to recreate it is roughly equivalent to the effort required to create it in the first place. When you create something in the virtual world, the process of creating an exact and perfect copy is as easy as a computer key stroke because the underlying code is persistent. Even if the underlying computer code is completely eradicated from Apple’s servers so as to be irretrievable, the person who created the destroyed code would have spent the time and effort to solve the software design, coding and implementation challenges. This process could be replicated. 

Thus, GovtOS would not be truly destroyed."