Friday, October 31, 2014

Tim Cook Speaks Up (BusinessWeek)


Tim Cook Speaks Up

Being gay has given me a deeper understanding of what it means to be in the minority and provided a window into the challenges that people in other minority groups deal with every day. It’s made me more empathetic, which has led to a richer life. It’s been tough and uncomfortable at times, but it has given me the confidence to be myself, to follow my own path, and to rise above adversity and bigotry. It’s also given me the skin of a rhinoceros, which comes in handy when you’re the CEO of Apple.
The world has changed so much since I was a kid. America is moving toward marriage equality, and the public figures Throughout my professional life, I’ve tried to maintain a basic level of privacy. I come from humble roots, and I don’t seek to draw attention to myself. Apple is already one of the most closely watched companies in the world, and I like keeping the focus on our products and the incredible things our customers achieve with them.
At the same time, I believe deeply in the words of Dr. Martin Luther King, who said: “Life’s most persistent and urgent question is, ‘What are you doing for others?’ ” I often challenge myself with that question, and I’ve come to realize that my desire for personal privacy has been holding me back from doing something more important. That’s what has led me to today.
For years, I’ve been open with many people about my sexual orientation. Plenty of colleagues at Apple know I’m gay, and it doesn’t seem to make a difference in the way they treat me. Of course, I’ve had the good fortune to work at a company that loves creativity and innovation and knows it can only flourish when you embrace people’s differences. Not everyone is so lucky.
While I have never denied my sexuality, I haven’t publicly acknowledged it either, until now. So let me be clear: I’m proud to be gay, and I consider being gay among the greatest gifts God has given me.who have bravely come out have helped change perceptions and made our culture more tolerant. Still, there are laws on the books in a majority of states that allow employers to fire people based solely on their sexual orientation. There are many places where landlords can evict tenants for being gay, or where we can be barred from visiting sick partners and sharing in their legacies. Countless people, particularly kids, face fear and abuse every day because of their sexual orientation.
I don’t consider myself an activist, but I realize how much I’ve benefited from the sacrifice of others. So if hearing that the CEO of Apple is gay can help someone struggling to come to terms with who he or she is, or bring comfort to anyone who feels alone, or inspire people to insist on their equality, then it’s worth the trade-off with my own privacy.
I’ll admit that this wasn’t an easy choice. Privacy remains important to me, and I’d like to hold on to a small amount of it. I’ve made Apple my life’s work, and I will continue to spend virtually all of my waking time focused on being the best CEO I can be. That’s what our employees deserve—and our customers, developers, shareholders, and supplier partners deserve it, too. Part of social progress is understanding that a person is not defined only by one’s sexuality, race, or gender. I’m an engineer, an uncle, a nature lover, a fitness nut, a son of the South, a sports fanatic, and many other things. I hope that people will respect my desire to focus on the things I’m best suited for and the work that brings me joy.
The company I am so fortunate to lead has long advocated for human rights and equality for all. We’ve taken a strong stand in support of a workplace equality bill before Congress, just as we stood for marriage equality in our home state of California. And we spoke up in Arizona when that state’s legislature passed a discriminatory bill targeting the gay community. We’ll continue to fight for our values, and I believe that any CEO of this incredible company, regardless of race, gender, or sexual orientation, would do the same. And I will personally continue to advocate for equality for all people until my toes point up.
When I arrive in my office each morning, I’m greeted by framed photos of Dr. King and Robert F. Kennedy. I don’t pretend that writing this puts me in their league. All it does is allow me to look at those pictures and know that I’m doing my part, however small, to help others. We pave the sunlit path toward justice together, brick by brick. This is my brick.
Tim Cook is the CEO of Apple.

Wednesday, October 29, 2014

Hack Turns Cats Into Wi-Fi-Sniffing Spies (PCMagazine)

Security researcher Gene Bransfield shows the DefCon audience how they can turn their pet into a Wi-Fi spy.
War Kitteh

It's not a drone mutiny or robot uprising we should be worried about, but animal warfare.
During last week's DefCon hacking conference, security researcher Gene Bransfield demonstrated his War Kitteh cat collar, and showed the audience how they, too, can turn their pet into a Wi-Fi spy.
To keep those who attend his talks engaged, Bransfield has long included photos and stories about cats in his rather technical presentations. After one presentation, an audience member offered him a cat-tracking collar that allows a pet owner to keep track of their feline around the neighborhood.
"Me being the guy I am, I thought 'All you need now is a Wi-Fi sniffing device and you'd have a War Kitteh,'" he said in a DefCon presentation summary. "I laughed, and started working on it."
But instead of simply keeping track of Fluffy as he perused the great outdoors, Bransfield decided to use the collar to sniff out insecure Wi-Fi setups. Bransfield, a principle system security engineer with Tenacity Solutions, outfitted the collar with custom-coded firmware, a Wi-Fi card, a miniature GPS module, and a battery, Wired reported.
He then sent Siamese cat Coco (pictured) off into a suburban Washington, D.C., neighborhood in hopes of identifying unprotected or weakly guarded Wi-Fi networks. Three hours later, the feline—owned by Bransfield's wife's grandmother—returned with data on eight routers that were left unprotected or were using a vulnerable form of encryption (and a mouse carcass).
Of the 23 Wi-Fi hotspots identified by the cat collar, more than a third remain exposed. Many, Bransfield said, were Verizon FiOS routers with unchanged default settings.
During his Sunday DefCon talk, the security researcher detailed the hack, offering instructions for anyone to replicate his WarKitteh collar, which uses the Spark Core Wi-Fi development board and Spark.io operating system.
Bransfield also took an opportunity at last week's hacking conference to discuss his Denial of Service Dog project, which he used to scan TVs in local bars, and turn them off with a remote control, the WiFi Pineapple Mark V wireless network auditing tool, and the TV-B-Gone kit—all attached to the pooch's back.
"There's no socially redeeming thing about the dog," he told The Guardian. "That was just trolling. I thought it would be funny so I did it."
For more, check out PCMag Live in the video below, which discusses the War Kitteh.

Tuesday, October 28, 2014

Why Rite Aid and CVS Stopped Taking Apple Pay (BusinessWeek)


Why Rite Aid and CVS Stopped Taking Apple Pay

The introduction of Apple Pay last Monday was widely described as the dawn of a new era for smartphone payments. But within a week, two major pharmacy chains,Rite Aid (RAD) and CVS (CVS), rejected Apple’s (AAPL) version of the future: Both disabled Apple Pay (as well as other tap-to-pay mobile payments systems Google Wallet and Softcard). As expected, customers took to Twitter to complain, and they almost universally sided with the smartphone company over the drugstores.
CVS hasn’t publicly explained itself. Rite Aid spokeswoman Ashley Flower defended the company in an e-mail to Bloomberg Businessweek. “We are continually evaluating various forms of mobile payment technologies, and are committed to offering convenient, reliable, and secure payment methods that meet the needs of our customers,” she wrote.
That’s not the whole story. Objections to Apple Pay aren’t actually about convenience, reliability, or security—they are about a burgeoning war between a consortium of merchants, led by Walmart (WMT), and the credit card companies. Rite Aid, CVS, Walmart, Best Buy (BBY), and about 50 other retailers have been working on their own mobile payments system, called CurrentC. Unlike Apple Pay, which works in conjunction with Visa (V)MasterCard (MA), and American Express(AXP), CurrentC cuts out the credit card networks altogether. The benefit to the merchants is clear: They would save the swipe fees they now pay to the credit card companies, which average about 2 percent of the cost of transactions.
CurrentC is also likely to allow merchants to gather data about transactions and offer discounts and loyalty programs. This stands in marked contrast to the anonymity built into Apple Pay, which has drawn concerns even from some merchants that are actively supporting the system.
Apple Chief Executive Tim Cook would be happy to have this fight with CurrentC’s backers. When he introduced Apple Pay last month, Cook said mobile payments had failed so far because they were built to serve the business models of their creators, rather than to provide a useful experience for customers. Because Apple’s primary goal is to sell more phones, tablets, and laptops, its system is more straightforward.
Rite Aid and CVS screwed up the optics on this one. It’s hard to argue that you’re doing right by your customers when you stop accepting a form of payment that you’ve already demonstrated presents no technical hurdles. They also don’t have an alternative to offer. CurrentC isn’t expected to be ready until 2015, and the specifics of the system aren’t public.
The irony of this conflict is that Apple, the innovator, is in the position of endorsing the status quo. Walmart and its brick-and-mortar allies, on the other hand, are actively trying to turn the payments industry on its head and challenge the entrenched power of the credit card networks. Apple is happy to help the incumbents make the existing system feel slicker to customers, without touching the underlying economics. In return, American Express, Visa, and MasterCard have been solidly in Apple’s corner.
Brustein is a writer for Businessweek.com in New York.

Monday, October 27, 2014

Amazon Employees, Not Investors, Will Have to Pressure Jeff Bezos to Slow Down (BusinessWeek)



Thursday’s quarterly earnings report from Amazon (AMZN) spooked Wall Street. The 95¢ per share loss for the third quarter was worse than even the 74¢ loss analysts had expected. Revenue came in at $20.58 billion, a 20 percent jump from the same quarter a year ago and well ahead of the overall e-commerce growth rate of 15.7 percent. Yet analysts had expected slightly better sales, and Amazon’s projections for the all-important coming holiday quarter also missed estimates.
So the stock tanked, down 11 percent in after-hours trading—after already having fallen 20 percent for the year. It’s a terrible time to be an Amazon bull.
The reality is that the company is spending wildly on new initiatives. Amazon poured $21.1 billion into operations in the quarter, up 23 percent from a year earlier. The money is being funneled into a wide range of new initiatives, such as 13 fulfillment centers that were built this year and Amazon Fresh, its same-day grocery delivery service, which went live in Brooklyn earlier this month. There’s also category expansion (deeper into areas like apparel), geographic expansion (India, where the company is spending $2 billion), new digital freebies for loyal customers (Prime Music and Prime Video), and such devices as Kindle Fire tablets and Kindle e-readers.
The last category has been particularly expensive. The Fire Phone, which went on sale with AT&T (T) over the summer, was such a flop that the company slashed the price to effectively nothing and barely mentioned it in the earnings release. Chief Financial Officer Tom Szkutak said in a call with analysts that Amazon is taking a $170 million charge in the form of “inventory evaluations and supplier commitment costs.” In other words: Oops.
The biggest question is whether these stumbles will change the way Chief Executive Officer Jeff Bezos and company operate the e-commerce giant. Amazon is like a sports car with an accelerator that is frequently pressed all the way forward, mostly because its driver-CEO believes the road ahead is clear, and there’s a lucrative race to be won. Investor pessimism doesn’t seem to dampen Bezos’s appetite for risk.
Employees unsettled by Amazon’s steadily depreciating stock price are probably the only thing that can force Bezos to slow down. Amazon workers are compensated heavily with stock grants, which are parceled out over four year periods. Promises of great stock rewards motivate employees to stick around amid a grueling work environment. While Amazon is a huge company with plenty of employees coming and going, lately it’s been losing key players to rivals.
On the conference call with analysts, Morgan Stanley analyst Scott Devitt asked Szkutak how the company evaluates investments that don’t succeed, such as the Fire Phone and Amazon’s expensive move into China. In his response, Szkutak sounded an unusual note of restraint, one he repeated several times on the call.
“We try to learn from everything we do as we launch new opportunities,” Szkutak said. “The way I would describe it, from a looking-forward standpoint, [is that] we still think we have a lot of opportunities. That said, we need to be very selective about what opportunities we pursue. That’s the way we are thinking about it.”
There just might be a movement within the company to persuade Bezos to apply some brakes.

Stone is a senior writer for Bloomberg Businessweek in San Francisco. He is the author of The Everything Store: Jeff Bezos and the Age of Amazon (Little, Brown; October 2013). Follow him on Twitter @BradStone.

Thursday, October 16, 2014

Android Lollipop: 4 quick things business users should know (TechRepublic)

Google announced Android Lollipop. 
Here are four features that Android business users need to know about the operating system's newest version. 
lollipopforest.jpg

The Android operating system faces many of the same problems that other mobile operating systems face when it comes to enterprise adoption. However, Google continues its efforts to make Android more business-ready, and it shows.
On Wednesday, October 15, Google announced the latest iteration of the Android OS known as Android 5.0 Lollipop. The update was released alongside the Motorola-manufactured Nexus 6, the newest version of Google's flagship smartphone, the Nexus 9 tablet built by HTC, and the Nexus Player, the first device natively running Android TV made in partnership with Asus.
Android Lollipop, previously known as Android "L," was initially previewed at Google's I/O developer conference in San Francisco earlier this year. The focus then was on Material Design and the new APIs that would be released, but the launch shows that Google had a little more to show.
Don't let the candy-coated exterior fool you, Android Lollipop offers some valuable updates for business users. Here are four quick features that professional Android users should know about

Security

Security is important for any enterprise mobile user, regardless of the OS they are using. This is increasingly true for Android users, as the OS seems to get more and more press surrounding its susceptibility to malware attacks when it comes to third party apps stores.
To better address malware concerns, Android Lollipop has the Security-Enhanced Linux (SELinux) feature to lower the risk of vulnerabilities in all applications. With Android Lollipop, encryption is turned on automatically for new devices. This is the first time data will be encrypted by default on Android devices.
Android Smart Lock is the most unique security feature of Lollipop. This allows Android phones or tablets to be secured by bluetooth, pairing them with an Android Wear device or your automobile, assuming it's running Android Auto. The feature is eerily similar to the Easy Unlock feature that showed up in the Chrome Dev channel earlier this year, which lets users unlock a Chromebook with a paired device.

Multiple users

What came directly from the Knox integration earlier this year, more than likely, is the ability to have multiple users on a single Android device. The ability to "pin" a screen means that multiple users can get to the same content without altering the other's layout or apps. Business users should be able to run two separate users on their device, such as one for business and one for personal use.
One of the most useful scenarios I can see for this feature is the ability to sign in to any other Android phone running Lollipop to access your contacts, calls, and messages. This could prove extremely useful for employees in the field, or SMBs with limited resources that need dedicated business lines.

Notifications

Android users will now have even more control over their notifications, very similar to some of the newer features in iOS. Increased lock screen capabilities mean that users can view notifications and respond to them, if necessary, directly from the home screen.
Using the volume button, users can toggle the Priority Mode to lessen distraction, allowing only notifications from specific contacts or applications to get through. Android users will now also be able to see all their notifications by tapping the top of the screen.

Device continuity

Google's new approach to design through its Material Design increases the continuity of design across devices making the transition from watch, to phone, to tablet that much easier. Especially helpful with email, Android Lollipop shows the user's full inbox next to an open message when using a tablet.
Much like Apple's Continuity, introduced in iOS 8 and Yosemite, Android Lollipop lets users pick up with an app, song, or search on one device where they left off on another.

Wednesday, October 15, 2014

Verizon's Gamble on Internet Rules Might Have Backfired (BusinessWeek)


Verizon (VZ) set off a wide debate in January over how the federal government should regulate the Internet by winning a legal challenge to the existing rules. It now looks possible that the company’s victory has paved the way for its political defeat.
The Federal Communication Commission held the final roundtables on its net neutrality regulations on Tuesday, and FCC Chairman Tom Wheeler will presumably retreat to his office to finalize his proposal. He has said he wants to have new rules in place by the end of the year, meaning a vote could happen at the commission’s open meeting on Dec. 11.
Proponents of stronger rules have clearly won the battle for public opinion by turning the regulatory issue into a popularity contest: Netflix (NFLX) and John Oliver on one side, the cable industry on the other. The FCC received 3.7 million comments on the issue, sparked in no small part by Oliver’s savage takedown of the cable industryComcast (CMCSA) and Co. aren’t going to win a fight like that.
As if a debate over rules concerning Internet infrastructure wasn’t obscure enough, the real issue now is how the FCC claims legal authority to pursue those rules. Advocates of the most aggressive approach want the commission to reclassify broadband as a telecommunications service. This option, known as Title II, is what advocates see as the only way left open by the court to prohibit Internet providers from charging for preferential access to their customers. Opponents argue that the court actually did give the FCC the authority to pursue net neutrality rules without this reclassification. Confusingly, this side also believes the commission wouldn’t have the legal authority to ban such activity outright even after reclassification.
The Internet Association, a trade group whose members include Facebook (FB) andGoogle (GOOG), has remained noncommittal.
Marvin Ammori, a fellow at the New America Foundation who has been pushing for reclassification, says it’s a tossup as to which way Wheeler goes. Even getting to this point could be seen as a victory, given that Title II was politically untenable the last time the FCC wrote rules in 2010.

Tuesday, October 14, 2014

IBM says most security breaches are due to human error (ZDNet)

A recently released report from computing giant IBM attributes some 95% of IT security breaches to human error and that over 75% of attacks are targeted at just five industries, proving when it comes to security, people are the real problem. 
Perhaps the HAL 9000 computer of 2001 fame said it best, "It can only be attributable to human error." At least that is the sentiment that one gets while reading IBM's recent Security Services 2014 Cyber Security Intelligence Index report.
The report, which is based upon a sample of over 1,000 clients in 133 monitored countries, aims to address three key questions about IT Security:
  • What's happening across the threat landscape?
  • What kinds of attacks are being launched?
  • How many of those attacks result in incidents requiring investigation?
IBM's research into answering those questions proves quite impressive and offers a treasure trove of information for those charged with enterprise security. However, interpreting that information into actionable items may still prove to be a challenge for many IT managers. For example, determining that users are the primary problem is far from crafting a solution.
While countless hours can be spent arguing over the infallibilities of intelligent machines and the shortcomings of end users, it still comes down to offering those same users productivity enhancing solutions that do not compromise security - a age old challenge that arrived with the introduction of computing. Naturally, productivity comes from efficient access to resources, making threat identification a key component of enabling secure access.
IBM's report helps to flesh out some of the areas of concern - for example, the report identifies the top five industries under attack, with Finance and Insurance shouldering some 23.8% of security incidents, Manufacturing impacted by 21.7%, Information and Communication suffering 18.6%, Retail and Wholesale is targeted 6.2% of the time, while Health and Social Services deal with 5.8% of the attacks.
Beyond the obvious speeds and feeds, those numbers constitute a road map for the likelihood of attack, meaning that those business segments with the smaller percentiles are less likely to be targeted. Although that statistic may provide some comfort, it doesn't not eliminate the possibility of attack or excuse security professionals from doing everything possible to protect IT assets and data.
Case in point is the type of attack that is targeted at industries, where malicious code or denial of service based attacks are designed to disrupt operations, while credentials abuse and unauthorized access attacks are usually focused at stealing information. IBM categorized incidents to give some insight into what attacks make up the threat landscape showing that some 38% of attacks involve malicious code, 20% are based upon probes/scans, 19% involve unauthorized access, 12% are categorized as suspicious activity, 9% involve credentials abuse, while just 2% comprise of Denial of Service (DOS) attacks.
Once again, the numbers represent frequency and not the level of damage than can happen - for example, a DOS attack could effectively put an online retailer out of business, while unauthorized access to lead to millions of dollars of intellectual property falling into the wrong hands. Simply put, it all comes down to context and how a particular business is impacted - while some businesses may lack marketable intellectual property, they may be susceptible to credit card information being stolen - so while the numbers offered by IBM prove for a good read, using those numbers for the basis of action items means applying them to the appropriate business case.
Obviously, attacks involve people - either as attackers, victims, or those who have made mistakes. Luckily, those inadvertent actors consist of only 5% of those identified as attackers - indicating that mistakes can happen, but are relatively rare when compared to those with criminal intentions. For example, IBM claims that some 56% of attackers are outsiders, while malicious insiders account for 17%.
The threat from outsiders is most obvious, but many organizations are failing to account for how those threats may propagate into today's networks. The attack vectors have grown beyond brute force attempts, malicious code and even phishing scams - today's outsiders are leveraging social information to better target attacks and gain entry into systems.
IBM correctly identifies how social networking has impacted IT security and makes the point "Rather than seeing a particular enterprise as a single entity, attackers now also look at an enterprise as collections of individuals. That means they decide to target specific people instead of enterprise infrastructures or applications. In other words, the personal lives and business activities of employees can be leveraged to target an enterprise."
For the IT security professional, IBM has provided ample fodder (although self-serving) to light a fire under IT security projects and start deploying technologies that can protect people from themselves as well as businesses from those same people.