Showing posts with label Corporate. Show all posts
Showing posts with label Corporate. Show all posts

Thursday, May 23, 2013

Bits Blog: Senate Panel Questions Apple on Corporate Taxes

Timothy D. Cook being questioned at Tuesday's congressional hearing.Jason Reed/Reuters Timothy D. Cook being questioned at Tuesday’s congressional hearing.

In his statement to the Senate panel, Mr. Cook made several questionable assertions. Here are some examples:

1) “We don’t rely on tax gimmicks.” The precise definition of the word “gimmick” may be debatable, but Apple’s use of two Irish entities, which it claims are stateless (and help it sidestep $10 billion per year in taxes, according to the Congressional report) would seem to qualify.

2) “We don’t move its intellectual property into offshore tax havens.” Apple’s intellectual property is held by its Irish subsidiary, Apple Operations International, which has no employees or physical presence in Ireland, has received $30 billion in income since 2009 and paid no income tax to any government for the past five years, according to Congressional investigators. Ireland is not on the official list of tax havens compiled by the Organization for Economic Cooperation and Development, but it is offshore and Apple’s special deal with the country allowed the company to enjoy rates lower than some companies that shelter income in the Caribbean. What’s more, Apple’s unique agreement hinges on its ability to take advantage of a wrinkle in Irish tax law that allows it to avoid Irish taxes by holding a fraction of its ownership in a shell company called Baldwin Holdings Ltd. in the British Virgin Islands.

3) “We don’t stash money on some Caribbean island.” While perhaps true, this is not necessarily a strong defense. The tens of billions of dollars that Apple does not pay taxes on because they are classified as “permanently invested offshore” are actually held in New York banks. They are managed by Braeburn Capital, a subsidiary Apple opened in Reno, Nev., to avoid some state taxes in California and other states.

4) “These foreign earnings are taxed in the jurisdiction where they are earned.” Apple booked more than $74 billion in sales from dozens of countries around the world to its subsidiary Apple Sales International over the last four years. Although the subsidiary is based in Ireland, Apple accountants and corporate executives contend that, for tax purposes, it is not a resident of any country.

– David Kocieniewski

— David Kocieniewski

Sunday, March 31, 2013

Corporate Cyberattacks, Possibly State-Backed, Now Seek to Destroy Data

The assault, which took American Express offline for two hours, was the latest in an intensifying campaign of unusually powerful attacks on American financial institutions that began last September and have taken dozens of them offline intermittently, costing millions of dollars.

JPMorgan Chase was taken offline by a similar attack this month. And last week, a separate, aggressive attack incapacitated 32,000 computers at South Korea’s banks and television networks.

The culprits of these attacks, officials and experts say, appear intent on disabling financial transactions and operations.

Corporate leaders have long feared online attacks aimed at financial fraud or economic espionage, but now a new threat has taken hold: attackers, possibly with state backing, who seem bent on destruction.

“The attacks have changed from espionage to destruction,” said Alan Paller, director of research at the SANS Institute, a cybersecurity training organization. “Nations are actively testing how far they can go before we will respond.”

Security experts who studied the attacks said that it was part of the same campaign that took down the Web sites of JPMorgan Chase, Wells Fargo, Bank of America and others over the last six months. A group that calls itself the Izz ad-Din al-Qassam Cyber Fighters has claimed responsibility for those attacks.

The group says it is retaliating for an anti-Islamic video posted on YouTube last fall. But American intelligence officials and industry investigators say they believe the group is a convenient cover for Iran. Just how tight the connection is — or whether the group is acting on direct orders from the Iranian government — is unclear. Government officials and bank executives have failed to produce a smoking gun.

North Korea is considered the most likely source of the attacks on South Korea, though investigators are struggling to follow the digital trail, a process that could take months. The North Korean government of Kim Jong-un has openly declared that it is seeking online targets in its neighbor to the south to exact economic damage.

Representatives of American Express confirmed that the company was under attack Thursday, but said that there was no evidence that customer data had been compromised. A representative of the Federal Bureau of Investigation did not respond to a request for comment on the American Express attack.

Spokesmen for JPMorgan Chase said they would not talk about the recent attack there, its origins or its consequences. JPMorgan has openly acknowledged previous denial of service attacks. But the size and severity of the most recent one apparently led it to reconsider.

The Obama administration has publicly urged companies to be more transparent about attacks, but often security experts and lawyers give the opposite advice.

The largest contingent of instigators of attacks in the private sector, government officials and researchers say, remains Chinese hackers intent on stealing corporate secrets.

The American and South Korean attacks underscore a growing fear that the two countries most worrisome to banks, oil producers and governments may be Iran and North Korea, not because of their skill but because of their brazenness. Neither country is considered a superstar in this area. The appeal of digital weapons is similar to that of nuclear capability: it is a way for an outgunned, outfinanced nation to even the playing field. “These countries are pursuing cyberweapons the same way they are pursuing nuclear weapons,” said James A. Lewis, a computer security expert at the Center for Strategic and International Studies in Washington. “It’s primitive; it’s not top of the line, but it’s good enough and they are committed to getting it.”

American officials are currently weighing their response options, but the issues involved are complex. At a meeting of banking executives, regulators and representatives from the departments of Homeland Security and Treasury last December, some pressed the United States to hit back at the hackers, while others argued that doing so would only lead to more aggressive attacks, according to two people who attended the meeting.

The difficulty of deterring such attacks was also the focus of a White House meeting this month with Mr. Obama and business leaders, including the chief executives Jamie Dimon of JPMorgan Chase; Brian T. Moynihan of Bank of America; Rex W. Tillerson of Exxon Mobil; Randall L. Stephenson of AT&T and others.

Mr. Obama’s goal was to erode the business community’s intense opposition to federal legislation that would give the government oversight of how companies protect “critical infrastructure,” like banking systems and energy and cellphone networks. That opposition killed a bill last year, prompting Mr. Obama to sign an executive order promoting increased information-sharing with businesses.

“But I think we heard a new tone at this latest meeting,” an Obama aide said later. “Six months of unrelenting attacks have changed some views.”

Saturday, March 16, 2013

Bits Blog: Obama Discusses Computer Security With Corporate Chiefs

WASHINGTON – President Obama met with an invited group of 13 chief executives at the White House on Wednesday to discuss growing concerns about cybersecurity and enlist them to get behind his proposed legislation to combat the threat of computer warfare and corporate espionage.

Among those present were Rex W. Tillerson of Exxon Mobil, Randall L. Stephenson of AT&T, Wesley G. Bush of Northrop Grumman, Brian T. Moynihan of Bank of America, and Jamie Dimon of JPMorgan Chase, which had been attacked by foreign hackers as recently as Tuesday.

White House officials said the meeting in the White House Situation Room was intended as a “two way” information exchange. Aides said Mr. Obama wanted to hear directly from industry leaders about how vulnerable their companies were to computer attacks. The president also wanted to discuss efforts the government was taking to address threats.

“He has seen as various corporations and business leaders have gone public with their concerns about cybersecurity and the effects of breaches of cybersecurity on their operations,” said Jay Carney, the White House press secretary.

In recent weeks, Apple, Twitter, Facebook, The Washington Post, The Wall Street Journal and The New York Times have all stepped forward to say that their computer systems had been attacked. And since September, online banking sites of several American banks have been intermittently pulled offline by attacks that officials say originated in Iran.

But the president is also looking to drum up public support as he makes a renewed push for legislation that would give the administration new technological tools and broader authority in the battle against computer attacks by foreign governments. The president’s previous bill was killed by a Republican filibuster last year after intensive lobbying by the United States Chamber of Commerce and other business groups, which argued that the legislation would prove onerous.

“He also wants to convey to them how seriously he takes this issue and what he believes the right steps are moving forward,” Mr. Carney said. “And he certainly hopes that out of this meeting and the many others he has on this topic, that we will build the kind of consensus necessary to compel Congress to take appropriate action.”

The meeting Wednesday, which also included chief executives from American Electric Power, Xerox, Marathon Oil, Honeywell, United Parcel Service, ITT Exelis, Siemens and Frontier Communications, was just the latest step in the administration’s campaign to persuade Congress to pass a computer security bill.

In recent months, several senior administration officials — including Janet Napolitano, the secretary of homeland security; Robert S. Mueller III, the director of the Federal Bureau of Investigation; and Gen. Martin E. Dempsey, the chairman of the Joint Chiefs of Staff — have provided closed-door briefings to members of Congress about the threat.

As a stopgap measure, the president signed an executive order last month that promotes increased the sharing of information between the government and private companies.

The president has also been making his case directly to the public in speeches and media appearances in recent months. In his State of the Union speech, Mr. Obama spent more time on the topic of computer attacks than he did on North Korea and Iran combined.

In an interview on ABC News broadcast on Wednesday, Mr. Obama was careful to avoid saying that the United States is engaged in a computer war with China. He said officials need to “be careful with war analogies” in discussions about the topics.

But the president said that billions of dollars are lost when industrial secrets were stolen online. And he said that some of the attacks on the nation’s private and public computer networks were sponsored by foreign governments.

“Our companies are put into competitive disadvantage. You know, there are disruptions to our systems that, you know, involve everything from our financial systems to some of our infrastructure,” Mr. Obama said. “And this is why I’ve taken some very aggressive executive actions. But we need Congress to act.”

He said that the government was limited in what it could do to confront China and other sponsors of computer attacks. And he said the government needed the authority to require that critical infrastructure in the country is hardened against such attacks.

“There are ways that we can harden our critical infrastructure, our financial sector,” Mr. Obama said. “And the only thing that’s holding us back from doing that right now is we haven’t gotten the legislative authority out of Congress. They need to get this done.”

Monday, March 4, 2013

I.T. Managers Struggle to Contain Corporate Data in the Mobile Age

“I’ve got Dropbox, Box, YouSendIt, Teambox, Google Drive,” says Ms. Simons, a 42-year-old executive, naming just five of the many services on her iPhone to store memos, spreadsheets, customer information and soccer schedules.

She and her colleagues at Mashery, a 170-employee company that helps other companies build even more apps, also share corporate data on GroupMe, Evernote, Skype and Google Hangouts. “From the standpoint of corporate I.T.,” she says, “my team is a problem.”

And how. “My peers are killing me,” says John Oberon, Mashery’s information technology chief, who is supposed to keep track of company data. While the company’s most confidential information is encrypted and available only to authorized executives, he said, “there’s only so much you can do to stop people from forwarding an e-mail or storing a document off a phone.”

Chinese hackers are one problem. But so are employees who put company information online with their smartphones and tablets.

Once the data leaves the corporate network, protecting it becomes much harder. Searching for the name of almost any large company, plus the word “confidential,” yields supposedly secret documents that someone has taken from the company network and published.

Netflix, the streaming video service, recently found employees using 496 smartphone apps, primarily for data storage, communications and collaboration. Cisco Systems, which powers much of the Internet with computer networking gear, found several hundred apps, as well as services for shopping and personal scheduling, touching its own network via employees.

“People are going to bring their own devices, their own data, their own software applications, even their own work groups,” drawing off friends and contractors at other companies, said Bill Burns, the director of information technology infrastructure at Netflix. “If you try and implant software that limits an employee’s capabilities, you’re adding a layer of complexity.”

Almost no service is invulnerable. In 2011, Chinese hackers obtained access to hundreds of United States government accounts on Google’s Gmail. Last July, Dropbox, one of the most widely used storage services, reported a loss of data from a large number of customers. Without special instructions, customer sales information in the online service of Salesforce.com can be moved to private accounts at Box. On Saturday, Evernote said user names, e-mail address and encrypted passwords had been stolen in an attack, requiring the passwords of more than 50 million accounts to be reset.

In 2011, Juniper Networks found more than 28,000 samples of mobile malware, mostly for capturing and transferring information like passwords. In January this year, Florida’s Juvenile Justice Department reported that 114,538 youth and employee records had disappeared when a mobile storage device with no password was stolen. The state will pay for a year of credit monitoring for everyone whose data was lost.

Last September, a customer notified Rite Aid that he could obtain other customers’ names, addresses and prescription records from the company’s mobile app. (Rite Aid says the problem has been fixed and that it is not aware of any data loss.)

Even without proof of compromised accounts, such losses can cost a company both money and reputation. According to the Securities and Exchange Commission, unauthorized disclosures of confidential information, whether from unsecured devices, leaky apps or poor cloud security, must be announced publicly if the information could affect a company’s stock price.

Some apps onto which employees may move company information, like Facebook and Amazon, are well known. Others, like Remember the Milk, used for completing tasks, or CloudElephant, a data backup service, are news even to some of the experts in I.T. Skyhigh Networks, which recently started monitoring personal use of apps, has counted more than 1,200 services used in corporate networks from personal devices.