Apple Reports Second Quarter Results

Yesterday Apple® announced financial results for its fiscal 2014 second quarter ended March 29, 2014. The Company posted quarterly revenue of $45.6 billion and quarterly net profit of $10.2 billion, or $11.62 per diluted share. These results compare to revenue of $43.6 billion and net profit of $9.5 billion, or $10.09 per diluted share, in the year-ago quarter. Gross margin was 39.3 percent compared to 37.5 percent in the year-ago quarter. International sales accounted for 66 percent of the quarter’s revenue.

“We’re very proud of our quarterly results, especially our strong iPhone sales and record revenue from services,” said Tim Cook, Apple’s CEO. “We’re eagerly looking forward to introducing more new products and services that only Apple could bring to market.”

“We generated $13.5 billion in cash flow from operations and returned almost $21 billion in cash to shareholders through dividends and share repurchases during the March quarter,” said Peter Oppenheimer, Apple’s CFO. “That brings cumulative payments under our capital return program to $66 billion.”

Apple is providing the following guidance for its fiscal 2014 third quarter:
  • revenue between $36 billion and $38 billion
  • gross margin between 37 percent and 38 percent
  • operating expenses between $4.4 billion and $4.5 billion
  • other income/(expense) of $200 million
  • tax rate of 26.1 percent

Security Bug That Affects Most Of The Internet

You trust your banking or Web mail sites to protect your communications when you see the little lock icon in your Web browser. This is why you're OK with typing passwords into Hotmail or your credit card numbers into Amazon.

A popular piece of software called OpenSSL is used by Internet companies to provide this kind of security. On March 14, 2012, someone introduced a bug that would allow an attacker to get the "crown jewels," the encryption keys used to protect your communications directly from the companies themselves.

With those keys, an attacker could eavesdrop on your communications with that company and/or impersonate that company, making it possible for them to harvest things like credit card numbers or passwords with relative ease.

Why is this so devastating? It's devastating for several reasons. First, OpenSSL is used very broadly, from big companies like Yahoo to small companies and mom-and-pop shops with shopping carts provided by a vendor. And it's hard for you to tell who's affected or when they've fixed it because companies don't broadcast which versions of OpenSSL they're running to people like you and me.

Second, in order to fix the bug and guarantee secure communications with you, each company has to update OpenSSL on every Internet-facing computer that they own. Worse, they also ought to revoke their SSL certificates — the "crown jewels" mentioned above — and generate new ones, based on the assumption that they could have been stolen at any point since March of 2012. This process could take a company days or even weeks to do.

Finally, since the bug in OpenSSL has existed since March 14, 2012, there are more than two years of your communications that could have been intercepted by an attacker. Anything you've done — shopping at online stores, logging into your bank or your Web mail — could possibly have been compromised in the past. Because of the nature of the attack, you wouldn't know anything about it.

What can I do about it? Sadly, you're at the mercy of the individual Internet companies to get their software patched and their SSL keys revoked and regenerated. Once you feel certain this has been done at a particular company, you really ought to change your password, since this could easily have been fished out of your communications at any point in the last two years.

Additionally, it would be best to avoid things like shared Wi-Fi networks whenever possible as well, since attackers have their best access to your communications when you're sharing a network with them.

But generally, the burden is on Internet companies and not you. That's what makes this so frustrating.

Credit: npr.org

   You can test the vulnerability of any website by using this link:
ssllabs.com/ssltest


For Your Information:
Posts are presented in a stack with the most recent post at the top. Clicking Older Posts will show the next (#) older posts and so forth. Clicking Newer Posts will show the previous (#) newer posts. Clicking on the word Home will display the top (#) most recent posts. When viewing a single post, clicking Older or Newer Post shows a single post each time, but, clicking Home displays the top (#) most recent posts. There are 326 posts in the stack, as of 9-15-19.