phaZed
Well-Known Member
- Reaction score
- 3,153
- Location
- Richmond, VA
It's a few days old now, but, Apple devices suffer from a serious "glitch" when authenticating SSL/TLS - basically even if your SSL cert does not pass authentication your Apple device (iPhone 4 & 5 and OSX) WILL allow it and authenticate anyways. Big facepalm.
http://gizmodo.com/why-apples-huge-security-flaw-is-so-scary-1529041062
Which begs the question: Is this how the NSA and officials are gaining 100% access to users iPhones? According to an NSA slide released by Snowden and Wikileaks:
http://www.nydailynews.com/news/nat...phones-report-article-1.1562300#ixzz2uHQM7sNQ
Geez, how in the hell do you mess up SSL without knowing about it, not check it in the past 3-4 years to see if it's working.. and still not have a patch for OSX to remove the (presumably) single "goto fail" line?
Wow. Just wow.
http://gizmodo.com/why-apples-huge-security-flaw-is-so-scary-1529041062
Google's Adam Langley detailed the specifics of the bug in his personal blog, if you're looking to stare at some code. But essentially, it comes down to one simple extra line out of nearly 2,000. As ZDNet points out, one extra "goto fail;" statement tucked in about a third of the way means that the SSL verification will go through in almost every case, regardless of if the keys match up or not.
If attackers have access to a mobile user's network, such as by sharing the same unsecured wireless service offered by a restaurant, they could see or alter exchanges between the user and protected sites such as Gmail and Facebook. Governments with access to telecom carrier data could do the same.
http://finance.yahoo.com/news/apple-says-security-flaw-could-012356698.html
"It's as bad as you could imagine, that's all I can say," said Johns Hopkins University cryptography professor Matthew Green.
Which begs the question: Is this how the NSA and officials are gaining 100% access to users iPhones? According to an NSA slide released by Snowden and Wikileaks:
http://www.nydailynews.com/news/nat...phones-report-article-1.1562300#ixzz2uHQM7sNQ
Security expert Jacob Applebaum said during a presentation in Hamburg, Germany, that the NSA claims it has a 100% success rate when targeting a device running the iOS operating system, such as an iPhone or iPad .
The NSA “literally claims that anytime they target an iOS device, that it will succeed for implantation,” Applebaum said during an in-depth presentation on the top-secret hacking techniques revealed in the Der Spiegel article that he co-authored.
Geez, how in the hell do you mess up SSL without knowing about it, not check it in the past 3-4 years to see if it's working.. and still not have a patch for OSX to remove the (presumably) single "goto fail" line?
Wow. Just wow.