Apple releases OS X Mavericks 10.9.2 with SSL fix
81–90 of 246 posts
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#82Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#83Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#84Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#85Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
I don't know about that. Comcast doesn't seem to have any problem robbing its customers right now.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#86Earlier quoted context omitted.
It's still inexcusable. The security update should have been immediate and separate.
You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.
For quite a serious vulnerability, which requires removing one goto statement to solve? I am not sure by what standards that is a good response time. There is surely something wrong with Apple's procedures here.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#87Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
And that betrayed sense, which invokes a hint of paranoia - that bug looks too obvious to have been skipped in QA.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#88Earlier quoted context omitted.
You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.
I don't think a simple 10.9.1.1 (10.9.1 which was already tested, plus JUST the one-line SecureTransport fix) would have required >24h testing. It was their decision to put the fix in 10.9.2 which is the problem. I agree rushing 10.9.2 would have been bad.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#89I'm still not upgrading to Mavericks. I have a lot of work to do, and I dislike being asked to upend my system on somebody else's schedule.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#90Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies. But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.