Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

81–90 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#82
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies.

But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#83
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

Coffe Shops, Airports, your insecure home wlan, your office, GSM networks... actually, do you use tls at all or you just go plain text because you're using a "trustworthy ISP"?

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#85
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

> Comcast seems unlikely to try to steal your bank password

I don't know about that. Comcast doesn't seem to have any problem robbing its customers right now.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#86
post #45

Earlier quoted context omitted.

It's still inexcusable. The security update should have been immediate and separate.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

4 days for an OS update is pretty good response time IMHO

For quite a serious vulnerability, which requires removing one goto statement to solve? I am not sure by what standards that is a good response time. There is surely something wrong with Apple's procedures here.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#87
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

It's about the false sense of security.

And that betrayed sense, which invokes a hint of paranoia - that bug looks too obvious to have been skipped in QA.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#88
post #53
post #45

Earlier quoted context omitted.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

I don't think a simple 10.9.1.1 (10.9.1 which was already tested, plus JUST the one-line SecureTransport fix) would have required >24h testing. It was their decision to put the fix in 10.9.2 which is the problem. I agree rushing 10.9.2 would have been bad.

You don't know that at all. For all you know there are programs which depend on the undefined behaviour (very unlikely, but then what do we know?).

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#90
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies. But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.

This is true with or without this bug.
Post reply on HN