Earlier quoted context omitted.
Why does this matter? The browser isn't even at bankofamerica.com, it is at bankofamericaa.com: it "adds insult to injury", but it doesn't affect the attack. No browser would notice, even with the fanciest watchdog services and certificate pinning, that the certificate of an unrelated website is "authentic" or not. The only way you are going to notice the name being wrong is if the user opens the certificate details…
From my experience, people really do pay attention to EV certs ("the green bar"), so I'm not sure it's quite as simple as you're putting it.
Apple releases OS X Mavericks 10.9.2 with SSL fix
211–220 of 246 posts
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#212Earlier quoted context omitted.
This is all pointless handwaving; the update package itself is signed and will not install if tampered with, regardless of TLS certs used to download it. TLS is not used to authenticate the update.
Ah, right. That makes sense. If only it was mentioned on the download page!
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#213Earlier quoted context omitted.
>The only alternative would have been to delay the iOS release Right. This is basically Apple violating their own "responsible disclosure" policy and announcing a 0-day vulnerability in OS X. They should have delayed the release of the iOS patch until the OS X one was ready. This is the whole point of responsible disclosure: maybe the vulnerability is being used in the wild, but by delaying release of it until the ve…
As I said, the iOS bug was almost certainly already being exploited. Delaying the release of a fix for that seems like the absolute last thing anyone should be suggesting they do.
There is no justification for this bug. It never should have shipped. It never should have gone unnoticed for so long. It never should have been announced prior to a patch being available.
No matter how you slice it, Apple failed miserably, and "iOS was probably being exploited" is not an excuse. Apple has how much money? How much money do you think it costs to put their entire Core OS engineering staff on SHIPPING AN UPDATE FOR BOTH OPERATING SYSTEMS?
They could have afforded it. They were simply too incompetent, after a chain of incompetence, to do so.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#214Earlier quoted context omitted.
Its totally unacceptable. Even Microsoft does patches of this severity in less than 24 hours. I suspect what this points to is that Apple doesn't have automated testing and they need a bunch of old school "hands on keyboards testers" to run a test case list that takes 4 days.
The parent 'suspects' and doesn't actually know. It's not 'totally unacceptable' either. It's over a weekend and it's a set of trade offs about cutting a release made by a bunch of smart engineers who were probably very tired (last week for them has probably sucked) and they've just pulled a long weekend to get this out the door. If you find this 'totally unacceptable', my suggestion would be to either go join them a…
So call some employees in!
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#215Earlier quoted context omitted.
As I said, the iOS bug was almost certainly already being exploited. Delaying the release of a fix for that seems like the absolute last thing anyone should be suggesting they do.
As a fellow Mac user: your apologism is showing. There is no justification for this bug. It never should have shipped. It never should have gone unnoticed for so long. It never should have been announced prior to a patch being available. No matter how you slice it, Apple failed miserably, and "iOS was probably being exploited" is not an excuse. Apple has how much money? How much money do you think it costs to put the…
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#216Earlier quoted context omitted.
Ah, right. That makes sense. If only it was mentioned on the download page!
Meh, just admit you didn't realise how packages are signed and move on. TLS shouldn't and cannot be used to sign installation packages. After all, TLS stands for _Transport Layer_ Security...
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#217Earlier quoted context omitted.
Meh, just admit you didn't realise how packages are signed and move on. TLS shouldn't and cannot be used to sign installation packages. After all, TLS stands for _Transport Layer_ Security...
He followed some pretty logical steps and made a fair enough point, there's no reason for you to be a douche about it.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#218Earlier quoted context omitted.
While it's true that almost all software has bugs that can result in exploits, I think most of the exploits used in Pwn2Own are typically the result of complex interactions between subsystems that are hard to predict. As software gets more complex, the attack surface increases. The Apple bug isn't really in that class of exploit. It's a simple coding/merge error, and it's actually a regression from previously working…
Two entire operating systems.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#219Do they use the same code stack for iOS and OSX? This seems weird to me - even though parts of code could be used in both operating systems, I would imagine separate teams would be on iOS and OSX, each reviewing code bases on their own, running unit tests and whatnot. Still, this major flaw has been present for 2.5(?) years - all the more reason for paranoia about its presence.
Add to this, why wait so long with the OSX update? A security issue THIS serious MUST be patched instantly and rolled out as an individual/separate update as soon as possible, even if that means pushing back OSX 10.9.2. Or did they need some time to introduce a new flaw somewhere? o_O
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#220Earlier quoted context omitted.
It's even more unacceptable that it took them FOUR DAYS to fix it, just so they could add a couple of features to FaceTime while they were at it.
10.9.2 has been in beta for weeks and was evidently just about to be released. It made a lot of sense from a QA perspective to do it just the way they did.