Live data from Hacker News

Apple Says iOS, OS X and “Key Web Services” Not Affected by Heartbleed

recode.net

11–15 of 15 posts

Re: Apple Says iOS, OS X and “Key Web Services” Not Affected by Heartbleed

#12
post #9
post #4

Article is not very informative. If they don't use OpenSSL what do they use?

My jailbroken iOS 7.0.6 had OpenSSL 0.9.8y on it. I don't know if this is an addition of the jailbreak but it wouldn't surprise me if it's baked in - after all, iOS and OSX contains BSD roots via Darwin and BSD 9.x wasn't vulnerable for the same 'too old version' reasons.

Your iPhone having OpenSSL is probably the jailbreak, however all OSX computers ship with 0.9.8 for legacy reasons. It's not used by any other apple software to my knowledge.

Re: Apple Says iOS, OS X and “Key Web Services” Not Affected by Heartbleed

#13

"Sites that use OpenSSL will display a small “lock” icon in the top left-hand corner of your Web browser’s address bar (though not all sites showing this lock use OpenSSL);" This sentence physically hurt to read. I seriously hope that Google Translate wrote this.

I stopped reading at that line.

Re: Apple Says iOS, OS X and “Key Web Services” Not Affected by Heartbleed

#14
post #4

Article is not very informative. If they don't use OpenSSL what do they use?

They do use OpenSSL, just 0.9.8y version which is not affected.

And it's deprecated. It's there for older applications that depend on it.
Post reply on HN