Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

101–110 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#101
post #80
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

It's getting attention because: - It's an easy to spot bug, - in the most critical part of the code, - of a fundamental security library, - and it's been there for a long time, nobody knows how many systems have already been compromised due to it. With this bug, Apple's library isn't actually a SSL implementation. It does not perform the most essential part of a SSL implementation - verifying that the peer possesses…

> But it's completely unacceptable that those mistakes get unnoticed and into production code of such a critical component, and deployed to millions of users.

The handling has been abysmal as well. They dropped a 0-day on themselves by releasing the iOS update, and then delayed the fix by several days, apparently so they could release it along with the Facetime integration.

And even then they don't mention it on the release notes![0] If you look at the release notes for this update, you'd have no idea how important this is, if you didn't already know.

[0] The release notes (http://support.apple.com/kb/HT6114) link to this: http://support.apple.com/kb/HT1222 , which as of right now, lists Dec. 16th as the most recent OS X security update.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#102
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

I believe that the recent NSA revelations are the primary reason this bug is so concerning. We already know that the US government has access to the majority of packets being routed across the US, and this bug makes it trivial to decrypt those originating from Apple devices.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#103
post #8

Earlier quoted context omitted.

Maybe someone who has already installed this could check if the SSL bug is fixed? https://www.imperialviolet.org:1266

Just tried it with Safari on 10.9.2 >Safari can't open the page " https://www.imperialviolet.org:1266" because Safari can't establish a secure connection to the server "www.imperialviolet.org".

That means the patch worked.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#104
post #53

Earlier quoted context omitted.

I don't think a simple 10.9.1.1 (10.9.1 which was already tested, plus JUST the one-line SecureTransport fix) would have required >24h testing. It was their decision to put the fix in 10.9.2 which is the problem. I agree rushing 10.9.2 would have been bad.

You don't know that at all. For all you know there are programs which depend on the undefined behaviour (very unlikely, but then what do we know?).

It wasn't 'undefined' behaviour, it was 'misdefined'. And I'm sure there are/were programs that depended on it; that's the worrying thing ...

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#105
post #45

Earlier quoted context omitted.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

Why do you think they only knew about this bug for 4 days?

Because that's all we actually know and anything else would be gross speculation.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#106
post #83
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

Coffe Shops, Airports, your insecure home wlan, your office, GSM networks... actually, do you use tls at all or you just go plain text because you're using a "trustworthy ISP"?

This seems like the key to me. Seems naive to think that your trusted ISP is the only person you'll ever get internet access through.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#109

Earlier quoted context omitted.

Its totally unacceptable. Even Microsoft does patches of this severity in less than 24 hours. I suspect what this points to is that Apple doesn't have automated testing and they need a bunch of old school "hands on keyboards testers" to run a test case list that takes 4 days.

The parent 'suspects' and doesn't actually know. It's not 'totally unacceptable' either. It's over a weekend and it's a set of trade offs about cutting a release made by a bunch of smart engineers who were probably very tired (last week for them has probably sucked) and they've just pulled a long weekend to get this out the door. If you find this 'totally unacceptable', my suggestion would be to either go join them a…

> my suggestion would be to either go join them and help them improve the situation

Uhh no, we're customers. I don't find it unacceptable but if I did, it's within my rights to say so without "help[ing] them" as I pay the Apple Tax happily and repeatedly.

Post reply on HN