About the security content of iOS 9.3
support.apple.com
About the security content of iOS 9.3
1–10 of 20 posts
Re: About the security content of iOS 9.3
#2 Impact: An attacker who is able to bypass Apple's certificate pinning,
intercept TLS connections, inject messages, and record encrypted attachment-
type messages may be able to read attachments
Description: A cryptographic issue was addressed by rejecting duplicate
messages on the client.
CVE-2016-1788 : Christina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers,
and Michael Rushanan of Johns Hopkins UniversityRe: About the security content of iOS 9.3
#3Re: About the security content of iOS 9.3
#4So many memory corruption issues, I'd like to think in 5/10 years time this would be solved and everything written in a safe language but maybe I'm being optimistic.
Re: About the security content of iOS 9.3
#5Re: About the security content of iOS 9.3
#6So many memory corruption issues, I'd like to think in 5/10 years time this would be solved and everything written in a safe language but maybe I'm being optimistic.
If you mean safe like there's no way a programer can screw this (100% memory managed like JavaScript, Python, Ruby) than I'd bet not.
Re: About the security content of iOS 9.3
#7So many memory corruption issues, I'd like to think in 5/10 years time this would be solved and everything written in a safe language but maybe I'm being optimistic.
If by safe you mean memory managed by default with opting out ( unsafe keyword, or something similar), then I would bet so. If you mean safe like there's no way a programer can screw this (100% memory managed like JavaScript, Python, Ruby) than I'd bet not.
Re: About the security content of iOS 9.3
#8Waiting for the paper on this: Impact: An attacker who is able to bypass Apple's certificate pinning, intercept TLS connections, inject messages, and record encrypted attachment- type messages may be able to read attachments Description: A cryptographic issue was addressed by rejecting duplicate messages on the client. CVE-2016-1788 : Christina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers, and Michael Rushanan…
Re: About the security content of iOS 9.3
#9Re: About the security content of iOS 9.3
#10 CVE-2016-1752 : CESG
CVE-2016-1750 : CESG
I wonder if that's " rel="nofollow">https://www.cesg.gov.uk/>, which is "the Information Security Arm of GCHQ". If so I guess we should be thankful that they saw these vulnerabilities is a risk rather than an opportunity.