Page 1 of 1

Serious SSL flaw in Apple products

Posted: 24 Feb 2014, 00:59
by viking60
Apples encryption for several/all of their products simply fails! It affects iPhones and iPads and also appears in notebook and desktop machines running Mac OS X, so there goes the secure banking down the drain. :!:

The flaw was first published on the blog site Hacker News and was later confirmed by Apple via Reuters.

If this is bad?
"It's as bad as you could imagine, that's all I can say," said Johns Hopkins University cryptography professor Matthew Green.

My imagination covers a lot +1

There are heavy speculations that Apple forgot to close a backdoor that they had left open for the NSA. You be the judge of if this is another paranoid conspiration-theory or a realistic scenario.
The problem lies in the way the software recognizes the digital certificates used by banking sites, Google's Gmail service, Facebook and others to establish encrypted connections. A single line in the program and an omitted bracket meant that those certificates were not authenticated at all, so that hackers can impersonate the website being sought and capture all the electronic traffic before passing it along to the real site.

The error has been around for over a month so someone may have your bank account already.
The issue is a "fundamental bug in Apple's SSL implementation," said Dmitri Alperovitch, chief technology officer at security firm CrowdStrike Inc.

:S So do update your iPhone iPad and Mac immediately!!!

And use Linux for banking. +1

Re: Serious SSL flaw in Apple products

Posted: 25 Feb 2014, 13:21
by R_Head
In the way things are going, this is a real flaw or just made up story so you will patch your system with the real spyware.

As you see.... I trust nobody.

Re: Serious SSL flaw in Apple products

Posted: 25 Feb 2014, 14:09
by viking60
Well if you have a smartphone - you can't.

Soon they will come with voice functions and fingerprint identification. It will all be sold as fantastic new features that you must have.
But the real reason is that the NSA and GCHQ lack those data in their otherwise complete database.

After that they do not have to take the fingerprints of criminals anymore - they have all of them already. And voice recognition is helpful in fighting crime too.
Now they can check that photo of you from the speeding camera with face recognition comparing with facebook or your hacked phone - and searching by fingerprint does speed up the search and ensures the quality.

So it is all for your own good....

As the NSA and GHCQ see it you can divide the world into two kinds of people:

Those who understand that all they do is good for them: And the others who have not understood that - yet.....

On their supercomputers they can be found under the search criteria s; "smartphone"+" stupid patriot" and "smartphone"+"stupid".

So it looks like Obama has gathered the data of the Apple folks now. and he is not about to apologize - "just because he is good at it"
Obama wrote:We will not apologize simply because our services may be more effective. But heads of state and government with whom we work closely, and on whose cooperation we depend, should feel confident that we are treating them as real partners. The changes I’ve ordered do just that

So if you are the head of a friendly state; Obama will not spy on you..all to much... and if you are not? :confused You do the math...
Trusting nobody seems like a good plan...

Read more: http://defensetech.org/2014/01/17/obama ... z2uL7bGPml
Defense.org