{"id":17383,"date":"2014-02-26T13:33:56","date_gmt":"2014-02-26T20:33:56","guid":{"rendered":"http:\/\/www.technightowl.com\/?p=17383"},"modified":"2015-04-29T07:15:36","modified_gmt":"2015-04-29T14:15:36","slug":"the-notorious-ssl-bug-at-least-apple-fixed-it","status":"publish","type":"post","link":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/","title":{"rendered":"The Notorious SSL Bug: At Least Apple Fixed It"},"content":{"rendered":"<p>The headlines filled the airwaves and the daily newspapers. A serious SSL bug present in OS X Mavericks, iOS 6, and iOS 7 could result in Internet criminals eavesdropping or hijacking your account. To make matters worse, some suggested this bug provided an open door for the NSA to keep taps on you, although I wouldn&#8217;t presume that any of these things have actually happened.<\/p>\n<p>The signature verification bug, given the nickname &#8220;gotofail,&#8221; left literally hundreds of millions of users of Apple products vulnerable, because it allowed the attacker to use the hole in SSL and TLS\u00a0connections to \u00a0break in. Not a very pleasant prospect.<\/p>\n<p>Now there has been quite a bit of fear-mongering about this problem, though it&#8217;s surely a genuine issue, although it&#8217;s not as if there is any evidence that it has actually been exploited, at least not yet. News of the flaw arrived last Friday with the release of iOS 7.0.6 and iOS 6.1.6, both of which repaired the problem.<\/p>\n<p>But the bug also impacted OS X Mavericks, and that critical fix was added to the 10.9.2 update that arrived on Tuesday. According to published reports, the flaw involve a single line of code that allowed Internet criminals to bypass SSL\/TSL encryption, and if that happens all bets are off.<\/p>\n<p>If you want to know the raw details, you can examine a report posted at the Department of Homeland Security&#8217;s <a title=\"Here's the tech details of the SSL bug that impacted Apple products!\" href=\"http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2014-1266\" target=\"_blank\">National Vulnerability Database<\/a>.<\/p>\n<p>While some of you may not be inclined to install iOS and OS X updates until they&#8217;ve been tested and proven in the wild, this is one of those situations where you need to take a chance and get with the program. Now that the existence of the bug is known, the potential for exploitation is much greater.<\/p>\n<p>The updates for iOS 6 and iOS 7 were strictly targeted towards fixing the SSL bug. It&#8217;s not apparent that anything else was fixed. The next iOS 7 update, expected to be known as 7.1, is expected this coming March. The fix for OS X Mavericks was distributed as part of a regular maintenance update with 10 other updates and enhancements, along with a smattering of some other less severe, security fixes.<\/p>\n<p>Here&#8217;s a full ist of the changes, except for those additional issues that also impact security:<\/p>\n<ul>\n<li>Adds the ability to make and receive FaceTime audio calls<\/li>\n<li>Adds call waiting support for FaceTime audio and video calls<\/li>\n<li>Adds the ability to block incoming iMessages from individual senders<\/li>\n<li>Improves the accuracy of unread counts in Mail<\/li>\n<li>Resolves an issue that prevented Mail from receiving new messages from certain providers<\/li>\n<li>Improves AutoFill compatibility in Safari<\/li>\n<li>Fixes an issue that may cause audio distortion on certain Macs<\/li>\n<li>Improves reliability when connecting to a file server using SMB2<\/li>\n<li>Fixes an issue that may cause VPN connections to disconnect<\/li>\n<li>Improves VoiceOver navigation in Mail and Finder<\/li>\n<li>Provides a fix for SSL connection verification<\/li>\n<\/ul>\n<p>Of course the important issue is the last, the SSL bug. The other issues aren&#8217;t quite as severe, although it&#8217;s nice to have support for FaceTime audio. Also, one would hope that Mail has finally been fixed, since it was very much broken in some respects with the release of Mavericks.<\/p>\n<p>But you have to wonder about the security situation with, say, Google&#8217;s Android platform. After all, the vast majority of Android phones continue to use an older version of the OS. If this sort of bug happened on that platform, how would Google handle the situation? How would they be able to push the critical fix, when they have to negotiate with the handset makers and carriers to get the maintenance update in the hands of users?<\/p>\n<p>What indeed!<\/p>\n<p>According to an editorial posted this past weekend by Daniel Eran Dilger in <a title=\"Are members of the media paid to be nice to Samsung and Microsoft?\" href=\"http:\/\/appleinsider.com\/articles\/14\/02\/23\/apples-failure-to-pay-for-favorable-media-coverage-flies-in-the-face-of-samsungs-payola\" target=\"_blank\">AppleInsider<\/a>, &#8220;Android&#8217;s latest bug was a critical security flaw in Android&#8217;s WebView, first disclosed\u00a0<em>14 months ago<\/em>.&#8221;<\/p>\n<p>Daniel&#8217;s article further states that some 82% of iOS devices are using the latest version, with another 15% running iOS 6. There&#8217;s no indication that the SSL verification bug impacted older versions.<\/p>\n<p>In contrast, a mere 1.8% of Android handsets were reported using version 4.4 KitKat as of earlier this month. Some 20% are still saddled with version 2.3.x Gingerbread, first released in 2010.<\/p>\n<p>Just this week there was a story about yet another serious Android security bug. With the broken update structure, can anyone using an Android gadget be assured it will be fixed any time soon?<\/p>\n<p>Now to be fair, you can say that Apple should not have allowed this bug to make it through regular Q&amp;A testing. Certainly the people responsible should get a strong verbal lashing for making iOS and OS X severely vulnerable as the result of this foolish bug.<\/p>\n<p>But it&#8217;s also true that nothing is perfect, and perhaps the testing process made assumptions that allowed this defect to go through. After all, verification of SSL and TSL connections are certainly new technologies.<\/p>\n<p>So let this be an object lesson. Apple fixed the bug. But you have to look at other platforms and see if such issues would be addressed as quickly. With Android, the answer would no doubt be no, and I wonder why the media, amid the gloom and doom headlines, has failed to acknowledge that fact.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The headlines filled the airwaves and the daily newspapers. A serious SSL bug present in OS X Mavericks, iOS 6, and iOS 7 could result in Internet criminals eavesdropping or hijacking your account. To make matters worse, some suggested this bug provided an open door for the NSA to keep taps on you, although I [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[9351,202,8710,14507,143,11479,12291,176,14193,12368],"class_list":["post-17383","post","type-post","status-publish","format-standard","hentry","category-news","tag-android","tag-apple","tag-daniel-eran-dilger","tag-department-of-homeland-security","tag-google","tag-internet-criminals","tag-ios","tag-mac-os-x","tag-mavericks","tag-ssl"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Notorious SSL Bug: At Least Apple Fixed It - Gene Steinberg&#039;s Tech Night Owl<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Notorious SSL Bug: At Least Apple Fixed It - Gene Steinberg&#039;s Tech Night Owl\" \/>\n<meta property=\"og:description\" content=\"The headlines filled the airwaves and the daily newspapers. A serious SSL bug present in OS X Mavericks, iOS 6, and iOS 7 could result in Internet criminals eavesdropping or hijacking your account. To make matters worse, some suggested this bug provided an open door for the NSA to keep taps on you, although I [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/\" \/>\n<meta property=\"og:site_name\" content=\"Gene Steinberg&#039;s Tech Night Owl\" \/>\n<meta property=\"article:published_time\" content=\"2014-02-26T20:33:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-04-29T14:15:36+00:00\" \/>\n<meta name=\"author\" content=\"Gene Steinberg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@technightowl\" \/>\n<meta name=\"twitter:site\" content=\"@technightowl\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Gene Steinberg\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/\"},\"author\":{\"name\":\"Gene Steinberg\",\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/#\\\/schema\\\/person\\\/0fe9df12a34fed15d45e05db1c205e2a\"},\"headline\":\"The Notorious SSL Bug: At Least Apple Fixed It\",\"datePublished\":\"2014-02-26T20:33:56+00:00\",\"dateModified\":\"2015-04-29T14:15:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/\"},\"wordCount\":889,\"commentCount\":1,\"keywords\":[\"Android\",\"Apple\",\"Daniel Eran Dilger\",\"Department of Homeland Security\",\"Google\",\"Internet criminals\",\"iOS\",\"Mac Os X\",\"Mavericks\",\"SSL\"],\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/\",\"url\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/\",\"name\":\"The Notorious SSL Bug: At Least Apple Fixed It - Gene Steinberg&#039;s Tech Night Owl\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/#website\"},\"datePublished\":\"2014-02-26T20:33:56+00:00\",\"dateModified\":\"2015-04-29T14:15:36+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/#\\\/schema\\\/person\\\/0fe9df12a34fed15d45e05db1c205e2a\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/2014\\\/02\\\/the-notorious-ssl-bug-at-least-apple-fixed-it\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Notorious SSL Bug: At Least Apple Fixed It\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/\",\"name\":\"Gene Steinberg&#039;s Mac Radio Tech Blog\",\"description\":\"Tech Commentaries From Best-Selllng Author Gene Steinberg\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.technightowl.live\\\/blog\\\/#\\\/schema\\\/person\\\/0fe9df12a34fed15d45e05db1c205e2a\",\"name\":\"Gene Steinberg\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/24fa8d75c69c3030b03da85850df6d736f514f8393b61cc4ac158168b192df2e?s=96&r=r\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/24fa8d75c69c3030b03da85850df6d736f514f8393b61cc4ac158168b192df2e?s=96&r=r\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/24fa8d75c69c3030b03da85850df6d736f514f8393b61cc4ac158168b192df2e?s=96&r=r\",\"caption\":\"Gene Steinberg\"},\"sameAs\":[\"https:\\\/\\\/www.technightowl.live\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Notorious SSL Bug: At Least Apple Fixed It - Gene Steinberg&#039;s Tech Night Owl","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/","og_locale":"en_US","og_type":"article","og_title":"The Notorious SSL Bug: At Least Apple Fixed It - Gene Steinberg&#039;s Tech Night Owl","og_description":"The headlines filled the airwaves and the daily newspapers. A serious SSL bug present in OS X Mavericks, iOS 6, and iOS 7 could result in Internet criminals eavesdropping or hijacking your account. To make matters worse, some suggested this bug provided an open door for the NSA to keep taps on you, although I [&hellip;]","og_url":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/","og_site_name":"Gene Steinberg&#039;s Tech Night Owl","article_published_time":"2014-02-26T20:33:56+00:00","article_modified_time":"2015-04-29T14:15:36+00:00","author":"Gene Steinberg","twitter_card":"summary_large_image","twitter_creator":"@technightowl","twitter_site":"@technightowl","twitter_misc":{"Written by":"Gene Steinberg","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/#article","isPartOf":{"@id":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/"},"author":{"name":"Gene Steinberg","@id":"https:\/\/www.technightowl.live\/blog\/#\/schema\/person\/0fe9df12a34fed15d45e05db1c205e2a"},"headline":"The Notorious SSL Bug: At Least Apple Fixed It","datePublished":"2014-02-26T20:33:56+00:00","dateModified":"2015-04-29T14:15:36+00:00","mainEntityOfPage":{"@id":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/"},"wordCount":889,"commentCount":1,"keywords":["Android","Apple","Daniel Eran Dilger","Department of Homeland Security","Google","Internet criminals","iOS","Mac Os X","Mavericks","SSL"],"articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/","url":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/","name":"The Notorious SSL Bug: At Least Apple Fixed It - Gene Steinberg&#039;s Tech Night Owl","isPartOf":{"@id":"https:\/\/www.technightowl.live\/blog\/#website"},"datePublished":"2014-02-26T20:33:56+00:00","dateModified":"2015-04-29T14:15:36+00:00","author":{"@id":"https:\/\/www.technightowl.live\/blog\/#\/schema\/person\/0fe9df12a34fed15d45e05db1c205e2a"},"breadcrumb":{"@id":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.technightowl.live\/blog\/2014\/02\/the-notorious-ssl-bug-at-least-apple-fixed-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.technightowl.live\/blog\/"},{"@type":"ListItem","position":2,"name":"The Notorious SSL Bug: At Least Apple Fixed It"}]},{"@type":"WebSite","@id":"https:\/\/www.technightowl.live\/blog\/#website","url":"https:\/\/www.technightowl.live\/blog\/","name":"Gene Steinberg&#039;s Mac Radio Tech Blog","description":"Tech Commentaries From Best-Selllng Author Gene Steinberg","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.technightowl.live\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.technightowl.live\/blog\/#\/schema\/person\/0fe9df12a34fed15d45e05db1c205e2a","name":"Gene Steinberg","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/24fa8d75c69c3030b03da85850df6d736f514f8393b61cc4ac158168b192df2e?s=96&r=r","url":"https:\/\/secure.gravatar.com\/avatar\/24fa8d75c69c3030b03da85850df6d736f514f8393b61cc4ac158168b192df2e?s=96&r=r","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/24fa8d75c69c3030b03da85850df6d736f514f8393b61cc4ac158168b192df2e?s=96&r=r","caption":"Gene Steinberg"},"sameAs":["https:\/\/www.technightowl.live"]}]}},"_links":{"self":[{"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/posts\/17383","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/comments?post=17383"}],"version-history":[{"count":0,"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/posts\/17383\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/media?parent=17383"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/categories?post=17383"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.technightowl.live\/blog\/wp-json\/wp\/v2\/tags?post=17383"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}