exclamation-circle Recent Security Flaw in Apple's SSL Protocol [Mac / iOS Users Read]

  • Aayrl
  • Aayrl's Avatar Topic Author
  • Offline
  • Administrator
  • Administrator
  • Big Deal!
  • Posts: 1118
  • Thank you received: 368
24 Feb 2014 16:24 #1
Good Morning folks,

In light of recent events, I thought it would be important to inform the community of a recent software error in Apple's SSL authentication scripts that are falsely providing secure connections across networks. The error involves a misplaced line of code which will improperly make any authentic SSL connections invalid, allowing man-in-the-middle attacks to occur on sensitive transmissions. This article provides a fairly decent description of the flaw.

Those of you who have iPhones or Mac OS X are strongly recommended to update your software on your respective devices. Your iOS devices should have received an automatic update over the weekend (in the event yours did not update, you should manually check for an update). OS X Currently has no 'fix', though one should roll out later this week.

Effected software includes any built-in Apple software, including the Safari web browser. It's strongly recommended that you use an alternative web browser (Firefox and Chrome use their own SSL protocol, and both browsers are still secure for use on OS X and iOS devices) for secure transactions, such as banking or email, until a fix is available for Safari and OS X systems.

If anyone has any questions regarding this issue, feel free to respond and I will try to clarify any concerns you have. You should only be concerned about this security issue if you are performing password-sensitive transmissions using your phone's data network or wifi setting in a public setting (such as a school, shop, mall, etc) and have not grabbed the most recent phone update. In most cases, your OS X machine is on a trusted home or work network, and should have proper security settings in place to prevent man-in-the-middle attacks regardless of the individual machine software.

Thanks,
~Aayrl
The following user(s) said Thank You: RandomityGuy

Please Log in or Create an account to join the conversation.

  • RandomityGuy
  • RandomityGuy's Avatar
  • Offline
  • Administrator
  • Administrator
  • This entire place is bruh
  • Posts: 258
  • Thank you received: 61
25 Feb 2014 10:14 #2
I just got iOS update 7.0.6 which is of SSL verification in my iPad.

Github:
github.com/RandomityGuy
Feel free to support me at ko-fi.com/randomityguy

Please Log in or Create an account to join the conversation.

  • Posts: 521
  • Thank you received: 2
25 Feb 2014 23:26 #3
OS X 10.9.2 is released with the SSL patch.

Please Log in or Create an account to join the conversation.

Moderators: Doomblah
Time to create page: 0.941 seconds
We use cookies

We use cookies on our website. Some of them are essential for the operation of the site, while others help us to improve this site and the user experience (tracking cookies). You can decide for yourself whether you want to allow cookies or not. Please note that if you reject them, you may not be able to use all the functionalities of the site.