Tag Archives: Security

Behind iPhone’s Critical Security Bug, a Single Bad ‘Goto’

 

Some software bugs are infinitely subtle and complicated. Others are comprehensible almost at a glance to anyone who dabbled in BASIC as a kid. The iOS 7 bug is in the latter group.

Did you see it? This function is called when a iPhone connects to an encrypted site over SSL: it’s meant to verify that the encryption key is being vouched for — digitally signed — by the operator of the website.

But notice the two “goto fail” lines, one after the other. The first one belongs there. The second is a typo. That extra, duplicative line diverts the program’s execution, like a bypass stent, right past a critical authentication check. The part where the digital signature is actually checked is dead code, never reached.
Behind iPhone’s Critical Security Bug, a Single Bad ‘Goto’ | Threat Level | Wired.com.

Something just blew up. In Apple’s face. Big time.

Why Apple’s Recent Security Flaw Is So Scary.

On Friday, Apple quietly released iOS 7.0.6, explaining in a brief release note that it fixed a bug in which “an attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS.” That’s the understated version. Another way to put it? Update your iPhoneright now.

Oh, and by the way,OS X has the same issues—except there’s no fix out yet.

In simple terms, someone can intercept traffic between you and the site your accessing, and pull of a “Man in the Middle” attack:

I could make all manner of snarky comments on this, but I won’t.

Microsoft and Google lead coalition demanding limits on government surveillance

In October, the tech industry’s biggest companies petitioned congress to reform the US Government’s surveillance policies. Now, the firms are taking their pleas global. Microsoft, Apple, Facebook, Google, LinkedIn, Yahoo and AOL (Engadget’s parent company) have banded together to ask the world’s governments to reassess its intelligence practices. This time, however, the firms are presenting more than a strongly worded letter – they’ve laid out five core reform principals, detailed both on an official website and in full-page ads in national publications.
Continue reading

iOS 7 bug lets you call any number from a locked homescreen (video)

iOS 7 bug lets you call any number from a locked homescreen (video).

Facebook: We Failed Timeline Hacker

 

Facebook has long been associated with all manner of negative connotations, from murder, rape, party-crashing, yet, when one person tries to point out a security hole, they getting the virtual equivalent of a f**k off, denial that it is a bug, and a metaphorical middle finger? So the hacker then takes it higher and gets suspended for violating T+Cs? Why am I not surprised by Facebook’s behaviour? Because that is what I have come to expect of Facebook.

I am thankful I have no Facebook account. I used to many moons ago, and terminating it was probably the best decision of my life.

Facebook: We Failed Timeline Hacker.

LastPass Passwords Exposed for Some Internet Explorer Users

Internet Explorer, a malicious hacker’s dream. Am I the only one to think that as long as you have it installed, you’ve got a hole in your system?

LastPass Passwords Exposed for Some Internet Explorer Users.

Hacker posts Facebook bug report on Zuckerberg’s wall — RT News

Evidently, unfriending people on Facebook won’t stop them posting on your timeline, as this article proves. And the surprising thing (or unsurprising, depending on your perspective), is that Facebook refused to acknowledge it was a bug, so the whitehat went all the way to the top and posted on Zuckerberg’s wall.

Hacker posts Facebook bug report on Zuckerberg’s wall — RT News.