{"id":9296,"date":"2014-02-25T18:06:05","date_gmt":"2014-02-26T02:06:05","guid":{"rendered":"http:\/\/www.perivision.net\/wordpress\/?p=9296"},"modified":"2014-02-25T18:06:05","modified_gmt":"2014-02-26T02:06:05","slug":"apple-security-hole-patched-we-hope","status":"publish","type":"post","link":"https:\/\/www.perivision.net\/wordpress\/2014\/02\/apple-security-hole-patched-we-hope\/","title":{"rendered":"Apple security hole patched.  We hope"},"content":{"rendered":"<div id=\"attachment_9297\" style=\"width: 310px\" class=\"wp-caption alignright\"><a href=\"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2014\/02\/os-x-update-message.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9297\" class=\" wp-image-9297\" alt=\"os x update message\" src=\"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2014\/02\/os-x-update-message-300x154.png\" width=\"300\" height=\"154\" srcset=\"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2014\/02\/os-x-update-message-300x154.png 300w, https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2014\/02\/os-x-update-message.png 414w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-9297\" class=\"wp-caption-text\">Source: Apple Inc.<\/p><\/div>\n<p>This has been a rough few days for Apple.\u00a0 A &#8216;goto fail&#8217; hole appeared in the OS that lets people defect a security server key which lets them do .. well not sure.\u00a0 From a quick read of the code, seems like if you can get a false handshake to work then depending on the package you could redirect emails, sms messages, perhaps redirect the auth process and make the user buy something from the store?\u00a0 Not sure, but here is the code.<\/p>\n<blockquote>\n<address>static OSStatus SSLVerifySignedServerKeyExchange(SSLContext *ctx, bool isRsa, SSLBuffer signedParams, uint8_t *signature, UInt16 signatureLen) { OSStatus err; <i>&#8230;<\/i> if ((err = SSLHashSHA1.update(&amp;hashCtx, &amp;serverRandom)) != 0) goto fail; if ((err = SSLHashSHA1.update(&amp;hashCtx, &amp;signedParams)) != 0) goto fail; goto fail; if ((err = SSLHashSHA1.final(&amp;hashCtx, &amp;hashOut)) != 0) goto fail; <i>&#8230;<\/i> fail: SSLFreeBuffer(&amp;signedHashes); SSLFreeBuffer(&amp;hashCtx); return err; }<\/address>\n<\/blockquote>\n<p>However, Apple has said they released a fix, so if you are swinging an Apple device, you may want to path up quickly.<\/p>\n<div class=\"SPOSTARBUST-Related-Posts\"><H3>Related Posts<\/H3><ul class=\"entry-meta\"><li class=\"SPOSTARBUST-Related-Post\"><a title=\"The Bidding For An iPhone 6 Prototype On eBay Is Up To $94,000\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/10\/the-bidding-for-an-iphone-6-prototype-on-ebay-is-up-to-94000\/\" rel=\"bookmark\">The Bidding For An iPhone 6 Prototype On eBay Is Up To $94,000<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"Apple patent application reinvents remote control for the smartphone age\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/10\/apple-patent-application-reinvents-remote-control-for-the-smartphone-age\/\" rel=\"bookmark\">Apple patent application reinvents remote control for the smartphone age<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"iOS 8.0.1 May Have A Link To Apple Maps Fail From 2012\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/09\/ios-8-0-1-may-have-a-link-to-apple-maps-fail-from-2012\/\" rel=\"bookmark\">iOS 8.0.1 May Have A Link To Apple Maps Fail From 2012<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"If you have not heard already, change your iphone password because of phishing hack\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/05\/iphone-password-phising-hack\/\" rel=\"bookmark\">If you have not heard already, change your iphone password because of phishing hack<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"GooPhone i5 to take a bite out of Apple, with an Android iPhone and a lawsuit\" href=\"https:\/\/www.perivision.net\/wordpress\/2012\/09\/goophone-i5-andriod-iphone-lawsuite\/\" rel=\"bookmark\">GooPhone i5 to take a bite out of Apple, with an Android iPhone and a lawsuit<\/a><\/li>\n<\/ul><\/div>","protected":false},"excerpt":{"rendered":"<p>This has been a rough few days for Apple.\u00a0 A &#8216;goto fail&#8217; hole appeared in the OS that lets people defect a security server key which lets them do .. well not sure.\u00a0 From a quick read of the code, seems like if you can get a false handshake to work then depending on the&hellip; <a class=\"read-more\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/02\/apple-security-hole-patched-we-hope\/\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1397,21,755,577,3],"tags":[275,2143,2144],"class_list":["post-9296","post","type-post","status-publish","format-standard","hentry","category-apple-2","category-fail","category-ios","category-ipad","category-iphone","tag-apple","tag-bug","tag-software-update"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pjzQD-2pW","_links":{"self":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/9296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/comments?post=9296"}],"version-history":[{"count":1,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/9296\/revisions"}],"predecessor-version":[{"id":9298,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/9296\/revisions\/9298"}],"wp:attachment":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/media?parent=9296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/categories?post=9296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/tags?post=9296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}