4 ms·
Their legendary "goto fail" debacle as well as the ease with which ios has repeatedly been jailbroken would disagree. I think geohot once quipped: "My lawyer co
by this_user 6mo ago
Their legendary "goto fail" debacle as well as the ease with which ios has repeatedly been jailbroken would disagree. I think geohot once quipped: "My lawyer could write a better malloc."
- ninju 6mo ago12 year old coding bug https://www.imperialviolet.org/2014/02/22/applebug.html https://www.imperialviolet.org/2014/02/22/applebug.html
- Jtarii 6mo agoNever understood that if statement style, it seems to only exist to create subtle bugs.
- deleted 6mo ago[deleted]
- array_key_first 6mo agoIt's slightly less lines of code which is nice. I'm someone who prefers terseness so I get it. However, it's bad. I much prefer the rare, elusive, postfix if: goto fail if (condition); It can create some very readable code when used right, with short and simple conditionals.
- bch 6mo agoI think of it as BSD style, though of course it could be suggested/mandated elsewhere - [...]Use a space after keywords (if, while, for, return, switch). No braces are used for control statements with zero or only a single statement unless that statement is more than a single line, in which case they are permitted.[0] As I look, GNU guide is less specific, but examples[1] show the same style. The good thing is that -Wmisleading-indentation [2] (comes along with -Wall) catches this indentation error. [0] https://man.openbsd.org/style https://man.openbsd.org/style - happens to be same for at least NetBSD. [1] https://www.gnu.org/prep/standards/html_node/Syntactic-Conventions.html https://www.gnu.org/prep/standards/html_node/Syntactic-Conve... [2] https://gcc.gnu.org/onlinedocs/gcc/Warning-Options.html https://gcc.gnu.org/onlinedocs/gcc/Warning-Options.html
- youngtaff 6mo agoiOS (and MacOS) now use Google’s BoringSSL instead and have for many years
- dieortin 6mo agoDo they? Based on what I’ve seen with a quick search, this doesn’t seem to be true
- gsnedders 6mo agoSee e.g. https://developer.apple.com/documentation/network/creating-an-identity-for-local-network-tls#Configure-the-Client-Devices https://developer.apple.com/documentation/network/creating-a... where the logging output makes it clear BoringSSL is what is used. Or comments such as: https://github.com/apple-oss-distributions/Security/blob/rel/Security-61901/protocol/SecProtocolPriv.h#L2039-L2043 https://github.com/apple-oss-distributions/Security/blob/rel... Unsurprisingly, given BoringSSL doesn't have a stable API (yet alone ABI), it isn't exposed as a system library.
- dieortin 6mo agoSeems like they use BoringSSL on their open source distributions, but their own library on their own platforms: https://forums.swift.org/t/native-implementations-and-boringssl-backed-apple-platform-deployments/33404 https://forums.swift.org/t/native-implementations-and-boring...
- youngtaff 6mo agoiOS Safari definitely used BoringSSL last time I checked it with Frida
- gsnedders 6mo agoCryptoKit isn't relevant to `goto fail`, which was the origin of this thread, given CryptoKit merely implements primitives and not TLS. If you really are doubting what gets used for TLS, open up Console.app, start streaming, run `nscurl https://example.com/ https://example.com/` (or load it in Safari, etc.), and you'll see logging like: default com.apple.network boringssl 18:11:46.229209-0700 libboringssl.dylib nscurl boringssl_session_apply_protocol_options_for_transport_block_invoke(2360) [C1.1.1.1:2][0x1008cef10] TLS configured [server(0) min_version(0x0303) max_version(0x0304) name(redacted) tickets(false) false_start(false) enforce_ev(false) enforce_ats(false) ats_non_pfs_ciphersuite_allowed(false) cc_mode_enforced(false) ech(false) pqtls(true), pake(false)] It really is boringssl which is nowadays used for TLS by the Network framework.
- wfme 6mo agoDare we not look to Android. goto fail was relevant in 2014 - perhaps not the most useful point in 2026.
- Veserv 6mo agoI much prefer the defect where the root password was the empty string [1]. https://security.it.miami.edu/stay-safe/sec-articles/macosx-high-sierra-vulnerability/ https://security.it.miami.edu/stay-safe/sec-articles/macosx-... [1] Actually, the defect was that creating a root account was a unprivileged action, so anybody could create a root account on your machine with a password of their choice. The most obvious presentation is that you could login to root by pressing enter twice with the empty password; the first time creating root with the empty password and the second time logging you in.