4 ms·
Comedic derision appreciated :) However this is a pretty damn serious oversight. I've just shut down my MacBook and picked up my ThinkPad.
by d0 13y ago
Comedic derision appreciated :)
However this is a pretty damn serious oversight.
I've just shut down my MacBook and picked up my ThinkPad.
- homakov 13y agoMac os is not vulnerable
- LawnGnome 13y agoIt appears to be, per https://gist.github.com/rmoriz/fb2b0a6a0ce10550ab73 https://gist.github.com/rmoriz/fb2b0a6a0ce10550ab73 (and my own testing on OS X 10.9.1).
- aroch 13y agoNot in 10.9.2 which is using the same curl version: http://pastebin.com/AZ38WYaB http://pastebin.com/AZ38WYaB
- homakov 13y agoWhy in release note of Apple it wasn't mentioned?
- lawnchair_larry 13y agoThe patch isn't ready for OS X. It will be in the next minor OS update. Bad Apple.
- F30 13y agoI'm able to reproduce your results with cURL. However, Safari on OS X correctly shows a warning. Can anybody explain that?
- gsnedders 13y agocURL uses OpenSSL, Safari uses Apple's Secure Transport.
- F30 13y agoThat's not correct. The cURL version shipped with OS X uses SecureTransport.
- F30 13y agoOK, the answer to that is at the end of Adam Lengley's analysis: https://www.imperialviolet.org/2014/02/22/applebug.html https://www.imperialviolet.org/2014/02/22/applebug.html The lack of hostname checking for IP addresses in Apple's cURL is a completely different problem.
- d0 13y agoNo but it says something about the quality I can expect from the black boxes that Apple provide me with. And its not a good thing.
- brymaster 13y agoLock screen has been vulnerable with a bypass exploit on several occasions so caution is probably a good idea. Way too many times to give me any sort of confidence.
- deleted 13y ago[deleted]