7 ms·
Show HN: Check if your browser is vulnerable to the Apple SSL bug
- bsenftner 13y agoI'm seeing a positive (yes the bug is there) on all my Apple devices, including my OSX laptops - laptop sees the bug IF and only IF I browse using Safari. Chrome and FF browse to your page fine on the laptop. I've not seen any information about fixing this issue on OSX. Have I just missed it in the noise about the iOS fix?
- cantfindmypass 13y agoNo OS X patch is available yet. :-( Chrome/Firefox shouldn't be vulnerable.
- kalleboo 13y agoChrome on iOS also seems safe
- bcl 13y agoYou can already do this here - https://www.imperialviolet.org:1266/ https://www.imperialviolet.org:1266/ On OSX Firefox and Chrome fail and Safari happily loads it. Yay for not using system crypto libraries.
- cantfindmypass 13y agoI started making this before agl released that, though he had that up before I finished. Also, upon closer inspection, mine actually works differently from agl's.
- ef4 13y agoWhy the hell would Apple publish the vulnerability & fix for iOS without a concurrent update to OS X?!
- cantfindmypass 13y agoI don't know - I can't imagine that nobody on their security team pointed out that someone would promptly reverse engineer the patch and figure out that OS X is also vulnerable.
- praseodym 13y agoAnd having the source code available made that even easier.
- NelsonMinar 13y agoIt's common security practice to release the exploit before the bug is patched in the OS. Oh wait, no, the opposite of that. Unless you're Apple. I'm very angry.
- gress 13y agoPresumably because the vulnerability is already known outside of Apple, and it's better not to hold back the iOS patch while they get the OSX patch done.
- smnrchrds 13y agoHow hard is it to get the patch done? Isn't it, like, removing one line?
- cantfindmypass 13y agoYes, removing one line would fix it.
- cantfindmypass 13y agoIt became widely known outside of Apple due to the iOS patch.
- gress 13y agoHow do you know they hadn't already seen it exploited in the wild?
- oneplusone 13y agoOSX 10.8.4 fails correctly. Was this bug introduced with Mavericks?
- cantfindmypass 13y agoYes, the bug is a regression introduced in Mavericks.
- ef4 13y agoSo if you're on Mavericks and left hanging, there are some evasive actions you can take. As others have pointed out, Firefox and Chrome are not vulnerable. But what else may be relying on the system SSL implementation? Your IM client? Various software updaters? Dropbox? Skype? Etc. Rather than guess, I'm whitelisting only the things I trust. I'm using the pf firewall to block all outbound connections other than DNS and SSH, using SSH to open a SOCKS proxy tunnel, and configuring Firefox to use the proxy (not via the system proxy settings -- via Firefox's own proxy config, so other apps don't know about it and can't get out). A simpler solution for those who want to buy a commercial product would be to install Little Snitch and start with a completely empty list of approved apps, then turn on only Firefox.
- wlesieutre 13y ago>But what else may be relying on the system SSL implementation? Your IM client? Various software updaters? Dropbox? Skype? Etc. Mail seems like a huge concern. I use two-factor on my google account, but that's not worth much when SSL doesn't work. For the time being, at least there's webmail + Firefox.
- chmars 13y agoMany apps use WebKit and are therefore affected too. It is in particular obvious for special purpose browsers like Mailplane.
- krrrh 13y agoThis article claims that you can grep for the version number using otool and if it's not present the binary uses a different version of the library. http://www.theregister.co.uk/2014/02/23/apple_mac_os_x_10_9_ssl_fix/ http://www.theregister.co.uk/2014/02/23/apple_mac_os_x_10_9_... Latest Dropbox (v2.6.5), Adium, and Skype are fine according to this test. Most of Apple's software appears vulnerable however. I'm not at all sure if this test is definitie however.
- mirkules 13y agoCan anyone confirm this on an iOS 6 device? I don't have of those anymore. Good news is iPad running 5.1.1 is not affected, which almost leads me to believe this vuln was introduced with iOS 7
- allochthon 13y agoIt's becoming quite a chore to keep your computer and online accounts secure. I'm in the industry; anyone who is not is probably a babe in the woods these days.
- tantalor 13y agoWhat a delightful idiom. I had to look it up. https://en.wikipedia.org/wiki/Babes_in_the_Wood https://en.wikipedia.org/wiki/Babes_in_the_Wood
- gress 13y agoActually this demonstrates the opposite - this vulnerability has just been patched for half a billion people with no effort on their part.
- cantfindmypass 13y agoApple still hasn't released a fix for OS X...
- gress 13y agoDo you presume they won't?
- rlu 13y ago/facepalm
- gress 13y agoThat's a totally unhelpful comment. You imply that you know something that should be obvious and you think it's more helpful to be condescending than to contribute what you think.
- cantfindmypass 13y ago
- mh- 13y agoSafari fails on 10.9.1.
- firstplanthendo 13y agoUsing the program Little Snitch on OS X 10.8 now to block everything except Firefox (recommended by u/ef4 here)- successfully helped Safari pass this browser test. Can anyone else comment on if this is a decent solution?
- franl 13y agoI don't think 10.8 has the vulnerability. At least my MBP with 10.8 doesn't appear to have it. Both of the test URLs from HN had the desired behavior in Safari on that machine (ie they blocked content / didn't establish a connection). EDIT: I'm not using Little Snitch or anything other than the builtin OSX firewall.
- jmyc 13y agoYes, Little Snitch can help Safari pass this browser test (the unusual port was a red flag for me).
- deleted 13y ago[deleted]
- Jayschwa 13y agoFor HTTPS clients that don't execute Javascript (e.g. curl), GET https://gotofail.com:1266/ https://gotofail.com:1266/
- kylec 13y agoYou'll need to request the image directly: curl "https://gotofail.com:1266/test.png" curl on OS X 10.9.1 fetches the image without complaint, while curl on Debian is correctly reporting an RSA padding check error.
- aroch 13y agoI can confirm that this is fixed in 10.9.2 (Since the first build of it). From the looks of things (and some friends in the Mavericks dev group), the final 10.9.2 should be dropping very soon
- cantfindmypass 13y agoMy web logs show lots of systems identifying as 10.9.2 pulling the test image from the bad server.
- mikhailt 13y agoNo, it isn't. It is still affected in the latest 10.9.2 builds.
- aroch 13y agoNo...Not as far as I can tell. Attempting to connect over the bare IP address to an SSL site results in a curl error[1]. Whereas under 10.9.1 its allowed 1: http://pastebin.com/AZ38WYaB http://pastebin.com/AZ38WYaB
- cantfindmypass 13y agoThat is a different bug.
- rasengan0 13y agoOS X 10.7.5 passes; y'all should downgrade ;-)
- nraynaud 13y agoI get the red "PATCH IMMEDIATELY" in safari, where is the patch??? after a bit of research this looks like a good old UX fail since there is no patch yet anyways. Don't write something in red if there is no path to a solution.
- cantfindmypass 13y agoI'm not checking for Safari vs OS X. I'm not sure what else to say to vulnerable OS X users - there is not really any effective mitigation besides turning the computer off.
- ephemeralgomi 13y agoYou're doing fine, this guy is just bikeshedding. Thanks for the tool, it certainly helped me.
- cantfindmypass 13y agoI would be totally happy to put a proper stylesheet and some better copy together if someone wants to send me that (put it in a gist maybe?)
- cantfindmypass 13y agoI am now for informational purposes linking to the OS X patch released by i0n1c. http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.html http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.htm...
- ephemeralgomi 13y agoYeah, if there's no path to a solution, the text should say "Your computer is correctly following the undesired behavior described in HT6147" in a soothing green color. ...
- nraynaud 13y agonope, saying that there is a page to check for an upcoming solution. Stating that there is nothing to do for now anyways.
- userbinator 13y agoI use a filtering proxy which uses OpenSSL and it just reports "socket error" in the log and retries the connection around a dozen times before it gives up, so it seems I'm not vulnerable; non-Apple software isn't affected by this?
- djao 13y agoAnyone who thinks Chrome and Firefox are safe from this bug doesn't understand the issue. SecureTransport is used for updating software. So an attacker could trick you into installing a malicious update to Chrome, FireFox, or for that matter anything on your system. They could even slip in malware under the guise of a patch that purportedly fixes this bug. Using alternative browsers does NOT completely protect you.
- mikeash 13y agoChrome uses its own updater which presumably uses the same non-vulnerable SSL implementation as the rest of the program.
- djao 13y agoDoesn't matter, the system updater can blow away Chrome or anything else.
- mikeash 13y agoYes, I suppose that's true. However, I believe OS X's software update requires packages signed by Apple and doesn't simply trust the integrity provided by SSL, so I don't think that can happen.
- deleted 13y ago[deleted]
- djao 13y agoThat makes it slightly harder. Still, Apple will sign anything that is successfully submitted to the App Store for approval, right? So you just need to slip a single trojan past their approval process. Normally, the transport layer provides an important second level of defense: a victim would have to consciously choose to install YOUR program in order to get hacked. That doesn't work anymore when the security of the transport layer is compromised. Now anything that you install from the App Store could be surreptitiously compromised. Better hope that Apple's signature revocation infrastructure is sound.
- anoncow 13y agowhy does it say my browser is vulnerable? Using Ucbrowser on lumia.