13 ms·
Has goto fail been fixed yet?
- theandrewbailey 13y agoAm I the only one who despairs over redundant hashtags being appended to everything?
- gress 13y agoYes #iforonewelcomeourmemeoverlords
- rsync 13y ago... am I the only one that thinks "pound" would be a better phrase than "hashtag" when saying these out loud ? Cuts syllable usage in half ... has worked for decades with irc channel names ...
- CUViper 13y ago'#' is commonly called either "hash" or "pound", and "tag" as a suffix just describes this tagging use in context. For an apples-to-apples comparison you'd be saying "poundtag", but good luck getting that to catch on. :)
- acuozzo 13y agoOctothorpe FTW
- peteri 13y agoHmm over here on this side of the pond a pound symbol means £ not octothorpe / hash / sharp.
- rdl 13y agoOSX machines are now iOS development workstations; nothing more.
- ihuman 13y agoWhat do you mean?
- rdl 13y agoApple can't be trusted to do point releases for major security bugs in a timely fashion. OSX development can only be done on OSX. Because Apple security procedures are now known to be so horrible, the reasonable thing is to only use Apple hardware when you absolutely must -- iOS dev. I say this as someone who currently has only Macs except for servers; I'll probably not buy another one, and switch back to Linux. I might Linuxify the Macs I currently have, except for when I need to do iOS stuff.
- ihuman 13y agoCorrect me if I'm wrong, but you're almost completely abandoning an OS just because of 1 security problem?
- rdl 13y agoI don't actually care about the original bug much. It happens. That Apple's internal code review/static analysis/etc. doesn't exist is a bigger problem, but still not a showstopper. That Apple's incident response and prioritization is horrible is the reason. Look what they did with the dev center over the summer. Various past bugs.
- rimantas 13y agoYou say this as someone who does not understand the issue at all and has a very naive take on it. Alas, voice of tptacek was not heard on this issue for some reason :(
- rdl 13y agoFortunately we have your extensive experience in operating system security patching and policies about when to push a hotfix vs. a large update to a widely-deployed userbase to enlighten us!
- deleted 13y ago[deleted]
- mikeash 13y agoThis is absurd and unconscionable. There is no excuse whatsoever for not having a 10.9 patch ready to go at the same time as iOS. There is especially no excuse for still not having a 10.9 patch five days later. I would love to see a detailed postmortem about exactly how this bug happened in the first place and why it's taking so long to fix it on the Mac side. Unfortunately, given how secretive the company is, I'm sure we'll never have more than speculation.
- mandalar12 13y agoI am also very surprised by the lack of outrage in media, either mainstream or even tech related (including blogs and HN / netsec).
- seeken 13y agoI wonder if they are finding that a lot of their systems inadvertently relied upon this bug, and they are scrambling to test and fix them all rather than release a fix that causes a lot of other things to break
- 0x0 13y agoWonder if we'll see a patch for this 0day this side of WWDC...
- beat 13y agoMore likely they have to regression test a whole ton of things, just in case, and do all the recompiling in correct order. I can't see anything actually depending on the bug, but making sure they don't screw up the patch is hard. But a lot of programmers who have never done anything more difficult than mylamesocialstartup.com in PHP have no idea what it's like to build and test something as complex as an OS. No, recompiling your Linux kernel ain't the same thing.
- 0x0 13y agoIf they need more than a day to recompile one library with a one-line change and see if it still boots and runs software update, then they have much bigger issues than this single bug. It's now been 5 days PLUS however long they sat on this for ios.
- sheetjs 13y agoSince all of the computers in question are Intel-based, I suspect it would be possible for people to use bootcamp to run Linux or Windows. Are people switching over? EDIT: apparently I have to spell it out: if people are bothered by the situation, they will switch to a different OS. And since we are talking about OSX on computers with intel chips, that is an option.
- wyuenho 13y agoFor those who can get their way around a terminal, here's a temp fix: http://nakedsecurity.sophos.com/unofficial-patch-for-the-apple-securetransport-55741-bug/ http://nakedsecurity.sophos.com/unofficial-patch-for-the-app... I applied it this morning. It works. The one on gotofail.com can't be signed so it doesn't work. This patch still doesn't solve the real problem but at least it doesn't fail silently.
- nfoz 13y agoIf my debian system were to break, and noone was around to fix it... I could fix it myself. Free software ftw.
- pilif 13y agoThe security flaw is inside a library that has been released under a bsd style license (otherwise, the "goto fail;" hilarity would never have ensued). You're free to download the source of the 10.9 library, patch it, compile it and replace the vulnerable binary with the one you fixed.
- makomk 13y agoApparently someone tried it and the publicly-available source is incomplete and doesn't build.
- deleted 13y ago[deleted]
- CUViper 13y agoI think what's interesting is that this code is open source, in code if not development model, but it failed the law that "given enough eyeballs, all bugs are shallow." Until there was an inkling of trouble, at least, and then it was quite shallow indeed. So I wonder if white hats will now look at opensource.apple.com more routinely, because I'm sure black hats are there already.
- mikeash 13y agoOne trouble with that is that the "source dump" style of open source that Apple engages in doesn't really attract eyeballs very well. Sure, you can go read the source, but it's hard to do much with it. It's hard to tinker with it, since Apple doesn't provide any good facilities for installing the stuff into the system. There's no place to send patches. You can send in bug reports if you find anything, but why would you bother when it's so hard to contribute code? If you're interested in security and hacking on security code, OpenSSL would be a much better choice just because you can potentially become part of it, not just an observer.
- deleted 13y ago[deleted]
- stcredzero 13y agoIf the bug affects Software Update, couldn't we use it to patch it ourselves? We could basically MITM our own machines to apply our own patch. The above just made me think: This is a great datapoint in support of RMS and his rants against the dangers of proprietary software. Should we really be clamoring to some company for a fix, when we should just be able to patch it ourselves? (Should we choose to take the risk.) It's times like this when I feel like I don't quite own my own machine.
- mikeash 13y agoNo need to MITM anything. You can just patch the binaries on disk. People have already done the legwork for it: http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.html http://www.sektioneins.de/en/blog/14-02-22-Apple-SSL-BUG.htm...
- wyuenho 13y agoI tried it. Didn't work.
- aroch 13y agoI enjoy that they're serving the patch over HTTP with no signatures or anything. So their patch may be just as useless or maybe make things even worse due to MITM
- mikeash 13y agoAnd they go out of their way to give you a version that's all scripted up for you so you can apply it without knowing what's going on!
- wernerb 13y agoI can't afford to switch environments at the moment. I don't however use any apple applications such as calendar/reminders/safari. Does this mean I have a modicum of relative safety? https://www.imperialviolet.org:1266/ https://www.imperialviolet.org:1266/ produces an error for me. And from what I gather that means I am at least safe using google chrome on OSX.
- JohnTHaller 13y agoYou can always switch from Safari and Mail to Firefox and Thunderbird which do not suffer from this bug. As a bonus, they are also cross-platform, making it easier to switch to Linux or Windows later should the need or desire arise. As for Facetime, switching to Skype or similar will get you around the bug and permit you to chat, talk, and videochat with people that own technology from all sorts of companies... not just other Apple users (which is silly).
- ybaumes 13y agoopensourceapple.com ? If it's an open source part in apple code, then couldn't I fix the issue on my own machine? (by removing the second goto fail; and recompiling)
- lloeki 13y agoIn theory yes (especially since it's a framework, as it's dynamically linked against), but download [0] and see the README: you'll be missing some proprietary algorithms so some things depending on them are bound to fail. [0]: http://opensource.apple.com/tarballs/Security/Security-55471.tar.gz http://opensource.apple.com/tarballs/Security/Security-55471...
- pktgen 13y agoJust curious, what Linux distro is everyone switching to? At this point I am seriously considering it, because this is pathetic. (I suspect I'll remain with Apple hardware for the foreseeable future, because they still have the best laptops IMO, but running another OS is not out of the question.) I like elementaryOS, but it really doesn't feel as polished as OS X. Things like their choice of font don't help IMO.
- dradtke 13y agoIf you're seriously considering switching to Linux, then be aware that nothing you find is going to feel as polished as OS X. Linux developers tend to be more focused on security and under-the-hood improvements while Apple focuses on user experience, plus Apple is a business that can easily afford to hire as many developers as they need while most Linux distros are community-driven. That said, the Linux user experience has improved dramatically over the past several years, and my recommendation would be openSUSE (what I run), or Ubuntu if you're completely new to Linux.
- pktgen 13y agoYeah, this is what I was thinking. elementaryOS seems to get the closest but still isn't ideal. I have to think about it. Thanks. I use Linux on servers, but I've always found the options lacking in some way for desktop.
- pessimizer 13y agoDebian jessie.
- green7ea 13y agoI'm a fan of archlinux running the cinnamon desktop environment. Archlinux might be a bit intense depending on your command line fu; you might want to try Linux Mint instead. Hardware wise, Lenovo also makes decent hardware. The Yoga 2 is a pretty solid machine comparable to most of Apple's offerings.
- vertex-four 13y agoPersonally, I run Debian Wheezy in its default desktop install, GNOME3 and all. It works very well in my opinion, but is neither as shiny or "solid-feeling" as OSX.
- jamiesonbecker 13y agoI love how people keep making excuses for why their favorite cult leader just fed them cyanide.
- rdl 13y agoI blame the security community on this one, for not releasing an apocalyptic weaponized exploit for this vulnerability over the weekend, instead of stuff like agl's checker. If end users were on fire, Apple might be more motivated to push a fix.
- ereckers 13y agoIOS 7.0.6 This security update provides a fix for SSL connection verification. Just notified on my iPad.
- 0x0 13y agoThat was 5 days ago. OSX 10.9.1 is still vulnerable.
- hoverbear 13y agoTossed an email to my AppleCare contact expressing my frustration... You should too if you have one!
- hoverbear 13y agoTossed an email to my AppleCare contact expressing my frustration... You should too if you have one!
- FireBeyond 13y agoRegardless of the fact that you, and I, realize that two separate teams are working on these things, it looks really bad (well, at least to me) to have your flagship OS vulnerable to an amazingly easy to exploit security hole for multiple days, widely and loudly publicized ... And nothing comes out. Oh, except for iBeacon, a specification for pushing ads on you based on your location.
- robbyking 13y agoI really hate these long-url one-word-of-content sites. Doineedajacket.com was clever, but the swarm of copies are unaoriginal and annoying.
- plg 13y agoTim Cook had better make a public statement and make it soon. Think antennagate. It's one thing if your maps application is wrong ... but it's quite another if suddenly people feel like using your product puts their banking information at risk.
- EdwardMSmith 13y agoRight after reading this thread, I fired up Software Update, and OSX Update 10.9.2 is available for me. Links to here http://support.apple.com/kb/HT6114 http://support.apple.com/kb/HT6114 but nothing's on the page. Edit: big update. 460M (I think), and took about 10 minutes on an Air.
- 3JPLW 13y agoThere's now content at the support page you linked, but the security content of the patch still hasn't been published [1]. See the new thread about it here: https://news.ycombinator.com/item?id=7299287 https://news.ycombinator.com/item?id=7299287 [1] http://support.apple.com/kb/HT1222 http://support.apple.com/kb/HT1222
- stevoyoung 13y ago...and it's fixed. http://www.macrumors.com/2014/02/25/osx-update-ssl-facetime-audio/ http://www.macrumors.com/2014/02/25/osx-update-ssl-facetime-...
- STRML 13y agoLooks like this should be updated - 10.9.2 was just released. http://www.macrumors.com/2014/02/25/osx-update-ssl-facetime-audio/ http://www.macrumors.com/2014/02/25/osx-update-ssl-facetime-...
- dTal 13y agoLooking at the details of the bug, I'm surprised it wasn't flagged with a warning. Why don't we warn on unconditional gotos?