Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

villager

(26,001 posts)
Mon Feb 24, 2014, 05:09 PM Feb 2014

Was Apple security ‘flaw’ actually a NSA backdoor?

<snip>

Last week, Apple announced that it had discovered a majority security flaw in its OS operating system. The flaw, called “Gotofail,” allowed hackers or other actors — including spies — to access to theoretically secure data transmitted through wireless connections or along a shared network. Such data included that sent through SSL, a method employed by websites to protect credit card numbers and other personal information when establishing a connection between a customer and a merchant’s point of sale.

The flaw was a simple one, a mistake in a line of code. Just an “if” clause, nested deep within lines of code.

Over the weekend, coding experts examined the timeline of the NSA’s penetration of Apple’s data and the date the flaw first emerged. They made a curious discovery: that the flaw appeared in Apple’s code just a month before the NSA internally reported success in hacking Apple. Fortune’s Phillip Elmer-DeWitt reports:

* Sept. 24, 2012: iOS 6.0 is released
* Oct. 2012: Apple is added to the NSA’s list of penetrated servers
* Dec. 1, 2012 to May 31, 2013: Apple receives 4,000 to 5,000 requests about 9,000 to
10,000 accounts and devices. (Per “Apple’s Commitment to Customer Privacy“.)

One coder, Dancing Fireball‘s John Gruber, got down to the nitty gritty. Taking great pains to note the evidence was circumstantial, he nevertheless drew attention to the following facts. 1) The flaw first emerged in iOS 6.0, 2) iOS 6.0 was released publicly on Sept. 24, 2012, and 3) Snowden’s NSA slide has the agency tapping into Apple’s customers a month later.

<snip>

http://www.rawstory.com/rs/2014/02/24/speculation-emerges-apple-security-flaw-may-be-tied-to-nsa-spying/

3 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Was Apple security ‘flaw’ actually a NSA backdoor? (Original Post) villager Feb 2014 OP
More likely Apple didn't go through a code review before releasing the OS. randome Feb 2014 #1
For such a simple error ... GeorgeGist Feb 2014 #2
Any users of Markdown Language in the room? nadinbrzezinski Feb 2014 #3
 

randome

(34,845 posts)
1. More likely Apple didn't go through a code review before releasing the OS.
Mon Feb 24, 2014, 05:11 PM
Feb 2014

It's amazing how so few of the big companies really care about quality product. They just rush it out the door.
[hr][font color="blue"][center]If you don't give yourself the same benefit of a doubt you'd give anyone else, you're cheating someone.[/center][/font][hr]

 

nadinbrzezinski

(154,021 posts)
3. Any users of Markdown Language in the room?
Mon Feb 24, 2014, 06:34 PM
Feb 2014

Thank Mark Gruber for it by the way.

As to the flaw... I suspect it was not a flaw.

Latest Discussions»General Discussion»Was Apple security ‘flaw’...