Tuesday, 25 February 2014

GotoFail: How to Patch a Flaw When Your Update Process is Vulnerable

From GotTabeMobile

We first heard about the GoToFail security hole in Apple’s iOS and OS X Mavericks operating systems on Friday when a patch was rolled out to close the SSL security flaw in iOS. News quickly followed that OSX Mavericks was subject to the same vulnerability that could allow prying eyes to view data that users thought was encrypted. But instead of the encryption routine protecting that data an errant line of duplicate code featuring a GoTo FAIL command essentially bypassed the SSL encryption process.


It’s now late Monday night CST here in the US and Apple has issued nothing further .. Read More



No comments:

Post a Comment