Resend my activation email : Register : Log in 
BCF: Bike Chat Forums


Holy MITM attacks Batman!

Reply to topic
Bike Chat Forums Index -> The Geek Zone
View previous topic : View next topic  
Author Message

CaNsA
Super Spammer



Joined: 02 Jan 2008
Karma :

PostPosted: 17:32 - 24 Feb 2014    Post subject: Holy MITM attacks Batman! Reply with quote

https://www.slate.com/blogs/the_slatest/2014/02/22/apple_security_flaw_makes_iphones_ipads_macs_vulnerable_to_attack.html
Quote:

Apple acknowledged a major security flaw in its software for mobile devices on Friday but did so in such a low-key way that most users likely aren’t aware of just how at risk they might be if they fail to update their software. Plus, experts are saying that Mac computers could be even more exposed to attacks than the mobile software. So what is the problem? A Secure Socket Layer (SSL) vulnerability allowing hackers to intercept information that was supposed to be encrypted.
 Back to top
View user's profile Send private message You must be logged in to rate posts

stinkwheel
Bovine Proctologist



Joined: 12 Jul 2004
Karma :

PostPosted: 17:50 - 24 Feb 2014    Post subject: Reply with quote

I'm going to take a wild stab in the dark here and suggest that apple have modified a piece of functional and well established open source software so that it only works with apple computers and in doing so have broken it.
____________________
“Rule one: Always stick around for one more drink. That's when things happen. That's when you find out everything you want to know.
I did the 2010 Round Britain Rally on my 350 Bullet. 89 landmarks, 3 months, 9,500 miles.
 Back to top
View user's profile Send private message You must be logged in to rate posts

Rogerborg
nimbA



Joined: 26 Oct 2010
Karma :

PostPosted: 18:41 - 24 Feb 2014    Post subject: Reply with quote

An exploitable implementation of SSL does look more like enemy action than incompetence.

Did I say enemy? I meant friendly. Only The Terrorists rely on encryption.
____________________
Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike
 Back to top
View user's profile Send private message You must be logged in to rate posts

J.M.
World Chat Champion



Joined: 27 Mar 2011
Karma :

PostPosted: 19:45 - 27 Feb 2014    Post subject: Reply with quote

https://gist.github.com/hongrich/9176925

Seems very deliberate. The issue is caused by line 62. It essentially ensures that the hash used during the key exchange always returns true, which makes a MITM attack possible. It must be noted that the attack has to be done during the SSL handshake, rather than during an active SSL session.
____________________
2004 R1 & 2018 XSR900
 Back to top
View user's profile Send private message You must be logged in to rate posts
Old Thread Alert!

The last post was made 12 years, 200 days ago. Instead of replying here, would creating a new thread be more useful?
  Display posts from previous:   
This page may contain affiliate links, which means we may earn a small commission if a visitor clicks through and makes a purchase. By clicking on an affiliate link, you accept that third-party cookies will be set.

Post new topic   Reply to topic    Bike Chat Forums Index -> The Geek Zone All times are GMT + 1 Hour
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Read the Terms of Use! - Powered by phpBB © phpBB Group
 

Debug Mode: ON - Server: birks (www) - Page Generation Time: 0.05 Sec - Server Load: 1.02 - MySQL Queries: 13 - Page Size: 40.5 Kb