PDA

View Full Version : Apple quietly issues iOS update to patch faulty SSL authentication



wraggster
February 22nd, 2014, 10:30
http://www.blogcdn.com/www.engadget.com/media/2013/09/iphone5s-5c-1379618028.jpg (http://www.engadget.com/2014/02/21/apple-ssl-update/)Is that an iPhone (http://www.engadget.com/2013/09/17/iphone-5s-review/) in your pocket? Then you'd better pull it out, dive into the settings menu and check for updates: there may be an important patch waiting for you. Apple has quietly pushed out iOS 7.0.6 and 6.1.6 -- small updates that addresses a hitherto unknown security issue with its mobile OS. According to the company's security notes, the previous versions of iOS (http://www.engadget.com/2014/01/29/apple-iphone-5s-5c-update-china/) was missing key SSL validation steps that kept Secure Transport from validating authentic connections, making it possible for "attackers with a privileged network position" to "capture or modify data in sessions protected by SSL/TLS." In other words, iOS devices were failing to protect themselves on shady networks, unbeknownst to the user. It's not clear if this security flaw was known outside of Cupertino, but it certainly is now. Lucky you, then, that Apple has already issued the fix. Well, what are you waiting for? Update your phone/tablet/Apple TV, already.
Update: Researchers say (https://twitter.com/ashk4n/status/437112027270881280) they've found evidence that OS X also has SSL validation issues. Security firm Crowdstrike (http://www.crowdstrike.com/blog/details-about-apple-ssl-vulnerability-and-ios-706-patch/index.html) analyzed the iOS updates, and say they've found evidence both of Apple's platforms were vulnerable to man-in-the-middle attacks. They expect Apple will push a fix for OS X soon, but for now recommend avoiding shady WiFi hotspots and updating only on trusted networks -- good habits to practice any time.

http://www.engadget.com/2014/02/21/apple-ssl-update/