SSL bug fix coming 'very soon' for Macs: Apple

Advertisement
By Reuters | Updated: 23 February 2014 14:23 IST

Apple Inc said on Saturday it would issue a software update "very soon" to cut off the ability of spies and hackers to grab email, financial information and other sensitive data from Mac computers.

Confirming researchers' findings late Friday that a major security flaw in iPhones and iPads also appears in notebook and desktop machines running Mac OS X, Apple spokeswoman Trudy Muller told Reuters: "We are aware of this issue and already have a software fix that will be released very soon."

Advertisement

Apple released a fix Friday afternoon for the mobile devices running iOS, and most will update automatically. Once that fix came out, experts dissected it and saw the same fundamental issue in the operating system for Apple's mainstream computers.

That started a race, as intelligence agencies and criminals will try to write programs that take advantage of the flaw on Macs before Apple pushes out the fix for them.

Advertisement

The flaw is so odd in retrospect that researchers faulted Apple for inadequate testing and some speculated that it had been introduced deliberately, either by a rogue engineer or a spy. Former intelligence operatives said that the best "back doors" often look like mistakes.

Muller declined to address the theories.

"It's as bad as you could imagine, that's all I can say," said Johns Hopkins University cryptography professor Matthew Green.

Advertisement

Adam Langley, who deals with similar programming issues as a Google engineer, wrote on his personal blog that the flaw might not have shown up without elaborate testing.

"I believe that it's just a mistake and I feel very bad for whomever might have slipped," he wrote.

Advertisement

The problem lies in the way the software recognizes the digital certificates used by banking sites, Google's Gmail service, Facebook and others to establish encrypted connections. A single line in the program and an omitted bracket meant that those certificates were not authenticated at all, so that hackers can impersonate the website being sought and capture all the electronic traffic before passing it along to the real site.

In addition to intercepting data, hackers could insert malicious web links in real emails, winning full control of the target computer.

The intruders do need to have access to the victim's network, either through a relationship with the telecom carrier or through a WiFi wireless setup common in public places. Industry veterans warned users to avoid unsecured WiFi until the software patch is available and installed.

The bug has been present for months, according to researchers who tested earlier versions of Apple's software. No one had publicly reported it before, which means that any knowledge of it was tightly held and that there is a chance it hadn't been used.

But documents leaked by former U.S. intelligence contractor Edward Snowden showed agents boasting that they could break into any iPhone, and that hadn't been public knowledge either.

Apple did not say when or how it learned about the flaw in the way iOS and Mac OS handle sessions in what are known as secure sockets layer or transport layer security. Those are shown to users by the website prefix "https" and the symbol of a padlock.

The issue is a "fundamental bug in Apple's SSL implementation," said Dmitri Alperovitch, chief technology officer at security firm CrowdStrike Inc.

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, Apple Macs, Mac OS X
Advertisement

Related Stories

Popular Mobile Brands
  1. Epson Expands EcoTank Portfolio in India With 15 New Printer Models
  2. Samsung Galaxy Z Fold 8 Wide IMDA Certification Hints at Imminent Launch
  3. Microsoft Surface, Surface Pro Launched With Snapdragon X2 Chips: See Price
  4. Apple's Next Big Bet? AI AirPods and a Redesigned Anniversary iPhone
  5. Google's New Update Brings These Android 17 Features to Pixel Phones
  6. Android 17 Brings These New Features to Eligible Google Pixel Devices
  7. Redmi Turbo 5 vs Motorola Edge 70 Pro vs Samsung Galaxy A37 5G Compared
  8. Microsoft's Copilot Cowork Feature Rolls Out Globally for These Customers
  9. OnePlus N6 Confirmed to Launch in India With an 8,000mAh Battery
  10. Motorola Razr Fold Review: The Best First-Generation Foldable Ever Made?
  1. Xiaomi Mix Fold 5 Reportedly Passes Regulatory Hurdles, Might Be First Phone to Run HyperOS 4
  2. Pritam and Pedro OTT Release: Know When and Where to Watch Rajkumar Hirani's New Series Online?
  3. Roblox Kids, Roblox Select Accounts With Enhanced Safety Tools, Age-Based Protections Rolled Out in India
  4. Micosoft Planned to Shut Ninja Theory Before Senua Was Announced at Xbox Games Showcase: Report
  5. OnePlus N6 Will Launch in India With the Same Battery as the Higher-End OnePlus Nord CE 6
  6. Google's Wear OS 7 Update Rolls Out to Pixel Watch With Live Updates, Better Battery Life
  7. Android 17 Starts Rolling Out to Compatible Google Pixel Devices With Bubbles, Screen Reactions and New AI Features
  8. Silo Season 3 OTT Release Date Revealed: When and Where to Watch it Online?
  9. Samsung Galaxy Z Fold 8 Wide Appears on IMDA Database, New Wide Foldable Phone Could Arrive Soon
  10. Xiaomi 18 Pro Could Launch Before Standard Xiaomi 18 Model, Tipster Claims
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.