pull down to refresh

This left the user vulnerable: an attacker with privileged network access could intercept the HTTP request and redirect the user to a phishing website
That's not a phishing attack. That sounds like a profound security hole in the TLS implementation.
reply
I think it’s MITM since they weren’t enforcing TLS to begin with
reply
Notably this is not the first time Apple has issues with checking identities on TLS initial connection. There was a famous bug years ago called "Goto Fail" where MacOS would just accept any signature/identity in certain cases.
Sometimes you just want to shake Apple management and scream: implement. basic. unit. tests. for. security. stuff. aaaaa.
reply
17 sats \ 0 replies \ @kepford 21h
Not surprised. Apple has never done a good job on their apps. There are good alternative third party apps that are open source as well.
reply
stackers have outlawed this. turn on wild west mode in your /settings to see outlawed content.