pull down to refresh
114 sats \ 2 replies \ @zuspotirko 18h \ on: Apple's Password app was vulnerable to phishing attacks for 3 months post launch security
That's not a phishing attack. That sounds like a profound security hole in the TLS implementation.
I think it’s MITM since they weren’t enforcing TLS to begin with
reply
Notably this is not the first time Apple has issues with checking identities on TLS initial connection. There was a famous bug years ago called "Goto Fail" where MacOS would just accept any signature/identity in certain cases.
Sometimes you just want to shake Apple management and scream: implement. basic. unit. tests. for. security. stuff. aaaaa.

reply