Hacker News new | ask | show | jobs
by prehkugler 4499 days ago
> I see five levels of paranoia: ... 5. Apple, complicit with the NSA, added it.

While it seems possible that Apple conspired with the NSA to add a security hole in SecureTransport, I doubt it. According to sources in the article, this bug was introduced in iOS6; and I haven't heard a mention of it until yesterday, despite it being open-sourced (http://opensource.apple.com/source/Security/Security-55471/l...).

Since nobody was raging on the internet about this bug, I see it as a good-faith effort by Apple to fix a bug that they've just discovered.

1 comments

Consider this: it was only at the end of December when Appelbaum showed some documents about iPhones being hacked by the NSA, and it made a pretty big splash in the media. I think it even forced Apple to respond at the time. Especially if this was open sourced, and everyone could see they fixed it, they wouldn't immediately try to plug the bug/backdoor after that piece of news came out, especially with such a weird bug.
Those documents were about NSA bein able to plant a malware on a iPhone (1st generation) when given physical access. I would say it has nothing to do with this TLS bug