{"id":1283,"date":"2014-02-24T09:49:52","date_gmt":"2014-02-24T15:49:52","guid":{"rendered":"https:\/\/sodpit.com\/?p=1283"},"modified":"2014-02-26T19:27:31","modified_gmt":"2014-02-27T01:27:31","slug":"goto-fail-major-security-flaw-in-apple-ios-and-osx","status":"publish","type":"post","link":"https:\/\/sodpit.com\/?p=1283","title":{"rendered":"goto fail; Major Security Flaw in Apple iOS and OSX"},"content":{"rendered":"<p><a href=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge.jpg\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1285\" data-permalink=\"https:\/\/sodpit.com\/?attachment_id=1285\" data-orig-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge.jpg\" data-orig-size=\"640,360\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge-300x168.jpg\" data-large-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge.jpg\" class=\"alignnone size-full wp-image-1285\" alt=\"\" src=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge.jpg\" width=\"640\" height=\"360\" srcset=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge.jpg 640w, https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/ku-xlarge-300x168.jpg 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><span style=\"line-height: 1.5;\">If you are an Apple user, stop what you are doing right now, disconnect from WiFi, and take 5 minutes to read everything on this page.<\/span><\/p>\n<p>I read several articles yesterday about a serious security flaw in Apple&#8217;s iOS (iPhone, iPad, etc.) and OSX (Mac) that has existed since September&#8230; of 2012. Internally Apple has been well aware of this problem for almost a year and a half (17 months), yet for some reason (shocker) they chose not to disclose this flaw publicly&#8230; so most users never knew there was a problem.<\/p>\n<p>The flaw allows a hacker to intercept all of your data even though you might see a secure link (padlock) icon which means SSL (Secure Socket Layer) is enabled. This flaw can normally only be exploited when you (and a hacker) are on a public WiFi hotspot and it only affects iOS 6.0 through 7.0.5 on iPhones and Macs running OSX. There is a fix for iOS but currently there is no fix for Mac OSX.<\/p>\n<p>Let&#8217;s just <del>hope<\/del>\u00a0pray you haven&#8217;t been checking your bank account at Starbucks or Facebooking at McDonald&#8217;s.<\/p>\n<p>iPhone users: until the iOS 7.0.6 update is installed please do NOT use WiFi in any public places.<\/p>\n<p>Mac users: avoid using publicly accessible WiFi until Apple releases an update.<\/p>\n<p><span style=\"line-height: 1.5;\">Go to your iPhone\/iPad and open Settings &gt; General &gt; About. Scroll down to see your device&#8217;s version information. If your device is running anything between 6.0 and 7.0.5 you need to upgrade to 7.0.6 NOW. To upgrade, connect to your personal or trusted WiFi hotspot (only use WiFi at your house or work) and open Settings &gt; General. You should see an available upgrade. Install it immediately.<\/span><\/p>\n<p><span style=\"line-height: 1.5;\">Please send a link to this page (using either of the two links below) to friends and family who might be using Apple products:<\/span><\/p>\n<p><a href=\"https:\/\/sodpit.com\/2014\/02\/24\/goto-fail-major-security-flaw-in-apple-ios-and-osx\/\" target=\"_blank\">https:\/\/sodpit.com\/2014\/02\/24\/goto-fail-major-security-flaw-in-apple-ios-and-osx\/<\/a><\/p>\n<p><a href=\"http:\/\/j.mp\/OtJHKI\" target=\"_blank\">http:\/\/j.mp\/OtJHKI<\/a><\/p>\n<p>Update #1 &#8211; 2\/24\/14 &#8211; Mostly for OSX users:<\/p>\n<p><a href=\"http:\/\/www.engadget.com\/2014\/02\/21\/apple-ssl-update\/\" target=\"_blank\">Apple quietly issues iOS update to patch faulty SSL authentication (update 2: OS X patch coming)<\/a><\/p>\n<p><a href=\"http:\/\/macdailynews.com\/2014\/02\/22\/protect-a-mac-from-the-ssl-tls-security-bug-until-fix-arrives\/\" target=\"_blank\"><span style=\"line-height: 1.5;\">Protect a Mac from the \u2018GotoFail\u2019 SSL \/ TLS security bug (until fix arrives)<\/span><\/a><\/p>\n<p><a href=\"http:\/\/osxdaily.com\/2014\/02\/22\/protect-mac-ssl-tls-security-bug\/\" target=\"_blank\"><span style=\"line-height: 1.5;\">Help Protect a Mac from the SSL \/ TLS Security Bug (Until a Fix Arrives)<\/span><\/a><\/p>\n<p><span style=\"line-height: 1.5;\">Hint&#8230; the next two links should be clicked from your Mac: Use <a href=\"http:\/\/support.mozilla.org\/en-US\/kb\/install-firefox-mac\" target=\"_blank\">Mozilla Firefox for OSX<\/a>\u00a0or <a href=\"http:\/\/www.google.com\/mac\/\" target=\"_blank\">Google Chrome for OSX<\/a>\u00a0until an OSX patch is released.<\/span><\/p>\n<p>Update #2 &#8211; 2\/26\/14: Mac OSX Patch Finally Available!<\/p>\n<p><a href=\"http:\/\/www.apple.com\/osx\/how-to-upgrade\/\" target=\"_blank\">OSX Mavericks 10.9.2 Upgrade<\/a><\/p>\n<p><a href=\"http:\/\/www.zdnet.com\/apple-releases-os-x-10-9-2-update-patches-severe-ssl-bug-7000026765\/\" target=\"_blank\">Apple releases OS X 10.9.2 update, patches severe SSL bug<\/a><\/p>\n<p><a href=\"http:\/\/support.apple.com\/kb\/HT6150\" target=\"_blank\">About the security content of OS X Mavericks v10.9.2 and Security Update 2014-001<\/a><\/p>\n<p><span style=\"line-height: 1.5;\">Resources:<\/span><\/p>\n<p><a href=\"http:\/\/gizmodo.com\/why-apples-huge-security-flaw-is-so-scary-1529041062?utm_campaign=socialflow_gizmodo_facebook&amp;utm_source=gizmodo_facebook\" target=\"_blank\">Why Apple&#8217;s Recent Security Flaw Is So Scary<\/a><\/p>\n<p><a href=\"http:\/\/www.slate.com\/blogs\/the_slatest\/2014\/02\/22\/apple_security_flaw_makes_iphones_ipads_macs_vulnerable_to_attack.html\" target=\"_blank\">Apple Security Flaw Is \u201cAs Bad As You Could Imagine\u201d<\/a><\/p>\n<p><a href=\"http:\/\/arstechnica.com\/security\/2014\/02\/extremely-critical-crypto-flaw-in-ios-may-also-affect-fully-patched-macs\/\" target=\"_blank\">Extremely critical crypto flaw in iOS may also affect fully patched Macs<\/a><\/p>\n<p><a href=\"https:\/\/www.google.com\/search?q=ios+flaw&amp;oq=ios+flaw&amp;aqs=chrome..69i57j0l5.3840j0j7&amp;sourceid=chrome&amp;espv=210&amp;es_sm=122&amp;ie=UTF-8#q=ios+flaw&amp;safe=off&amp;tbm=nws\" target=\"_blank\">More&#8230;<\/a><\/p>\n<p>goto fail;<\/p>\n<p>A sample of the code showing where the problem occurred.<\/p>\n<p>fail:<\/p>\n<p><a href=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1284\" data-permalink=\"https:\/\/sodpit.com\/?attachment_id=1284\" data-orig-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail.png\" data-orig-size=\"640,325\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail-300x152.png\" data-large-file=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail.png\" class=\"alignnone size-full wp-image-1284\" alt=\"\" src=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail.png\" width=\"640\" height=\"325\" srcset=\"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail.png 640w, https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/goto-fail-300x152.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>The second instance of &#8220;goto fail;&#8221; (above) is what caused the flaw. Supposedly it was accidentally copy\/pasted before the OS was released.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you are an Apple user, stop what you are doing right now, disconnect from WiFi, and take 5 minutes to read everything on this page. I read several articles yesterday about a serious security flaw in Apple&#8217;s iOS (iPhone, iPad, etc.) and OSX (Mac) that has existed since September&#8230; of 2012. Internally Apple has &hellip; <a href=\"https:\/\/sodpit.com\/?p=1283\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">goto fail; Major Security Flaw in Apple iOS and OSX<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1286,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[4],"tags":[14,10],"class_list":["post-1283","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-main","tag-apple","tag-featured"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/sodpit.com\/wp-content\/uploads\/2014\/02\/1580169x.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p2FmUa-kH","jetpack_likes_enabled":false,"_links":{"self":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts\/1283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1283"}],"version-history":[{"count":5,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts\/1283\/revisions"}],"predecessor-version":[{"id":1299,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/posts\/1283\/revisions\/1299"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=\/wp\/v2\/media\/1286"}],"wp:attachment":[{"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sodpit.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}