TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

About the security content of iOS 9.3

52 pointsby woosterabout 9 years ago

7 comments

jgrahamcabout 9 years ago
Waiting for the paper on this:<p><pre><code> Impact: An attacker who is able to bypass Apple&#x27;s certificate pinning, intercept TLS connections, inject messages, and record encrypted attachment- type messages may be able to read attachments Description: A cryptographic issue was addressed by rejecting duplicate messages on the client. CVE-2016-1788 : Christina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers, and Michael Rushanan of Johns Hopkins University</code></pre>
评论 #11332413 未加载
mhwabout 9 years ago
Hmm:<p><pre><code> CVE-2016-1752 : CESG CVE-2016-1750 : CESG </code></pre> I wonder if that&#x27;s &lt;<a href="https:&#x2F;&#x2F;www.cesg.gov.uk&#x2F;&gt;" rel="nofollow">https:&#x2F;&#x2F;www.cesg.gov.uk&#x2F;&gt;</a>, which is &quot;the Information Security Arm of GCHQ&quot;. If so I guess we should be thankful that they saw these vulnerabilities is a risk rather than an opportunity.
评论 #11333592 未加载
kabdibabout 9 years ago
Apple&#x27;s basically saying &quot;Here are a bunch of bugs <i>that are not fixed in the version of the phone the FBI has</i>. You don&#x27;t need us, or source code, or anything other than to hire someone to take advantage of these holes. Go away.&quot;<p>Nice timing.<p>Probably pissed off a bunch of the intelligence community today.
abritishguyabout 9 years ago
So many memory corruption issues, I&#x27;d like to think in 5&#x2F;10 years time this would be solved and everything written in a safe language but maybe I&#x27;m being optimistic.
评论 #11331772 未加载
评论 #11332260 未加载
daenneyabout 9 years ago
&quot;This issue was addressed through improved input validation.&quot; Valuable refresher for everyone.
brokentoneabout 9 years ago
Is the big security roll up here due to external or internal scrutiny of iOS security spawned by the FBI inquiry perhaps?
评论 #11332786 未加载
评论 #11333702 未加载
kevincoxabout 9 years ago
Am I reading this wrong or does it not say which devices received fixes? Or is it not including which devices were affected?
评论 #11334934 未加载
评论 #11333137 未加载
评论 #11334937 未加载