TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Check if your browser is vulnerable to the Apple SSL bug

118 pointsby cantfindmypassabout 11 years ago

16 comments

ef4about 11 years ago
Why the hell would Apple publish the vulnerability & fix for iOS without a concurrent update to OS X?!
评论 #7282649 未加载
评论 #7283078 未加载
评论 #7282369 未加载
评论 #7283156 未加载
评论 #7285557 未加载
评论 #7283742 未加载
ef4about 11 years ago
So if you&#x27;re on Mavericks and left hanging, there are some evasive actions you can take.<p>As others have pointed out, Firefox and Chrome are not vulnerable. But what else may be relying on the system SSL implementation? Your IM client? Various software updaters? Dropbox? Skype? Etc.<p>Rather than guess, I&#x27;m whitelisting only the things I trust. I&#x27;m using the pf firewall to block all outbound connections other than DNS and SSH, using SSH to open a SOCKS proxy tunnel, and configuring Firefox to use the proxy (<i>not</i> via the system proxy settings -- via Firefox&#x27;s own proxy config, so other apps don&#x27;t know about it and can&#x27;t get out).<p>A simpler solution for those who want to buy a commercial product would be to install Little Snitch and start with a completely empty list of approved apps, then turn on only Firefox.
评论 #7282836 未加载
评论 #7288656 未加载
评论 #7285559 未加载
allochthonabout 11 years ago
It&#x27;s becoming quite a chore to keep your computer and online accounts secure. I&#x27;m in the industry; anyone who is not is probably a babe in the woods these days.
评论 #7283045 未加载
评论 #7283067 未加载
bclabout 11 years ago
You can already do this here - <a href="https://www.imperialviolet.org:1266/" rel="nofollow">https:&#x2F;&#x2F;www.imperialviolet.org:1266&#x2F;</a><p>On OSX Firefox and Chrome fail and Safari happily loads it. Yay for not using system crypto libraries.
评论 #7282265 未加载
djaoabout 11 years ago
Anyone who thinks Chrome and Firefox are safe from this bug doesn&#x27;t understand the issue. SecureTransport is used for updating software. So an attacker could trick you into installing a malicious update to Chrome, FireFox, or for that matter anything on your system. They could even slip in malware under the guise of a patch that purportedly fixes this bug. Using alternative browsers does NOT completely protect you.
评论 #7285698 未加载
firstplanthendoabout 11 years ago
Using the program Little Snitch on OS X 10.8 now to block everything except Firefox (recommended by u&#x2F;ef4 here)- successfully helped Safari pass this browser test.<p>Can anyone else comment on if this is a decent solution?
评论 #7283158 未加载
评论 #7284255 未加载
评论 #7283478 未加载
bsenftnerabout 11 years ago
I&#x27;m seeing a positive (yes the bug is there) on all my Apple devices, including my OSX laptops - laptop sees the bug IF and only IF I browse using Safari. Chrome and FF browse to your page fine on the laptop.<p>I&#x27;ve not seen any information about fixing this issue on OSX. Have I just missed it in the noise about the iOS fix?
评论 #7282255 未加载
评论 #7282306 未加载
userbinatorabout 11 years ago
I use a filtering proxy which uses OpenSSL and it just reports &quot;socket error&quot; in the log and retries the connection around a dozen times before it gives up, so it seems I&#x27;m not vulnerable; non-Apple software isn&#x27;t affected by this?
mirkulesabout 11 years ago
Can anyone confirm this on an iOS 6 device? I don&#x27;t have of those anymore. Good news is iPad running 5.1.1 is not affected, which <i>almost</i> leads me to believe this vuln was introduced with iOS 7
评论 #7283457 未加载
评论 #7283055 未加载
评论 #7283074 未加载
评论 #7283366 未加载
Jayschwaabout 11 years ago
For HTTPS clients that don&#x27;t execute Javascript (e.g. curl), GET <a href="https://gotofail.com:1266/" rel="nofollow">https:&#x2F;&#x2F;gotofail.com:1266&#x2F;</a>
评论 #7283171 未加载
oneplusoneabout 11 years ago
OSX 10.8.4 fails correctly. Was this bug introduced with Mavericks?
评论 #7282479 未加载
mh-about 11 years ago
Safari fails on 10.9.1.
arochabout 11 years ago
I can confirm that this is fixed in 10.9.2 (Since the first build of it). From the looks of things (and some friends in the Mavericks dev group), the final 10.9.2 should be dropping very soon
评论 #7283242 未加载
评论 #7283515 未加载
rasengan0about 11 years ago
OS X 10.7.5 passes; y&#x27;all should downgrade ;-)
anoncowabout 11 years ago
why does it say my browser is vulnerable? Using Ucbrowser on lumia.
nraynaudabout 11 years ago
I get the red &quot;PATCH IMMEDIATELY&quot; in safari, where is the patch??? after a bit of research this looks like a good old UX fail since there is no patch yet anyways. Don&#x27;t write something in red if there is no path to a solution.
评论 #7283798 未加载
评论 #7283968 未加载
评论 #7283695 未加载