Уровень 0 · материалов: 5
В кластер входят документы о технических уязвимостях, багах и брешах в безопасности программного обеспечения Apple, но не входят истории о блокировке аккаунтов разработчиков за нарушение правил.
Общие признаки: ошибки безопасности Apple, эксплойты в iOS и macOS, проблемы App Store, технические сбои в ПО Apple
Группа выше: Уязвимости конкретных продуктов и платформ
Смысл: The main idea is that a security vulnerability in iTunes allowed a malicious developer to steal money from users and manipulate App Store rankings, exposing flaws in Apple's vetting process and account security.
A developer hacked iTunes accounts to buy his own apps, stealing money from users and gaming the App Store charts, prompting warnings for users to secure their accounts.
Смысл: The main idea is that a trivial programming mistake—a redundant line of code—led to a massive security hole in Apple's encryption implementation, allowing unauthorized interception of 'secure' traffic.
A redundant 'goto fail' line in Apple's code bypassed SSL/TLS signature verification, enabling Man-in-the-Middle attacks on iOS and OS X.
Смысл: The text informs readers about a specific bug in the Mac App Store that allows users to obtain paid Apple software (iWork and Aperture) for free by updating an older trial version.
A Mac App Store bug allows users to upgrade trial versions of iWork and Aperture to full versions for free.
Смысл: The text warns about a critical remote exploit for the iPhone discovered by Charlie Miller, highlighting Apple's failure to patch a known vulnerability before its public disclosure at Black Hat 2009.
Hacker Charlie Miller threatened to release a universal SMS exploit for iPhones at Black Hat 2009, potentially triggering a global viral security crisis.
Смысл: The main idea is to demonstrate how security vulnerabilities in certificate validation allowed researchers to decode the proprietary communication protocol between the iPhone 4S and Siri servers, effectively enabling the use of Siri's speech recognition engine on non-Apple devices.
Applidium reverse-engineered the Siri protocol by bypassing HTTPS encryption via a custom root certificate, revealing the use of the ACE method, zlib compression, and Speex audio coding.