thewayne: (Default)
[personal profile] thewayne
Basically when iTunes launched in Windows, (prior to the 10.5.1 update) it would send an unencrypted HTTP request. If you controlled someone's network upstream of their computer, you could intercept this request and proffer an "update" that was malware that could give the government all sorts of information that you might rather they didn't get, including the ability to listen to Skype conversations before they are encrypted.

Just the thing if you're living in an Arab Spring country.

The sad thing is that Apple was informed of this flaw in 2008. They fixed it last week.

It only affected Windows users of iTunes (and probably, by extension, Safari) as the Mac OS-X updater is a more secure subsystem.

http://www.h-online.com/security/news/item/iTunes-security-vulnerability-had-been-present-for-over-three-years-1384718.html

http://apple.slashdot.org/story/11/11/25/1343201/itunes-flaw-allowed-spying-on-dissidents

Date: 2011-11-26 04:31 am (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
...and they just didn't think it was important?

Date: 2011-11-26 04:51 am (UTC)
From: [identity profile] thewayne.livejournal.com
There's a lot of speculation on why it took so long to get fixed, up to and including government conspiracy. The key word being speculation. Who knows if we'll ever really know why.

Date: 2011-11-26 07:57 am (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
I doubt we'll ever really know why. Too many possibilities for it being worse PR than it already is.

January 2026

S M T W T F S
    1 23
45678910
11121314151617
18192021222324
25262728293031

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 3rd, 2026 03:14 am
Powered by Dreamwidth Studios