thewayne: (Default)
[personal profile] thewayne
Basically when iTunes launched in Windows, (prior to the 10.5.1 update) it would send an unencrypted HTTP request. If you controlled someone's network upstream of their computer, you could intercept this request and proffer an "update" that was malware that could give the government all sorts of information that you might rather they didn't get, including the ability to listen to Skype conversations before they are encrypted.

Just the thing if you're living in an Arab Spring country.

The sad thing is that Apple was informed of this flaw in 2008. They fixed it last week.

It only affected Windows users of iTunes (and probably, by extension, Safari) as the Mac OS-X updater is a more secure subsystem.

http://www.h-online.com/security/news/item/iTunes-security-vulnerability-had-been-present-for-over-three-years-1384718.html

http://apple.slashdot.org/story/11/11/25/1343201/itunes-flaw-allowed-spying-on-dissidents
This account has disabled anonymous posting.
(will be screened if not validated)
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org

June 2025

S M T W T F S
123456 7
8910 11121314
15 161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 18th, 2025 10:08 am
Powered by Dreamwidth Studios