thewayne: (Default)
The Wayne ([personal profile] thewayne) wrote2011-11-25 10:44 am
Entry tags:

Apple iTunes for Windows update flaw allowed malware infiltration

Basically when iTunes launched in Windows, (prior to the 10.5.1 update) it would send an unencrypted HTTP request. If you controlled someone's network upstream of their computer, you could intercept this request and proffer an "update" that was malware that could give the government all sorts of information that you might rather they didn't get, including the ability to listen to Skype conversations before they are encrypted.

Just the thing if you're living in an Arab Spring country.

The sad thing is that Apple was informed of this flaw in 2008. They fixed it last week.

It only affected Windows users of iTunes (and probably, by extension, Safari) as the Mac OS-X updater is a more secure subsystem.

http://www.h-online.com/security/news/item/iTunes-security-vulnerability-had-been-present-for-over-three-years-1384718.html

http://apple.slashdot.org/story/11/11/25/1343201/itunes-flaw-allowed-spying-on-dissidents
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)

[personal profile] silveradept 2011-11-26 04:31 am (UTC)(link)
...and they just didn't think it was important?

[identity profile] thewayne.livejournal.com 2011-11-26 04:51 am (UTC)(link)
There's a lot of speculation on why it took so long to get fixed, up to and including government conspiracy. The key word being speculation. Who knows if we'll ever really know why.
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)

[personal profile] silveradept 2011-11-26 07:57 am (UTC)(link)
I doubt we'll ever really know why. Too many possibilities for it being worse PR than it already is.