Re: [Full-disclosure] Apple SSL fail

2014-02-22 Thread Reed Black
More specifically: https://www.imperialviolet.org/2014/02/22/applebug.html Charitably, it looks like a merge fail. Uncharitably, it's moderately sneaky. On Sat, Feb 22, 2014 at 6:47 AM, imipak wrote: > As no-one else seems to have mentioned it, I'll just leave this here: > > > http://www.zdne

[Full-disclosure] Apple SSL fail

2014-02-22 Thread imipak
As no-one else seems to have mentioned it, I'll just leave this here: http://www.zdnet.com/major-apple-security-flaw-patch-issued-users-open-to-mitm-attacks-726624/ \a -- wake up the past and tell it to stay away ___ Full-Disclosure - We be