It is unfortunate that Apple are getting so much flack for this bug. Yes it is bad and blatantly obvious (or would have been if they just decent testing or used good analysis tools). But this kind of vulnerability is pervasive, depressingly so. See https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html which is a paper from 2012 modestly titled "the most dangerous code in the world".
Comments 1
Reply
Leave a comment