GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 01-Feb-2024 18:25:34 JSTRyan Castellucci :nonbinary_flag:Ryan Castellucci :nonbinary_flag:
    • Matthew Green

    It's been ten years, so a short story about the "gotofail" bug.

    Someone came to me about a catastrophic vulnerability in Apple's TLS implementation.

    I shit you not, they'd overheard someone at a bar drunkenly bragging about how they were going to sell it to a FVEY intelligence agency for six figures.

    They didn't know exactly what it was, just some vague details and the key point is that it allowed use of the real certificate.

    This was enough for me to find the bug (yay open source), which would go on to be known as "gotofail", and produce a working exploit in less than a day.

    The details were anonymously back channelled to Apple, who released a fix.

    @matthew_d_green posted on Twitter about it, concerned by the Apple's vague release notes.

    I used a burner phone to share the details with him anonymously.

    Then everyone forgot about the whole thing because heartbleed.

    ¯_(ツ)_/¯

    In conversationabout a year ago from infosec.exchangepermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.