26: Episode 26 - Worm in the Apple

Published: March 7, 2014, 8 p.m.

The News\n\n\n\n OmniGroup Open Sources OmniGraphSketcherFree\n Flesky, a keyboard app with an SDK\n StackMob sudden end of life\n New Apple device configuration options\n\n\n\nTweet Shoutouts\n\n\n\n @marksands - Unfair to call Flappy Bird Crappy Bird?\n\n\n\nThe Discussion\n\n\n\n Worm in the Apple,\xa0Apple TLS bug - Discussion of what this means to support of iOS 6.\n\n Actual Source\n What is it? Description of bug, Deep Dive Description\n\n \u201cNote the two goto fail lines in a row. The first one is correctly bound to the if statement but the second, despite the indentation, isn't conditional at all. The code will always jump to the end from that second goto, err will contain a successful value because the SHA1 update operation was successful and so the signature verification will never fail.\u201d\n Lack of curly braces on single line conditional to blame, or lack of testing the code?\n\n\n What does it mean for users?\n How could this have happened and gone undiscovered for so long?\n\n\n Background User Input recording discovered - Reported Monday night. Ars Article\n\n Can you actually infer keyboard touch events?\n Potential attackers can use such information to reconstruct every character the victim inputs\n\n Note that the demo exploits the latest 7.0.4 version of iOS system on a non-jailbroken iPhone 5s device successfully\n\n\n The only way to prevent attacks is to open the iOS task manager and stop questionable apps from running in the background\n\n\n\n\n\nPicks\n\n\nJohn (@johnsextro)\n\n\n MindNode for mind mapping on the Mac and iPad. Allows for document sharing via Dropbox and MyMindNode\n\n\n\nJoe Hainline (@josephhainline)\n\n\n Rookiesapp.com of course!\n\n\n\nNeem Serra (@teamneem)\n\n\n Ray Wenderlich\u2019s blog - Simplified tutorials that are easy to follow with complex results\n Xscope - measuring, inspecting & testing on-screen graphics and layouts, $30 but very helpful for making apps match the mocks. \xa0Cool color blindness testing!\n\n\n\nAdam Hitt\n\n\n bitfulsoftware.com - Fluxboard - Kanban board for your GitHub issues.\n \nhttps://projecteuler.net - Ultimate Code Kata resource!