Apple promises fix “very soon” for Macs with failed encryption
(Reuters) - Apple Inc said on Saturday it would issue a software update “very soon” to cut off the ability of spies and hackers to grab email, financial information and other sensitive data from Mac computers.
Reuters Joseph Menn
Context & Ripple Effects
The Mac promise lands a day after Apple shipped iOS 7.0.6 and 6.1.6 on February 21 to close an SSL/TLS snooping bug that put millions of iPhone users at risk of communications hijacking — leaving OS X 10.9 owners as the exposed population, with no desktop patch yet shipped. The story travelled widely on pickup: Wired traced the iOS failure to a single misplaced 'goto' statement, while John Gruber's Daring Fireball framed commentary around the awkward timing of the disclosure alongside Apple's reported addition to the NSA's PRISM program.
That surveillance backdrop matters for how the promise reads: Reuters reports Apple committing to cut off spies and hackers from email, financial information and other sensitive Mac data 'very soon,' a vow made under post-Snowden scrutiny where patch latency itself becomes the story.
First-order effects
- OS X users — especially anyone on shared or public networks running Safari and Mail — remain interceptable until the update ships, since the confirmed flaw lets a network-positioned attacker grab email and financial data mid-session.
- Apple's credibility is staked on delivery speed: having fixed iOS within roughly a day of disclosure while the desktop waits, any further slippage on the Mac patch invites exactly the criticism its iOS timeline just deflected.
Second-order effects
- Security researchers now have proof Apple's TLS implementation failed at a single line of code, so audit pressure will spread from Safari to every Apple surface sharing that SSL stack — Mail, iMessage and other built-in clients become the obvious next places to look.
- Rival platforms gain a talking point: Google and Microsoft can contrast their own TLS patch cadence against Apple's mobile-fixed-desktop-waiting gap when pitching enterprise buyers deciding which ecosystem to standardize on.
Third-order effects
- If the pattern holds — vulnerability disclosed, mobile patched fast, other platforms trailing — vendors face structural pressure to unify patch rollout across all their operating systems simultaneously rather than per-platform, because attackers simply pivot to whichever device lags.
- Post-Snowden, encryption failures in consumer platforms are shifting from technical footnotes to board-level reputational events, raising the odds that regulators and enterprises demand published patch-latency commitments as a condition of trust.
The trend: Surveillance-era scrutiny is forcing consumer platform makers into rapid-response TLS patching across every OS they ship, turning patch latency itself into a competitive metric.
Related: Apple Inc · Mac · Information-access conflict surface
Related Coverage
- Behind iPhone's Critical Security Bug, a Single Bad ‘Goto’ Wired · Kevin Poulsen
- On the Timing of iOS's SSL Vulnerability and Apple's ‘Addition’ to the NSA's PRISM Program Daring Fireball · John Gruber
- ZDNet ZDNet · Zack Whittaker
- AppleInsider AppleInsider
- Softpedia News Softpedia News · Filip Truta
- iPhone Hacks iPhone Hacks · Jason
- Computerworld Computerworld
- SlashGear SlashGear · Chris Davies
- The Register The Register · Chris Williams
- PBS PBS · Hari Sreenivasan
- Ars Technica Ars Technica · Dan Goodin
- ImperialViolet ImperialViolet · Adam Langley
- Gotta Be Mobile Gotta Be Mobile · Warner Crocker
- Gizmorati Gizmorati · Eric Brown
- iMore iMore · Nick Arnott
- Reuters Reuters · Joseph Menn
- TechCrunch TechCrunch · Jonathan Shieber
- Threatpost Threatpost · Dennis Fisher
- Mac|Life Mac|Life · Leif Johnson
- CSO Blogs CSO Blogs · Dave Lewis
- iDownloadBlog.com iDownloadBlog.com iDownloadBlog.com iDownloadBlog.com · Cody Lee
- Security Watch Security Watch · Fahmida Y. Rashid
- Daring Fireball Daring Fireball · John Gruber
- Graham Cluley Graham Cluley
- MacRumors MacRumors · Juli Clover
- Slate Slate · Daniel Politi
- Nelson's Weblog Nelson's Weblog · Nelson Minar
- Geeky Gadgets Geeky Gadgets · Hammad Saleem
- 9to5Mac 9to5Mac · Jordan Kahn
- Vacuum Vacuum · Edward Vielmetti
- Engadget Engadget · Sean Buckley
- The Loop The Loop · Dave Mark
- The Next Web The Next Web · Josh Ong
- Breaking Apple News … Breaking Apple News … · Erica Sadun
- @mattblaze @mattblaze · Matt Blaze
- @grittygrease @grittygrease · Nick Sullivan
- @ashk4n @ashk4n · Ashkan Soltani
- @musclenerd @musclenerd
- @davewiner @davewiner · Dave Winer
- @kentinpublic @kentinpublic · Kent Hudson
- @billwscott @billwscott · Bill Scott
- @sdkstl @sdkstl · Staci D Kramer
- Gizmodo Gizmodo · Brian Barrett
- Fortune Fortune · Philip Elmer-DeWitt
- Re/code Re/code · James Temple
- Forbes Forbes · Andy Greenberg
- iPhone in Canada Blog iPhone in Canada Blog · Gary Ng
- Securosis Highlights Securosis Highlights · Rich
- Nadim Kobeissi Nadim Kobeissi
- CNET CNET · Richard Nieva
- @matthew_d_green @matthew_d_green · Matthew Green
- @agl__ @agl__ · Adam Langley
- @tomwarren @tomwarren · Tom Warren
- @csoghoian @csoghoian · Christopher Soghoian
- View article ZDNet
- View article AppleInsider
- View article Softpedia News
- View article iPhone Hacks
- View article Computerworld
- View article SlashGear
- View article The Register
- View article PBS
- View article Ars Technica
- View article ImperialViolet
- View article ZDNet
- View article Gotta Be Mobile
- View article Gizmorati
- View article iMore
- View article Reuters
- View article TechCrunch
- View article Threatpost
- View article Mac|Life
- View article CSO Blogs
- View article iDownloadBlog.com …
- View article Security Watch
- View article Daring Fireball
- View article Graham Cluley
- View article MacRumors
- View article Slate
- View article Nelson's Weblog
- View article Geeky Gadgets
- View article 9to5Mac
- View article Vacuum
- View article Engadget
- View article The Loop
- View article The Register
- View article The Next Web
- View article Breaking Apple News …
- View article @mattblaze
- View article @grittygrease
- View article @ashk4n
- View article @musclenerd
- View article @davewiner
- View article @kentinpublic
- View article @billwscott
- View article @sdkstl
- View article Gizmodo
- View article Fortune
- View article Re/code
- View article Forbes
- View article iPhone in Canada Blog
- View article ZDNet
- View article Securosis Highlights
- View article Nadim Kobeissi
- View article iPhone Hacks
- View article CNET
- View article @matthew_d_green
- View article @agl__
- View article @matthew_d_green
- View article @tomwarren
- View article @matthew_d_green
- View article @matthew_d_green
- View article @matthew_d_green
- View article @csoghoian