bagder,
@bagder@mastodon.social avatar

the incident 12604 - or why CA cert verification is unreliable with curl on apple OS

https://daniel.haxx.se/blog/2024/03/08/the-apple-curl-security-incident-12604/

bagder,
@bagder@mastodon.social avatar
krinkle, (edited )
@krinkle@fosstodon.org avatar

deleted_by_author

  • Loading...
  • BasieP,

    @krinkle @bagder or the nsa for that matter...

    jevinskie,
    @jevinskie@mastodon.social avatar

    @bagder they should just put that “extended behavior” behind a new command line flag/environment variable.

    bjst,
    @bjst@mastodon.social avatar

    @bagder
    Minor clarification nitpick: It's not unreliable with "curl on an apple OS", it's unreliable with "apple's build of curl".

    slink, (edited )
    @slink@fosstodon.org avatar

    @bagder daniel, i respect and admire you for your considerate and respectful behavior, but would it be appropriate to point out the potential of unintended interception more clearly in this case?
    i mean, the title could also have been "apple does not want you to notice when you are being wiretapped", or do i miss any other precaution they took for this not to happen?

    also, i find it shocking that i don't find this shocking any more… 🤯

    bagder,
    @bagder@mastodon.social avatar

    @slink it is not in my interests to be alarmist. I believe I describe the problems in the blog post.

    slink,
    @slink@fosstodon.org avatar

    @bagder you do indeed, thank you.

    schamschula,
    @schamschula@mastodon.social avatar

    @bagder Good to know! I generally build and install curl under #MacPorts with the gnutls variant. However, there is no variant that builds against Apple's flavor of LibreSSL. The default build may use the MacPorts version of LibreSSL, if installed in place of OpenSSL.

    bagder,
    @bagder@mastodon.social avatar

    @schamschula turns out to be very clever!

    bagder,
    @bagder@mastodon.social avatar

    if doing a tool working everywhere is not already hard enough, some vendors decide to actively work against us and sneakily add backdoor functionality so that curl does not work the same way on their platforms. So now our documentation is wrong. But only if you use the curl bundled by Apple with macOS. If you get curl with homebrew on the same machine, it will act as documented..

  • All
  • Subscribed
  • Moderated
  • Favorites
  • apple
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • provamag3
  • ethstaker
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • tacticalgear
  • anitta
  • megavids
  • Leos
  • cisconetworking
  • JUstTest
  • lostlight
  • All magazines