It is UNSAFE to use Google, Skype, Microsoft and Yahoo on iOS 4.3 or Before

Discussion in 'iPhone' started by SomeDudeAsking, Mar 25, 2011.

    It is unsafe to use Google, Skype, Microsoft and Yahoo on iOS 4.3 or before if you use it check your e-mail, VOIP, or send anything sensitive when using iOS 4.3 or before because you are vulnerable to man in the middle attacks. Since iOS Safari and derived browsers have no means of updating trusted certificates or blacklisting them, you absolutely MUST upgrade to iOS 4.3.1 released today, which I believe should contain the blacklisted certificates.

    iOS 4.3.1 is *not* optional people, it is a security upgrade.
    I fail to see what this has to do with 4.3.1. These sites would have cleared authentication because they had valid ssl certificates.

    Care to elaborate?
  3. Ashin, Mar 25, 2011
    The security holes he speaks of are well documented, and this is why 4.3.1 has come out so fast without full beta testing cycles like normal.
  4. SomeDudeAsking, Mar 25, 2011
    The problem is that supposedly nefarious hackers for the "Iranian government", "Israel pertaining to be the Iranian government", or "China pertaining to be Israel pertaining to be Iran" hacked into one of the root authorities that make those SSL certificates and gave themselves valid working ones for Google, Skype, Microsoft, and Yahoo. That means in iOS 4.3 if you use Safari or any other Safari based brower (ie: all of them), you can get all your passwords, data, and communications stolen from those sites if the cellular network or wifi network you are on routes through one of their routers (last week, AT&T 3G data was routed through China for some time) because iOS 4.3 is now vulnerable to man in the middle attacks. iOS 4.3.1 should have the stolen certificates blacklisted so you wouldn't be vulnerable to these specific attacks. And attacks in the wild have already been spotted using these certificates, especially for Yahoo.
    Please post evidence that AT&T's 3G data was routed through china for some time last week.

    That defies even knowing how networking works.
    You should listen to me when I tell you something. I know more about this stuff than you do.
  8. SomeDudeAsking, Mar 25, 2011
    Then you don't know what man in the middle attacks are because if you do, you would realize the significance of the stolen SSL certificates from COMODO coupled with routing through foreign countries. iOS 4.3.1 should have blacklisted the stolen certificates to make these attacks not possible.
    I had to restrain myself from posting yesterday.. you are posting information you've found on the internet (granted, like most people) with little or no knowledge. If an SSL certificate can't be validated, what do you think happens?

    'Smart' people don't tell others how smart they are, it's usually based on their intellectual posts and/or evidence, unlike yourself reeling off links and as another user said commanding people.

    Also, have a guess how many people connect to i.e. Facebook without https, through Wifi networks, cellular etc. Easy interception. Maybe you should look into this!

    A quote from your link also has the interesting paragraph:
    Do you think this is any different to any other practice?

    So, how does this affect 4.3.1 in anyway, SomeDudeAsking?
    (in regards to the fact they were blacklisted without the need of iOS software (4.3.1)
    not only that, but I believe that only the Yahoo certificate was used for testing by the hackers. The other ones weren't released yet. And the have all been pulled by COMODO. 4.3.1 has nothing to do with this.
    Hey look! I can cut and paste, too!

    From the article:

    Facebook issued a statement that read:

    We are investigating a situation today that resulted in a small amount of a single carrier's traffic to Facebook being misdirected. We are working with the carrier to determine the cause of this error.

    Our initial checks of the latency of the requests indicate that no traffic passed through China.
    The X.X.1, X.X.2, etc. builds never have a beta cycle. They are just security updates and only fix minor bugs. They don't redo the public APIs.

