The latest vulnerability in Apple's iOSand OS X that was revealed in recent days may have been something we should have expected, especially those involved in technology. If we carefully observe the timeline of the SSL vulnerability in iOS and at the same time, Apple's "addition" to the NSA's PRISM program, we will probably encounter evidence that will make us reconsider the way we view the big tech company.
Saturday, February 22, 2014
Jeffrey Grossman, on Twitter:
[tweet_embed id=437273379855667201]
I have confirmed that the SSL vulnerability “came” with iOS 6.0. It was not present in 5.1.1 and is present in 6.0.
iOS 6.0 was released on September 24, 2012.
According to slide 6 of the leaks that presented the NSA's PRISM program, Apple joined the program in October 2012.
Do the above facts prove anything? Are they purely circumstantial?
It would certainly be interesting to know who added the vulnerability code to the operating system. Conspiratorially, one could assume that the NSA planted the bug, via an employee, as daringfireball. Maybe. Harmless, Occam's Razor explanation states that the vulnerability was inadvertently introduced by an Apple technician. It sounds like the kind of vulnerabilities that could arise if something in the merge goes wrong, when copying and pasting code.
The NSA didn’t even need to read the source code to find the vulnerability. All it would have to do was run automated tests using forged certificates with each new version of the OS. Apple releases iOS, and the automated tests with the NSA’s forged certificates find the vulnerability, and boom, Apple is “added” to PRISM. It’s a pretty good story, and quite convenient for Apple, since no one can blame it.
It may be so, but it may not be so..
Of course, many thoughts and paranoias arise..
- The NSA was not aware of this vulnerability.
- The NSA knew about it, but never exploited it.
- The NSA knew about it and exploited it.
- The NSA itself planted the vulnerability.
- Apple is complicit with the NSA.
The first case is the most convenient for everyone, it is the most optimistic scenario that exonerates everyone, but then why Apple added to PRISM? If the second case is true, this means that it is possible that there is another vulnerability that remains open, otherwise (let's go again) how Appleadded to PRISM?
The third case is what we call the “clear” case. There is no doubt that Apple is on PRISM, but for it to be anything, it would have to have given, regardless of the company’s categorical statements, that all of this is lies and fabrications.

