[cryptography] OT: DigiNotar Certificates Are Pulled, but Not on Smartphones

Steven Bellovin smb at cs.columbia.edu
Sat Sep 10 11:09:10 EDT 2011


On Sep 10, 2011, at 3:30 11AM, Jeffrey Walton wrote:

> On Thu, Sep 8, 2011 at 1:19 AM, Jeffrey Walton <noloader at gmail.com> wrote:
>> (As far as I know, Apple has not fixed their desktop/server software
>> either. The folks that have to deal with it are still hacking
>> solutions [1]. Its not a big surprise, since Apple's PKI appears to be
>> generally broken from a programmer's perspective [2]).
>> 
> 
> Apple finally got around to DigiNotar on 10.6 and 10.7: "Security
> Update 2011-005", http://support.apple.com/kb/HT4920.

Yes -- an update that for some really strange reason requires a reboot.


		--Steve Bellovin, https://www.cs.columbia.edu/~smb








More information about the cryptography mailing list