• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

2

Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster

3

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

1

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

2

Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster

3

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

Apple’s security bug: Five NSA conspiracy theories

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
February 23, 2014, 2:14 PM ET
Add Fortune on Google for similar content.

SOUCE: NSA via Edward Snowden

FORTUNE — You don’t have to put on a tin hat to find the timing of the “Apple” entry in the attached Powerpoint slide suspicious, although a tin hat probably helps.

The slide, marked TOP SECRET, was one of the first documents leaked to The Guardian and the Washington Post by NSA whistleblower Edward Snowden last June. It lays out the timeline for when the U.S. government’s top cyberspies gained access to user data on the servers of the major U.S. Internet companies: Microsoft (MSFT) in 2007, Google (GOOG) in 2009, AOL (AOL) in 2011 and Apple (AAPL) in Oct. 2012.

What makes that last entry so intriguing to conspiracy theorists is what computer experts discovered over the weekend about the security hole Apple patched — at least in part — on Friday. By comparing the original code to Apple’s fix, Adam Langley, a web encryption expert at Google, was able to pinpoint the problem.

The culprit, if you care about such things, was a short line of code — a “goto fail” without a corresponding “if” clause (see below) — in the software Apple uses to make sure a computer you are connecting to securely over the Internet is the computer it claims to be. This is critical when the website belongs to, say, a bank.

“It’s as bad as you could imagine, that’s all I can say,” Johns Hopkins University cryptography professor Matthew Green told Reuters. 

[Readers who know more about this subject than I disagree. “It takes an elaborate hoax to exploit,” henry3dogg wrote in the comment stream to an earlier version of the story. “Nobody is going to benefit from it accidentally. And it is unlikely that anyone would set up such an elaborate hoax, unless they knew that the loop hole existed.”]

Anyway, here’s where the timing gets interesting. According to Jeffrey Grossman, whose Confide iPhone app depended on Apple’s security protocols to deliver “off the record conversations,” the bug appeared in iOS 6.0 and was not present in iOS 5.11.

iOS 6.0 was released in September 2012, just before the NSA penetrated Apple’s servers .

To summarize:

  • Sept. 24, 2012: iOS 6.0 is released
  • Oct. 2012: Apple is added to the NSA’s list of penetrated servers
  • Dec. 1, 2012 to May 31, 2013: Apple receives 4,000 to 5,000 requests about 9,000 to 10,000 accounts and devices. (Per “Apple’s Commitment to Customer Privacy“.)

The evidence is purely circumstantial, but as Daring Fireball‘s John Gruber notes, “the shoe fits.” He goes on to connect the dots and offer “five levels of paranoia”:

1. Nothing. The NSA was not aware of this vulnerability.
2. The NSA knew about it, but never exploited it.
3. The NSA knew about it, and exploited it.
4. NSA itself planted it surreptitiously.
5. Apple, complicit with the NSA, added it.

Apple has explicitly denied No. 5. Gruber leans to No. 3, which leaves open the possibility that there are other, still undiscovered security holes through which user data is being funneled to the NSA.

The patch Apple released on Friday closed the “goto fail” hole for iPhones, iPads and iPod Touches. It remains open on the current version of OS X for the Mac.

“We are aware of this issue,” an Apple spokesperson told Reuters on Saturday, “and already have a software fix that will be released very soon.”

Below: The bug. (Can you spot the extra “goto fail”?)

LINKS:

  • A good write-up for security professionals: ThreatPost‘s Dennis Fisher
  • Analysis of the press coverage: AppleInsider’s Daniel Eran Dilger
About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Forget the ceasefire — The U.S. and Iran are still exchanging attacks over the Strait of Hormuz as Tehran tries to shut down a competing route
Middle EastIran
Forget the ceasefire — The U.S. and Iran are still exchanging attacks over the Strait of Hormuz as Tehran tries to shut down a competing route
By Jason MaJune 27, 2026
35 minutes ago
p
RetailWorld Cup
The 2 billion-print, $2-pack last hurrah for a World Cup legend: the Panini sticker album’s last ride
By Dave Skretta and The Associated PressJune 27, 2026
2 hours ago
‘I’ll listen to ‘Only the Young’ at home on my own’: Zohran doesn’t know about a Swift-Kelce wedding at MSG, but he’s not going
Arts & EntertainmentNew York City
‘I’ll listen to ‘Only the Young’ at home on my own’: Zohran doesn’t know about a Swift-Kelce wedding at MSG, but he’s not going
By Kimberlee Kruesi and The Associated PressJune 27, 2026
2 hours ago
Australia to strengthen enforcement of under-16 social media ban
PoliticsSocial Media
Australia to strengthen enforcement of under-16 social media ban
By Ainslie Chandler and BloombergJune 27, 2026
2 hours ago
g
EuropeGermany
It’s so hot in Germany the Autobahn literally burst open at the seams and had to be closed down
By Kirsten Grieshaber, Sylvia Hui, John Leicester and The Associated PressJune 27, 2026
2 hours ago
Apple seeks U.S. approval to buy chips from blacklisted CXMT: FT
Big TechChips
Apple seeks U.S. approval to buy chips from blacklisted CXMT: FT
By Angela Cullen and BloombergJune 27, 2026
3 hours ago

Most Popular

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
Success
MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
By Sydney LakeJune 25, 2026
2 days ago
Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster
Success
Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster
By Preston ForeJune 27, 2026
7 hours ago
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
3 days ago
The bond market knows something about the $39 trillion national debt that Washington doesn’t
Economy
The bond market knows something about the $39 trillion national debt that Washington doesn’t
By Eva RoytburgJune 25, 2026
2 days ago
Current price of oil as of June 26, 2026
Personal Finance
Current price of oil as of June 26, 2026
By Joseph HostetlerJune 26, 2026
1 day ago
Leon Black says Epstein's network included Elon Musk, Sergey Brin and Peter Thiel, while saying 'I knew Jekyll. I didn't know Hyde'
Politics
Leon Black says Epstein's network included Elon Musk, Sergey Brin and Peter Thiel, while saying 'I knew Jekyll. I didn't know Hyde'
By Joey Cappelletti and The Associated PressJune 26, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.