• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Apple’s security bug: Five NSA conspiracy theories

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
February 23, 2014, 2:14 PM ET

SOUCE: NSA via Edward Snowden

FORTUNE — You don’t have to put on a tin hat to find the timing of the “Apple” entry in the attached Powerpoint slide suspicious, although a tin hat probably helps.

The slide, marked TOP SECRET, was one of the first documents leaked to The Guardian and the Washington Post by NSA whistleblower Edward Snowden last June. It lays out the timeline for when the U.S. government’s top cyberspies gained access to user data on the servers of the major U.S. Internet companies: Microsoft (MSFT) in 2007, Google (GOOG) in 2009, AOL (AOL) in 2011 and Apple (AAPL) in Oct. 2012.

What makes that last entry so intriguing to conspiracy theorists is what computer experts discovered over the weekend about the security hole Apple patched — at least in part — on Friday. By comparing the original code to Apple’s fix, Adam Langley, a web encryption expert at Google, was able to pinpoint the problem.

The culprit, if you care about such things, was a short line of code — a “goto fail” without a corresponding “if” clause (see below) — in the software Apple uses to make sure a computer you are connecting to securely over the Internet is the computer it claims to be. This is critical when the website belongs to, say, a bank.

“It’s as bad as you could imagine, that’s all I can say,” Johns Hopkins University cryptography professor Matthew Green told Reuters. 

[Readers who know more about this subject than I disagree. “It takes an elaborate hoax to exploit,” henry3dogg wrote in the comment stream to an earlier version of the story. “Nobody is going to benefit from it accidentally. And it is unlikely that anyone would set up such an elaborate hoax, unless they knew that the loop hole existed.”]

Anyway, here’s where the timing gets interesting. According to Jeffrey Grossman, whose Confide iPhone app depended on Apple’s security protocols to deliver “off the record conversations,” the bug appeared in iOS 6.0 and was not present in iOS 5.11.

iOS 6.0 was released in September 2012, just before the NSA penetrated Apple’s servers .

To summarize:

  • Sept. 24, 2012: iOS 6.0 is released
  • Oct. 2012: Apple is added to the NSA’s list of penetrated servers
  • Dec. 1, 2012 to May 31, 2013: Apple receives 4,000 to 5,000 requests about 9,000 to 10,000 accounts and devices. (Per “Apple’s Commitment to Customer Privacy“.)

The evidence is purely circumstantial, but as Daring Fireball‘s John Gruber notes, “the shoe fits.” He goes on to connect the dots and offer “five levels of paranoia”:

1. Nothing. The NSA was not aware of this vulnerability.
2. The NSA knew about it, but never exploited it.
3. The NSA knew about it, and exploited it.
4. NSA itself planted it surreptitiously.
5. Apple, complicit with the NSA, added it.

Apple has explicitly denied No. 5. Gruber leans to No. 3, which leaves open the possibility that there are other, still undiscovered security holes through which user data is being funneled to the NSA.

The patch Apple released on Friday closed the “goto fail” hole for iPhones, iPads and iPod Touches. It remains open on the current version of OS X for the Mac.

“We are aware of this issue,” an Apple spokesperson told Reuters on Saturday, “and already have a software fix that will be released very soon.”

Below: The bug. (Can you spot the extra “goto fail”?)

LINKS:

  • A good write-up for security professionals: ThreatPost‘s Dennis Fisher
  • Analysis of the press coverage: AppleInsider’s Daniel Eran Dilger
About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

AIJobs
Nobel laureate Joe Stiglitz says not only can AI take your job, it’ll make the ‘tech bro’ class richer while doing it
By Catherina GioinoMarch 6, 2026
25 minutes ago
palmer luckey
AIPentagon
Palmer Luckey says Silicon Valley has the Pentagon all wrong: ‘Stick to a position that this is in the hands of the people’
By Jake AngeloMarch 6, 2026
2 hours ago
Personal FinanceCertificates of Deposit (CDs)
Best certificates of deposit (CDs) for March 2026
By Glen Luke FlanaganMarch 6, 2026
3 hours ago
AIdisruption
OpenAI investor Vinod Khosla believes AI will be able to do 80% of all jobs by 2030. Here’s how life could be affordable after mass unemployment
By Nick LichtenbergMarch 6, 2026
3 hours ago
Startups & VentureVenture Capital
February was the biggest month in venture history, thanks to OpenAI, Anthropic, and Waymo in particular
By Lily Mae LazarusMarch 6, 2026
3 hours ago
Future of WorkElectric vehicles
Nearly 1,000 workers laid off at SK Battery plant in Georgia as companies cancel EVs and Trump Admin eliminates auto company incentives
By The Associated Press, Jeff Amy and Alexa St. JohnMarch 6, 2026
3 hours ago

Most Popular

placeholder alt text
Economy
The Treasury may need to borrow an extra $1.6 trillion to cover the hole left by tariff ruling and pay a further $400 billion in debt interest
By Eleanor PringleMarch 6, 2026
11 hours ago
placeholder alt text
Success
Chinese billionaire who has fathered more than 100 children hopes to have dozens of U.S.-born boys to one day take over his business
By Emma BurleighMarch 5, 2026
1 day ago
placeholder alt text
Politics
Meet Markwayne Mullin, the new multimillionaire head of DHS, who owns a cattle ranch in Oklahoma
By Jacqueline MunisMarch 5, 2026
24 hours ago
placeholder alt text
AI
OpenAI investor Vinod Khosla predicts today’s 5-year-olds won’t ever need to get jobs thanks to AI
By Sasha RogelbergMarch 4, 2026
3 days ago
placeholder alt text
Politics
Iran is turning out to be a more effective enemy than many thought, and U.S. allies are losing their patience with the war
By Jim EdwardsMarch 6, 2026
11 hours ago
placeholder alt text
Middle East
The Iran conflict will be the ’straw that breaks the camel’s back’ for the U.S. economy if it goes on much longer, Nobel laureate Paul Krugman warns
By Tristan BoveMarch 6, 2026
15 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.