Skip to main content

Apple finally using HTTPS for AppStore

posted onMarch 11, 2013
by l33tdawg

Apple has begun using secure Web pages -- HTTPS -- for all App Store communications. The move mitigated a number of vulnerabilities that attackers could have exploited to steal App Store passwords, force users to pay for unwanted apps or intercept user data.

Apple announced the security change earlier this year, noting that "active content is now served over HTTPS by default" for App Store via its iTunes applications. Apple's security notice credited multiple researchers for alerting it to the vulnerability, including Google researcher Elie Bursztein.

Bursztein said Friday in a blog post that Apple's previous failure to use HTTPS for App Store communications -- except on purchase pages – along with its failure to confirm certain activities and the dynamic manner in which App Store pages get generated left users open to "an active network attack that is able to read, intercept and manipulate non-encrypted (HTTP) network traffic," for example, via unencrypted public Wi-Fi hotspots.

Source

Tags

Apple Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th