Skip to main content

Apple Remote Desktop software was vulnerable to snooping

posted onAugust 21, 2012
by l33tdawg

Apple users employing Apple's Remote Desktop software to administer other servers have been doing so without their data being encrypted if they asked the software to do so, and were running the latest version.

In a patch released by the Cupertino, California, company today, Apple stated that when connecting to third-party virtual network computing (VNC) servers, data is not being encrypted, even when the user selects "Encrypt all network data". Additionally, no warning is being provided to the user.

According to Apple's security bulletin, the issue does not affect Apple Remote Desktop 3.5.1 and earlier, indicating that the error was introduced in a subsequent patch. Version 3.5.2 of the client for Apple Remote Desktop was released in February this year, while the 3.5.2 admin version of the tool was released in June. Apple recommends upgrading to Apple Remote Desktop 3.6.1, which removes the flaw. This latest version now sets up a secure SSH tunnel to provide end-to-end encryption, and stops the connection if a secure tunnel cannot be established.

Source

Tags

Apple Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th