Friday, 15 March 2019
Apple invalidates 355,000 signing certificates, affecting users globally
Apple recently invalidated thousands of signing certificates owing to a major SSL bug. Here’s all you need to know about it and more.
SSL CERTIFICATE ISSUE RESULTS IN THOUSANDS OF CERTIFICATES BEING INVALIDATED
On March 3, 2019, Apple determined that they were issuing TLS Server and S/MIME certificates with non-compliant serial numbers
According to an Apple representative, Apple first became aware of the issue while reviewing an updated version of the CA (Certificate Authority) software used for issuing SSL certificates.
Since this incident was detected, more than 878,000 certificates have been affected, out of which Apple has already invalidated 355,000 certificates.
This causes new Mobile Provisioning files to not include application-identifier and keychain-access-groups entitlement entries.
This bug only affects tools that use a new profile each time they build or sign an app.
WHICH TOOLS AND CERTIFICATES ARE AFFECTED?
Since both XCode and Cydia Impactor rely on profiles, they can’t build or sign apps anymore using a free or paid developer certificate. XCode simulator, on the other hand, continues to work as expected.
Apple users are not alone, however. Google, GoDaddy, Instagram, and Facebook (which is why it went down for maintenance yesterday) users are affected as well.
Surprisingly, this bug doesn’t seem to affect enterprise-grade certificates.
This explains how users are still able to utilize signing services like Panda Helper that distribute jailbreak tools and hacked apps signed with an enterprise certificate.
WHEN WILL APPLE PATCH THIS BUG?
Apple has stopped issuing signing certificates with non-compliant serial numbers and intends to roll out a patch soon.
Though some users have reported success with several XCode tweaks, there’s no single solution that works for all users.
If you own a jailbroken device, there’s a pretty straightforward workaround to this bug.
Just go ahead and install ReProvision signing tool, which works with both free and paid certificates. However, it will only work for apps or IPA files that were installed yesterday or before. Also Read:jihosoft Free iPhone Data Recovery
Sponsor ads:
Gihosoft Free iPhone Data Recovery:https://www.gihosoft.com/iphone-data-recovery-free.html
Gihosoft iPhone Data Recovery Free
Free iPhone Data Recovery Software for Windows/Mac
Recover up to 12+ types of files, including contacts, SMS, photos, WhatsApp, Viber, notes, etc.
Restore lost data from iOS devices directly or from iTunes and iCloud backup
Recover iPhone data lost due to iOS upgrade/jailbreak, accidental deletion, device lost or broken
Support all the latest iPhone, iPad and iPod Touch
Both Free and Pro version.
If you lost data after you updated to a new iPhone, you can always use Gihosoft iPhone Data Recovery to get the data back from the old iPhone or backup.You may also like: iphonerecovery.com
Cydia Impactor signing utility will remain defunct for the time being. Thankfully, Saurik is in the know and will push a patch, if need be, once the dust settles.
Subscribe to:
Post Comments (Atom)
Easily Transfer/Move OS to Another Hard Drive in Windows 10/11 2023
Easily Transfer/Move OS to Another Hard Drive in Windows 10/11 2023 Here's how you can easily transfer or move your OS to another hard...
-
Are you using your iPhone as a speaker while you listen to music, and wishing there was a little more oomph to the the audio? Here's...
-
The Apple Card got everyone’s attention with special offers and low-interest rates. It also made headlines for accepting applicants with ave...
-
What are the differences between the RTX 4070 and the RTX 3080? Here are the main differences between the upcoming RTX 4070 and the curr...
No comments:
Post a Comment