• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Apple’s security bug: Five NSA conspiracy theories

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
February 23, 2014, 2:14 PM ET

SOUCE: NSA via Edward Snowden

FORTUNE — You don’t have to put on a tin hat to find the timing of the “Apple” entry in the attached Powerpoint slide suspicious, although a tin hat probably helps.

The slide, marked TOP SECRET, was one of the first documents leaked to The Guardian and the Washington Post by NSA whistleblower Edward Snowden last June. It lays out the timeline for when the U.S. government’s top cyberspies gained access to user data on the servers of the major U.S. Internet companies: Microsoft (MSFT) in 2007, Google (GOOG) in 2009, AOL (AOL) in 2011 and Apple (AAPL) in Oct. 2012.

What makes that last entry so intriguing to conspiracy theorists is what computer experts discovered over the weekend about the security hole Apple patched — at least in part — on Friday. By comparing the original code to Apple’s fix, Adam Langley, a web encryption expert at Google, was able to pinpoint the problem.

The culprit, if you care about such things, was a short line of code — a “goto fail” without a corresponding “if” clause (see below) — in the software Apple uses to make sure a computer you are connecting to securely over the Internet is the computer it claims to be. This is critical when the website belongs to, say, a bank.

“It’s as bad as you could imagine, that’s all I can say,” Johns Hopkins University cryptography professor Matthew Green told Reuters. 

[Readers who know more about this subject than I disagree. “It takes an elaborate hoax to exploit,” henry3dogg wrote in the comment stream to an earlier version of the story. “Nobody is going to benefit from it accidentally. And it is unlikely that anyone would set up such an elaborate hoax, unless they knew that the loop hole existed.”]

Anyway, here’s where the timing gets interesting. According to Jeffrey Grossman, whose Confide iPhone app depended on Apple’s security protocols to deliver “off the record conversations,” the bug appeared in iOS 6.0 and was not present in iOS 5.11.

iOS 6.0 was released in September 2012, just before the NSA penetrated Apple’s servers .

To summarize:

  • Sept. 24, 2012: iOS 6.0 is released
  • Oct. 2012: Apple is added to the NSA’s list of penetrated servers
  • Dec. 1, 2012 to May 31, 2013: Apple receives 4,000 to 5,000 requests about 9,000 to 10,000 accounts and devices. (Per “Apple’s Commitment to Customer Privacy“.)

The evidence is purely circumstantial, but as Daring Fireball‘s John Gruber notes, “the shoe fits.” He goes on to connect the dots and offer “five levels of paranoia”:

1. Nothing. The NSA was not aware of this vulnerability.
2. The NSA knew about it, but never exploited it.
3. The NSA knew about it, and exploited it.
4. NSA itself planted it surreptitiously.
5. Apple, complicit with the NSA, added it.

Apple has explicitly denied No. 5. Gruber leans to No. 3, which leaves open the possibility that there are other, still undiscovered security holes through which user data is being funneled to the NSA.

The patch Apple released on Friday closed the “goto fail” hole for iPhones, iPads and iPod Touches. It remains open on the current version of OS X for the Mac.

“We are aware of this issue,” an Apple spokesperson told Reuters on Saturday, “and already have a software fix that will be released very soon.”

Below: The bug. (Can you spot the extra “goto fail”?)

LINKS:

  • A good write-up for security professionals: ThreatPost‘s Dennis Fisher
  • Analysis of the press coverage: AppleInsider’s Daniel Eran Dilger
About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Mrs. Dow Jones on what women get wrong about money
NewslettersMPW Daily
Mrs. Dow Jones on what women get wrong about money
By Sydney LakeMay 13, 2026
24 minutes ago
Current price of Bitcoin for May 31, 2026
Personal FinanceCryptocurrency
Current price of Bitcoin for May 31, 2026
By Joseph HostetlerMay 13, 2026
1 hour ago
Current price of Ethereum for May 31, 2026
Personal FinanceEthereum
Current price of Ethereum for May 31, 2026
By Joseph HostetlerMay 13, 2026
1 hour ago
Top CD rates from major banks May 13, 2026: Chase CDs, Bank of America CDs, Citibank CDs, and more
Personal FinanceCertificates of Deposit (CDs)
Top CD rates from major banks on May 13, 2026: Chase CDs, Bank of America CDs, Citibank CDs, and more
By Joseph HostetlerMay 13, 2026
1 hour ago
Current price of gold as of May 13, 2026
Personal Financegold prices
Current price of gold as of May 13, 2026
By Danny BakstMay 13, 2026
1 hour ago
Current price of oil as of May 13, 2026
Personal FinanceOil
Current price of oil as of May 13, 2026
By Joseph HostetlerMay 13, 2026
1 hour ago

Most Popular

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
18 hours ago
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
Travel & Leisure
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
By Catherina GioinoMay 12, 2026
21 hours ago
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
North America
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
By Sasha RogelbergMay 12, 2026
1 day ago
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
Economy
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
By Jason MaMay 11, 2026
2 days ago
It’s not just Canadian tourists snubbing U.S. cities. Business leaders are cancelling more trips to America as geopolitical tensions continue
North America
It’s not just Canadian tourists snubbing U.S. cities. Business leaders are cancelling more trips to America as geopolitical tensions continue
By Sasha RogelbergMay 12, 2026
19 hours ago
Anthropic’s Daniela Amodei says entrepreneurs should go on vacation to road test potential cofounders—if they’re a drain, they’re ‘the wrong choice’
Success
Anthropic’s Daniela Amodei says entrepreneurs should go on vacation to road test potential cofounders—if they’re a drain, they’re ‘the wrong choice’
By Emma BurleighMay 12, 2026
23 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.