Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hi, I'm the author of the referenced article. Thanks for pointing to it!

However, can you change HN thread to the article title, which is: "The Apple goto fail vulnerability: lessons learned"?

I never used the term "backdoor" in the entire article, and I certainly never claimed that this was an intentional backdoor or that it looked just like a backdoor. I said, "The Apple goto fail vulnerability was a dangerous vulnerability that should have been found by Apple." - but I never said it was intentional. I personally doubt it was intentional (it's possible, but I have no specific evidence suggesting it).

While I'm here... ask me anything (AMA)!



Fixed now. Thanks!

(Submitted title was "The Most Backdoor-Looking Bug I’ve Ever Seen: Apple's goto fail bug (2014)". Submitters: please don't do that—it's against the site guidelines, which ask: "Please use the original title, unless it is misleading or linkbait; don't editorialize." We eventually take submission privileges away for breaking that rule, so please follow it.)


Thanks! And while I'm here, THANK YOU for all the thankless work you do. MANY people, including me, appreciate it!


Excuse me.


No problem! Thanks for pointing people to the article, I write articles with the hope that someone will read them :-).

That article is part of a series of articles called "Learning from Disaster": https://dwheeler.com/essays/learning-from-disaster.html I think we can learn from the past, and sometimes learning a story & working to gain lessons learned from it can really help.


Excuse me for changing the title of your essay. I should not do that.

The title was just my opinion. Some days ago, I read the excellent newsletter [1] of Filippo Valsorda about a Telegram's bug [2]. Yesterday, I googled for bugdoors and read about them and found this Apple's bug and your excellent essay (with many useful hyperlinks) about it.

[1] https://news.ycombinator.com/item?id=25726068

[2] https://habrahabr.ru/post/206900


> ... your excellent essay (with many useful hyperlinks) about it.

Thank you so much!


This was obviously a merge error.


I think that's very likely, but I've never seen a post mortum from Apple where they track down what happened.

I wish they would be more open about what happened. Mistakes happen. It's better for the industry if we can all learn from them.


The OP has re-used the title of an unrelated article posted a few days ago, for some reason:

https://news.ycombinator.com/item?id=25726068


Flagged in hopes the title gets changed




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: