• Home
  • About

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
By using Twitter’s services you agree to our Cookie Use and Data Transfer outside the EU. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
rbrockerhoff's profile
Rainer Brockerhoff
Rainer Brockerhoff
Rainer Brockerhoff
@rbrockerhoff

Rainer Brockerhoff

@rbrockerhoff

Mac developer since 1969.

Joined March 2008
  • © 2016 Twitter
  • About
  • Help
  • Terms
  • Privacy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @

Retweet this to your followers?

Optional comment for Retweet
 
 

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
140

Are you sure you want to delete this Tweet?

Promote this Tweet

Block

  • Add a location to your Tweets

    When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

    Profile summary

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    Preview

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Buy Now

    Hmm... Something went wrong. Please try again.

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Previous Tweet Next Tweet
    1. Glenn Fleishman ‏@GlennF 13 Nov 2015

      I got a bunch of interesting info about the Mac App Store cert situation, but it’s so technical, I’m not sure it’s worth explaining.

      0 replies 2 retweets 4 likes
    2. Greg Minton ‏@gregminton 13 Nov 2015

      @GlennF I, for one, would love a technical article about this. And it might help spur change.

      0 replies 0 retweets 0 likes
    3. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

      .@gregminton I'm about to post about this; @GlennF's article would be correct if Apple's root cert had expired, but it was the MASleaf cert.

      0 replies 0 retweets 1 like
    4. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

      @gregminton @glennf argh, things keep happening too fast for me to post about them… :-/

      0 replies 0 retweets 0 likes
      Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

      My take on the Mac App Store meltdown: http://brockerhoff.net/blog/2015/11/14/a-tale-of-two-certs/ … Comments? // @gregminton @glennf @mjtsai

      • Retweets 6
      • Likes 8
      • Evan Barry Martin fusenigk Jorge Hannes Juutilainen Michael Tsai Count Franken Michael Yacavone Andreas Monitzer
      12:47 PM - 14 Nov 2015
      0 replies 6 retweets 8 likes
        1. Glenn Fleishman ‏@GlennF 14 Nov 2015

          @rbrockerhoff “so only very old apps would be affected by that”: unfortunately, some modern apps do, too! I don’t have a list.

          0 replies 0 retweets 0 likes
        2. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @glennf so, modern apps that use an outdated version of OpenSSL or some other library, then?

          0 replies 0 retweets 0 likes
        3. Glenn Fleishman ‏@GlennF 14 Nov 2015

          @rbrockerhoff The word is an old version of OpenSSL. If you’re using the pre-1.0.0 chain, you can wind up w/o SHA-256 support, IIRC.

          0 replies 0 retweets 0 likes
        4. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @glennf hmm. Not up on the history, but it seems 1.0.0 came out in March 2010, so some people stayed on the 0.9.x branch because of APIs…?

          0 replies 0 retweets 0 likes
        5. View other replies
        6. Glenn Fleishman ‏@GlennF 14 Nov 2015

          @rbrockerhoff Yeah, 1.0.0 wasn’t broadly supported for a long time b/c of how crappy OpenSSL was due to a lack of financial support.

          0 replies 0 retweets 0 likes
        7. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @glennf I use a very small subset of OpenSSL for cert/receipt checking and, frankly, didn't notice anything crappy beyond the major opacity.

          0 replies 0 retweets 0 likes
        8. View other replies
        9. Glenn Fleishman ‏@GlennF 14 Nov 2015

          @rbrockerhoff I mean, it’s not the OpenSSL folks’ *fault*—they did what they could. 1.0 being better funded = better code

          0 replies 0 retweets 0 likes
        10. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @glennf I agree it's not their fault (nor really anyone's in particular). As I said, meltdown was a coincidence of several point failures.

          0 replies 0 retweets 0 likes
        11. Show more
        1. Glenn Fleishman ‏@GlennF 14 Nov 2015

          @rbrockerhoff Thanks for this rundown! I need to tweak my story. The fragility is really something and the UI presentation of failure.

          0 replies 0 retweets 0 likes
        2. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @GlennF don't trust me too much either, better double-check and tell me. Will amend my comments on the OpenSSL aspect.

          0 replies 0 retweets 0 likes
        3. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @glennf …and, amended my comments, linking to your article.

          0 replies 0 retweets 0 likes
        1. Rainer Brockerhoff ‏@rbrockerhoff 16 Nov 2015

          RT because of timezones/weekend: My take on the Mac App Store meltdown: http://brockerhoff.net/blog/2015/11/14/a-tale-of-two-certs/ … Comments?

          0 replies 2 retweets 1 like
        2. Rainer Brockerhoff ‏@rbrockerhoff 16 Nov 2015

          Again, RT because of timezones/weekend: My take on the Mac App Store meltdown: http://brockerhoff.net/blog/2015/11/14/a-tale-of-two-certs/ … Comments?”

          0 replies 0 retweets 0 likes
      1. Glenn Fleishman ‏@GlennF 14 Nov 2015

        @rbrockerhoff @gregminton @mjtsai Some apps use outdated SSL libs and couldn’t check the newly issued SHA-256 cert (from Sept)

        0 replies 0 retweets 0 likes
        1. Michael Tsai ‏@mjtsai 14 Nov 2015

          @rbrockerhoff Good post. I noted two other cases of Apple blaming developers.

          0 replies 0 retweets 0 likes
        2. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @mjtsai probably not Apple-as-corporate-person, but some clueless employee, one hopes...

          0 replies 0 retweets 0 likes
        3. Michael Tsai ‏@mjtsai 14 Nov 2015

          @rbrockerhoff Of course, because corporate wouldn’t go on record. Unclear whether employees were following training or not.

          0 replies 0 retweets 0 likes
        1. Edward Marczak ‏@marczak 14 Nov 2015

          @rbrockerhoff Nice writeup. What about what Apple can do to prevent this in the future?

          0 replies 0 retweets 0 likes
        2. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @marczak update sample code, better docs — beyond that, depends on what really caused the "damaged" thing. We may never hear details.

          0 replies 0 retweets 0 likes
        3. Edward Marczak ‏@marczak 14 Nov 2015

          @rbrockerhoff Sure, but it wasn’t something that developers could have prevented. It’s 100% Apple’s fault.

          0 replies 0 retweets 0 likes
        4. Rainer Brockerhoff ‏@rbrockerhoff 14 Nov 2015

          @marczak insofar as it's anyone's fault, it's Apple's, true. But, really, the meltdown was a coincidence of several point failures.

          0 replies 0 retweets 0 likes
        5. Edward Marczak ‏@marczak 14 Nov 2015

          @rbrockerhoff So, only Apple can do something to prevent this from happening again. It needs to be a learning experience for them.

          0 replies 0 retweets 0 likes

      Loading seems to be taking a while.

      Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

        Promoted Tweet

        false

        • © 2016 Twitter
        • About
        • Help
        • Terms
        • Privacy
        • Cookies
        • Ads info