{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:49:01Z","timestamp":1750308541263,"version":"3.41.0"},"reference-count":16,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2014,5,1]],"date-time":"2014-05-01T00:00:00Z","timestamp":1398902400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2014,5]]},"abstract":"<jats:p>In February Apple revealed and fixed an SSL (Secure Sockets Layer) vulnerability that had gone undiscovered since the release of iOS 6.0 in September 2012. It left users vulnerable to man-in-the-middle attacks thanks to a short circuit in the SSL\/TLS (Transport Layer Security) handshake algorithm introduced by the duplication of a goto statement. Since the discovery of this very serious bug, many people have written about potential causes. A close inspection of the code, however, reveals not only how a unit test could have been written to catch the bug, but also how to refactor the existing code to make the algorithm testable - as well as more clues to the nature of the error and the environment that produced it.<\/jats:p>","DOI":"10.1145\/2620660.2620662","type":"journal-article","created":{"date-parts":[[2014,5,13]],"date-time":"2014-05-13T12:18:28Z","timestamp":1399983508000},"page":"10-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Finding More Than One Worm in the Apple"],"prefix":"10.1145","volume":"12","author":[{"given":"Mike","family":"Bland","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,5]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Apple Inc. 2014. Xcode overview; https:\/\/developer.apple.com\/library\/ios\/documentation\/ToolsLanguages\/Conceptual\/Xcode_Overview\/Xcode_Overview.pdf.  Apple Inc. 2014. Xcode overview; https:\/\/developer.apple.com\/library\/ios\/documentation\/ToolsLanguages\/Conceptual\/Xcode_Overview\/Xcode_Overview.pdf."},{"key":"e_1_2_1_2_1","series-title":"February 25","volume-title":"Apple's SSL iPhone vulnerability: how did it happen, and what next? The Guardian,","author":"Arthur C.","year":"2014"},{"key":"e_1_2_1_3_1","series-title":"February 25","volume-title":"An extraordinary kind of stupid. Slate","author":"Auerbach D.","year":"2014"},{"key":"e_1_2_1_4_1","unstructured":"Bellovin S. M. 2014. Goto Fail. SMBlog (February 23); https:\/\/www.cs.columbia.edu\/~smb\/blog\/2014-02\/2014-02-23.html.  Bellovin S. M. 2014. Goto Fail. SMBlog (February 23); https:\/\/www.cs.columbia.edu\/~smb\/blog\/2014-02\/2014-02-23.html."},{"key":"e_1_2_1_5_1","unstructured":"Bland M. 2014. AutoTest Central; http:\/\/autotestcentral.com\/small-medium-and-large-test-sizes.  Bland M. 2014. AutoTest Central; http:\/\/autotestcentral.com\/small-medium-and-large-test-sizes."},{"key":"e_1_2_1_6_1","unstructured":"Bland M. 2011. Test Certified; http:\/\/mike-bland.com\/2011\/10\/18\/test-certified.html.  Bland M. 2011. Test Certified; http:\/\/mike-bland.com\/2011\/10\/18\/test-certified.html."},{"key":"e_1_2_1_7_1","unstructured":"Bland M. 2012. Test Mercenaries; http:\/\/mike-bland.com\/2012\/07\/10\/test-mercenaries.html.  Bland M. 2012. Test Mercenaries; http:\/\/mike-bland.com\/2012\/07\/10\/test-mercenaries.html."},{"volume-title":"Testing on the Toilet","year":"2011","author":"Bland M.","key":"e_1_2_1_8_1"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/362929.362947"},{"volume-title":"TestableSecurity: demonstrating that SSLVerifySignedServerKeyExchange() is trivially testable","year":"2014","author":"Fuller L.","key":"e_1_2_1_10_1"},{"key":"e_1_2_1_11_1","unstructured":"Google Inc. 2008. Too many tests. Google Testing Blog (February 21); http:\/\/googletesting.blogspot.com\/2008\/02\/in-movie-amadeus-austrian-emperor.html.  Google Inc. 2008. Too many tests. Google Testing Blog (February 21); http:\/\/googletesting.blogspot.com\/2008\/02\/in-movie-amadeus-austrian-emperor.html."},{"key":"e_1_2_1_12_1","series-title":"July 30","volume-title":"Why Apple's power cords keep breaking. The Wire","author":"Greenfield R.","year":"2012"},{"key":"e_1_2_1_13_1","unstructured":"Langley A. 2014. Apple's SSL\/TLS bug. Imperial Violet (February 22); https:\/\/www.imperialviolet.org\/2014\/02\/22\/applebug.html.  Langley A. 2014. Apple's SSL\/TLS bug. Imperial Violet (February 22); https:\/\/www.imperialviolet.org\/2014\/02\/22\/applebug.html."},{"key":"e_1_2_1_14_1","series-title":"February 23","volume-title":"TDD and signed SSLVerifySignedServerKeyExchange. Exploring Agile Solutions: Software Development with Agile Practices","author":"Ray C. K.","year":"2014"},{"key":"e_1_2_1_15_1","series-title":"February 27","volume-title":"Was the iOS SSL flaw deliberate? Schneier on Security: A Blog Covering Security and Security Technology","author":"Schneier B.","year":"2014"},{"key":"e_1_2_1_16_1","series-title":"February 22","volume-title":"Learning from Apple's #gotofail security bug. Arie van Deursen: Software Engineering in Theory and Practice","author":"van Deursen A.","year":"2014"}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2620660.2620662","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2620660.2620662","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T18:56:15Z","timestamp":1750272975000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2620660.2620662"}},"subtitle":["If you see something, say something."],"short-title":[],"issued":{"date-parts":[[2014,5]]},"references-count":16,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2014,5]]}},"alternative-id":["10.1145\/2620660.2620662"],"URL":"https:\/\/doi.org\/10.1145\/2620660.2620662","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"type":"print","value":"1542-7730"},{"type":"electronic","value":"1542-7749"}],"subject":[],"published":{"date-parts":[[2014,5]]},"assertion":[{"value":"2014-05-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}