By John Gruber
Due — never forget anything, ever again.
Fixes a serious security flaw:
Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS
Description: Secure Transport failed to validate the authenticity of the connection. This issue was addressed by restoring missing validation steps.
★ Friday, 21 February 2014