Reply to post: Re: client should never accept a time that's wildly different

iOS 'date bug' can be exploited over Wi-Fi using NTP

Anonymous Coward
Anonymous Coward

Re: client should never accept a time that's wildly different

NTP is unauthenticated. DNSSEC won't help if you can set up a server which will service the IP address that the DNS hands out.

time.apple.com resolves to 17.253.x.x (lots, in a round robin config)... it would be trivial to set up a device locally to impersonate those addresses.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon