<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zero-day in Sign in with Apple in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Zero-day-in-Sign-in-with-Apple/m-p/36008#M2707</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;&amp;nbsp; So why did Apple not do complete Application Lifecycle testing within DevOps or during CI/CD development phases?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or was this a case, lets push it out and hope and pray - Pretty dumb decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jun 2020 00:20:59 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2020-06-01T00:20:59Z</dc:date>
    <item>
      <title>Zero-day in Sign in with Apple</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Zero-day-in-Sign-in-with-Apple/m-p/36001#M2705</link>
      <description>&lt;P&gt;Here is the &lt;A href="https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/" target="_blank" rel="noopener"&gt;technical write-up&lt;/A&gt; from the researcher that discovered the zero-day bug&amp;nbsp;in "Sign in with Apple" that affected third-party applications which were using it and didn’t implement their own additional security measures. &lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="AppleZeroDay.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4153i643B390906823627/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AppleZeroDay.png" alt="AppleZeroDay.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:32:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Zero-day-in-Sign-in-with-Apple/m-p/36001#M2705</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Zero-day in Sign in with Apple</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Zero-day-in-Sign-in-with-Apple/m-p/36008#M2707</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;&amp;nbsp; So why did Apple not do complete Application Lifecycle testing within DevOps or during CI/CD development phases?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or was this a case, lets push it out and hope and pray - Pretty dumb decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 00:20:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Zero-day-in-Sign-in-with-Apple/m-p/36008#M2707</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-06-01T00:20:59Z</dc:date>
    </item>
  </channel>
</rss>

