<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Will Brattain on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/will-brattain/</link><description>Recent content in Will Brattain on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 30 Oct 2023 08:00:57 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/will-brattain/index.xml" rel="self" type="application/rss+xml"/><item><title>The issue with ATS in Apple’s macOS and iOS</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/10/30/the-issue-with-ats-in-apples-macos-and-ios/</link><pubDate>Mon, 30 Oct 2023 08:00:57 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/10/30/the-issue-with-ats-in-apples-macos-and-ios/</guid><description>Trail of Bits is publicly disclosing a vulnerability (CVE-2023-38596) that affects iOS, iPadOS, and tvOS before version 17, macOS before version 14, and watchOS before version 10. The flaw resides in Apple’s App Transport Security (ATS) protocol handling. We discovered that Apple’s ATS fails to require the encryption of connections to IP […]</description></item></channel></rss>