iTunes flaw not exactly at the top of Apple’s to-do list

Dec 2, 2011 10:01 GMT  ·  By

A prominent security researcher warned Apple about a dangerous vulnerability in iTunes roughly three years ago, yet the Mac maker waited until last month to patch up the Trojan horse.

Security writer Brian Krebs should know - he was the first person to spread the word about the vulnerability in July 2008. Seeing how Apple waited no less than 1,200 days to fix the security flaw, the blogger believes this raises questions about whether and when the Mac maker knew about it, and how big of a priority it was for the giant company.

Francisco Amato, the Argentinian security researcher who alerted Apple to the issue, said, “Maybe they forgot about it, or it was just on the bottom of their to-do list.”

Mikko Hypponen, chief research officer for Finnish security firm F-Secure, chimed in to say, “It is an unusually long time to patch anything, so it doesn’t make much sense.”