Apple SSL/TLS bug is possibly a deliberate job
gist.github.com
gist.github.com
If we're going to entertain conspiracy theories, I favour "A rogue Google agent snuck in to Apple headquarters and edited the file whilst the user was out for lunch". Or perhaps Zergloids. Come on people, we're getting as bad as Slashdot over here!
If we're going to claim this is deliberate, then the same accusation can be levelled at every security bug ever introduce in an edit. This is not evidence, it's just trolling.
Similarly, given how the rest of the changes seemed to be attempts to rename and clean up the API, I expect that it was a junior intern cleaning up code as a whole. It would be more interesting to see the history of the commits, but that's not public (that I know of). It does highlight how we get that data with Google's Android, even though the development and release process is basically the same.
And the author of that headline is possibly beating his wife.
So even though at the two end points we see the addition of only one line in a block (which is being touted as the justification for this accusation), the intermediate steps could have included the addition and subtraction of other lines in that block.
(A plausible example might be the addition of another hash updating if statement + goto fail, then the removal of only the if statement.)
That said sorry but I don't buy this. Just seeing a diff with that one + makes me more inclined to believe there was an if(...) goto fail that someone removed without removing the statement as well.
There is more than enough incompetence in our industry that a deliberate job is completely unnecessary, why bother when engineers break security all the time anyways?
[1] - http://opensource.apple.com/source/Security/Security-55179.1...
[2] - http://opensource.apple.com/source/Security/Security-55471/l...
Even if its Apple and really tempting to target I don't buy it.