Live data from Hacker News

About the security content of Security Update 2017-001

support.apple.com

71–80 of 158 posts

Re: About the security content of Security Update 2017-001

#71

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

> We are auditing our development processes to help prevent this from happening again. That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?

> Or does development in AppleSpeak mean everything?

It's a press release. It doesn't mean anything.

Re: About the security content of Security Update 2017-001

#72

Earlier quoted context omitted.

Apple says "Not impacted: macOS Sierra 10.12.6 and earlier" in their security advisory for the patch.

My fear is that Apple doesn't know that it still affects El Capitan, though the poster I linked to could have just been lying.

It doesn't appear to affect (regular) Sierra, so if this issue exists on El Capitan, I'm guessing it's a separate, though relevant, problem, rather than being the exact same one.

Re: About the security content of Security Update 2017-001

#73

Earlier quoted context omitted.

They force-pushed code to your box without you agreeing to this? Can anyone else confirm?

Not for me, it's waiting for me to click install in the App Store. Its pretty well highlighted though.

It almost shouts at you. Mine says "Install this update as soon as possible"

Re: About the security content of Security Update 2017-001

#74
post #44

Earlier quoted context omitted.

The ability to write is largely ignored at tech firms these days. Grammar is viewed as a bunch of stodgy rules to be ignored at will. Some are indeed silly throwbacks, but the basic structures are what allow us to communicate effectively. Drop them and errors in understanding creep into nearly every email. Yesterday I had a back-and-forth with a boss over "login", "log in", "log in to" and "log into". That might seem…

Surely: log into -> write to a specific log log in to -> access a certain host no?

Fwiw, I've always used "log to" for writing out logs. "Log to stderr". So, you know, extra fun deciding what's "correct".

Re: About the security content of Security Update 2017-001

#75

Earlier quoted context omitted.

Actually entering blank passwords and automated password entry should be Test Cases #0 and #1 for any thing that has a login. OS and other critical infrastructure vendors should go beyond that and explore the vast space to make sure nothing like this ever happens.

And I'm sure they've had privilege escalation vulns before and a workflow already in place for catching a lot of them. I mean, it's not like Apple's totally asleep at the wheel here. OSX may not be a front-burner project anymore, but they're still supporting it better than Microsoft manages to support Windows. But that's the nasty thing about InfoSec. It's a never-ending process. There's always realms you haven't con…

> but they're still supporting it better than Microsoft manages to support Windows.

I don't know what metric if any you're using to make that statement but any person working Enterprise/Corporate IT will tell you what MS manages to pull year over year with Windows, Office and bunch of other stuff is fairly monumental given the demands of their operating space. Only way Apple can survive there with their current Engineering setup/culture is if they only did simple stuff and told the customers no interop and you only get to do what we think is best for you!

Re: About the security content of Security Update 2017-001

#76
> We are auditing our development processes to help prevent this from happening again

The root of the problem is the CEO has put an emphasis on flashy useless features rather than quality. Jobs realized that quality was ultimately what sells first, followed by practicality, which was driven by need and innovation.

The Steve Ballmer of Apple thinks has squeezed creativity at Apple dry. Sad to see problems from the hardware division start to creep into the software division. :(

Re: About the security content of Security Update 2017-001

#77
post #2

Kinda aggressive. I don't even clicked on update and they already did that for me.

Apple has used the force-upgrade path which you cannot opt out of (at least not easily) and which is permitted by their TOU, exactly twice, both to address serious security vulnerabilities.

Once for this problem, and once for the NTP security bug in 2014. That is it.

https://support.apple.com/en-us/HT204425

Re: About the security content of Security Update 2017-001

#78
post #74
post #44

Earlier quoted context omitted.

Surely: log into -> write to a specific log log in to -> access a certain host no?

Fwiw, I've always used "log to" for writing out logs. "Log to stderr". So, you know, extra fun deciding what's "correct".

Sure, but that wasn't one of the options, and doesn't (to me) make the "into" case ambiguous :)

Re: About the security content of Security Update 2017-001

#79
Real problem is that if you are nobody then your private bug reports mean nothing. Only public shaming helps here.

https://medium.com/@lemiorhan/the-story-behind-anyone-can-lo...

Author of this tweet said that Apple was informed at least week before tweet, but zero response.

Re: About the security content of Security Update 2017-001

#80
post #74
post #44

Earlier quoted context omitted.

Surely: log into -> write to a specific log log in to -> access a certain host no?

Fwiw, I've always used "log to" for writing out logs. "Log to stderr". So, you know, extra fun deciding what's "correct".

In my tech writing class for the sciences, my teacher said, "Never use a noun when you could use a verb".

Meaning, she would suggest saying: "Write a log to" and "User logs in to"; which are far more clear in their intent. :)

I think it's amazing we can even understand each other sometimes; English is quite a terrible language.

Post reply on HN