Live data from Hacker News

Apple patches CVE-2020-9859 (unc0ver)

support.apple.com

31–40 of 79 posts

Re: Apple patches CVE-2020-9859 (unc0ver)

#31
post #20

Earlier quoted context omitted.

Strawman. An almost full 256 GB SSD MBP would obviously need the next one up, but it's moot if it's soldered on unless you're a Louis Rossmann fan with the microsoldering and microscope play-at-home pack.

No my point is 1.5 GB is too small a transient (you delete the download when done) requirement to make someone have to bump up disk sizes.

You didn't communicate that. There is no "download" to delete on iOS (and derivatives) and it's managed by the system on macOS. It's not a small delta when it should be tiny (100 MiB), that eats up data plan and storage.

Re: Apple patches CVE-2020-9859 (unc0ver)

#32
post #14

Be nice if they could patch a kernel bug in macOS with less than a 1.5GB download.

It might seem strange, but they are using a change/build/deploy mechanism designed to deliver updates to any and all parts of an OS across a range of hardware devices. I'm pretty sure the mechanism, from end-to-end, is complex, and providing an optimized path for small changes would require resources, introduce more risk, and come at the expense of something else. Sucks, though, for everyone who doesn't have a reason…

I work on a ship part of the year. Satellite internet shared between 50 people. These Apple updates would saturate the network and grind it to a halt before we started blocking them on the firewall. iMessage got caught in the crossfire and now sometimes works and sometimes doesn't.

Re: Apple patches CVE-2020-9859 (unc0ver)

#33
post #14

Be nice if they could patch a kernel bug in macOS with less than a 1.5GB download.

It might seem strange, but they are using a change/build/deploy mechanism designed to deliver updates to any and all parts of an OS across a range of hardware devices. I'm pretty sure the mechanism, from end-to-end, is complex, and providing an optimized path for small changes would require resources, introduce more risk, and come at the expense of something else. Sucks, though, for everyone who doesn't have a reason…

I apologize if this is a stupid question, but, is there a reason they can't do a diff patch on the binary? Would it end up not introducing savings?

Re: Apple patches CVE-2020-9859 (unc0ver)

#34
post #14

Earlier quoted context omitted.

It might seem strange, but they are using a change/build/deploy mechanism designed to deliver updates to any and all parts of an OS across a range of hardware devices. I'm pretty sure the mechanism, from end-to-end, is complex, and providing an optimized path for small changes would require resources, introduce more risk, and come at the expense of something else. Sucks, though, for everyone who doesn't have a reason…

I work on a ship part of the year. Satellite internet shared between 50 people. These Apple updates would saturate the network and grind it to a halt before we started blocking them on the firewall. iMessage got caught in the crossfire and now sometimes works and sometimes doesn't.

^ This is why you should always be able to turn off automatic downloading of updates.

Re: Apple patches CVE-2020-9859 (unc0ver)

#35
post #21

Earlier quoted context omitted.

I'm confused by the GP's us-vs-them animosity. There was an interesting issue that got buried in a polarizing "fan" vs "hater" dynamic. :'( Sigh Like, shouldn't most high-end consumer devices include a dedicated update storage partition or flash area so that user storage is never impacted?

And it's a much more interesting topic than trying to figure out if I'm an Apple astroturfer, which in itself is strange because the top comment in this very thread is me pointing out that Apple unpatched this bug in iOS 13…plus it's against the site guidelines, which is why I assume that the comments have been flagged. But back on topic: there are some devices that do include a specific partition for updates, but I…

As someone who has been corrected by you when quoting from inaccurate sources on iOS and jailbreak related info, thanks for what you do and how you go about it. You're curt and courteous, which can come off as being short, but you're always accurate in my experience. I don't think you should worry too much about people thinking you're an astroturfer, because those who know the technical side know that you know your stuff.

Re: Apple patches CVE-2020-9859 (unc0ver)

#36
post #14

Earlier quoted context omitted.

It might seem strange, but they are using a change/build/deploy mechanism designed to deliver updates to any and all parts of an OS across a range of hardware devices. I'm pretty sure the mechanism, from end-to-end, is complex, and providing an optimized path for small changes would require resources, introduce more risk, and come at the expense of something else. Sucks, though, for everyone who doesn't have a reason…

I work on a ship part of the year. Satellite internet shared between 50 people. These Apple updates would saturate the network and grind it to a halt before we started blocking them on the firewall. iMessage got caught in the crossfire and now sometimes works and sometimes doesn't.

If you're all on the same LAN, then you can configure one device to download it from Apple and share it with the rest.

Re: Apple patches CVE-2020-9859 (unc0ver)

#37
post #31

Earlier quoted context omitted.

No my point is 1.5 GB is too small a transient (you delete the download when done) requirement to make someone have to bump up disk sizes.

You didn't communicate that. There is no "download" to delete on iOS (and derivatives) and it's managed by the system on macOS. It's not a small delta when it should be tiny (100 MiB), that eats up data plan and storage.

You can delete a downloaded (but not installed) update on iOS.

Re: Apple patches CVE-2020-9859 (unc0ver)

#38
post #29

From the equivalent macOS patch: https://support.apple.com/en-us/HT211215 > Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15.5 That's interesting—did the bug exist on both 10.13 and 10.15, but not 10.14?

If it is true the bug was present in iOS 11 and fixed in iOS 12 before being reintroduced in iOS 13, that might align with macOS 10.14 (≈ iOS 12) being unaffected.

So much for regression tests.

Re: Apple patches CVE-2020-9859 (unc0ver)

#39

Earlier quoted context omitted.

And it's a much more interesting topic than trying to figure out if I'm an Apple astroturfer, which in itself is strange because the top comment in this very thread is me pointing out that Apple unpatched this bug in iOS 13…plus it's against the site guidelines, which is why I assume that the comments have been flagged. But back on topic: there are some devices that do include a specific partition for updates, but I…

As someone who has been corrected by you when quoting from inaccurate sources on iOS and jailbreak related info, thanks for what you do and how you go about it. You're curt and courteous, which can come off as being short, but you're always accurate in my experience. I don't think you should worry too much about people thinking you're an astroturfer, because those who know the technical side know that you know your s…

Thanks for the kind words, but you'll find that I'm not always right ;)

Re: Apple patches CVE-2020-9859 (unc0ver)

#40
post #14

Be nice if they could patch a kernel bug in macOS with less than a 1.5GB download.

It might seem strange, but they are using a change/build/deploy mechanism designed to deliver updates to any and all parts of an OS across a range of hardware devices. I'm pretty sure the mechanism, from end-to-end, is complex, and providing an optimized path for small changes would require resources, introduce more risk, and come at the expense of something else. Sucks, though, for everyone who doesn't have a reason…

That’s not an axiomatic truth. Binary diff algorithms exist (ask me, I’ve written several) that can identify and isolate changes across versions even when content is changed at non-block boundaries, non-contiguously, etc and while they are computationally expensive patches to create, they are trivial to unpack/apply.

But generally the software industry has moved to a model where diffs are shunned and “recreate from scratch” is embraced for reasons that range from reproducibility to speed of development to architectural purity and everything in between.

Post reply on HN