Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

1–10 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#3
They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

Re: Apple isn’t patching all the security holes in older versions of macOS

#5

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.

Re: Apple isn’t patching all the security holes in older versions of macOS

#6

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

[deleted]

Re: Apple isn’t patching all the security holes in older versions of macOS

#7
Yawn. More Apple bashing that is not backed up by any facts.

Name me one widely deployed OS that promises its users patches ad-infinitum.

Microsoft certainly doesn't patch all older versions of Windows.

Neither do all the widely deployed Linux flavours, they all have clearly defined EOL policies.

Nor do the BSDs, e.g. OpenBSD has a "current plus previous" policy.

You have to draw a line in the sand somewhere in terms of patching historical versions. Promising your users you will patch all historical versions forever is not feasible, because it means you are promising you will patch all dependencies forever, and that will require a lot of massive teams of developers doing nothing all day but patching legacy software.

Re: Apple isn’t patching all the security holes in older versions of macOS

#8
post #5

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.

To be fair El Capitan has been replaced by Sierra which is compatible with machines that are more than 10 years old.

Re: Apple isn’t patching all the security holes in older versions of macOS

#9
I'd love to know the "true" histogram of MacOS versions. I'm currently typing this on a machine running Mojave as it is the last one to support 32-bit code. I bet I am not the only one – 10.14 happens to match up with the last "perpetually licensed" adobe suite, for example, as well as older versions of Office.

I'm sure Apple know exactly how many people they inconvenience at any given point, and make a calculated decision about support.

Re: Apple isn’t patching all the security holes in older versions of macOS

#10
post #8
post #5

Earlier quoted context omitted.

This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.

To be fair El Capitan has been replaced by Sierra which is compatible with machines that are more than 10 years old.

AFAIK the youngest machine stuck on El Capitan (released 6 years ago, not 5) is a MacBook Air released 11 years and one month ago. Anything newer is at least on High Sierra (relased 4 years ago).
Post reply on HN