Apple isn’t patching all the security holes in older versions of macOS
1–10 of 132 posts
Re: Apple isn’t patching all the security holes in older versions of macOS
#2Re: Apple isn’t patching all the security holes in older versions of macOS
#3Re: Apple isn’t patching all the security holes in older versions of macOS
#4Re: Apple isn’t patching all the security holes in older versions of macOS
#5They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.
Re: Apple isn’t patching all the security holes in older versions of macOS
#6They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.
Re: Apple isn’t patching all the security holes in older versions of macOS
#7Name me one widely deployed OS that promises its users patches ad-infinitum.
Microsoft certainly doesn't patch all older versions of Windows.
Neither do all the widely deployed Linux flavours, they all have clearly defined EOL policies.
Nor do the BSDs, e.g. OpenBSD has a "current plus previous" policy.
You have to draw a line in the sand somewhere in terms of patching historical versions. Promising your users you will patch all historical versions forever is not feasible, because it means you are promising you will patch all dependencies forever, and that will require a lot of massive teams of developers doing nothing all day but patching legacy software.
Re: Apple isn’t patching all the security holes in older versions of macOS
#8They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.
This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.
Re: Apple isn’t patching all the security holes in older versions of macOS
#9I'm sure Apple know exactly how many people they inconvenience at any given point, and make a calculated decision about support.
Re: Apple isn’t patching all the security holes in older versions of macOS
#10Earlier quoted context omitted.
This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.
To be fair El Capitan has been replaced by Sierra which is compatible with machines that are more than 10 years old.