Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

21–30 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#21

Earlier quoted context omitted.

The problem is they don't allow the latest MacOS on not very old hardware. If they allowed the latest OS there would be less call to keep the older versions patched. > Name me one widely deployed OS that promises its users patches ad-infinitum. > Microsoft certainly doesn't patch all older versions of Windows. > Neither do all the widely deployed Linux flavours. But the latest and greatest Windows and Linux releases…

> But the latest and greatest Windows and Linux releases are installable on older devices. So is OS X Big Sur[1] and Monterey[2] For the majority of people all they need to do is pull their finger out and upgrade the OS from Catalina to Big Sur or Monterey. [1]https://support.apple.com/en-us/HT211238 [2]https://support.apple.com/en-us/HT212551

Those show about 8 years. My 2011 iMac was dropped by Mojave (7 years).

Modern computers should last a lot longer than that, especially if you can pass them on to users with less demanding requirements.

And fortunately Macs do last longer than that, but you have to install Linux or Windows to keep them up to date.

Re: Apple isn’t patching all the security holes in older versions of macOS

#22
post #5

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.

Which part of upgrading macos to a supported version is not working?

Re: Apple isn’t patching all the security holes in older versions of macOS

#24
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

I find fewer and fewer new features motivating an upgrade. These days it's integration or fluff like tracking the time you spend on each app. I'm on Catalina and have no incentive to upgrade, but have many incentives not to (e.g. breaking compatibility)

Re: Apple isn’t patching all the security holes in older versions of macOS

#25
post #8
post #5

Earlier quoted context omitted.

This caught out a family member. Until you said that I thought it was user error. Gone are the days of recommending apple because 'it just works'.

To be fair El Capitan has been replaced by Sierra which is compatible with machines that are more than 10 years old.

All I know is that they followed the default and ended up being unable to even open the app store to update their OS. Whatever OS support is available for whatever hardware, Apple effectively orphaned that machine.

Re: Apple isn’t patching all the security holes in older versions of macOS

#26
post #15

I'd love to know the "true" histogram of MacOS versions. I'm currently typing this on a machine running Mojave as it is the last one to support 32-bit code. I bet I am not the only one – 10.14 happens to match up with the last "perpetually licensed" adobe suite, for example, as well as older versions of Office. I'm sure Apple know exactly how many people they inconvenience at any given point, and make a calculated de…

This was exactly my case especially with the Adobe. Then my MBP died just few days before deadline. So I got new one with M1 chip. And I had to go with Adobe subscription. Not only it was bloatware it was also buggy. Then Affinity had sale and I bought three Affinity apps for the price of three months with Adobe. Affinity Designer is better for my needs then combination of Photoshop/Illustrator. However Adobe Indesig…

The subscription still sucks.

Re: Apple isn’t patching all the security holes in older versions of macOS

#27

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

Why don’t you consider downloading isrgrootx1.der from its official source[1] and adding it to Keychain Access to be safe?

It’s what I did on my machine running OS X 10.9. No second computer required.

1: https://letsencrypt.org/certificates/

Re: Apple isn’t patching all the security holes in older versions of macOS

#28
They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa.

So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

Re: Apple isn’t patching all the security holes in older versions of macOS

#29

They are offering free upgrades to newer versions of operating system instead. The only case where you're not getting it is when your laptop has been EOLed by Apple, which is effectively the same thing.

To note, 32bit compat has been discontinued with Catalina, so people who kept an old version around for that purpose are SOL.

Moving to a virtualized instance is an option, but then I wonder how PITA it is to keep the virtual one secure.

Re: Apple isn’t patching all the security holes in older versions of macOS

#30

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

Why don’t you consider downloading isrgrootx1.der from its official source[1] and adding it to Keychain Access to be safe? It’s what I did on my machine running OS X 10.9. No second computer required. 1: https://letsencrypt.org/certificates/

Yes that's how you solve it. But you need the updated certificate to view this website without warning, thus the need for another computer.
Post reply on HN