Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

31–40 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#31

Yawn. More Apple bashing that is not backed up by any facts. Name me one widely deployed OS that promises its users patches ad-infinitum. Microsoft certainly doesn't patch all older versions of Windows. Neither do all the widely deployed Linux flavours, they all have clearly defined EOL policies. Nor do the BSDs, e.g. OpenBSD has a "current plus previous" policy. You have to draw a line in the sand somewhere in terms…

The problem is they don't allow the latest MacOS on not very old hardware. If they allowed the latest OS there would be less call to keep the older versions patched. > Name me one widely deployed OS that promises its users patches ad-infinitum. > Microsoft certainly doesn't patch all older versions of Windows. > Neither do all the widely deployed Linux flavours. But the latest and greatest Windows and Linux releases…

> But the latest and greatest Windows and Linux releases are installable on older devices.

This was certainly true until recently when Microsoft went all Windows 11, which only works on a small, whitelisted subset of X86-compatible CPUs and also mandated TPM 2.0.

Now only Linux offers semi-guaranteed support for older hardware.

Re: Apple isn’t patching all the security holes in older versions of macOS

#32
post #20

Earlier quoted context omitted.

The key point for this IMHO is, as mentioned in the article "But it's also time for better communication on this subject. Apple should spell out its update policies for older versions of macOS, as Microsoft does, rather than relying on its current hand-wavy release timing". If Apple properly supported Catalina, that would be great; if Apple explicitly said that Catalina is out of support / EOL and people need to upgr…

I really don’t get this. Apple does provide free updates for all. If you skip major versions, you’re shooting yourself in the foot and blaming Apple for allowing it. Apple is giving you the update: Install it and now it’s up to date. They don’t have to support multiple versions of the same thing indefinitely. The situations (devices) where the update isn’t possible (i.e. they’re outdated too early) can probably be co…

Only when using a release that is EOL is it shooting yourself in the foot in regards to security. It doesn't matter if the new release is free or not (Linux and BSD are), not everyone wants to track the latest release for whatever reason they like and there's no problem with that if it still receives timely security updates, which is a standard practice on every other OS. If Apple doesn't want to do this, it should be clearly stated. Otherwise as this behavior is outside of the norm, Apple should be rightly critised for it.

Re: Apple isn’t patching all the security holes in older versions of macOS

#34
post #8

Earlier quoted context omitted.

To be fair El Capitan has been replaced by Sierra which is compatible with machines that are more than 10 years old.

AFAIK the youngest machine stuck on El Capitan (released 6 years ago, not 5) is a MacBook Air released 11 years and one month ago. Anything newer is at least on High Sierra (relased 4 years ago).

Does Apple not charge for OS upgrades anymore ?

Re: Apple isn’t patching all the security holes in older versions of macOS

#35

Naive question: why is it that the newest version of macos doesn't run on older machines? (The solution is, of course, to install Linux on them.)

Lack of drivers, or the newer OS may require a specific instruction set or feature not present on older hardware.

Re: Apple isn’t patching all the security holes in older versions of macOS

#36

Earlier quoted context omitted.

Why don’t you consider downloading isrgrootx1.der from its official source[1] and adding it to Keychain Access to be safe? It’s what I did on my machine running OS X 10.9. No second computer required. 1: https://letsencrypt.org/certificates/

Yes that's how you solve it. But you need the updated certificate to view this website without warning, thus the need for another computer.

> But you need the updated certificate to view this website without warning

I didn’t. IIRC they did some whacky thing on their own site such that it still worked in Chromium.

Re: Apple isn’t patching all the security holes in older versions of macOS

#37
post #34

Earlier quoted context omitted.

AFAIK the youngest machine stuck on El Capitan (released 6 years ago, not 5) is a MacBook Air released 11 years and one month ago. Anything newer is at least on High Sierra (relased 4 years ago).

Does Apple not charge for OS upgrades anymore ?

The last paid version was OS X Mountain Lion (10.8, released 2012).

Re: Apple isn’t patching all the security holes in older versions of macOS

#38
post #35

Naive question: why is it that the newest version of macos doesn't run on older machines? (The solution is, of course, to install Linux on them.)

Lack of drivers, or the newer OS may require a specific instruction set or feature not present on older hardware.

But why don't they just keep the drivers etc. from the previous version? This doesn't seem to be a problem for Linux.

Re: Apple isn’t patching all the security holes in older versions of macOS

#39
post #8

Earlier quoted context omitted.

To be fair El Capitan has been replaced by Sierra which is compatible with machines that are more than 10 years old.

All I know is that they followed the default and ended up being unable to even open the app store to update their OS. Whatever OS support is available for whatever hardware, Apple effectively orphaned that machine.

I recently updated an old MacbookPro6,2 from Yosemite to High Sierra and that was a complete disaster. Took me a huge amount of time.

I think there two problems: the upgrade could not handle the way the disk was partitioned (or something else). Everything I tried kept failing until I removed the disk, and completely wiped it. Discussions I found online were not helpful.

The other part is the magic you need to download High Sierra on a newer Macbook. It is not as if you can just go to the Apple store and download it.

That said, I have been using Macbooks for work for the last 10 years or so. They always get upgraded a couple of times during their lifetimes. Usually not a big problem. So I was quite surprised how bad it went.

Re: Apple isn’t patching all the security holes in older versions of macOS

#40

Earlier quoted context omitted.

Why don’t you consider downloading isrgrootx1.der from its official source[1] and adding it to Keychain Access to be safe? It’s what I did on my machine running OS X 10.9. No second computer required. 1: https://letsencrypt.org/certificates/

Yes that's how you solve it. But you need the updated certificate to view this website without warning, thus the need for another computer.

Maybe with curl/wget?
Post reply on HN