Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

51–60 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#51

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

That's a neat hack if you only have one input box. But all the extra code on the backend needed to differentiate between a normal password and a password+pin sounds like something which could accidentally weaken security.

Re: Apple isn’t patching all the security holes in older versions of macOS

#52

Earlier quoted context omitted.

The problem is they don't allow the latest MacOS on not very old hardware. If they allowed the latest OS there would be less call to keep the older versions patched. > Name me one widely deployed OS that promises its users patches ad-infinitum. > Microsoft certainly doesn't patch all older versions of Windows. > Neither do all the widely deployed Linux flavours. But the latest and greatest Windows and Linux releases…

> But the latest and greatest Windows and Linux releases are installable on older devices. This was certainly true until recently when Microsoft went all Windows 11, which only works on a small, whitelisted subset of X86-compatible CPUs and also mandated TPM 2.0. Now only Linux offers semi-guaranteed support for older hardware.

To note: Windows 10 is still supported and will be up to 2025. And when that date arrives, Microsoft has a history of patching out of support Operating Systems. Mostly because they have large enterprise contracts which last longer than the EOL of their OS.

Also Microsoft provides an official guide on how to install Windows 11 on older hardware. My neighbor has Windows 11 on his 10 year old laptop running an i7 2500 and it's butter smooth.

Re: Apple isn’t patching all the security holes in older versions of macOS

#53
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

Even worse: Sierra. Ouch. 10 years ago I used to go for every upgrade immediately (even .0’s). IMO new versions since maybe 10.8 added mostly data collecting bloat. macOS moved far away from the OS I once loved (peaked at Snow Leopard IMO). Funnily, macOS became “free” after Snow Leopard, so you’ve probably paid with your data ever since.

Re: Apple isn’t patching all the security holes in older versions of macOS

#54

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

WHAT! How did I not know the append-the-code trick

I spent some time searching the web in my frustration thinking that 2fa was impossible on this MacBook. I think it was a stackoverflow comment somewhere that said to try this...

Re: Apple isn’t patching all the security holes in older versions of macOS

#55
post #20

Earlier quoted context omitted.

The key point for this IMHO is, as mentioned in the article "But it's also time for better communication on this subject. Apple should spell out its update policies for older versions of macOS, as Microsoft does, rather than relying on its current hand-wavy release timing". If Apple properly supported Catalina, that would be great; if Apple explicitly said that Catalina is out of support / EOL and people need to upgr…

I really don’t get this. Apple does provide free updates for all. If you skip major versions, you’re shooting yourself in the foot and blaming Apple for allowing it. Apple is giving you the update: Install it and now it’s up to date. They don’t have to support multiple versions of the same thing indefinitely. The situations (devices) where the update isn’t possible (i.e. they’re outdated too early) can probably be co…

I agree that they don’t have to support multiple versions of the same thing indefinitely, however they do have to say what they are supporting and for how long they're going to support what.

The fact that Big Sur was released does not automatically mean anything about the support for Catalina, because there are all kinds of reasons not to make a major version upgrade even if the hardware is still compatible with the new version; the major upgrades do break certain aspects of software and implement changes to functionality and UI, not just fixes for security bugs.

The core issue is that simple questions like "Is Catalina being supported as of 14th November 2021 or not" and "Which is the date when Big Sur support ends and you are expected to migrate to Monterey or later for security updates" deserve a clear answer from Apple, and it seems that they are refusing to answering that with any official, published policy.

Re: Apple isn’t patching all the security holes in older versions of macOS

#57

Earlier quoted context omitted.

Yes that's how you solve it. But you need the updated certificate to view this website without warning, thus the need for another computer.

> But you need the updated certificate to view this website without warning I didn’t. IIRC they did some whacky thing on their own site such that it still worked in Chromium.

Doesn't Chromium use its own CA store, or is that different on the OS X version?

Re: Apple isn’t patching all the security holes in older versions of macOS

#58
post #56
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

With all due respect. How much time do you think it will take to download and install an update every few years?

Especially since the update downloads in the background and doesn't require your input after starting it. You can start the update, go do something else, come back and hour later and it's done.

Re: Apple isn’t patching all the security holes in older versions of macOS

#59

Microsoft has spoiled us these many decades by providing patches for out-of-support operating systems.

It’s their responsibility as they programmed allowing these flaws to begin with. Companies that write software and EOL it have a moral obligation to support it until the end of times, or provide an upgrade path to keep it supported.

Re: Apple isn’t patching all the security holes in older versions of macOS

#60
post #49

Earlier quoted context omitted.

But why don't they just keep the drivers etc. from the previous version? This doesn't seem to be a problem for Linux.

Linux would also require drivers to be recompiled for a new kernel. This is not an option for most proprietary drivers for products long abandoned by the manufacturer. For the more common and popular hardware there is a good chance that open source drivers can be maintained by the community but if your laptop relies on a somewhat obscure chipset or microcontroller then your mileage will vary...a lot. Look up "Intel G…

> Most notably, OSX dropped support for all nVidia GPUs from Mojave onwards

Not those shipped with Macs. The GeForce kexts to support the NVIDIA GPU gens that Apple shipped, Fermi and Kepler, are still present even on Monterey.

Post reply on HN