Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

71–80 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#71
post #68

Earlier quoted context omitted.

The bit where Apple's OS tries to connect to Apple's update servers, and can't authenticate because Apple switched to an incompatible root CA.

Ah yeah, I've recently received for free an iMac running Macos 10.9. It's simply impossible to upgrade; the only proposed upgrade release is 10.11, the installation starts then fails in a loop. Fortunately I don't actually need to save anything from this machine, and I have another Mac to download a newer OS installer, but that's quite painful.

If it's a 2007/2008 model iMac then it will be able to run 10.11 (El Capitan). If it's a Late 2009 iMac or newer then it will be able to run at least 10.13 (High Sierra).

If the default/upgrade installation is failing then I'd try creating a bootable installer on USB [1]. If it still fails then try erasing the target drive first to do a clean install (you can do this by running Disk Utility from within the installer).

[1] Instructions here: https://support.apple.com/HT201372

Re: Apple isn’t patching all the security holes in older versions of macOS

#72
post #49

Earlier quoted context omitted.

But why don't they just keep the drivers etc. from the previous version? This doesn't seem to be a problem for Linux.

Linux would also require drivers to be recompiled for a new kernel. This is not an option for most proprietary drivers for products long abandoned by the manufacturer. For the more common and popular hardware there is a good chance that open source drivers can be maintained by the community but if your laptop relies on a somewhat obscure chipset or microcontroller then your mileage will vary...a lot. Look up "Intel G…

[deleted]

Re: Apple isn’t patching all the security holes in older versions of macOS

#73
post #70
post #51

Earlier quoted context omitted.

That's a neat hack if you only have one input box. But all the extra code on the backend needed to differentiate between a normal password and a password+pin sounds like something which could accidentally weaken security.

Maybe they’re leveraging radius for some of of that?

Or PAM, or BSD_Auth, or AD, or ... there's a lot of options.

Supposedly they can also see which capabilities the client has, allowing the fix server side. Why they did that we can only speculate, same with why its not well known.

I can imagine an engineer with a kid who got a handmedown from mom/pop, and they silently fixing it this way because its within their expertise.

I'd like to hear the authentic story behind it. Hopefully one day!

Re: Apple isn’t patching all the security holes in older versions of macOS

#74

Yawn. More Apple bashing that is not backed up by any facts. Name me one widely deployed OS that promises its users patches ad-infinitum. Microsoft certainly doesn't patch all older versions of Windows. Neither do all the widely deployed Linux flavours, they all have clearly defined EOL policies. Nor do the BSDs, e.g. OpenBSD has a "current plus previous" policy. You have to draw a line in the sand somewhere in terms…

>Microsoft certainly doesn't patch all older versions of Windows. This is not about EOL OS releases, this is about Catalina (macOS 10.15, released in 2019). Apple advertises Catalina as still supported, last update was 15.15.7 on October 25 of this year ( https://en.wikipedia.org/wiki/MacOS_version_history#Releases ). >Neither do all the widely deployed Linux flavours, they all have clearly defined EOL policies. The…

Exactly on point regarding Debian. I've been running Debian stable since 2012 or 2013, and I've only upgraded my hardwear when a motherboard died or when I wanted a new laptop for reasons other than the OS.

Re: Apple isn’t patching all the security holes in older versions of macOS

#75
post #26
post #15

Earlier quoted context omitted.

This was exactly my case especially with the Adobe. Then my MBP died just few days before deadline. So I got new one with M1 chip. And I had to go with Adobe subscription. Not only it was bloatware it was also buggy. Then Affinity had sale and I bought three Affinity apps for the price of three months with Adobe. Affinity Designer is better for my needs then combination of Photoshop/Illustrator. However Adobe Indesig…

The subscription still sucks.

Welcome to the world of big-tech commercial software. You either pay a subscription fee in money or your private information for ad targeting. Sometimes even both.

Re: Apple isn’t patching all the security holes in older versions of macOS

#76

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

I made the mistake of reinstalling macOS on my late 2015 rMBP using internet recovery. I found myself locked in a loop where I couldn't upgrade to the latest macOS because it required 2FA.

I called Apple Support and didn't tell me this information and simply said they can't bypass or disable 2FA. It was only by researching that I discovered this workaround.

This was one of the worst user experiences I have experienced on an Apple product.

Re: Apple isn’t patching all the security holes in older versions of macOS

#77

Earlier quoted context omitted.

Yes that's how you solve it. But you need the updated certificate to view this website without warning, thus the need for another computer.

Maybe with curl/wget?

Both of which will also need a certificate store

Re: Apple isn’t patching all the security holes in older versions of macOS

#79

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

I made the mistake of reinstalling macOS on my late 2015 rMBP using internet recovery. I found myself locked in a loop where I couldn't upgrade to the latest macOS because it required 2FA. I called Apple Support and didn't tell me this information and simply said they can't bypass or disable 2FA. It was only by researching that I discovered this workaround. This was one of the worst user experiences I have experience…

I feel like they patched in an error message explaining this on older versions of OS X, because I definitely was prompted to do it this way. Maybe just in iTunes?

Re: Apple isn’t patching all the security holes in older versions of macOS

#80
post #68

Earlier quoted context omitted.

Ah yeah, I've recently received for free an iMac running Macos 10.9. It's simply impossible to upgrade; the only proposed upgrade release is 10.11, the installation starts then fails in a loop. Fortunately I don't actually need to save anything from this machine, and I have another Mac to download a newer OS installer, but that's quite painful.

If it's a 2007/2008 model iMac then it will be able to run 10.11 (El Capitan). If it's a Late 2009 iMac or newer then it will be able to run at least 10.13 (High Sierra). If the default/upgrade installation is failing then I'd try creating a bootable installer on USB [1]. If it still fails then try erasing the target drive first to do a clean install (you can do this by running Disk Utility from within the installer)…

It's a 2014 model, it can definitely run Macos 11. But as it has been unused for the past few years, it hasn't been upgraded and it's quite funny how utterly unusable it became: very few websites work at all (certificates problem), it's impossible to install any current application because even Firefox LTS requires 10.13 or so, and it's impossible to upgrade without using another Mac to download the update tool. That's not very user-friendly if you ask me :)
Post reply on HN