Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

91–100 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#92
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

My a1502 still has Mojave, and I'm not planning on returning to MacOS until they reinstate 32-bit support. It feels like I'm screaming into the void when I tell other people about this, they almost always just shrug their shoulders and say something along the lines of "the Twitter app still works though".

Re: Apple isn’t patching all the security holes in older versions of macOS

#93
post #88
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

I wish I could run Mojave or Catalina on my brand new 16". It came with Monterey, which is ugly. Whoever thought light grey text on dark grey background was a good or reasonable UI choice should be fired. It's the Windows XP Home of operating systems.

The biggest thing preventing me from upgrading to Big Sur+ is how ugly the UI is. Gone are the elegant, sleek windows of old, replaced by bubbly flat sheets and weird, incongruous menu systems. It feels like Apple was taking the piss out of the GNOME desktop and then forgot to press the "we're just joking" button before they shipped it.

Re: Apple isn’t patching all the security holes in older versions of macOS

#94
> The simple solution for this problem is that Apple should actually provide all of the security updates for all of the operating systems that it is actively updating

That's circular reasoning. The older operating systems are only getting security updates, as the article notes, so their definition of "actively updating" is "getting security updates". When Apple isn't issuing security updates, it is not "actively updating".

Maybe what the author wants to say is something along the lines that Apple should provide timely security updates for all operating systems released over the past 10-15 years.

Re: Apple isn’t patching all the security holes in older versions of macOS

#95
post #56
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

With all due respect. How much time do you think it will take to download and install an update every few years?

I know... not much. And it's the same kind of argument one would use when postponing say, garden work, cleaning the oven, etc. I have taken a vacation day next week to get this done - not just the macOS upgrade of course, but a long list of pending household tasks.

Re: Apple isn’t patching all the security holes in older versions of macOS

#96

Earlier quoted context omitted.

Maybe with curl/wget?

Both of which will also need a certificate store

Use the -k switch on curl to skip certificate verification.

Use a phone, or a phone call to a trusted friend, to verify the signature of the certificate.

Obviously not instructions you can give to an ordinary user, but that line was crossed at curl.

Re: Apple isn’t patching all the security holes in older versions of macOS

#97

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

Oddly, this is explicitly spelled out in old versions of iOS. I learned of it recently because my aging iPhone 8 died and I tried to revive my iPhone 5 while waiting for a replacement. (It did start up but was basically useless otherwise.)

Re: Apple isn’t patching all the security holes in older versions of macOS

#98
post #47
post #24

Earlier quoted context omitted.

I find fewer and fewer new features motivating an upgrade. These days it's integration or fluff like tracking the time you spend on each app. I'm on Catalina and have no incentive to upgrade, but have many incentives not to (e.g. breaking compatibility)

One aspect I find infuriating is UX changes. I like the way things were, change for change's sake is annoying.

It would be good to just have a choice. The designers can go nuts every year, just give me a drop down and I'll pick the skin I like.

Re: Apple isn’t patching all the security holes in older versions of macOS

#99

I'd love to know the "true" histogram of MacOS versions. I'm currently typing this on a machine running Mojave as it is the last one to support 32-bit code. I bet I am not the only one – 10.14 happens to match up with the last "perpetually licensed" adobe suite, for example, as well as older versions of Office. I'm sure Apple know exactly how many people they inconvenience at any given point, and make a calculated de…

According to the Steam Hardware & Software Survey [0], where the 32-bit thing hit really hard, the numbers could look a little like this: MacOS 11.6.0: 11.22% MacOS 11.5.2: 2.87% MacOS 10.16.0: 44.92% MacOS 10.15.7: 11.66% MacOS 10.14.6: 6.80% MacOS 10.13.6: 6.41% Other 16.12% According to this other usage plot [1] it doesn't like the number of people staying on Mojave was any significant. Please note that macOS 10.1…

So, roughly 70% are running Catalina or later.

This is pretty good. Macbooks do usually get software updates for many years - as do iPhones and iPads of late.

People who bought early Apple Watches (some of which were very expensive!) didn't get updates past watchOS 4 however, which was sad to see.

Re: Apple isn’t patching all the security holes in older versions of macOS

#100
post #23

I'm still running Mojave. Never found the time to upgrade. Ridiculous, I know. Anyone else in the same boat?

My a1502 still has Mojave, and I'm not planning on returning to MacOS until they reinstate 32-bit support. It feels like I'm screaming into the void when I tell other people about this, they almost always just shrug their shoulders and say something along the lines of "the Twitter app still works though".

32-bit support is not coming back, and nor should it. Having a mix of apps means having both 32-bit and 64-bit copies of system libraries loaded in memory all the time, which is inefficient.

For security reasons, you probably should partition your Mac, run Catalina or Big Sur* on your main partition with your personal stuff, PGP keys, and other important things, and have a separate partition with Mojave for your legacy apps. If those are mostly games, then you may be better off with a Windows partition instead of Mojave, because that would support even more games.

* A1502 does not get Monterey, I think.

Post reply on HN