Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

121–130 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#121
>Apple should spell out its update policies for older versions of macOS, as Microsoft does, rather than relying on its current hand-wavy release timing.

I maintain endoflife.date/iphone and endoflife.date/macos, and this has been a continuous problem - Apple doesn't provide a document that notes supported OS releases anywhere. The closest we got was in the iOS 15 releases notes which confirmed Apple would provide iOS14 with security updates (something that they clearly failed at).

Apple also released an emergency security fix for iOS12 when it was unsupported, which was nice - but Apple needs to clearly document when can users expect such fixes.

The only pages Apple does provide is list of supported devices, which only covers the latest OS, and is unreliable as a result.

https://support.apple.com/en-in/guide/iphone/iphe3fa5df43/io...

Re: Apple isn’t patching all the security holes in older versions of macOS

#122
post #44

Naive question: why is it that the newest version of macos doesn't run on older machines? (The solution is, of course, to install Linux on them.)

I think their main reason is that Apple is a hardware company. They think of new features, build hardware for them, and then tweak their software (OS and applications) to aggressively use that new hardware. Supporting older hardware is extra work that doesn’t bring in extra money. Also, oftentimes, it isn’t possible to backport features in a performant way (a lot of the ML stuff would only crawl on 10 year old hardwa…

I have a macbook pro late 2013 with a retina display, i7 cpu, 16gb ram and 512gb ssd that doesn’t get monterrey. I am not very happy about it, it’s a waste

Re: Apple isn’t patching all the security holes in older versions of macOS

#123

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

From memory, the error message it gives says this is what you do. Though I've long since accepted that no one ever reads what the message says.

Re: Apple isn’t patching all the security holes in older versions of macOS

#124

They are not even shipping root certificates in El Capitan (os from 5 years ago) and there is no way to update them safely without another computer. This is arguably the most important aspect of the trust ecosystem and there is no way to browse safely without those.

I did this exact thing for a client last week. No need for another computer I just downloaded the installer from the app store and run it as normal. Maybe they have tweaked things.

Re: Apple isn’t patching all the security holes in older versions of macOS

#125

Earlier quoted context omitted.

Sorry, I'm not sure I understand your comment. You can presume whatever you want, but I'm telling you how it works. :) IIRC there are plans to switch Chromium to its own certificate store on all platforms, but they seem to be a ways off.

When you add a root certificate to a browser, typically it is configured to accept BOTH the added cert and the built-in/system certs. There would certainly be no reason not to in this case.

[deleted]

Re: Apple isn’t patching all the security holes in older versions of macOS

#126
post #108

Earlier quoted context omitted.

32-bit support is not coming back, and nor should it. Having a mix of apps means having both 32-bit and 64-bit copies of system libraries loaded in memory all the time, which is inefficient. For security reasons, you probably should partition your Mac, run Catalina or Big Sur* on your main partition with your personal stuff, PGP keys, and other important things, and have a separate partition with Mojave for your lega…

(I'm not the person to whom you were replying) One of my "important things" is a 32-bit app required for a freelance project. This freelance project also requires some 64-bit apps, so I don't see how two partitions would help here. Am I missing something? (Sincere question -- I'm looking for a new solution because I know Mojave won't be supported forever.)

If that 32-bit app has a Windows version, you could run it on current macOS using CrossOver. Performance might take a hit depending on what you're doing, but the MacBook Pro M1 runs Windows games fairly well in CrossOver. Wine might also work.

If the app only available for 32-bit macOS, I suppose your remaining options are running Mojave in a local VM, or in the cloud (AWS offers Mojave instances for example) for your freelance work.

Out of curiosity, is this an internal enterprise app, or a consumer app? Most consumer apps have alternatives for 64-bit macOS.

> I know Mojave won't be supported forever.

It's unlikely to receive further security updates at this point.

If you're not on the latest macOS, you're not getting all the security updates. You will still get many security updates if you're one version prior (Big Sur right now), and if you're two versions prior you might get a few updates (Catalina). But you're unlikely to get updates to Mojave after this year.

Re: Apple isn’t patching all the security holes in older versions of macOS

#127
post #110

Earlier quoted context omitted.

What are these 32-bit apps people seem to keep running? If they are games, Boot Camp is an option on Intel macs, and CrossOver [1] is an option on Apple Silicon. https://applesilicongames.com/games

WXtoImg is what I miss the most. There’s a long tail of unsupported old software with unique capabilities.

I see it's no longer being updated. Does the Windows version[1] work on macOS using Wine/CrossOver?

1. https://wxtoimgrestored.xyz/downloads/

Re: Apple isn’t patching all the security holes in older versions of macOS

#128
post #39

Earlier quoted context omitted.

All I know is that they followed the default and ended up being unable to even open the app store to update their OS. Whatever OS support is available for whatever hardware, Apple effectively orphaned that machine.

I recently updated an old MacbookPro6,2 from Yosemite to High Sierra and that was a complete disaster. Took me a huge amount of time. I think there two problems: the upgrade could not handle the way the disk was partitioned (or something else). Everything I tried kept failing until I removed the disk, and completely wiped it. Discussions I found online were not helpful. The other part is the magic you need to downloa…

High Sierra introduced APFS, so I'm not surprised you might have had formatting issues. Still, I wonder how common multiple partitions really are - among nerds, sure - in the broader userbase.

Re: Apple isn’t patching all the security holes in older versions of macOS

#129
post #65

Earlier quoted context omitted.

Especially since the update downloads in the background and doesn't require your input after starting it. You can start the update, go do something else, come back and hour later and it's done.

Ahaha yes, and then you're left "only" with a few hours figuring out what broke in your setup because stuff like /usr/local was "liberally" modified by the update. Plus, of course, oops all your 32bit games are ded. (Yeah sure, not your average Mac user, but still - don't discount the pain that any arbitrary update can and will inflict).

In my experience, updates have been completely painless to the point that at first you hardly notice you updated at all.

Re: Apple isn’t patching all the security holes in older versions of macOS

#130
post #110

Earlier quoted context omitted.

WXtoImg is what I miss the most. There’s a long tail of unsupported old software with unique capabilities.

I see it's no longer being updated. Does the Windows version[1] work on macOS using Wine/CrossOver? 1. https://wxtoimgrestored.xyz/downloads/

Yes, it's no longer being updated, which is why we're stuck on the 32-bit version for MacOS.

I've not gotten it to work in Wine/CrossOver, but perhaps someone more skilled than I am could get it to work. I've just used it in virtualized Linux for now.

Post reply on HN