Live data from Hacker News

About the security content of macOS Tahoe 26.6

support.apple.com

21–30 of 157 posts

Re: About the security content of macOS Tahoe 26.6

#21
post #18

Map the amount of fixes with "... improved bounds checking..." , "...improved memory handling..." , "...improved memory management..." into the amount of developer, QA and release management teams salaries per hour, versus other stuff they could be working on, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers a…

>>, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers are always exposed to the world network.

You need also factor development time and ease of finding developers willing to work in a specific language. There are other factors like readability of the code (very verbose languages are likely to be worse) and cost of maintenance - languages forcing a lot of abstractions are likely much worse.

Re: About the security content of macOS Tahoe 26.6

#22
post #8

Earlier quoted context omitted.

Apple isn’t friends with OpenAI anymore

What happened?

The gist is, OpenAI hired a high ranking Apple employee who helped other Apple employees get hired by OpenAI and exfiltrate Apple trade secrets in the process.

Allegedly of course.

Re: About the security content of macOS Tahoe 26.6

#23
post #7

Earlier quoted context omitted.

One CVE even lists the same person twice! CVE-2026-64691: Ruslan Dautov, Ruslan Dautov

One of them lists an anonymous person! CVE-2026-43744: Mathis Mansière, an anonymous researcher

It's Ted Danson.

Re: About the security content of macOS Tahoe 26.6

#24
post #19
post #14

Earlier quoted context omitted.

Apple also hosts a copy of Claude internally in their servers.

Do they? As in Claude but on premises? Wonder if this is gonna be the solution that e.g. banks will require, exactly like they do now for cloud services (e.g. Azure on premises).

Pretty extreme solution… you can get Claude models from AWS Bedrock and Google Model Zoo. These are both very helpful for compliance and security, but do require you to have a cloud strategy.

Re: About the security content of macOS Tahoe 26.6

#25
post #10

Earlier quoted context omitted.

One of them lists an anonymous person! CVE-2026-43744: Mathis Mansière, an anonymous researcher

It reads as if "an anonymous researcher" is describing Mathis Mansière, which is quite humorous.

This reminds me of my favorite segment of the TV show Curb Your Enthusiasm: https://youtu.be/JqrJ4wGid4Y

Re: About the security content of macOS Tahoe 26.6

#26
post #7
post #4

Collision counts are absurd. CVE-2026-43739 has roughly twenty credited researchers; CVE-2026-43816 has nearly as many. And ai attribution getting credit.

One CVE even lists the same person twice! CVE-2026-64691: Ruslan Dautov, Ruslan Dautov

> One CVE even lists the same person twice!

Not necessarily. Could be two persons sharing that name. See https://revstat.ine.pt/index.php/REVSTAT/article/view/382

Re: About the security content of macOS Tahoe 26.6

#27
post #18

Map the amount of fixes with "... improved bounds checking..." , "...improved memory handling..." , "...improved memory management..." into the amount of developer, QA and release management teams salaries per hour, versus other stuff they could be working on, and that gives an approximate value of how using specific languages maps into monetary loss, and why companies are starting to care nowadays, given computers a…

“nah bro, all those other developers are just garbage, I am the one person that can write memory safe C”

Re: About the security content of macOS Tahoe 26.6

#28
post #24
post #19

Earlier quoted context omitted.

Do they? As in Claude but on premises? Wonder if this is gonna be the solution that e.g. banks will require, exactly like they do now for cloud services (e.g. Azure on premises).

Pretty extreme solution… you can get Claude models from AWS Bedrock and Google Model Zoo. These are both very helpful for compliance and security, but do require you to have a cloud strategy.

Yeah, albeit an increasingly second-rate experience, at least when it comes to Bedrock.

Re: About the security content of macOS Tahoe 26.6

#29
post #24
post #19

Earlier quoted context omitted.

Do they? As in Claude but on premises? Wonder if this is gonna be the solution that e.g. banks will require, exactly like they do now for cloud services (e.g. Azure on premises).

Pretty extreme solution… you can get Claude models from AWS Bedrock and Google Model Zoo. These are both very helpful for compliance and security, but do require you to have a cloud strategy.

Some data is so sensitive it likely has to stay on premises though.

Re: About the security content of macOS Tahoe 26.6

#30

Lots of "in collaboration with Claude and Anthropic Research" mentions, no mentions of other labs. I'd assume Apple already had access to whatever the most powerful model is at the various US-based labs, but perhaps not?

Those were voluntary disclosures by two Anthropic researchers and the security firm Calif. I know one more CVE on the list that was discovered using an AI agent and wasn't disclosed as such. I suspect there are many more.
Post reply on HN