Live data from Hacker News

About the security content of macOS Tahoe 26.6

support.apple.com

141–150 of 157 posts

Re: About the security content of macOS Tahoe 26.6

#141

Earlier quoted context omitted.

What I mean is that for “honest” software, built-in to the OS or otherwise, the programmer finds a situation where they take some user-supplied input and concatenate that into a path, and call something like OS.read(). If they want to prevent the user from causing havoc, they now find themselves dealing with path validation in their software instead of calling OS.safeOpen(), which would be a reduced subset of allowed…

If the OS is working properly, the havoc should just result in "permission denied." If there's a path on the system that the user should not be able to read, that's the job of the OS to handle, not the individual applications.

How is it permission denied if the app is running as admin? The OS "handled" it by giving admin app admin access. Sure, it was tricked by the user input, but that's what the fixes are for?

Re: About the security content of macOS Tahoe 26.6

#142

Earlier quoted context omitted.

You can already turn off most glass effects in 26 via "System Settings => Accessibility => Display => Reduce Transparency". I had that turned off years ago (for reasons I don't remember), and was wondering what all the fuzz was about when 26 came out because I didn't see much of a difference ;) IMHO the actual important visual changes in the 27 beta is that rolls back the bizarre oversized corner radius in Finder win…

I think that is just iOS no? Or does that work on MacOS too

It works on macOS too, I don't own any iOS devices.

Re: About the security content of macOS Tahoe 26.6

#143

Earlier quoted context omitted.

Same thing happens almost every release. I've stopped updating my Mac machine until I see something in the release notes I literally have to have in order to continue doing macOS/iOS builds, otherwise I'm staying on the version I've validated to work, and I know the existing bugs with.

As we used to say in the Windows world, wait for service pack 3.

That doesn't work any longer given patch tuesdays, at work wait that IT validates them and pushes the updates via managed WSU, at home, it is worthwhile wanting if something hits the news on WindowsCentral, Verge or what have you.

Re: About the security content of macOS Tahoe 26.6

#144

Earlier quoted context omitted.

He left in 2019 and formed his own company, that did design work for Apple until 2022. He "took" several Apple employees with him when he left and there's been a steady stream of Apple employees going to OpenAI. Ive isn’t responsible for all of them obviously, but the articles about lawsuits says there are 400 former Apple employees at OpenAI.

Sounds like Apple needs to do a better job at being a place where employees want to stay.

Given that his departure was marked by Apple products getting more reliable and usable, they arguably did too much in that regard (one of Cook’s more notable bad calls). Once he stopped blocking it, the keyboards were fixed and pro devices regained enough ports for pro users.

Without his support, his protege Alan Dye left for Meta and improved the design skills at both companies.

Re: About the security content of macOS Tahoe 26.6

#145
post #140

Earlier quoted context omitted.

The vagueness could be intentional. There’s been a big issue with linux where proof of concept exploit code gets posted before the bug is announced because people reverse engineer it from the fix commits. Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before…

> before it was ever used. But since this is never known, does the user need to know?

Remember that they have a great deal of telemetry around things like crashes and work with groups like Citizen Lab for certain high-risk users. You can’t prove that something was never used in a perfectly targeted and concealed attack but it’s likely they can say it wasn’t used outside of such contexts, and once you’re at the level of things like “the Mossad deployed an exploit after configuring the local cell tower to drop external network access before crash reporter could phone home” user notifications in the release notes aren’t effective anyway.

Re: About the security content of macOS Tahoe 26.6

#146

Earlier quoted context omitted.

As long as the UI improves and I can ignore all the AI stuff they're starting to push through, that's fine with me, though like many longtime macOS users, I'm not holding my breath for a bug-free experience.

> AI stuff they're starting to push through iOS 26 anecdote: A couple of weeks ago, I had a Baltimore Oriole (a cool-looking bird, not a baseball player) in my yard. They aren't rare, per se , but they are uncommon. Took my iPhone out to snap a picture, and pressed the camera button. I hadn't used it, since upgrading to 26. It takes the picture. It's there. I can see it, but it won't let me save it. Instead, it wants…

for real? it did, like every subsequent photo taken on the device after pressing the shutter “button”. You must be a bot, just another living shill. another confident user error in the field

Re: About the security content of macOS Tahoe 26.6

#147
post #143

Earlier quoted context omitted.

As we used to say in the Windows world, wait for service pack 3.

That doesn't work any longer given patch tuesdays, at work wait that IT validates them and pushes the updates via managed WSU, at home, it is worthwhile wanting if something hits the news on WindowsCentral, Verge or what have you.

It doesn't work with Windows anymore, since Microsoft no longer allows the user to control their own computer.

However, Software Update on Apple devices still allows you to turn off automatic update installation the way Windows used to.

Re: About the security content of macOS Tahoe 26.6

#148

Earlier quoted context omitted.

As long as the UI improves and I can ignore all the AI stuff they're starting to push through, that's fine with me, though like many longtime macOS users, I'm not holding my breath for a bug-free experience.

> AI stuff they're starting to push through iOS 26 anecdote: A couple of weeks ago, I had a Baltimore Oriole (a cool-looking bird, not a baseball player) in my yard. They aren't rare, per se , but they are uncommon. Took my iPhone out to snap a picture, and pressed the camera button. I hadn't used it, since upgrading to 26. It takes the picture. It's there. I can see it, but it won't let me save it. Instead, it wants…

Holding down the camera button does open the AI search for me instead of the Camera app. This can be disabled, if I remember correctly.

Re: About the security content of macOS Tahoe 26.6

#149
post #143

Earlier quoted context omitted.

That doesn't work any longer given patch tuesdays, at work wait that IT validates them and pushes the updates via managed WSU, at home, it is worthwhile wanting if something hits the news on WindowsCentral, Verge or what have you.

It doesn't work with Windows anymore, since Microsoft no longer allows the user to control their own computer. However, Software Update on Apple devices still allows you to turn off automatic update installation the way Windows used to.

It does when using Professional and Workstation, there are still a few knobs available.

For quite some time that I don't use home edition.

I also would not bet on Apple staying that way.

Re: About the security content of macOS Tahoe 26.6

#150
post #149

Earlier quoted context omitted.

It doesn't work with Windows anymore, since Microsoft no longer allows the user to control their own computer. However, Software Update on Apple devices still allows you to turn off automatic update installation the way Windows used to.

It does when using Professional and Workstation, there are still a few knobs available. For quite some time that I don't use home edition. I also would not bet on Apple staying that way.

"You can delay this update for a little while" simply isn't the same thing as "you still have full control over updates".

It's right up there with Microsoft's "you are not allowed to turn telemetry all the way off", or all the efforts to require the use of an online Microsoft account to access your own computer.

Post reply on HN