Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

31–40 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#31
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

It's still inexcusable. The security update should have been immediate and separate.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#32
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

It makes a bit more sense why they'd make us wait a few days, now.

It's still terrible. They should have pushed out a fix for this vulnerability first and push back 10.9.2 if necessary. Or perhaps introduce a modern package system for the base system.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#33
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

It's still inexcusable. The security update should have been immediate and separate.

[deleted]

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#37
post #2

> The release notes, however, do not make mention of the SSL security bug that was squashed on iOS late last week.

If anyone from Apple is reading and can influence this - could you convince whomever needs to be convinced that you ought to have less vague/shitty release notes, particularly wrt issues like this?

It's definitely included in that update. Just tested Safari post-update.

http://imgur.com/qXLQUSh

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#39
post #20

Is it possible to manually verify the code signature with Apple's built-in public key before installing?

I would hope the built-in software-upgrade process does exactly that (independent of transport-layer SSL), but I have no evidence either way.

The manual-download pages on http://support.apple.com/downloads/ publish SHA1 sums. Unfortunately those pages aren't served over SSL. You could download the update and compare its hash against those of your friends: at least then you'd all be installing the same thing (preventing narrowly-targetted attacks).

Post reply on HN