Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

41–50 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#41
post #21

Finally. Unfortunately we'll probably always be in the dark about the HOW, WHO and WHY. :(

Of course.

If it was an honest mistake, they're not going to publically throw an employee under the bus.

If it was a malicious action from the NSA, they're not allowed to make it public.

I suspect the only hypothetical way we'd hear about the "who" is if an employee weakened it for his own personal gain, and criminal charges were raised.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#45
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

It's still inexcusable. The security update should have been immediate and separate.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out.

What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#48
Apple has also changed the behavior of the power button on notebooks. Previously, pressing the button made the Mac instantly go to sleep. Now, just pressing it doesn't do anything. You can still hold the power button for 3 seconds to get the usual "Are you sure you want to shut down your computer now?" dialog box.

Awesome for those of us using FileVault who have to enter their login password each time they wake up their computer.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#49
post #25

Earlier quoted context omitted.

They cover security issues in a separate announcement (listed on http://support.apple.com/kb/HT1222 ), but only a few hours after the update has been released. I do think high-impact security issues like this SSL bug deserve a mention in the release notes as well.

Looks like they're just trying to not make it obvious that Macs can have security problems. I don't think many regular users (who probably think Macs are invincible) are going to actively look for security announcements about their invincible Mac. And when they look at the release notes, many of them won't be convinced to stop what they're doing and install some unnecessary updates. (Not trashing Mac, I am a Mac user…

I wonder if their hope is everything transitions to something like iOS before this is falsified in a widespread way on OSX in public.

In corporate settings with desktop management, Macs are actually a huge pain to deal with; Windows maybe starts from crappier defaults but there's a much more mature industry around locking it down.

Post reply on HN