Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

51–60 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#51
post #45

Earlier quoted context omitted.

It's still inexcusable. The security update should have been immediate and separate.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

Nope, I disagree. Microsoft releases emergency hotfixes within about 24 hours usually, if a security vuln is critical enough. And this one is definitely extremely critical.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#52

Apple has also changed the behavior of the power button on notebooks. Previously, pressing the button made the Mac instantly go to sleep. Now, just pressing it doesn't do anything. You can still hold the power button for 3 seconds to get the usual "Are you sure you want to shut down your computer now?" dialog box. Awesome for those of us using FileVault who have to enter their login password each time they wake up th…

This changed back when 10.9 was released:

http://support.apple.com/kb/HT5869

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#53
post #45

Earlier quoted context omitted.

It's still inexcusable. The security update should have been immediate and separate.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

I don't think a simple 10.9.1.1 (10.9.1 which was already tested, plus JUST the one-line SecureTransport fix) would have required >24h testing.

It was their decision to put the fix in 10.9.2 which is the problem. I agree rushing 10.9.2 would have been bad.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#54
post #42

This should really have been a separate fix & installed without user interaction. Instead this is 450 Megs & requires a restart. It'll take days for it to get out to those at risk.

> This should really have been a separate fix & installed without user interaction

Considering it needs to update the TLS support on the rescue partition too, doing it outside of single-user mode is probably not a good idea.

You're nitpicking, it seems.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#55
post #20

Is it possible to manually verify the code signature with Apple's built-in public key before installing?

I would hope the built-in software-upgrade process does exactly that (independent of transport-layer SSL), but I have no evidence either way. The manual-download pages on http://support.apple.com/downloads/ publish SHA1 sums. Unfortunately those pages aren't served over SSL. You could download the update and compare its hash against those of your friends: at least then you'd all be installing the same thing (preventi…

The Apple site http://support.apple.com/kb/DL1726 reports

  c06a63982b522e43997a05cedc04b0bdb1a10207
which matches my download using `shasum -a OSXUpdCombo10.9.2.dmg`

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#56
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

Its totally unacceptable. Even Microsoft does patches of this severity in less than 24 hours.

I suspect what this points to is that Apple doesn't have automated testing and they need a bunch of old school "hands on keyboards testers" to run a test case list that takes 4 days.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#57

>> • Adds call waiting support for FaceTime audio and video calls Cool. Someday I'd like to be able to leave a FaceTime voicemail message if the receiver declines the FaceTime call.

That day was the last 4 days , between when Apple disclosed the SSL bug by patching it in iOS(effectively zero daying themselves) and when they bothered to fix it in OSX. If you are in North America, please contact the National Security Agency to retrieve your messages. For Asia, please contact the Chinese Ministry of State Security.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#58
post #26

PHP Available for: OS X Lion v10.7.5, OS X Lion Server v10.7.5, OS X Mountain Lion v10.8.5, OS X Mavericks 10.9 and 10.9.1 Impact: Multiple vulnerabilities in PHP Description: Multiple vulnerabilities existed in PHP, the most serious of which may have led to arbitrary code execution Didn't know it's in Mac OS X… But yeah, it is… /usr/bin/php

Both the webserver (Apache) and PHP are off by default and have to be enabled separately, the latter by editing a config file.

Essentially, only Mac-owning web developers who enable these things (and serve PHP from their box to the world) are affected by any security problems in PHP. I imagine that most such web developers actually only dev locally and push the code to another server. It's nice that they updated them anyway.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#60

Does it fix the networking stack also? Please dear god let it fix the networking stack. ( https://discussions.apple.com/thread/5551686?start=0&tstart=... )

I sure as hell hope it fixes this issue... I am X-Istence on that thread, and I get almost daily emails with other people with the same issues.
Post reply on HN