Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

61–70 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#61
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

They already knew about the TLS issue. Remember, they found and fixed it themselves. It is not like Apple's release of iOS 7.0.6 was what alerted Apple to the vulnerability in OS X.

The problem was not coordinating the release of 10.9.2 and iOS 7.0.6. The other problem is their patching cycle in general.

This update includes many high severity fixes from mid 2013 and one issue as far back as 2011. That tells you all you need to know about Apple's security program management. They release uncoordinated and when they feel like it, with no sense of urgency. It's convenient for them to just toss critical security fixes in to their 6 month OS updates, so they do.

Some criticize Microsoft for their "slow" patching, but they at least have a dedicated monthly cycle just for security updates, and they will send them out of band if a 0day gets exposed. And rarely will you see them drop 0day on themselves (though this wasn't always the case).

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#62
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

Its totally unacceptable. Even Microsoft does patches of this severity in less than 24 hours. I suspect what this points to is that Apple doesn't have automated testing and they need a bunch of old school "hands on keyboards testers" to run a test case list that takes 4 days.

The parent 'suspects' and doesn't actually know. It's not 'totally unacceptable' either. It's over a weekend and it's a set of trade offs about cutting a release made by a bunch of smart engineers who were probably very tired (last week for them has probably sucked) and they've just pulled a long weekend to get this out the door.

If you find this 'totally unacceptable', my suggestion would be to either go join them and help them improve the situation or to move to another OS. Bitching on the internet merely indicates how little experience you have with the trade offs that need to be made when pushing latge volumes of software.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#63
post #49
post #25

Earlier quoted context omitted.

Looks like they're just trying to not make it obvious that Macs can have security problems. I don't think many regular users (who probably think Macs are invincible) are going to actively look for security announcements about their invincible Mac. And when they look at the release notes, many of them won't be convinced to stop what they're doing and install some unnecessary updates. (Not trashing Mac, I am a Mac user…

I wonder if their hope is everything transitions to something like iOS before this is falsified in a widespread way on OSX in public. In corporate settings with desktop management, Macs are actually a huge pain to deal with; Windows maybe starts from crappier defaults but there's a much more mature industry around locking it down.

Hence why you want to be the odd one out with a Mac at Corporates: IT leaves you alone and you can manage it yourself.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#64
post #45

Earlier quoted context omitted.

It's still inexcusable. The security update should have been immediate and separate.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

They could have done the OSX testing at the same time as the iOS and the AppleTV testing. Remember, it's not 4 days response time, it's (4 days + however long the ios response time was). They unleashed a 0day on themselves.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#65
post #45

Earlier quoted context omitted.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

Nope, I disagree. Microsoft releases emergency hotfixes within about 24 hours usually, if a security vuln is critical enough. And this one is definitely extremely critical.

Let's be honest, Microsoft is better at security than Apple, mostly as auto-immune response, but regardless of the cause, they've been battle-tested and they know how to handle it.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#66
Forgive me, but I'm not really sure why this is getting so much attention.

It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla.

As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs.

That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies.

It seems like this primarily affects people connecting to untrustworthy access-points, such as Coffee Shops, or Airport Wifi - While that's certainly something that needs to be fixed, it seems far less crucial than remote-code-execution [1], or many other bugs we see regularly.

I'm sure I'm missing something here, can someone help me understand? Is it just the "Ick" factor of having something you thought was encrypted actually being fairly open?

I don't understand why this is getting more attention that other (seemingly) more dangerous exploits.

[1] - http://msisac.cisecurity.org/advisories/2013/2013-088.cfm

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#67
post #59

I cant believe they don't even mention the SSL bug in this. That's just insulting.

It's mentioned in the last line here http://support.apple.com/kb/HT6114 And yeah, that's kind of bizarre.

Nice call. Yea very strange. Seems like the most important thing in this update. It should at least be at the top of the bug fix list.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#68
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

Its totally unacceptable. Even Microsoft does patches of this severity in less than 24 hours. I suspect what this points to is that Apple doesn't have automated testing and they need a bunch of old school "hands on keyboards testers" to run a test case list that takes 4 days.

How is that 'totally unacceptable' when this is not? http://m.slashdot.org/story/198449

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#69

>> • Adds call waiting support for FaceTime audio and video calls Cool. Someday I'd like to be able to leave a FaceTime voicemail message if the receiver declines the FaceTime call.

I wonder if Apple is taking a stance against voicemail since many people find it to be a nuisance.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#70

Earlier quoted context omitted.

Nope, I disagree. Microsoft releases emergency hotfixes within about 24 hours usually, if a security vuln is critical enough. And this one is definitely extremely critical.

Let's be honest, Microsoft is better at security than Apple, mostly as auto-immune response, but regardless of the cause, they've been battle-tested and they know how to handle it.

Microsoft has had to deal with more security issues for obvious reasons. Apple has not had a serious security protocol on the basis of assuming the platform is flaw free. Even if that were the case, it's how seriously and professionally each is handled is what builds or breaks PR/credibility. IOW, you're only as good as your last performance.
Post reply on HN