Earlier quoted context omitted.
It's still inexcusable. The security update should have been immediate and separate.
You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.
Apple releases OS X Mavericks 10.9.2 with SSL fix
91–100 of 246 posts
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#92Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#93I cant believe they don't even mention the SSL bug in this. That's just insulting.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#94Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#95Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
It's getting attention because: - It's an easy to spot bug, - in the most critical part of the code, - of a fundamental security library, - and it's been there for a long time, nobody knows how many systems have already been compromised due to it. With this bug, Apple's library isn't actually a SSL implementation. It does not perform the most essential part of a SSL implementation - verifying that the peer possesses…
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#96This should really have been a separate fix & installed without user interaction. Instead this is 450 Megs & requires a restart. It'll take days for it to get out to those at risk.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#97Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#98Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.
Is it more critical to have 4 days of protection, or 4 days of "WTF is Apple incompetent" press?
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#99Earlier quoted context omitted.
> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies. But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.
This is true with or without this bug.
Practically speaking, that probably doesn't matter, because someone who understands that won't click on an email and log in to bankofamericaa.com. But there is a difference.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#100Earlier quoted context omitted.
> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies. But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.
This is true with or without this bug.