Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

91–100 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#91
post #45

Earlier quoted context omitted.

It's still inexcusable. The security update should have been immediate and separate.

You still need a minimal amount of testing and release packing. 4 days for an OS update is pretty good response time IMHO, and I thank the Apple engineers that probably worked their asses off to get this mess sorted out. What this doesn't excuse is disclosing the iOS bug before all fixes are ready. THAT was the major scrweup.

Why do you think they only knew about this bug for 4 days?

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#93

I cant believe they don't even mention the SSL bug in this. That's just insulting.

That is normal in the general update notice. There is always a more detailed security update notice, for OS X 10.9.2 it can be found at:

http://support.apple.com/kb/HT6150

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#94
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

You're not necessarily totally off-base, but potential attackers include far more than who you think operates your first hop.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#95
post #80
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

It's getting attention because: - It's an easy to spot bug, - in the most critical part of the code, - of a fundamental security library, - and it's been there for a long time, nobody knows how many systems have already been compromised due to it. With this bug, Apple's library isn't actually a SSL implementation. It does not perform the most essential part of a SSL implementation - verifying that the peer possesses…

It's even more unacceptable that it took them FOUR DAYS to fix it, just so they could add a couple of features to FaceTime while they were at it.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#96
post #42

This should really have been a separate fix & installed without user interaction. Instead this is 450 Megs & requires a restart. It'll take days for it to get out to those at risk.

Looks like it's because they packaged a ton of other security patches with this update, too. See:

http://support.apple.com/kb/HT6150

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#97
post #66

Forgive me, but I'm not really sure why this is getting so much attention. It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla. As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs. That's certainly a problem, but most people are…

If you trust every network hop, are sure that you are never impacted by aberrant if not even malicious routes, never touched by DNS spoofing....SSL becomes irrelevant, doesn't it?

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#98
post #22

Ahh, so they probably had to restart the QA on the whole release a few days ago (including FaceTime Audio and associated features) after adding the TLS fix at the last minute. It makes a bit more sense why they'd make us wait a few days, now.

I think it's more likely that both were in the pipeline, and QA finished iOS 7.0.6 first - last week, and QA for 10.9.2 was slated to finish this week. So do you hold it or not?

Is it more critical to have 4 days of protection, or 4 days of "WTF is Apple incompetent" press?

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#99
post #90

Earlier quoted context omitted.

> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies. But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.

This is true with or without this bug.

The difference is this bug will grant you the lock icon, and your browser will "guarantee" you're speaking to the real bankofamerica.

Practically speaking, that probably doesn't matter, because someone who understands that won't click on an email and log in to bankofamericaa.com. But there is a difference.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#100
post #90

Earlier quoted context omitted.

> That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies. But if you are tricked to go to bankofamericaa.com instead of bankofamerica.com, a crook can be the proxy between you and your bank and you are none the wiser.

This is true with or without this bug.

Without this bug, they wouldn't be able to use BofA's own certificate to do it.
Post reply on HN