Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

231–240 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#231
post #189

Earlier quoted context omitted.

This is all pointless handwaving; the update package itself is signed and will not install if tampered with, regardless of TLS certs used to download it. TLS is not used to authenticate the update.

Ah, right. That makes sense. If only it was mentioned on the download page!

Well. In a way it's mentioned here: http://support.apple.com/kb/ht5290

Yes. That's the marketing page explaining how Gatekeeper works, but yes, in the end it's a feature of Gatekeeper that makes it harder for you to open unsigned packages and impossible to open packages with a broken signature.

So even when you don't know about pkgutil (most people don't), Gatekeeper will still help you.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#233

Earlier quoted context omitted.

In arguing that they should add more people in order to ship faster, the only incompetence on display is your own. That's not how software development works, which you should know if you've done it professionally.

Huh? It's a one line change. The patch has to be validated across the entire testing matrix of their entire product line. That is a trivially parallelizable problem. Don't cargo cult 'common wisdom'; the only incompetence on display here is your axiomation of things you don't understand.

If you'd meant QA, you would have said QA, not engineering. You don't want engineers doing QA, which you would also know if you actually worked in the industry. They're notoriously bad at it. You'd also know that a test cycle takes a certain amount of time, and for something as complex as OS X, that amount is going to be measured in days per configuration, and there's nothing you can do about that -- adding more people will, again, just slow it down. Admit you don't know what you're talking about and move on. Or just stop talking, whatever.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#234

Earlier quoted context omitted.

Huh? It's a one line change. The patch has to be validated across the entire testing matrix of their entire product line. That is a trivially parallelizable problem. Don't cargo cult 'common wisdom'; the only incompetence on display here is your axiomation of things you don't understand.

If you'd meant QA, you would have said QA, not engineering. You don't want engineers doing QA, which you would also know if you actually worked in the industry. They're notoriously bad at it. You'd also know that a test cycle takes a certain amount of time, and for something as complex as OS X, that amount is going to be measured in days per configuration , and there's nothing you can do about that -- adding more peo…

I worked at Apple, in that department, so yes, I'm aware of what I'm saying and why.

Stop trying to acquire internet points by being a jerk.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#235
post #173

Earlier quoted context omitted.

The hell with GM process. There should be a way to push out simple changes like this, as soon as possible, for cases like this which is very important.

That's a great way to let a bad build slip out, which would do significantly more harm than any bug it could possibly hope to fix.

Which is why you need a process for shipping out emergency fixes. Microsoft can do it in 24 hours, and on the desktop, the impact of a broken build for Microsoft is staggeringly large when compared to Apple.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#236

Earlier quoted context omitted.

If, however, we don't engage in circular reasoning I agree with the point you're making, but you can also turn this idea around, after which it serves to highlight how insanely inadequate our current tools and infrastructure are from a security standpoint. Basically, you can only reasonably hope to verify a patch if you're not already owned, so you also have to assume you're not in order to verify. It's as if there w…

> Basically, you can only reasonably hope to verify a patch if you're not already owned, so you also have to assume you're not in order to verify. It's as if there was a contagious disease that has a good chance of killing you after a number of years, but the diagnostic tests can only be counted on to work if you don't have the disease in the first place. So then why would anyone ever bother getting tested? Our curre…

You have to trust some third-party that you believe to not be similarly compromised to do the verification for you.

Which effectively means that most people won't bother, unless a "trusted third party" is built into their machine.

But that has huge potential problems of its own.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#237

Earlier quoted context omitted.

If you'd meant QA, you would have said QA, not engineering. You don't want engineers doing QA, which you would also know if you actually worked in the industry. They're notoriously bad at it. You'd also know that a test cycle takes a certain amount of time, and for something as complex as OS X, that amount is going to be measured in days per configuration , and there's nothing you can do about that -- adding more peo…

I worked at Apple, in that department, so yes, I'm aware of what I'm saying and why. Stop trying to acquire internet points by being a jerk.

> I worked at Apple, in that department

Please have the bridge delivered to my home between noon and six.

(Though, really, I should just accept this absurd statement, since it amounts to you admitting your own incompetence.)

> Stop trying to acquire internet points by being a jerk.

This from the guy who decided his scintillating contribution to the thread would be redundantly accusing people of "apologism" and "incompetence". You do understand the people who actually do work at Apple are human beings, and that you are flinging insults at them, right?

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#239

Just installed this. Now I get a HSTS error on github for both Chrome and Safari.

I do too. Did you find any more details on this?

to fix it I had to reset my Keychain. Pain in the ass, but it was preventing me from working.

To do this, open Keychain Access, open Preferences, and click Reset Keychain. It will create a new login keychain and keep your old one backed up in the keychains folder.

Post reply on HN