Live data from Hacker News

Apple isn’t patching all the security holes in older versions of macOS

arstechnica.com

111–120 of 132 posts

Re: Apple isn’t patching all the security holes in older versions of macOS

#111

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

WHAT! How did I not know the append-the-code trick

It's a common hack, i.e. Salesforce does same for the security token, IIRC same with github.

Re: Apple isn’t patching all the security holes in older versions of macOS

#112
post #51

They also never bothered to implement the 2 factor code popup on old systems but forcing user to use 2fa. So you now get to explain to grandma that she needs to enter her icloud password, get a password error, click on approve on her iPhone, then enter her password again with the 6 digit code shown on the iphone appended to the end of her password.

That's a neat hack if you only have one input box. But all the extra code on the backend needed to differentiate between a normal password and a password+pin sounds like something which could accidentally weaken security.

It's really not that complicated given it's a fixed 6 digit appendage

Re: Apple isn’t patching all the security holes in older versions of macOS

#113

Incredibly short sighted when they shipped so many laptops with 128GB drives even till quite recently where upgrading is almost impossible once you've been using the machine because even basic apps and a few files push you beyond the limit required to update. Most of these laptops run at 2-4GB free space because MacOS already takes up a ton of space and throw on a few electron apps and its full.

It's not even much better with 256GB. I thought I'd be fine as I used to run Linux with 128GB and had loads of room. MacOS has been very tight with 256GB

Re: Apple isn’t patching all the security holes in older versions of macOS

#114

Incredibly short sighted when they shipped so many laptops with 128GB drives even till quite recently where upgrading is almost impossible once you've been using the machine because even basic apps and a few files push you beyond the limit required to update. Most of these laptops run at 2-4GB free space because MacOS already takes up a ton of space and throw on a few electron apps and its full.

It's not even much better with 256GB. I thought I'd be fine as I used to run Linux with 128GB and had loads of room. MacOS has been very tight with 256GB

I’m running a 256Gb mini. I have 100Gb free. That includes 25 years of carefully curated photos and videos. Depends what you do with it and how wasteful you are with storage.

Re: Apple isn’t patching all the security holes in older versions of macOS

#115
post #87
post #81

Please anyone, someone, does anyone think that these are all the same company? Same culture? Same quality of software? Apple releasing 10.4 Apple releasing 10.6 Apple releasing 10.11 Apple releasing 10.15

The amount of phone-home in the macOS these days is also absolutely astounding. My new mbp16 has at least 4 different processes talking to Apple Maps servers even with location services disabled, and if you press F8 it sends the machine's unchangeable hardware serial number to Apple (linking it to your IP) without consent. (FWIW it also says on screen that it is doing this when you press F8.)

It that Maps functionality, or OS functionality? Can it be remapped in Keyboard Shortcuts?

And most importantly, what the actual fuck?..

Re: Apple isn’t patching all the security holes in older versions of macOS

#116
post #51

Earlier quoted context omitted.

That's a neat hack if you only have one input box. But all the extra code on the backend needed to differentiate between a normal password and a password+pin sounds like something which could accidentally weaken security.

It's really not that complicated given it's a fixed 6 digit appendage

A secure app shouldn’t be sending passwords in the clear though.

Re: Apple isn’t patching all the security holes in older versions of macOS

#117

Earlier quoted context omitted.

Doesn't Chromium use its own CA store, or is that different on the OS X version?

Chromium uses its own HTTPS implementation but does not currently use its own CA store. If it did, adding the aforementioned certificate would not have fixed all of the “Your Connection Is Not Private” errors I was encountering previously. :)

They would presumably use both.

Re: Apple isn’t patching all the security holes in older versions of macOS

#118

Earlier quoted context omitted.

Chromium uses its own HTTPS implementation but does not currently use its own CA store. If it did, adding the aforementioned certificate would not have fixed all of the “Your Connection Is Not Private” errors I was encountering previously. :)

They would presumably use both.

Sorry, I'm not sure I understand your comment. You can presume whatever you want, but I'm telling you how it works. :)

IIRC there are plans to switch Chromium to its own certificate store on all platforms, but they seem to be a ways off.

Re: Apple isn’t patching all the security holes in older versions of macOS

#119

Earlier quoted context omitted.

They would presumably use both.

Sorry, I'm not sure I understand your comment. You can presume whatever you want, but I'm telling you how it works. :) IIRC there are plans to switch Chromium to its own certificate store on all platforms, but they seem to be a ways off.

When you add a root certificate to a browser, typically it is configured to accept BOTH the added cert and the built-in/system certs. There would certainly be no reason not to in this case.

Re: Apple isn’t patching all the security holes in older versions of macOS

#120
post #20

Earlier quoted context omitted.

The key point for this IMHO is, as mentioned in the article "But it's also time for better communication on this subject. Apple should spell out its update policies for older versions of macOS, as Microsoft does, rather than relying on its current hand-wavy release timing". If Apple properly supported Catalina, that would be great; if Apple explicitly said that Catalina is out of support / EOL and people need to upgr…

I really don’t get this. Apple does provide free updates for all. If you skip major versions, you’re shooting yourself in the foot and blaming Apple for allowing it. Apple is giving you the update: Install it and now it’s up to date. They don’t have to support multiple versions of the same thing indefinitely. The situations (devices) where the update isn’t possible (i.e. they’re outdated too early) can probably be co…

For iOS14, Apple provided users a prompt to optionally upgrade to 15 while guaranteeing security updates to ios14. This is the relevant text on the Apple website:

>iOS may now offer a choice between two software update versions in the Settings app. You can update to the latest version of iOS 15 as soon as it’s released for the latest features and most complete set of security updates. Or continue on iOS 14 and still get important security updates.

>https://www.apple.com/ios/ios-15/features/

Apple is not even meeting it's own guarantees.

Post reply on HN