Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

21–30 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#24
post #10

Earlier quoted context omitted.

http://support.apple.com/kb/HT6114 says at the bottom "For detailed information about the security content of this update, see Apple security updates.[1]" [1] http://support.apple.com/kb/HT1222

It's not there yet: Apple usually posts that information a few hours _after_ the update has been released.

Looks like it's at http://support.apple.com/kb/HT6150

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#25

Earlier quoted context omitted.

If anyone from Apple is reading and can influence this - could you convince whomever needs to be convinced that you ought to have less vague/shitty release notes, particularly wrt issues like this?

They cover security issues in a separate announcement (listed on http://support.apple.com/kb/HT1222 ), but only a few hours after the update has been released. I do think high-impact security issues like this SSL bug deserve a mention in the release notes as well.

Looks like they're just trying to not make it obvious that Macs can have security problems. I don't think many regular users (who probably think Macs are invincible) are going to actively look for security announcements about their invincible Mac. And when they look at the release notes, many of them won't be convinced to stop what they're doing and install some unnecessary updates.

(Not trashing Mac, I am a Mac user.)

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#26

  PHP
  Available for:  OS X Lion v10.7.5, OS X Lion Server v10.7.5,
  OS X Mountain Lion v10.8.5, OS X Mavericks 10.9 and 10.9.1
  Impact:  Multiple vulnerabilities in PHP
  Description:  Multiple vulnerabilities existed in PHP, the most
  serious of which may have led to arbitrary code execution 
Didn't know it's in Mac OS X… But yeah, it is… /usr/bin/php

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#29
post #26

PHP Available for: OS X Lion v10.7.5, OS X Lion Server v10.7.5, OS X Mountain Lion v10.8.5, OS X Mavericks 10.9 and 10.9.1 Impact: Multiple vulnerabilities in PHP Description: Multiple vulnerabilities existed in PHP, the most serious of which may have led to arbitrary code execution Didn't know it's in Mac OS X… But yeah, it is… /usr/bin/php

Oddly enough, the release notes states they upgraded to "5.4.22"... but "/usr/bin/php -v" gives "5.4.24" here.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#30
post #2

> The release notes, however, do not make mention of the SSL security bug that was squashed on iOS late last week.

If anyone from Apple is reading and can influence this - could you convince whomever needs to be convinced that you ought to have less vague/shitty release notes, particularly wrt issues like this?

most definitely the right person is reading this, Apple is a bottom-up corporation and someone reading HN could just talk to their manager and have the complaint heard by the right person.
Post reply on HN