Live data from Hacker News

Apple releases OS X Mavericks 10.9.2 with SSL fix

9to5mac.com

241–246 of 246 posts

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#241
post #133

Earlier quoted context omitted.

In addition to pillf's suggestion: 1. Use linux/fbsd/obsd/win box to download update. 2. Verify authenticity of cert/sha1 3. scp dmg / copy to USB drive 4. Apply update and move on.

"Mom, First use linux/fbsd/obsd/win box to download update. Next verify authenticity of cert/sha1. Then just scp dmg / copy to USB drive, apply update and move on." If you're 13, add "duh" at the end.

My mom would go ahead and do it.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#242

Earlier quoted context omitted.

I worked at Apple, in that department, so yes, I'm aware of what I'm saying and why. Stop trying to acquire internet points by being a jerk.

> I worked at Apple, in that department Please have the bridge delivered to my home between noon and six. (Though, really, I should just accept this absurd statement, since it amounts to you admitting your own incompetence.) > Stop trying to acquire internet points by being a jerk. This from the guy who decided his scintillating contribution to the thread would be redundantly accusing people of "apologism" and "incom…

> Please have the bridge delivered to my home between noon and six.

Why? Do you not already have a bridge to troll under?

> You do understand the people who actually do work at Apple are human beings, and that you are flinging insults at them, right?

Yes, and I know who they are.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#243

Earlier quoted context omitted.

I do too. Did you find any more details on this?

to fix it I had to reset my Keychain. Pain in the ass, but it was preventing me from working. To do this, open Keychain Access, open Preferences, and click Reset Keychain. It will create a new login keychain and keep your old one backed up in the keychains folder.

I use digicert for my own company, and I had some old certificates in the key chain. Deleting those solved the problem.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#244
post #226
post #179

Earlier quoted context omitted.

While it's true that almost all software has bugs that can result in exploits, I think most of the exploits used in Pwn2Own are typically the result of complex interactions between subsystems that are hard to predict. As software gets more complex, the attack surface increases. The Apple bug isn't really in that class of exploit. It's a simple coding/merge error, and it's actually a regression from previously working…

In this case, the very test you're describing would not have worked. For a better writeup, see agl's post[1] on the matter. The basic gist of it: On affected systems, the server may use any combination of private key and certificate. Most SSL libraries used on the server side will make sure the moduli of cert and private key match (and abort if this isn't the case). Unit testing would thus require a server with some…

I see what you mean, the amount of work and foresight needed to predict the bug and write a test for it does seem unrealistic in that light. Hingdsight is 20/20, etc.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#245
post #120

Does it fix the networking stack also? Please dear god let it fix the networking stack. ( https://discussions.apple.com/thread/5551686?start=0&tstart=... )

Yes, this should be fixed in 10.9.2.

Any proof or reference? I'd prefer not to wait about 23 days for my server to explode.

Re: Apple releases OS X Mavericks 10.9.2 with SSL fix

#246
post #227
post #207

A compelling way to get holdouts to upgrade iOS/OSX. Get those iPhone 4 folks who are content with iOS 6.x to install iOS 7.x. God only knows what incompetence and disregard for user privacy and sanity awaits in these "new" versions. What are they adding that we really need? Oh, the ability to use SSL PKI. Yeah, I guess you have to upgrade. Why isn't HN discussing the effects this screw up has on email? Email is bigg…

Don't be a ignorant. Together with 7.0.6 there was also a security update to iOS 6.1.6. http://support.apple.com/kb/HT6146

[deleted]
Post reply on HN