Earlier quoted context omitted.
In addition to pillf's suggestion: 1. Use linux/fbsd/obsd/win box to download update. 2. Verify authenticity of cert/sha1 3. scp dmg / copy to USB drive 4. Apply update and move on.
"Mom, First use linux/fbsd/obsd/win box to download update. Next verify authenticity of cert/sha1. Then just scp dmg / copy to USB drive, apply update and move on." If you're 13, add "duh" at the end.
Apple releases OS X Mavericks 10.9.2 with SSL fix
241–246 of 246 posts
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#242Earlier quoted context omitted.
I worked at Apple, in that department, so yes, I'm aware of what I'm saying and why. Stop trying to acquire internet points by being a jerk.
> I worked at Apple, in that department Please have the bridge delivered to my home between noon and six. (Though, really, I should just accept this absurd statement, since it amounts to you admitting your own incompetence.) > Stop trying to acquire internet points by being a jerk. This from the guy who decided his scintillating contribution to the thread would be redundantly accusing people of "apologism" and "incom…
Why? Do you not already have a bridge to troll under?
> You do understand the people who actually do work at Apple are human beings, and that you are flinging insults at them, right?
Yes, and I know who they are.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#243Earlier quoted context omitted.
I do too. Did you find any more details on this?
to fix it I had to reset my Keychain. Pain in the ass, but it was preventing me from working. To do this, open Keychain Access, open Preferences, and click Reset Keychain. It will create a new login keychain and keep your old one backed up in the keychains folder.
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#244Earlier quoted context omitted.
While it's true that almost all software has bugs that can result in exploits, I think most of the exploits used in Pwn2Own are typically the result of complex interactions between subsystems that are hard to predict. As software gets more complex, the attack surface increases. The Apple bug isn't really in that class of exploit. It's a simple coding/merge error, and it's actually a regression from previously working…
In this case, the very test you're describing would not have worked. For a better writeup, see agl's post[1] on the matter. The basic gist of it: On affected systems, the server may use any combination of private key and certificate. Most SSL libraries used on the server side will make sure the moduli of cert and private key match (and abort if this isn't the case). Unit testing would thus require a server with some…
Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#245Re: Apple releases OS X Mavericks 10.9.2 with SSL fix
#246A compelling way to get holdouts to upgrade iOS/OSX. Get those iPhone 4 folks who are content with iOS 6.x to install iOS 7.x. God only knows what incompetence and disregard for user privacy and sanity awaits in these "new" versions. What are they adding that we really need? Oh, the ability to use SSL PKI. Yeah, I guess you have to upgrade. Why isn't HN discussing the effects this screw up has on email? Email is bigg…
Don't be a ignorant. Together with 7.0.6 there was also a security update to iOS 6.1.6. http://support.apple.com/kb/HT6146