Curl and http/2 on Mac
daniel.haxx.se
daniel.haxx.se
[0] https://i.imgur.com/cg4DBUT.jpg
Edit: Apple is excellent with their hardware. That iPhone 4 was still charging with the plug like that..
brew install curl --with-nghttp2 --with-openssl
brew link curl --force
You can also use --with-libressl instead of --with-openssl if you prefer LibreSSL.I'd focus instead on how several more recent vulnerabilities with OpenSSL have not affected LibreSSL, and the code quality being improved with LibreSSL, hopefully resulting in fewer vulnerabilities in the future.
In addition, Apple makes it difficult to modify or upgrade installed software, even when is it vulnerable. The default installation of git in OS X once had a remote code execution vulnerability that could not be patched by users: http://rachelbythebay.com/w/2016/04/17/unprotected/
nscurl -h
gives some useful infoTake vim for instance. The reason why I know vi is because it's everywhere. I know full well that any unix machine I log into will have it available to me if I need to edit a file. Now imagine that OSX released a new file structure, and the native vi installation couldn't read those files. Yea I could install a newer version of vi, but it means that I can't use any mac to fix something if I really need to. It means there's an inconsistency in the very basic command line functionality that I trust and rely on to be there.
Things like curl, vi, sed, etc are my fallback tools. If my reserve chute doesn't work, problems will arise at some point.
So? Macs are used as personal machines, not interchangeable accounts on servers.
For small values of "many".
The decision to drop OpenSSL for Secure Transport IMO was not the best given it's lacking (public) API.