Getting Drivers for Old Hardware Is Harder Than Ever
vice.com
vice.com
For the past month, I've been on a bit of a quest to downgrade my my life to OS X 10.9 Mavericks, which came out in 2013. It's something I've wanted to do for years, for a variety of personal reasons, and it should be able to do everything I need.
My primary issue has not been software compatibility per se, but actually obtaining the software I need. The trial version of NetNewsWire 4 looks beautiful on my Mavericks install, but I can't buy a license key because BlackPixel no longer sells them. Ditto for Scapple, and Day One, and Parallels, and many others.
I had to hunt through the Internet Archive to find the last compatible versions of Intel Power Gadget and Kaleidoscope. I had to manually download and test each version to figure out where they dropped compatibility.
These are all fully offline apps, so there's no reason I shouldn't be able to buy and download old versions. I'm not asking for support or development time—I totally expect to be on my own—but please, developers, just give me a way to obtain what you previously created.
> For your license key issue, did you try to just contact the vendors?
Yes, I have! I've received some very nice responses, but none that actually helped. Which I kind of get, I guess, but it feels like this shouldn't happen.
Where possible, I've actually turned to pirating stuff—I normally hate doing this, but if you're not going to sell to me, I don't think it's wrong for me to find another way. I finally found a copy of NetNewsWire this way, after a lot of searching.
P.S. This isn't an offline app, but shoutouts to Bitwarden for the stupidest problem. The old version of their desktop app keeps helpfully replacing itself with the newer, incompatible version, which then won't open. If I mark the app read-only, Bitwarden just endlessly asks for my admin password.
In some ways, I actually see the advent of dark mode as Apple recognizing this problem—and papering over it with a bad solution. Old OS X was neither light nor dark to begin with. (Particularly circa-10.5—after Snow Leopard they began slowly brightening everything).
Separately from the visuals... this is a bit more opaque because I'm not a developer, but Yosemite introduced a lot of instability, and I'm convinced that Apple has never fully recovered. El Capitan (10.11) and High Sierra (10.13) were pretty stable by their final releases, but 10.9.5 is just really rock solid.
Running an old version of an operating system that’s not actively getting security updates, let alone gotten any at all for over three years, is crazy. It’s one thing to run it offline or heavily firewalled for a limited purpose, like running some important application that doesn’t work on current versions. But to actually use it day to day is absolute madness.
I hope you’re not handling any information that you have a duty to someone else to keep safe. Putting it on such an old OS release, through intentional and tedious effort on your part, would be outrageously negligent. Even logging into work email through that setup would be irresponsible. Or accessing any email account to which someone has sent private information (so just about any email account you actually use). It’s negligent with regards to your own data too of course, but at least that’s just your problem.
I think trying to make any moral argument in this situation is pointless as the risks are so minuscule. But should we go down that road the environmental benefits of keeping older hardware in use for longer far outweighs any security risks they may impose on others.
And the reason I'm expending effort is because this is important to me. My computer isn't just a tool, it's where I spend a significant portion of my life.
I want Mavericks's beautiful interface in my life. That has inherent value.
A few weeks ago, I pointed out to one of our clients that they are using vulnerable TLS library (with know exploits) on internet facing service.
They scheduled upgrade for service in august next year.
So honestly op running obsolete version of osx is really drop in the bucket.
What remote exploits are you concerned about in that scenario? Where it would affect 10.9, but not 10.16.
I'm not doubting they exist, but I'm really curious the threat scenario that would apply here, and how likely you think that might be.
This machine:
• Is connected to the internet.
• Is behind a router. All incoming ports are closed, except one for ssh. (An updated SSH binary has been installed via Macports.)
• Runs Little Snitch, so I can monitor what data gets sent out of my machine.
• Is running an up-to-date copy of Firefox.
• Has all important data backed up to cold storage regularly.
I consider any application I install locally to be trusted code, so the only source of untrusted code is the Javascript that I run inside of Firefox, which is up to date.
Some attack scenarios I can imagine:
1. There's a Firefox zero day. My vulnerable OS does not offer the extra layers of protection that a newer one might.
2. Someone exploits Spectre/Meltdown/etc via Javascript. My attacker is incredibly lucky, and the tiny portion of memory they retrieve just so happens to be the bit that contains something vital, like my master password.
3. Someone emails me a malicious image, which isn't caught by Gmail (personal accounts) or Microsoft Exchange (work account), and infects my machine when it's rendered by Apple Mail.
4. A person I know/trust is tricked into sending me an infected document, likely a PDF or MS Office file. Even though I don't have Acrobat or Microsoft Office installed, the vulnerability is compatible with Preview or iWork '09.
I'm not a particularly important person, so I think I'm more likely to die in a plane crash than get hit by 1 or 2. The latter two scenarios are maybe a bit more concerning, but not to the point where I consider them real threats. Particularly given that I also have cold data backups and Little Snitch.
You're also going to have to use outdated versions of various software packages, as you describe in your post. That's another security hole.
As you note, bugs are often found in video and image decoders. The one in your OS isn't being updated anymore.
And consider that not every fix for a segfault or other bug gets labeled as a "security patch", but that doesn't mean that they don't present security issues. I imagine most engineers fix the buggy code and move on, and never really consider if there was a security hole there. In other words, it's common for vulnerabilities to be discovered long after they were fixed. And there are probably many more that remain undiscovered despite being present in old versions.
Separately:
> And consider that not every fix for a segfault or other bug gets labeled as a "security patch", but that doesn't mean that they don't present security issues.
But this would imply that the newer version is inherently less buggy, wouldn't it? At least in terms of user-visible bugs, Mavericks is actually a lot more solid in my experience. That's a part of why I want to do this. Apple keeps adding new features and breaking old ones in the process.
There is no question Mavericks has more known vulnerabilities, and that's significant. But as an academic question, I'm not at all convinced that Mavericks has more unknown vulnerabilities. If nothing else, it almost certainly has a smaller attack surface.
Both still have great battery life and screens are still responsive ... but I made the mistake of wiping both to give as gifts for some nieces in El Salvador, and you can't actually install anything on them anymore.
They come with Safari and the other baked-in Apple apps, but that's it. None of the most common apps in their store have versions available for the iOS version the devices are limited to.
What the hell am I supposed to do with two fully functional (hardware-wise) devices?
or you jailbreak...
If the same app is still available on the store, but the newest version isn't compatible with your old OS, you won't be able to buy the that app on your old OS.
However, if you can log into the same Apple account on a new OS, you can buy the app there (pressing "get" on a free app counts as buying for our purposes). Once purchased, you'll be able to install the last compatible version on your old device.
This also works on the Mac App Store.
Beware of situations where what's currently available on the store isn't actually the same app. If the developer released a new version as a separate app at one point, this process won't work.
This is made more confusing by the fact that GP mentioned the original iPad and the iPad Air in the same sentence.
Or at least no in the near futur.
Debian dropped support of ppc32 with stretch.
The drop in the cost of hardware after 2k makes repurposing less useful then it was previously.
2. Some of the BIOS's being removed by Intel are only six years old.
It would also be nice if tracking down an old driver didn't require an hour of work...
I also have a younger relative using a 2008 Dell d630 for all his schoolwork, running Ubuntu 16.04. Again, the old Nvidia Quadro worked out of the box.
I still remember when I plugged it in into a Ubuntu 8.04 laptop in 2009 and Ubuntu told me nothing about it. Trained by years of Windows and countless popups and notifications I assumed it didn't work. I even looked for Linux drivers then I tried the OS scanner program: the driver was already in the kernel and the scanner was working, no need to bother me with messages. I never had problems with anything else (printers, webcams, etc).
On the sad side, my laptop from 2006 is still working (actually it's resting in a drawer most of the time) but it can't use a kernel more recent than some old 3.x version because anything newer won't support its ATI X1600 graphic card. I should try to boot it from a 19.10 USB stick but I'm not confident that somebody bothered to readd support for something that was dropped along the way.
Just in case you need a silly project for the holiday season...
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1791312
I'll give it a try. Thank you!
Of course if you need proprietary or old out of tree modules the story gets worse, but most interesting hardware I’ve plugged in works without me needing to worry about the details, in my experience.
There are LTS releases committed to supporting the 32-bit OS for several years to come, but the writing is on the wall: They have entered the long twilight of no official support, but still working if you can hack it together.
On the other hand, if your old hardware is used for games, there's probably some game emulator to help :)
Just throw it on a separate archive domain, plaster the thing full of scary legal disclaimers and call it a day
For instance, last weekend I had to figure out how to get RARP packets through the windows firewall, and even though I eventually got the setup working the complexity was not encapsulated by the virtual machine abstraction.