Apple neglects to patch two zero-day, wild vulnerabilities for Big Sur, Catalina
intego.com
intego.com
But, of course, hysterics get you clicks.
Also
>This isn’t the first time that we’ve observed Apple neglecting to patch serious vulnerabilities, or even actively exploited ones.
* Rushing out a patch that introduces possible instability
Which action do you think is better for business?
I doubt the security team is sitting there choosing not to patch this, given that they are passionate about security. And it's unlikely that management has told them "don't release the patch, we want the people on old OSs to suffer!!".
Most likely is that they just don't have as many resources for writing and testing the patch on the old versions, so it's taking longer.
For some, lagging updates for critical applications render a complete OS upgrade infeasible. Apple patching old versions was reliable enough to inform security praxis and they should warn users about delays, even if the policy hasn't changed.
It's the reboot, for me. It's just inconvenient enough that I put off upgrades for a long time, usually. I usually apply iOS updates promptly, because it's much easier to say "yes" to those since it's not going to lose much useful state on re-boot. Plus they seem to complete a lot faster.
Apple doesn't support old hardware as long as Microsoft/Linux.
Backporting to older releases means finding potentially new solutions to the same problems depending on where the bugs sit in the codebase. This could also mean backporting more than just the fix itself, depending on how the codebase has evolved.
Here's some media literacy training for anyone seeing this: the title uses the word "neglecting". It's an odd word to choose but extremely deliberate. The author can't say "refusing" because that would require evidence as would "downplaying" or "dragging their feet". But "neglecting" allows you to use no action as "evidence" so you should be automatically suspicious of it.
It's the same as "[Big Company] considering [controversial thing]". The word "considering" is deliberately chosen because it allows baseless speculation... which is the point.
This week's episode of the the podcast run by the Intego Mac Antivirus company talked about a new malware affecting Macos that was severe enough that Apple released Xprotect signatures for it, but didn't provide details to the rest of the security community, so anti-virus vendors had to reverse engineer the Xprotect signatures to figure out what they were for. Apple usually only updates Xprotect for the highest severity malware that's circulating widely.
https://podcast.intego.com/233
Most of the tech industry participates in information sharing through groups like the Cyber Tech Accord, the Cyber Threat Alliance, and several others. Apple is conspicuously absent from these groups.
https://cybertechaccord.org/signatories/
https://www.cyberthreatalliance.org/
What reason does Apple have to withhold information about vulnerabilities from the rest of the industry? It just puts their customers at risk. They have a trillion dollars. There's no reason they couldn't dedicate entire teams to disseminating information in a responsible way, just like every other tech company that you've heard of.
In the case of these Big Sur / Catalina patches, what benefit is it for them to not share their plans if they are in fact planning to release patches once the "regressions" are accounted for?
Eh, I disagree. While it's fair to wonder what's taking them so long, attributing malice or incompetence is unreasonable without more evidence than mere delay.
> What reason does Apple have to withhold information about vulnerabilities from the rest of the industry? It just puts their customers at risk.
I think the jury is out on the conclusion. While Apple is unquestionably peculiar with respect to their security community engagement, I think most would agree that they also have an outstanding overall security track record when you take into account the immense number of devices out there, all of which are connected to the Internet. It's difficult to identify a company that does better (again, relative to the overall risk exposure) than Apple in this aspect.
> They have a trillion dollars. There's no reason they couldn't [insert anything here]
Money can't buy you everything. Even Apple's war chest can't buy them the exact talent they need at the exact time. Talent is scarce and often happy and well-compensated at other engagements. Same goes for any of the FAANGs, one of whom I currently work for.
Lack of transparency is inexcusable for a business with such an overwhelmingly prolific ecosystem that has such a broad impact on derivative technologies and the businesses that use it.
Please refer to the very top of the thread where I try to provide a reasonable and much more likely explanation behind what's going on.
We're still the ones being hit by a bus.
That a company selling antivirus software is more willing to devote an essay to doomsaying than technical info that might actually help users is a good indication to look for alternative sources.
So the first vulnerability affects only M1 macs, all of which are compatible with Monterey. There’s your patch.
> We have high confidence that CVE-2022-22674 likely affects both macOS Big Sur and macOS Catalina. Nearly all vulnerabilities [..]
“High confidence” that it is “likely”? I have “absolute certainty” that it is “possible”, then.
Sure, it’s a reasonable guess. But there’s a lot of strongly worded outrage in this text. Personally, I’d hedge a bit on the accusations until they are shown to be true.
Or do I understand this completely wrong?
It's shorthand for "an exploit that wasn't responsibly reported".
So again, it’s lost any useful meaning I think.
I don't think that's even remotely true.
And given that it's not true, it's still a useful distinction. 0-day means an exploit that is being exploited before it was reported to the vendor, which is different than most exploits, which are reported to the vendor first.
But naturally, unless you are the vendor, you will likely not have heard of these. Otherwise, by definition, they would be zero-day vulns.
Any vulnerability that was reported and not fixed could probably be considered one?
Or any unfixed one for that matter (any widely exploitable vulnerability).
Like, there's a big difference between actively exploited vulnerability that requires physical access to the machine or conscious user decision to run an untrusted executable, versus actively exploited vulnerability that can bite a user when they visit a website or read a text message. If these vulnerabilities are in the second category, maybe I freak out and upgrade to monterey today; if in the first, I just rely on the perfectly good lock on my front door until apple backports the updates.
Ah...are the headline vulnerabilities related to date & time functions, perhaps?
Update: They fixed it.