But, of course, hysterics get you clicks.
But, of course, hysterics get you clicks.
This week's episode of the the podcast run by the Intego Mac Antivirus company talked about a new malware affecting Macos that was severe enough that Apple released Xprotect signatures for it, but didn't provide details to the rest of the security community, so anti-virus vendors had to reverse engineer the Xprotect signatures to figure out what they were for. Apple usually only updates Xprotect for the highest severity malware that's circulating widely.
https://podcast.intego.com/233
Most of the tech industry participates in information sharing through groups like the Cyber Tech Accord, the Cyber Threat Alliance, and several others. Apple is conspicuously absent from these groups.
https://cybertechaccord.org/signatories/
https://www.cyberthreatalliance.org/
What reason does Apple have to withhold information about vulnerabilities from the rest of the industry? It just puts their customers at risk. They have a trillion dollars. There's no reason they couldn't dedicate entire teams to disseminating information in a responsible way, just like every other tech company that you've heard of.
In the case of these Big Sur / Catalina patches, what benefit is it for them to not share their plans if they are in fact planning to release patches once the "regressions" are accounted for?
Eh, I disagree. While it's fair to wonder what's taking them so long, attributing malice or incompetence is unreasonable without more evidence than mere delay.
> What reason does Apple have to withhold information about vulnerabilities from the rest of the industry? It just puts their customers at risk.
I think the jury is out on the conclusion. While Apple is unquestionably peculiar with respect to their security community engagement, I think most would agree that they also have an outstanding overall security track record when you take into account the immense number of devices out there, all of which are connected to the Internet. It's difficult to identify a company that does better (again, relative to the overall risk exposure) than Apple in this aspect.
> They have a trillion dollars. There's no reason they couldn't [insert anything here]
Money can't buy you everything. Even Apple's war chest can't buy them the exact talent they need at the exact time. Talent is scarce and often happy and well-compensated at other engagements. Same goes for any of the FAANGs, one of whom I currently work for.
Lack of transparency is inexcusable for a business with such an overwhelmingly prolific ecosystem that has such a broad impact on derivative technologies and the businesses that use it.
Please refer to the very top of the thread where I try to provide a reasonable and much more likely explanation behind what's going on.
We're still the ones being hit by a bus.
For some, lagging updates for critical applications render a complete OS upgrade infeasible. Apple patching old versions was reliable enough to inform security praxis and they should warn users about delays, even if the policy hasn't changed.
* Rushing out a patch that introduces possible instability
Which action do you think is better for business?
I doubt the security team is sitting there choosing not to patch this, given that they are passionate about security. And it's unlikely that management has told them "don't release the patch, we want the people on old OSs to suffer!!".
Most likely is that they just don't have as many resources for writing and testing the patch on the old versions, so it's taking longer.
Here's some media literacy training for anyone seeing this: the title uses the word "neglecting". It's an odd word to choose but extremely deliberate. The author can't say "refusing" because that would require evidence as would "downplaying" or "dragging their feet". But "neglecting" allows you to use no action as "evidence" so you should be automatically suspicious of it.
It's the same as "[Big Company] considering [controversial thing]". The word "considering" is deliberately chosen because it allows baseless speculation... which is the point.
Also
>This isn’t the first time that we’ve observed Apple neglecting to patch serious vulnerabilities, or even actively exploited ones.
It's the reboot, for me. It's just inconvenient enough that I put off upgrades for a long time, usually. I usually apply iOS updates promptly, because it's much easier to say "yes" to those since it's not going to lose much useful state on re-boot. Plus they seem to complete a lot faster.
Apple doesn't support old hardware as long as Microsoft/Linux.
Backporting to older releases means finding potentially new solutions to the same problems depending on where the bugs sit in the codebase. This could also mean backporting more than just the fix itself, depending on how the codebase has evolved.