Apple has just released the first Rapid Security Response for Ventura
eclecticlight.co
eclecticlight.co
EDIT: Seems to be working as of 15min ago.
https://reddit.com/r/apple/comments/134u12e/apple_releases_r...
So far I haven't seen Mac OS force any update on me, not only that but when I accidentally activated automatic updates it showed a notification that stays on screen until you confirm/cancel the setting change.
And neither can Linux, contrary to popular belief. Anything that involves system services or god forbid the kernel requires a reboot.
Yes, if the kernel wasn't updated you could meticulously reboot each individual system service that was updated instead, but why bother when you can just reboot and be done with it?
This is not true. NixOS, as one example, is able to figure out which services (including system) need to be restarted.
> god forbid the kernel
This is not true either. Live kernel updates are possible (but are usually a paid addition, e.g. https://ubuntu.com/security/livepatch).
It might actually be a useful tool for NixOS: finding out which processes have a specific version of a module loaded, so that the user can be warned to restart those processes.
If the user wants to restart processes they can, if they want to just reboot they can also. Simply because it's "simpler" to do one, doesn't mean it's the correct universal choice in all circumstances. My wife, for example, leaves way to much crap open and leaves her laptop suspended - a restart is a serious issue for her.
That is not true at all, and anyone can confirm this by upgrading the kernel and system services (e.g. desktop environment, display manager, systemd) on Arch Linux and verifying that just about everything continues to work normally. In my experience, the only things that require a reboot are a few particular kernel modules (such as the VirtualBox host modules) and only if you are going to use those modules. Even in that case, it is still your choice whether you want to reboot.
Edit: Another classic is upgrading the kernel on Arch, not rebooting, then trying to use a thumb drive for the first time since the last boot. Since Arch uses one package for all kernel versions, only one set of loadable modules is installed per kernel package - so upgrading the package removes the loadable modules of the currently running kernel.
This is not new. I got the same notice earlier today updating a MacBook running Big Sur, which is two versions before Ventura.
you can resume in software update by clicking "Restart Now".
Bad: still requires a reboot, and is still irrelevant noise for non-users of safari.
Safari vends an in-app view controller used by lots of third party apps to display web content.
I guess it depends on what the bug is.
Plenty do display arbitrary _content_ thought. Mail clients, RSS readers, various messaging (twitter, mastodon, ...) clients, etc use it. Obviously these days many apps instead just ship a 400mb out of date copy of chrome instead of using the builtin frameworks, so it's less of an addressable problem, but so it goes.
An RSS reader would be one of those few apps that might have the full risk.
Messaging platforms have to worry about unicode bugs and image bugs, but almost all html or javascript exploits don't matter to them. If there is a safari-specific problem, it's very likely they don't care about it.
But it doesn't matter what proportion of the app ecosystem is or is not using the system webkit framework, we both know that if Apple does update only Safari say, and then people are compromised through their RSS reader, the HN comments will be asking why Apple didn't update the system framework.
Don't get me wrong - I do get annoyed at having to reboot, but I'm not sure what the better solution is given the constraints of macOS and iOS (at least iOS apps are better designed in terms of saving and restoring state).
I mean that whitelist-style, which isn't a losing strategy.
But that's a side issue. I'm trying to argue that the vast majority of programs that use webkit aren't affected by the vast majority of webkit-specific bugs.
> But it doesn't matter what proportion of the app ecosystem is or is not using the system webkit framework, we both know that if Apple does update only Safari say, and then people are compromised through their RSS reader, the HN comments will be asking why Apple didn't update the system framework.
I'm not suggesting not to update. But yes it does matter how many programs are vulnerable.
What are you trying to filter with your "whitelist"? Anything you'd want to filter can be controlled directly via browser embedding APIs, without any vagaries or guesswork.
> I'm trying to argue that the vast majority of programs that use webkit aren't affected by the vast majority of webkit-specific bugs.
I'm not sure what you mean here. The whole point of a security bug is that an entity is trying to compromise the system. We aren't talking a "webkit specific rendering bug", we're talking about the goal being code execution. So "affected by" is "displays untrusted content".
RSS apps, Mail apps, Messaging, and Social media apps are all subject to that. Messaging isn't arbitrarily constrained - any properly encrypted messaging system requires the client to assume that any received message is completely attacker controlled. Even in these hypothetically constrained messaging and social media apps, if nothing else, often allow you to just view web content from within the app. The goal of an attacker is to get some specific content to hit a web view. They do not necessarily care what application is driving that web view - arguably they'd prefer non-safari as 3rd party apps generally aren't sandboxed, so gaining code execution in the host is yet more powerful.
> I'm not suggesting not to update. But yes it does matter how many programs are vulnerable.
What matters is how many users would be exposed, which is a function of the number of apps, the number of users of all of those apps, and the degree to which those apps are exposed to arbitrary content. WebKit on macOS is widely used, and it is often (if not typically) used for untrusted content.
Then they'll already be immune to many exploits, great. You're not really arguing against my point here.
> I'm not sure what you mean here
Sorry. What I meant by webkit-specific was basically a bug that is in webkit but not a more general text or image rendering bug that affects the entire system.
> any properly encrypted messaging system requires the client to assume that any received message is completely attacker controlled
I disagree. Many messaging systems don't send html. If they do send raw html, for most of those apps it's not unreasonable to trust the server, because if the server is compromised they could just send a malicious update. So you only care about things that can make it through the system, which is a tiny percent of html, and renders 90% or whatever of web engine bugs unreachable.
> Even in these hypothetically constrained messaging and social media apps, if nothing else, often allow you to just view web content from within the app.
Now that is an app that is vulnerable! But only some do that, especially on desktop.
> What matters is how many users would be exposed, which is a function of the number of apps, the number of users of all of those apps, and the degree to which those apps are exposed to arbitrary content.
I agree. I just don't want to overstate the degree.
If I'm not mistaken, it is the renderer for many arbitrary pages like PDFs and Preview documents. Could be wrong though.
I guess the software updater wasn't built to make those steps easy, so an OS reboot might've been the easiest way to ship this.
EDIT: I feel obligated to say this: pitchforks down, please. I'm not trying to disparage the macOS kernel. As a designer of software systems interested in how OSes are built, I found the choices taken interesting.
I... what?
Which is to say, / under Catalina and above (so, since 2019), the root partition is really the mount of an APFS snapshot. There's security as a reason, but also from a system perspective, it makes it more robust to upgrade/downgrade OS versions under such a scheme because you always have a known-good system image to revert back to.
Safari though is a special case, and so /Applications/Safari.app is a symlink to ../System/Cryptexes/App/System/Applications/Safari.app
https://superuser.com/questions/1495124/read-only-file-syste...
https://support.apple.com/guide/security/signed-system-volum...
Can you explain this more? Despite being a longtime Apple user, I've never heard of RSR before. If it's just an update for Safari, why does it require the computer to be rebooted? Does it not affect me if I use other browsers for 99% of my web usage?
>They deliver important security improvements between software updates — for example, improvements to the Safari web browser, the WebKit framework stack, or other critical system libraries. They may also be used to mitigate some security issues more quickly, such as issues that might have been exploited or reported to exist "in the wild."
I believe they are vague on purpose (and because they're Apple) but it does not strike me as something strictly limited to affecting just Safari, especially given the libraries may be used elsewhere.
ETA: To further quote from https://support.apple.com/guide/deployment/manage-rapid-secu...:
>Rapid Security Responses that involve the operating system require the device to restart. On macOS, the updated operating system content may be made available to Safari and its associated processes with just a relaunch of those processes, though a restart is required to make this content broadly available to the rest of the operating system.
>Rapid Security Responses that involve the operating system require the device to restart. On macOS, the updated operating system content may be made available to Safari and its associated processes with just a relaunch of those processes, though a restart is required to make this content broadly available to the rest of the operating system.
Also, isn't one of the arguments for Apple's stronghold on all the software running on their machines that they know 100% what everything is doing? Should be trivial to look up which processes are using specific parts and restart those.
What stronghold? You can run whatever apps you want on a Mac.
As for identifying libraries in use. you can do that on any platform: Pause all processes, scan the address space of all processes to find anything the looks like a pointer to an impacted library, then hope/assume that there's no pointer tagging or munging going on, and voila that's your list. Hopefully you didn't miss anything.
The problem is that that's just a heuristic and you'd want to be _really_ sure you were right, or weird crashes will happen.
On macOS specifically there are other hurdles, the biggest being that the system partition is readonly, and so system libraries can't be replaced outside of early on in the boot process.
Or worse, you leave running applications vulnerable to a critical security vulnerability while telling the user that they've applied all security patches.
However updating the system requires updating the system partition, which is readonly, so requires rebooting.
This one does, but I don’t think they all will. The language around it seems clear that’s a possibility.
> By default, your device allows Rapid Security Responses to be applied automatically and, if necessary, will prompt you to restart your device.
https://support.apple.com/en-us/HT201224
Unfortunately, the article does not say whether the update is applied automatically even if the device is locked.
why would that be?
Probably to ensure someone can go back if this fix breaks functionality (which it shouldn't do).
iOS also really needs to trigger the automatic Photos + Apps storage reclamation process since statistically everyone I know who delays updates does it because their phone is full of pictures & videos. The iCloud offload works beautifully so I don’t know why they haven’t added a trigger multiple years into that feature existing.
As I recall there’s something they can’t decrypt without your password that they need to decrypt during updates. You could say “that’s their choice” but maybe they worry if their signing keys leaked that at least you’d also need to type your password in to kick off an update.
> The iCloud offload works beautifully so I don’t know why they haven’t added a trigger multiple years into that feature existing.
Guessing this comes down more to bandwidth as to why it’s opt in. If there’s enough speed to upload your photos but not download them when the update completes, you’re going to be upset. Or if you get on a plane and your iPad is doing an update and it completes after takeoff but all your movies/games were offloaded, you’d be upset.
(That’s probably fixable by doing some math to figure out if it’s workable, or by asking the user on the update screen if they’d like to offload and reload. But it wouldn’t be 100% automated, which is what I think you were asking?)
> Or if you get on a plane and your iPad is doing an update and it completes after takeoff but all your movies/games were offloaded, you’d be upset.
I could see something like that (although you could do things like install at night when you’re at home) but it’s completely opaque: you’ll just stop getting updates, nothing will ever prompt you, and it forces you to do cleanup manually. At the very least I’d expect a prompt and a “clear up space” button.
As someone who doesn't use iCloud to store pictures or videos, can you explain what this has anything to do with updates? Is it because their device is so full that they don't have disk space to download the update? And Apple doesn't temporarily grant them additional iCloud storage?
edit: MacOS reports iPhone being up to date.
edit 2: Selecting 'use mobile data' when downloading and installing does work. Go to Settings > General > iPhone Storage and delete the update package. Restart the download & install process and let it use mobile data this time.
I get the feeling checking the hash does work over LTE as opposed to Wi-Fi, based on absolutely wild speculation.
This is the most Canadian-hostile update in the history of computing!
NSO prefers devices to be 99% secure.
Both platforms are extremely vulnerable and actively exploited. Make of that what you will.
Partly due to more android devices out there than iPhones ex-US
I think I've even seen an insane person with a marginally operational openbsd phone.
I believe this affected ~1000 VIPs and caused the death of at least 1 person.
Either 0 VIPs use Android, or it is much harder to break into. (From my research, there wasnt any 0 click exploits, you always had to manually download something and approve it outside the play store)
UAC on a Mac has always been good, but now there is this new layer that even protects the system from the admin. I think the real risk with Apple's model is that there are these choke points now that, if compromised, can cause truly catastrophic failure—especially because of the false sense of security that's out there. If an Apple update server or signing certificate were compromised it would be a potential company ending event. Other ecosystems are much more fragmented, and there is some resilience baked into that. I remember a few years back when an OCSP server went down and internet connected Macs around the world ground to a halt. You couldn't open any application because it took 10 minutes for the server that verifies its certificate to time out.
OpenSSH, for example, is an OpenBSD project and damn near everybody uses it.