Apple promises fix 'very soon' for Macs with failed encryption
reuters.com
reuters.com
None of my ios devices asked to install the fix and I had to do a manual update check. This should not happen for major security issues.
(Last time I tethered to a friend's android phone!)
It shouldn't be like this; my main source of bandwidth _is_ 3G.
That's bizarre; I'm tempted to try it out when I get back to a country in which I have mobile data.
"More happening in this iPhone, I feel, than has been revealed"
I always giggle at it being called that.
I heard about this thing yesterday on HN and did the update manually. My dad and sister's iOS devices hadn't notified them yet when I told them about it today, more than 24 hours later.
Because yes, why not even hold the iOS fix for a day or two until they can both be pushed together? Obviously that’s not good, but isn’t it better than basically making an implicit irresponsible disclosure against your own operating system?
Maybe this bug is being exploited in the wild already and that’s the reason for the urgency?
Again, not that this should not be urgent, but why help your iOS users and at the same time potentially harm your OS X users? It just seems like a really weird decision.
(Although priority is relative even for iOS. We have many iOS devices in the family and not a single one had asked to install the fix until yesterday evening. The fix, however, was available after a manually initiated update check.)
I'm not saying it's a great move, but if you're going to prioritize, doesn't it make sense to start with what you know will protect the most users ?
Maybe not. It could just be that OSX has a higher testing effort. There is a bigger spread of versions across the OSX platform than iOS. And also Apple does have quite a few hardware specific builds of OSX they need to test.
Still completely unacceptable though.
The fact that it takes sooo long, and that the fix will be bundled in a blob with all sorts of other "fixes" gives me the feeling that one attack-vector cannot be closed until another is available. I got this feeling years back when a huge back-door-enabling was not closed for months until big fat service pack was issued that "fixed" it (amongst fixing a million+1 other things; probably opening the next attack-vector).
Call me paranoid.
Even for trivial stuff. Why? Cause in a a giant corporation, even a hotfix takes ages to get through all QA.
The risk isn't that high either, anyway.
wat
It's better to leave them vulnerable than to leave them vulnerable?
Good point. Still the update will likely come as part of a large blob.
Finally, I'm just disagreeing with the "tech savvy" crowd going en-masse for Apple products. OSX is a huge step fwd to Windoze in terms of internal software architecture -- yet it carries the same risk as it is proprietary and closed in parts that are critical to its security.
Yes Mr IT-geek; your MBP is probably rooted from the moment you opened the box.
Again: call me paranoid :)
[1]: http://opensource.apple.com/source/Security/Security-55471/l...
That was my first thought as well, but on reflection this sort of logic has a certain "quality." (Yes, that's a reference.)
Not true, at least on iOS. iOS 7 is on over 80% of devices less than 6 months after launch.
> The code will always jump to the end from that second goto, err will contain a successful value because the SHA1 update operation was successful and so the signature verification will never fail.
Wait, Apple still uses SHA1? Are they aware it's banned from use (by NIST, no less) starting with this year?
http://www.zdnet.com/nist-makes-a-hash-of-sha-1-ban-70000259...
Maybe they'd want to take this opportunity to fix that, too...
This is verifying certificates for HTTPS connections - not creating them. If they removed the SHA1 verification, you can no longer visit hundreds of millions of sites that haven't updated their certificates yet.
It's the people still using certificates with SHA1 hashes that need to upgrade.
There has been such a rush from many places to cast this as a "mistake". We just don't know whether this was deliberate or a mistake, anything else is just an opinion. I don't see one explanation being less likely than the other, it's annoying to see one explanation being pushed more than the other.
From the wikipedia entry on Occam's Razor.
> In the scientific method, Occam's Razor is not considered an irrefutable principle of logic or a scientific result.
It's amazing how elusive the obvious can be when your mind's on something else. Given that, I personally assume good faith until there's significant reason to doubt that assumption.
Here's an embarrassingly stupid bug I created (or rather, the one-line patch that fixes it): https://github.com/LnxPrgr3/message_queue/commit/b21944ab63f...
Until someone else makes a laptop OS that's even half as good as OSX we're all stuck with it.
I would say that Snow Leopard was their peak, even though it did follow Leopard.