I hate Apple's new yearly release cycle. There's not enough time to stabilize and improve OS's.
This update just rolled out, but it indicates the admin fixes are only for Yosemite:
https://support.apple.com/en-us/HT204659
How worried should I be about not having updated? There's still a risk I may lose some program compatibility by updating.
For a single-user desktop machine, realistically, user/root privilege separation doesn't matter, because all your important data is in your home directory and not protected by root privileges anyhow. The root-protected stuff is actually the stuff that's easiest to replace, because it's just a bunch of software that you can re-install. Viruses don't need to infect your software to stay resident; they can just as easily register a login hook without root permissions.
(That said, some people will violently disagree with me on this.)
It's dumbfounding how people here are simply shrugging this off and posting "So what? Just upgrade. Simples" type comments. This isn't acceptable. I know many people in creative industries alone who can't just upgrade immediately any time something comes out as they've to wait for their products to support the newer version. Similarly there are many who are using Macs in work whose corporate policies won't let them simply update immediately.
Then there's many who don't immediately upgrade versions as a point while bugs/other issues in that new version are found and resolved.
It's not an acceptable answer whatsoever.
Zero people is dumbfounding to you? Because that's how many people are saying that.
Reread the comments.
The second comment from the top when you go to
This is nothing close to "So what? Just upgrade." He's saying that from apple's perspective the best customer is one who upgrades their machine on every upgrade cycle which explains why they don't care about previous generation OSes. And how can you say this comment is apple-apologetic when he goes on to say that Microsoft does a better job maintaining backwards-compatibility?
The next one is a 3 year old Mac Mini. I upgraded to Yosemite and it performs TERRIBLY. It has 16G of RAM. I've tried everything. Yosemite just sucks. The machine is now much slower than the 6 or 7 year old iMac with only 4G or RAM. If it was practical to back out to Mavericks I would.
The last one is a 2 year old Macbook. I rely on it for my job. There is no way I'm going to risk the crappy Yosemite performance to upgrade. I'll live with the security flaw.
Here is what I now know about Apple: They will not support you for the lifetime of the product. They consistently release buggy code these days. Unless you are willing to shell out more money for new hardware every time they come out with something new, you will be stuck "as-is (with bugs)" until you get rid of it.
No more Apple anything for me. I'm thinking I'll switch the Mac Mini to Ubuntu if I can get it to work there. I'll use the iMac until it doesn't work any more, and when my Macbook is ready for an upgrade (in another year or two), I'll be trading in that still-Mavericks based system for a Linux laptop or maybe I'll go back to Windows.
I'd upgrade to Yosemite today with the latest updates. They just freed up 4 GB of ram for me. Sadly if I had known all of this beforehand I wouldn't have gone out of the way to buy some old Mac Pro where I could upgrade the memory to 32 GB or more, so I just wasted about $1500 for the whole setup.
Then again like you, I transitioned my work to an Ubuntu box, but even for my personal stuff my Mac was just really slow unless you get an SSD drive which is time consuming to install on an iMac.
For 2009 and up Mac Pros, there are plenty of hardware options for upgrades; and firmware as well for 2009.
If only it were that easy. Yosemite just seems to "break" some things and I've still been waiting it out.
> To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.
> While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.
> Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken.
> Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.
> Referring to Snow Leopard now not secure > Still pretty much the best OSX.
> Among other things upgrading (to 10.10.3) will do, it'll fix the issue in the article.
>Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.
He was rebutting that regular upgrades are somehow a type of revenue to apple since they are free and work on some previous generation hardware. How is that apologetic?
A similar force seems to drive politics, or at least motivates disturbingly huge blocs of voters. :(
I don't like Apple's business practices, hard to hack devices and technology philosophy doesn't mean I am Tribal.
I have many machines that are over 5 years old.
I have never seen Apple as being honest or making products for me as a nerd. So I live mostly in Linux nowadays.
I have no credibility since I don't like a company? What about the opposite people who like the company?
Credible people are always upfront with their biases. I never trust anyone that says they are neutral.
Well the answer to that is when someone says something you call for proof. You don't throw out the baby with the bathwater. That's what I do with David Pouge and Walt Mossberg. But I usually get my news from Tech Press that has been black balled by Apple.
I don't intend that to be apologetic for Apple. I called it a 'significant vulnerability' but at the end of the day, it's a privilege escalation like those that have come before and will likely continue to be found occasionally, regardless of OS. I don't see what's apologetic about acknowledging a significant vulnerable while questioning whether it should be called a backdoor.
If you want to talk about Apple's response - I find it concerning that they aren't backporting the fix.
I don't see a single comment in this thread that says that.
We do not allow developers to criticize our revolutionary and beautiful platform. Good luck ever getting an app featured again.
- Apple