Hacker News new | ask | show | jobs
by ef4 4500 days ago
Why the hell would Apple publish the vulnerability & fix for iOS without a concurrent update to OS X?!
6 comments

It's common security practice to release the exploit before the bug is patched in the OS. Oh wait, no, the opposite of that. Unless you're Apple. I'm very angry.
Presumably because the vulnerability is already known outside of Apple, and it's better not to hold back the iOS patch while they get the OSX patch done.
How hard is it to get the patch done? Isn't it, like, removing one line?
Yes, removing one line would fix it.
It became widely known outside of Apple due to the iOS patch.
How do you know they hadn't already seen it exploited in the wild?
I don't know - I can't imagine that nobody on their security team pointed out that someone would promptly reverse engineer the patch and figure out that OS X is also vulnerable.
And having the source code available made that even easier.
I haven't upgraded to Mavericks, and I haven't been able to replicate the bug. I've been applying other updates, everything except Mavericks, all along.
The deployment on iOS was not very active either. I learned about the 'bug' through online sources and I had to initiate the iOS update myself.
OSX 10.8.5 here, Safari not vulnerable according to the site
This bug was introduced in Mavericks.
Can't say I'm surprised

The reason I'm in 1.8.5 is because I upgraded to Mavericks, but one of their updates forced me to recover from Time Machine (which wasn't as smooth as I expected)