Remix.run Logo
▲ fg137 6 hours ago

> Obviously I should have — and will be — using a VPN going forward

That's my takeaway from the article. I have trouble understanding how the author managed to extrapolate all these things about Apple from an obvious oversight on their part. I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.

Software WILL have bugs and vulnerabilities, regardless of whether it's an OS or user application, whether it's from Apple or another company, or the update frequency/mechanism. If you can't even follow the most basic security practice on your part, you simply don't have any authority to discuss security otherwise.

▲user43928 3 hours ago | parent | next [-]

Disagree.

Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.

Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.

Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.

That doesn't excuse the mistakes on Apple's part.

▲fg137 an hour ago | parent [-]

> That doesn't excuse the mistakes on Apple's part.

Let's first establish that Apple definitely has a stake in this.

How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.

That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?

▲user43928 an hour ago | parent [-]

I don't think anyone criticized the timing of the patch.

But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.

I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?

Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.

If it doesn't, that's understandable, but still hardly the user's fault.

▲someguyiguess 4 hours ago | parent | prev [-]

> I would never write a 3,000-word article about how bad someone else is because of an issue I caused for myself.

Welcome to hacker news!

▲otterley 4 hours ago | parent [-]

In this case, the author literally writes blog posts for a living. This just happened to be a free article, and, well, you get what you pay for.