Remix.run Logo
▲ user43928 3 hours ago

Disagree.

Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.

Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.

Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.

That doesn't excuse the mistakes on Apple's part.

▲fg137 an hour ago | parent [-]

> That doesn't excuse the mistakes on Apple's part.

Let's first establish that Apple definitely has a stake in this.

How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.

That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?

▲user43928 an hour ago | parent [-]

I don't think anyone criticized the timing of the patch.

But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.

I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?

Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.

If it doesn't, that's understandable, but still hardly the user's fault.