Many Mac OS Users Not Getting Security Updates
AmiMoJo writes "According to security company Sophos, around 55% of home users and 18% of enterprise users have updated to Mavericks, the latest version of Mac OS (10.9). Unfortunately Apple appears to have stopped providing security updates for older versions. Indeed, they list Mavericks itself as a security update. This means that the majority of users are no longer getting critical security patches. Sophos recommends taking similar precautions to those recommended for people who cannot upgrade from Windows XP."
Since you know, the switch ads told me Macs don't get viruses or other bad stuff
I'm woking in a large university where you find a larger percentage of Mac and Linux systems. It's hell keeping all operating systems updated properly. Researchers get grants to do something then spend $2million on the custom systems build on a particular version of an OS. Now it's 5 years later are still using the old OS because it would cost another $1million to upgrade the custom code and get new equipment that doesn't use parallel ports for data transfers.
It all starts at 0
Far be it for me to say that a security company was using dodgy numbers to hype its product, but their MacOS adoption numbers are soley from Sophos-for-MacOS users, which I'd have to imagine is a really spectacularly unrepresentative sample. And their assertions that Mavericks was the only way to get security updates for MacOS going forwards seems to be contradicted by the fact that the previous version of MacOS was security patched when Mavericks was launched.
No kidding!!! What do you say at this point?
It is unfortunate that Apple didn't think that one through a little further.
If they are adopting the model of "the OS Upgrade IS a security update", then throw it in their normal update mechanism rather than having people seek it out.
Since they didn't, they must realize that there is a chance that their Upgrade could break things for people, so let them upgrade in their own time, and as such should back port the occasional update to the computers that they sold 3 months or so ago.
Thirty four characters live here.
I'm not sure where the author gets the idea that Apple has stopped releasing security updates for older systems. The page linked from the summary lists updates for software for OS X 10.7 and up as recently as 16 December, a Java update for versions 10.6 and up on 15 October, and the most recent actual security update, also for versions 10.6 and up, on 12 September. Apple releases security updates when necessary, not every Tuesday like Microsoft. The fact that they've released an OS update, which includes security patches, for the most recent version of the OS without releasing one for older versions most likely means that the vulnerabilities addressed were not present in older versions; this has been the Apple release strategy for at least a decade.
That's some real troll-bait comparing Mac OS to Windows XP. There's really little similarity. Microsoft is discontinuing security patches for a 12 year old OS. Apple is discontinuing security updates for an 18 month old OS.
I don't respond to AC's.
Looking at the Apple update release page there hasn't been a Security Update since Mavericks was released so there is no evidence to support the assertion from Sophos.
The last Security Update from Apple was 2013-004 and included updates for Snow Leopard, Lion, and Mountain Lion. Until Apple releases a security update that *only* targets Mavericks this is just Sophos FUD.
You may think me a tired, old, cynic. I'd have to disagree about the tired bit.
Mac OS was deprecated 12 years ago when OS X stepped in.
I have a 5.5 year old MBP and it runs Mavericks almost perfectly as well as it ran Leopard. The case for not upgrading to Mavericks if you have a x86 Mac that is the age of mine or newer is based almost entirely on being a curmudgeon who doesn't want someone telling him to just move onto the next version. The vast majority of the refuseniks are likely not savvy users objecting to the "iOSification" of MacOS X or something like that, but ordinary idiots who blink at you with a blank expression when you ask what version of OS X they use. "Huh? Macs haver versions?" Yeah. My wife and I have met a lot of casual Mac users who don't seem to understand that no, really, MacOS X has versions just like Windows and that using the same OS X that came with your Mac three or four years later is like saying "I don't need that service pack shit" on Windows.
When iOS 4 came out, you switched to Android because you wanted more software updates? Summer 2010, at the height of the Android software update panic, when Motorola had to be pressured to even update the Droid to 2.2, and most phones were lucky to see an update outside of the first six months?
Then when you couldn't get a new version of MacOS for a five-year-old laptop, rather than just install Windows 7 on it, you bought a whole new computer?
Talk about cutting off your nose to spite your face.
No kidding!!! What do you say at this point?
I have an old, first-gen Mac Pro, which I use as a regular desktop. I tend to spend the bulk of my time in Windows, but I use OS X on occasion.
For whatever reason, the firmware on it is for 32-bit systems, something Mountain Lion and now Mavericks does not support. I'm still running Lion because I don't care about their new features and don't want to risk breaking something trying to hack it into working. Getting 64-bit Windows onto the machine was difficult enough.
So yeah, for me at least, it's because Apple doesn't want to give me security updates, not because I don't want to download them.
Troll detected. But just in case... iOS 4 does actually run on the 3G, and Mavericks runs on as hold hardware as the last normal MB models prior to the Pro notation, which I believe were released in 2007.
For quite some time now, it's been Apple's policy to support the current OS release as well as the previous OS release. That means that since the release of Mavericks, they would be supporting Mavericks (current release) and Mountain Lion (previous release). But, this is also the first generation that the new OS 1) supports every machine that the previous release supported 2) is offered for completely free. So, practically speaking, there's very little reason to not just force all Mountain Lion users to upgrade to Mavericks to have support. However, I don't see any evidence on their page that they are even instating this policy? If they did, though, it would be very aggressive, but not really unremarkable for Apple.
Scorta futuere amo!
You switched to Android because you iPhone couldn't get an update? Hope you picked the right model. Android phones have terrible track records for receiving updates. Many of them never receive an update after leaving the factory floor. People say the Nexus line of phones get better support, but I'm not sure if I believe that. The Nexus One is stuck on Gingerbread (2.3) after only being released in 2010. The Nexus S is only at 4.1, Then Galaxy Nexus is at 4.2 or 4.3 depending on the hardware revision. The only ones you can run the latest OS on are the Nexus 4 and 5, the former of which is only from late 2012. Meanwhile, in with Apple, IOS 7 is supported all the way back to the iPhone 4, which was released in early 2011.
Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
That doesn't mean that all your software works. If your company has decided to run OS X and their mission critical business app doesn't work with the new OS then they can't upgrade. And add the fact that new machines can't be downgraded to the older OS, so you can't buy new hardware either.
When was the last time iOS 4 recieved a security update? Additionally, if you actually had an iPhone 3G you would know that upgrading to iOS 4 basically rendered it useless even though it was technically possible.
As long as it runs POSIX and an X11 server, it should run desktop applications designed for desktop Linux or FreeBSD with minimal porting work. The POSIX-certified versions of Windows did not include an X11 server and therefore were not very useful as *n?x workstations. Likewise, despite using the Linux kernel, Android uses different apps because its GUI layer runs on something other than an X11 server.
The Mac was a PC exactly to the extent that an ST or Amiga was a PC. Until the Intel transition, the architecture of the Mac wasn't anywhere near that of the IBM-compatible (now Lenovo-compatible) PC. Nor was the architecture of Mac OS or OS X anything like that of MS-DOS or Windows.
I think the main difference is that Apple does things in small steps rather than large steps so transitions are easier. For example between OS X Cheetah (10.1) and Leopard (10.5) there was so much change that many programs that worked in Cheetah may not work in Leopard but each versions was only a small change from the previous. MS did the same thing in the same time from XP -> Vista but the changes were so abrupt that it broke so many things. Leopard brought in the new Intel CPUs. Snow Leopard contained a great deal of changes to the core systems including the transition to 64-bit. The pattern from Apple has been major architectural changes then refinements for a few versions then major architectural change.
Well, there's spam egg sausage and spam, that's not got much spam in it.
Unfortunately Apple appears to have stopped providing security updates for older versions.
A statement that is cast into severe doubt by the continuing appearance of security updates for older versions, like Safari 6.1.1 on December 16th, Apple Remote Desktop 3.5.4 on 22 October and the lack of any claim that Apple has stopped releasing security updates in the article they link to to support their claim that Apple has stopped releasing security updates. It does talk about some of the security updates in 10.9 - a couple of which are covered by those Safari and Remote Desktop updates. As for the rest, TFA doesn't take the trouble to actually establish whether they are fixes c.f. 10.8 or fixes for issues in the 10.9 beta that was widely released to developers - so neither will I.
Now, is Apple maybe prioritising which security fixes it backports to 10.8 or earlier, and only bothering with the "OMG remote pwnage imminent" ones? Maybe. I will try and contain my fear.
In a survey of 100 programmers, 111111 thought that duck-typing was a good idea.
Sophos says that the security updates have stopped for anything older than Mavericks, but the article they link to has updates for 10.7, 10,8, and 10.9 in it that are less than 30 days old.
So I'm not sure how they are reading this that Apple isn't releasing updates.
So pay a premium for the hardware then spend loads more getting a non-OEM install of windows and potentially a license for your VM solution.
Yes, because getting an OEM versions of Windows for the PC I built myself is rather easy and cheap. Also the cost of Windows is $0 for all OEM systems right? I didn't pay anything for it at all.
Well, there's spam egg sausage and spam, that's not got much spam in it.