7 ms·
Isn't this why projects such as Homebrew thrive? For me personally, I just `brew install git`, and I keep it updated that way (`brew update && brew upgrade`)...
by reedloden 10y ago
Isn't this why projects such as Homebrew thrive? For me personally, I just `brew install git`, and I keep it updated that way (`brew update && brew upgrade`)...
Sure, Apple should ship a fix, but there are ways around it for now.
- aorth 10y agoYes, indeed, but Mac OS X users who use Homebrew are a subset of all Mac OS X users. The problem is in the default software. Apple's update model isn't good for this type of software, so the fact that it is possible for a user to install secure versions from Homebrew (or compile their own) doesn't matter.
- xyzzy123 10y agoExcept that git is used specifically by users who are downloading and compiling software.
- brightball 10y agoAnd at this point the first instruction for any OSX user who downloads and compiles anything is "Install Homebrew"
- stephenr 10y agoExcept for those who have used it and refuse to use it again. There are prebuilt binaries of up to date git distributed via .pkg. The yeast infection that is Homebrew is unnecessary
- brightball 10y agoThat's kind've harsh. What's the issue? Homebrew was about the best option that's existed on OSX for a few years now I thought...
- stephenr 10y agoThe dependency management is a joke, compile-by-default means it's slow as hell.
- anu_gupta 10y agoI look forward to your release of something better
- stephenr 10y agoSo your world view is that only those with a competing solution are allowed to identify issues in something?
- deleted 10y ago[deleted]
- mwfunk 10y agoIf you're going to be that snarky and nonconstructive about it, you're going to get snarky and nonconstructive comments back. Or at the very least, you're not going to inspire any thoughtful and interesting observations from anyone.
- danieldk 10y agoMost commonly-used dependencies are bottled (precompiled) these days.
- stephenr 10y agoExcept the dependency management solution is terrible, unless you want to compile everything yourself. For example: https://github.com/Homebrew/legacy-homebrew/issues/35995 https://github.com/Homebrew/legacy-homebrew/issues/35995
- icedchai 10y agoPersonally I use MacPorts.
- atdt 10y agoThe Homebrew installation process uses the system git.
- arm 10y agoYep, since Homebrew requires the Xcode Developer Tools to be installed (which of course includes the outdated Git).
- danieldk 10y agoYes, but if Homebrew is malicious, you'd have more problems than a specially-crafted repository that exploits a git vulnerability. You are installing something that has all user access rights.
- gpvos 10y agoCan you inunstall XCode again once you have installed a compiler, toolchain, and git via Homebrew?
- matt4077 10y agoYou can just install the command line tools without xcode. From those tools, most can be replaced with their homebrew versions so you only need them for bootstrapping. But if you want to do hardware- or OS X related development, you will need to keep the tools around. CUDA, for example, needs clang et. all. They don't take much space, though, and the toolchain is treated a bit better by Apple than utilities like git, vim etc.
- gpvos 10y agoI don't know about homebrew, but macports has clang and other toolchain stuff, so I think it might be possible to uninstall Xcode after installing all necessary tools through macports?
- OJFord 10y agoYou _could_ get recent git by some other means prior to installing homebrew. Anything short of compiling from source wouldn't require ever installing XCLT.
- bronxbomber92 10y agoXcode is distributed and released over the AppStore and can be rev-ed at any frequency, independently of the OS; Apple's update model not does prevent an expedient update. Perhaps the main cause for delay is the associated QA efforts to make sure that other components in the stack which depend on git don't break in the case that git has broken binary compatibility (i.e. changed its public interface).
- atdt 10y agoIf things are tied up in QA, that is a problem in and of itself, because relevance is an important quality for a security bugfix to have. If my system is compromised today, it will do me little good that the bugfix Apple ships next month was tested extensively for compatibility with Xcode. It is too late for there to be an expedient update from Apple. The vulnerability was disclosed to oss-security over a month ago, on March 15[0]. SUSE had a patch out the next day[1]. By March 24, Debian, Ubuntu, Red Hat, CentOS and Oracle had all issued fixes.[2] [0]: http://www.openwall.com/lists/oss-security/2016/03/15/5 http://www.openwall.com/lists/oss-security/2016/03/15/5 [1]: http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00059.html http://lists.opensuse.org/opensuse-security-announce/2016-03... [2]: http://www.securitytracker.com/id/1035290 http://www.securitytracker.com/id/1035290
- bronxbomber92 10y agoI should clarify that I don't know why an update hasn't been pushed. I was only speculating why it might be taking so long.
- ascagnel_ 10y agoGit is not part of the default configuration on OS X. You need to install XCode first.
- sbuk 10y agoI'd argue that the the OS X user who use git are a subset of Mac OS X users. In fact, a similar subset to that which uses Homebrew...
- atdt 10y agoIt's a bit too precarious to be an adequate solution, in my opinion. It depends on /usr/local/bin always being ahead of /usr/bin in $PATH, and on scripts never invoking the system git via its full path, and on Homebrew never accidentally uninstalling git due to a botched upgrade. Not to mention the fact that Homebrew itself uses the system git to install itself.
- tobylane 10y agoWhen would the order of $PATH vary?
- OJFord 10y agoWhen someone's changed it? Which people do _all the time_.
- tobylane 10y agoMine is changed for Heroku, but it only prepends. I've never seen $PATH be rearranged.
- OJFord 10y agoIf you prefix it with something already in there then it's effectively rearranged. You wouldn't do this deliberately, of course, but it happens a lot - people end up with massive PATHs because they blindly prefix when something's gone wrong and it _may_ be the solution.
- dchest 10y agoSure, but your /usr/bin/git is still vulnerable. You're one config mistake (or maybe running a "malicious" script) away from executing.
- jaequery 10y agoI'm pretty sure git isn't the only thing that is (or will be) vulnerable. Vulnerabilities happen, it's a fact of life. You will have to constantly update your systems no matter which OS you run.
- dchest 10y agoDid you read the linked article?
- developer2 10y agoYes we did, and the author appears to be posting with the primary intent of spreading anti-Apple sentiments. The opening paragraph begins by insulting startups for being full of Macs. The rest of the post is full of snide comments. They go off on a tangent about System Integrity Protection and the fact that OS X is not Linux ("Apple... keeps you from twiddling", "Well, sorry. You also can't chmod", "I'll just strace it to see what it execs! Oh wait, this isn't Linux."). This could easily have been posted as a simple statement of the CVEs in question and the version of git shipped with latest OS X patch. Not difficult to post facts about a specific issue without insulting an entire operating system - and taking cheap shots at the people that use it. >> If you rely on machines like this, I am truly sorry. I feel for you. I don't feel sorry for myself. Odd that a stranger finds it necessary to offer me their sympathy, let alone condescending pity.
- chris_wot 10y agoThe opening paragraph reads: "Sometimes I think about all of those pictures which show a bunch of people in startups. They have their office space, which might be big, or it might be small, but they tend to have Macs. Lots of Macs. A lot of them also use git to do stuff, perhaps via GitHub, or via some other place entirely. There are lots of one-off repos all over the place." If you can see a cheap shot in that paragraph, then you are reading things that aren't there. A blog post gives a certain amount of freedom for the author to elaborate on a theme. You seem a bit defensive. I'm not sure why, but I certainly don't think that Rachel was attacking those who use Macs.
- raimue 10y agoIsn't this the perfect setting where an attacker will ask you to replace this binary with a custom binary with an additional backdoor? In the best case the attacker would fake an email that looks like it came from your IT department. Even if you were suspicious, a quick search on the web would confirm that Apple really ships a vulnerable binary. So you believe the email is real. Then you go along and replace the binary with the malicious binary provided in the mail. The fixed binary needs to be shipped by Apple.