11 ms·
Go upgrade Xcode. Fix your Git security hole
- cauthon 10y ago`brew upgrade git` No need to wait for Apple.
- pdpi 10y agoThat still leaves the system git vulnerable, which might be exploitable if you can trick the user into choosing the wrong git binary
- matt_wulfeck 10y agochmod -x /usr/bin/git
- orange_county 10y agoYou can't even remove execute permissions on it. This was stated in the article as well.
- cuckcuckspruce 10y agoThat doesn't work for OS 10.11[1]. There's a workaround in that article. [1] http://rachelbythebay.com/w/2016/04/17/unprotected/ http://rachelbythebay.com/w/2016/04/17/unprotected/
- chris_wot 10y agoYou can't. That's the point!
- Kristine1975 10y agoSince the system git redirects to the git in Xcode (or whereever Apple's command line tools are installed), copy homebrew's git there. Updating Xcode itself might be easier, though. Edit: Copy homebrew's git into the directory inside the Xcode application where Xcode's outdated git is.
- chris_wot 10y agoYou can't, not even root can. El Capitan is the only Unix in existence that will not allow root to update files in the /usr/bin directory. Edit: turns out that I'm wrong, there are plenty of examples - SELinux, Sun had a version, lots and lots of other examples I just didn't look very hard to find them. Sorry if I misled anyone.
- cmrx64 10y agoNot even close to true... mandatory access control systems are pretty common on widely-used UNIX-like systems. Apple is just the first vendor to ship them enabled by default to end users.
- chris_wot 10y agoCan you give an example?
- curt15 10y agoApparmor and SeLinux (in Ubuntu and Fedora respectively) can both be configured to restrict the root user (http://unix.stackexchange.com/questions/106595/myth-or-reality-selinux-can-confine-the-root-user http://unix.stackexchange.com/questions/106595/myth-or-reali...).
- chris_wot 10y agoYeah, I have to agree with cmrx64 - I really was totally wrong. I appreciate the correction, even if I made myself look a bit silly as I learned something valuable! I definitely deserved those downvotes.
- jdeibele 10y agoRight. And because of System Integrity Protection you have to turn SIP off, remove /usr/bin/git and then turn it back on. Had to do that with Java, which was installed on the family Mac just for Minecraft. Minecraft doesn't require it anymore: http://www.howtogeek.com/210907/minecraft-doesnt-need-java-installed-anymore-its-time-to-remove-it/ http://www.howtogeek.com/210907/minecraft-doesnt-need-java-i... Now that Apple is having a (seemingly) permanent beta option for Mac OS it would be nice if they'd have a developer option that would update much more quickly. And would hopefully have better bug reports ... hopefully.
- acdha 10y agoAs was discussed extensively last time (https://news.ycombinator.com/item?id=11517894 https://news.ycombinator.com/item?id=11517894) that's not a complete fix because it doesn't overwrite /usr/bin/git and so you're hoping that there's no way /usr/bin/git is executed instead of /usr/local/bin/git. It's better than nothing but no substitute for a complete fix — maybe your shell has the right PATH but are you certain there's no way your editor, GUI clients, or third-party utilities like convenience Docker launchers, etc. all use the same search order?
- deleted 10y ago[deleted]
- teamhappy 10y agoThe git versions Apple ships are reasonable up to date. Too bad they don't include the contrib directory.
- masklinn 10y ago> The git versions Apple ships are reasonable up to date. More than usual, but still not exactly up to date, as of April 17 Xcode shipped with Git 2.6.4, which was 2 minors and ~4 months out of date (2.6.5 in January and 2.6.6 in March) on its maintenance branch, and a major out of date (2.7.0 had been released in January)
- chris_wot 10y agoAnd this wouldn't be a problem if they didn't make a wide variety of system directories immutable to anyone (including root) but the installation user. Apparently this is a very unpopular opinion, so even though I really like Apple and use them on a daily basis, I await the brickbats for daring to offer even the smallest criticism of decisions they made about El Capitan. Please, feel free to reboot your server to disable this security feature so that you can install security updates for software Apple take a rather long time to supply themselves.
- vertex-four 10y agoOS X isn't a server OS and hasn't been for a while.
- chris_wot 10y agoFunny how I just installed OS X Server just today...
- vertex-four 10y agoYou can also install Apache, a mail server, etc etc on Windows 10. Doesn't make Windows 10 a server OS.
- cwyers 10y agoNo, he installed OS X SERVER https://www.apple.com/osx/server/ https://www.apple.com/osx/server/ Which is a server product that Apple sells, through the app store, for $20.
- chris_wot 10y agoIt's an operating system that runs server software. How does that not make it a "server OS"? It runs a VPN service, an update service, it's largely based on OpenBSD, how are you defining what is and isn't this magical "server OS"? Incidentally, I didn't actually need to purchase that, it just made my life easier. I was quite readily able to install OpenVPN on it via Homebrew and configure the pf rules without their GUI. The only thing I couldn't do was to install the caching update service. Do you know of an alternative I could have used to update a network full of Macs? No mockery needed, just an answer will do fine - if you know.
- evolve2k 10y agoIs it enough to update Xcode command line tools or do I need to install full Xcode? (I don't usually use Xcode)
- deleted 10y ago[deleted]
- zatkin 10y agoI use git from Homebrew, which updates more frequently. It might also be even smarter to pull the project from GitHub and build it from there. (Assuming Homebrew doesn't already do this.)
- jalons 10y agoThis doesn't address the issue, as that still leaves the vulnerable git binary on your system. It just takes one call to /usr/bin/git instead of /usr/local/bin/git to fall victim.
- hunterwerlla 10y agoCan't you just delete /usr/bin/git and symlink /usr/local/bin/git to it?
- Spidler 10y agoNo, see [the previous post](http://rachelbythebay.com/w/2016/04/17/unprotected/ http://rachelbythebay.com/w/2016/04/17/unprotected/)
- hunterwerlla 10y agoWow that is awful, I understand why they thought it was a good idea but hopefully this incident will change their mind.
- 10y ago
- skimmas 10y agoProbably not really related but to me that update is stuck at 0KB. I wonder if it has anything to do me having changed country in the middle of the process.
- morning_star 10y agoWhy would I go upgrade Xcode if I don't use apple's piece of crap software? Why don't you post this in some apple support board or whatever? Also, learn how to write so you don't sound like an autist. "there's a bug in Xcode" sounds better than "go upgrade xcode".
- epistasis 10y agoYour aggression is misinformed and misplaced. Why do you think any part of this comment is appropriate for HN?
- rebelde 10y agoXcode 7.3.1 doesn't seem to be enough. I installed Xcode 7.3.1, but git hasn't been updated to 2.7.4. $ git --version git version 2.5.0 Do I need to do something more?
- bcruddy 10y agoGit seems to be included with the xcode command line tools, make sure that's up to date.
- Stratoscope 10y agoIf you have Xcode, you don't need the command line tools and are better off removing them. The Xcode.app bundle itself contains all the command line tools, so having both is redundant. The command line tools are just provided for people who don't want to install the full Xcode.
- emmelaich 10y agomdfind -name git | grep -w bin/git\$
- OJFord 10y agoMeanwhile, Homebrew's Git is at 2.8.2 (latest).
- bcruddy 10y agousr/bin/git is still vulnerable and is much more difficult than it appears to be to remove, homebrews git binary is stored in usr/local/bin/git
- comex 10y agoThe claim you're making has been widely spread but is mistaken. /usr/bin/git is just a wrapper that execs the real git from /Applications/Xcode.app or /Library/Developer/CommandLineTools (depending on what you have installed), and some things will invoke the latter directly anyway; thus removing the wrapper is neither necessary nor sufficient to prevent exposure to the vulnerability.
- chris_wot 10y agoOr you set the DEVELOPMENT_DIR environment variable... what could possibly go wrong?
- OJFord 10y agoI know; my point wasn't "`brew install git` and you're safe" - it was "Apple don't let you upgrade when you want, and even when they do let you, they don't give you latest."
- Sir_Substance 10y agoAny chance that blog is based off a static site generator I can use? it looks like pretty much my ideal blog format.
- dchest 10y agoApple's developer responsible for maintaining Git wrote that the fixed version didn't make it into Xcode 7.3, because the vulnerability was announced later than they released it [1][2]. It took some time to release 7.3.1, indeed, and maybe even Rachel's original post made them release it faster. It's sad that they can't do it more quickly, but let's hope they'll improve release process. [1] https://twitter.com/jeremyhu/status/722272350272512000 https://twitter.com/jeremyhu/status/722272350272512000 [2] https://twitter.com/jeremyhu/status/722482144082157568 https://twitter.com/jeremyhu/status/722482144082157568
- chris_wot 10y agoTheir release process, IMHO, leaves a lot to be desired. I honestly feel Apple takes far too long to release fixes, especially when it comes to security matters. I also feel that their decision making process in general is opaque and often arbitrary. Their lack of openness and transparency leave a lot to desired. Ironically, I love their products and I'm often astounded by their high level of customer service - it's the only company I know where they have setup a system where you submit a support request and they call you, and frankly their Apple Stores are a genuine pleasure to walk into and their staff have always been attentive and helpful when I go in there. I really have a love-hate relationship with Apple, but on balance far more love than hate. There's a reason they inspire a passionate reaction in people, I just wish that many of those who are so passionate (the much maligned "Apple fan boi") would accept that you can be both critical AND supportive of a company.
- kazinator 10y ago> My reading suggests that if you were to point a vulnerable version at a repository which is controlled by an attacker, then they could run code as you on your machine. This threat exists regardless, because git repos usually contain code, which you pull, compile and execute. As you, on your machine.
- mordocai 10y agoYes, but normally you get to inspect that code before compiling and executing if you wish to.
- kazinator 10y agoBut you don't get to do that with the updated git from Apple any more than the original.
- rajivm 10y agoI clone repositories all the time to inspect/learn/debug dependencies without ever building them.
- Cthulhu_ 10y agoIn theory, yes, but in practice, things like Chromium and Linux and probably most non-npm-microlibraries are far too large to feasibly inspect before running. So basically be careful about who is given commit rights. Also, might be a good idea (if you're just running the software instead of working on it) to just pick a recent (signed) tag.
- CodeWriter23 10y agoOne would expect however that the tool used for downloading the source should be free from risk.