4 ms·
Let me tell you a little story from the inside… So, when you build something as big and complex as an operating system, your single biggest enemy is: change. T
by IdeaHamster 16y ago
Let me tell you a little story from the inside…
So, when you build something as big and complex as an operating system, your single biggest enemy is: change. The more things change, the more you need to test and retest to be absolutely sure that those changes didn't have any unintended side-effects. This is why, in the process of reaching a GM build, the ability for groups to change components is gradually locked down. The final lock-down is GM, and this usually happens around 1 month before the first customers see the next OS. This time is needed to "prime the channel". That is: you need to press the disks, prepare the marketing material and the packaging, do all of the final validation testing, and start shipping the software to stores.
In the case of SnowLeopard, that meant that development was done, and GM was declared, in the 3rd week of July. SnowLeopard shipped on Aug. 28th. Know what happened between those two dates?
Flash Player v10.0.32.18 ships on July 30 with critical security fixes: http://www.adobe.com/support/security/bulletins/apsb09-10.html http://www.adobe.com/support/security/bulletins/apsb09-10.ht...
Remember all the fuss? No? Here's a reminder: http://www.zdnet.com/blog/security/snow-leopard-ships-with-vulnerable-flash-player/4175 http://www.zdnet.com/blog/security/snow-leopard-ships-with-v...
In particular, people were incensed that installing SnowLeopard on top of their Leopard systems that already had an updated Flash player actually reverted to the vulnerable version. Why? Because Flash was part of the OS. It was part of the install package that gets laid down fresh, instead of being part of the user installed software that gets migrated from old to new OS. And because Adobe didn't get the Flash update to Apple before GM was declared.
- DeusExMachina 16y agoThis is also what Gruber wrote at the time: http://daringfireball.net/2009/09/flash_snow_leopard http://daringfireball.net/2009/09/flash_snow_leopard
- IdeaHamster 16y agoGruber has good sources ;)
- mkramlich 16y agoA little birdie told me that Gruber may have heard it from a hamster. Animals, they talk when we listen to them. :)
- smackfu 16y agoIf you buy Snow Leopard today, has the disc been updated with all the security updates since its release? If not, that would have the same issue, that you are vulnerable for the time between you install and when you run system update for the first time. I don't really see how Flash is special here.
- jakestein 16y agoThe difference as I see it is that Snow Leopard will get the security updates via Apple's Software Update program. You're on your own for updating flash player, or at best you get notified by Adobe that a new version of flash player is installed. Apple can control or at least heavily influence the updates for Snow Leopard. It can't for flash.
- smackfu 16y agoThe example given was that Apple shipped an out-of-date Flash player because a new version was released after RTM. They then presumably updated that immediately with System Update. My point is that the same thing can happen with the actual OS. You can install Snow Leopard with a vulnerability that has already been fixed in a point security release of Leopard. So is it really a good reason to stop shipping Flash?
- tptacek 16y agoHuh? How does Apple get a security update in its own software too late for GM? Apple handles the SDL for its own security flaws internally. It tends to know where it stands with them. Apple cannot say the same thing about Flash; Adobe (as a simple matter of course) may have tens of queued vulnerabilities, with some arbitrary subset of them having actual fixes in the pipe. That's the nature of software security on large projects. Apple can't wash its hands of Snow Leopard vulnerabilities, but it essentially can do that for 3rd party software like Flash.
- smackfu 16y ago>Huh? How does Apple get a security update in its own software too late for GM? Apple ships plenty of GNU code. What if an exploit is released between RTM and the ship date? That's the kind of thing I am thinking of. But I don't disagree that this is Apple saying "this is somebody else's problem now". I just wonder if that somebody is Adobe or the end-user.
- deleted 16y ago[deleted]
- nikster 16y agoThis is spot on, IdeaHamster. I think the main question Apple asked itself is "why do we ship Flash with every Mac?". The answer is that back in the day when Flash was added, Adobe was a very good partner, and Flash was cool. These days, Adobe is turning more an more into an enemy - even holding talks with arch-enemy Microsoft. So if you asked again - why do we ship Macs with Flash - the answer would be: We shouldn't. It should just be yet another plug-in that needs to be installed. I think the bottom line is, there are good technical reasons, and there are good political reasons to dump Flash from the OS. It's about 50/50. Adobe has some power with Flash but it's standing on pretty shaky ground - videos work just as well in HTML5 which leaves Facebook games as the one application that really matters.
- pedanticfreak 16y agoThe problem is not whether the latest version shipped with the installation disc. It's how quickly it got put up on Software Update. Lots of products have downloadable updates on the day it appears. Flash should have been a required update within days of Adobe releasing the new version. There would have been no story if the headline was "Snow Leopard requires Flash update on install." I seem to remember I got my Snow Leopard late and I still had to go straight to Adobe for my update.