30 ms·
So, is this an issue on my old mac running 10.11.6 that will not get fixed?
by oblib 6y ago
So, is this an issue on my old mac running 10.11.6 that will not get fixed?
- jhugo 6y ago10.11 is unsupported since September 2018. This is definitely not the only security issue you have.
- deleted 6y ago[deleted]
- Wowfunhappy 6y agoI'm on 10.9 and I don't want to use anything newer. I can deal with some risk, but this vulnerability is unacceptably bad. The core problem is that really dumb feature which auto-expands certain zip files. I need to turn that off. MailWebAttachment.h contains a method: - (BOOL)isAutoArchiveAttachment; I bet that if I Swizzle that to always return false, this "feature" will go away. I'll found out this weekend... Edit: Is the author's PoC available anywhere? Not that I really need it...
- Wowfunhappy 6y ago^ Yeah, that didn't work, the method never gets called. I'll have dig more...
- Wowfunhappy 6y agoGot it. Made very quickly but is working for me (which is all that really matters.) https://github.com/Wowfunhappy/Fix-Apple-Mail-CVE-2020-9922 https://github.com/Wowfunhappy/Fix-Apple-Mail-CVE-2020-9922 Had to make `-(BOOL)isAutoArchivePart` in `MCMimePart` return false.
- Hnrobert42 6y agoI’m curious and not attacking. Do you follow all security-related announcements for Mac OS and do your own back ports and fixes? How did you decide 10.9 is the right balance of risk for you?
- KirillPanov 6y agoIt might not be a matter of risk balance. MacOS 10.9 was pretty much when Apple jumped the shark. That was the last version I ran before switching back to Linux, and I ran it pretty damn long in the tooth as well -- until ~2018ish. I still have a few VM images with MacOS 10.9 that I spin up from time to time in order to run commercial software like Adobe Acrobat.
- dcow 6y agoJust curious, what did Apple do (or not do) in 10.10 to earn the “jumped the shark” description?
- Wowfunhappy 6y agoI use 10.9 because out of all the OS's I've ever used, I like 10.9 the most by far, and I consider that worth the security risks. I browse the web in an up-to-date version of Chromium[0], I keep my computer behind an up-to-date router, and I trust my local software. An experienced hacker who wants to spend a few days getting into my computer will succeed, but they'd probably succeed anyway, and that's why I take measures like keeping backups in cold storage. This was the first time I've actually backported a security fix. Apple Mail is easily where I'm most vulnerable, because it's not merely an outdated app which opens untrusted content—it opens untrusted content which anyone can push to me! 0: https://github.com/blueboxd/chromium-legacy https://github.com/blueboxd/chromium-legacy