Jump to content

macOS 10.13.2 already patched the Intel Security bug

Quote

The critical design flaw discovered in the way Intel CPUs process information has reportedly already been fixed by Apple in a recent release of macOS.

 

Quote

Apple’s fix came out at the beginning of December with the release of macOS 10.13.2. But according to one developer, the company has a few additional patches for Intel’s blunder in a current beta build.

 

Quote

The question on everyone's minds: Does MacOS fix the Intel #KPTI Issue? Why yes, yes it does. Say hello to the "Double Map" since 10.13.2 — and with some surprises in 10.13.3 (under Developer NDA so can't talk/show you). cc @i0n1c @s1guza@patrickwardle pic.twitter.com/S1YJ9tMS63

— Alex Ionescu (@aionescu) January 3, 2018

 

So it would appear that Apple has already patched one of the security holes in the Intel chips their Macs run a while ago. What is interesting to me is that they noticed that there was a problem and implemented a fix before anyone else. 

 

It also appears that they have the patches for the rest of the vulnerabilities and maybe some macOS specific fixes lined up for 10.13.3. 

 

macOS best OS! 

 

Source: https://www.cultofmac.com/521443/apple-already-fixed-intels-massive-chip-flaw/

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

Interesting; did they somehow know about it in advance or did they unintentionally fixed part of the issue while adding a different feature? If they knew it already I wonder why they didn't tell Intel... it would be weird, I'm leaning towards the second case.

 

Still, good news for mac users.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Sauron said:

If they knew it already I wonder why they didn't tell Intel

Maybe they did, hence the Intel insider training news. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Matu20 said:

Shit on Apple all you want, but their focus on single OS and product line has it's benefits.

Focus or not, unless they were prescient they couldn't have known about this in november unless they somehow discovered the issue themselves in a mind boggling coincidence - and then kept it to themselves. If that is the case, I must both compliment them for finding it and condemn them for not telling anyone...

 

The more likely scenario is that they added a new feature that required that change and ended up patching part of the issue in a stroke of luck.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, DrMacintosh said:

Maybe they did, hence the Intel insider training news. 

But the dates don't match, if they knew about this in november linux and windows devs would have known about it in early december.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

29 minutes ago, DrMacintosh said:

implemented a fix before anyone else. 

Correct me if wrong but I believe Microsoft issued an emergency security patch yesterday.

Make sure to quote me or tag me when responding to me, or I might not know you replied! Examples:

 

Do this:

Quote

And make sure you do it by hitting the quote button at the bottom left of my post, and not the one inside the editor!

Or this:

@DocSwag

 

Buy whatever product is best for you, not what product is "best" for the market.

 

Interested in computer architecture? Still in middle or high school? P.M. me!

 

I love computer hardware and feel free to ask me anything about that (or phones). I especially like SSDs. But please do not ask me anything about Networking, programming, command line stuff, or any relatively hard software stuff. I know next to nothing about that.

 

Compooters:

Spoiler

Desktop:

Spoiler

CPU: i7 6700k, CPU Cooler: be quiet! Dark Rock Pro 3, Motherboard: MSI Z170a KRAIT GAMING, RAM: G.Skill Ripjaws 4 Series 4x4gb DDR4-2666 MHz, Storage: SanDisk SSD Plus 240gb + OCZ Vertex 180 480 GB + Western Digital Caviar Blue 1 TB 7200 RPM, Video Card: EVGA GTX 970 SSC, Case: Fractal Design Define S, Power Supply: Seasonic Focus+ Gold 650w Yay, Keyboard: Logitech G710+, Mouse: Logitech G502 Proteus Spectrum, Headphones: B&O H9i, Monitor: LG 29um67 (2560x1080 75hz freesync)

Home Server:

Spoiler

CPU: Pentium G4400, CPU Cooler: Stock, Motherboard: MSI h110l Pro Mini AC, RAM: Hyper X Fury DDR4 1x8gb 2133 MHz, Storage: PNY CS1311 120gb SSD + two Segate 4tb HDDs in RAID 1, Video Card: Does Intel Integrated Graphics count?, Case: Fractal Design Node 304, Power Supply: Seasonic 360w 80+ Gold, Keyboard+Mouse+Monitor: Does it matter?

Laptop (I use it for school):

Spoiler

Surface book 2 13" with an i7 8650u, 8gb RAM, 256 GB storage, and a GTX 1050

And if you're curious (or a stalker) I have a Just Black Pixel 2 XL 64gb

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, DocSwag said:

Correct me if wrong but I believe Microsoft issued an emergency security patch yesterday.

They did but macOS fixed it in December

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

Just now, DrMacintosh said:

They did but macOS fixed it in December

My bad, I didn't read the post too closely.

Make sure to quote me or tag me when responding to me, or I might not know you replied! Examples:

 

Do this:

Quote

And make sure you do it by hitting the quote button at the bottom left of my post, and not the one inside the editor!

Or this:

@DocSwag

 

Buy whatever product is best for you, not what product is "best" for the market.

 

Interested in computer architecture? Still in middle or high school? P.M. me!

 

I love computer hardware and feel free to ask me anything about that (or phones). I especially like SSDs. But please do not ask me anything about Networking, programming, command line stuff, or any relatively hard software stuff. I know next to nothing about that.

 

Compooters:

Spoiler

Desktop:

Spoiler

CPU: i7 6700k, CPU Cooler: be quiet! Dark Rock Pro 3, Motherboard: MSI Z170a KRAIT GAMING, RAM: G.Skill Ripjaws 4 Series 4x4gb DDR4-2666 MHz, Storage: SanDisk SSD Plus 240gb + OCZ Vertex 180 480 GB + Western Digital Caviar Blue 1 TB 7200 RPM, Video Card: EVGA GTX 970 SSC, Case: Fractal Design Define S, Power Supply: Seasonic Focus+ Gold 650w Yay, Keyboard: Logitech G710+, Mouse: Logitech G502 Proteus Spectrum, Headphones: B&O H9i, Monitor: LG 29um67 (2560x1080 75hz freesync)

Home Server:

Spoiler

CPU: Pentium G4400, CPU Cooler: Stock, Motherboard: MSI h110l Pro Mini AC, RAM: Hyper X Fury DDR4 1x8gb 2133 MHz, Storage: PNY CS1311 120gb SSD + two Segate 4tb HDDs in RAID 1, Video Card: Does Intel Integrated Graphics count?, Case: Fractal Design Node 304, Power Supply: Seasonic 360w 80+ Gold, Keyboard+Mouse+Monitor: Does it matter?

Laptop (I use it for school):

Spoiler

Surface book 2 13" with an i7 8650u, 8gb RAM, 256 GB storage, and a GTX 1050

And if you're curious (or a stalker) I have a Just Black Pixel 2 XL 64gb

 

Link to comment
Share on other sites

Link to post
Share on other sites

19 minutes ago, Matu20 said:

Shit on Apple all you want, but their focus on single OS and product line has it's benefits.

Yeah you get a potential performance regression before anybody even had the chance to test that out.

 

Now lets hear folk say it doesn't matters because it wasn't that big deal this time.

-------

Current Rig

-------

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Misanthrope said:

Yeah you get a potential performance regression before anybody even had the chance to test that out.

 

Now lets hear folk say it doesn't matters because it wasn't that big deal this time.

?

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, Sauron said:

Interesting; did they somehow know about it in advance or did they unintentionally fixed part of the issue while adding a different feature? If they knew it already I wonder why they didn't tell Intel... it would be weird, I'm leaning towards the second case.

From what I could gather, one of the research firms told the relevant stakeholders in private. The nice thing to do as a white hat researcher is to tell the affected parties in private and give them time to fix the problem before going public with it. It's a compromise between making sure as few people as possible have an unfettered ability to exploit it and letting everyone know there's a problem.

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, M.Yurizaki said:

From what I could gather, one of the research firms told the relevant stakeholders in private. The nice thing to do as a white hat researcher is to tell the affected parties in private and give them time to fix the problem sell their shares before going public with it. It's a compromise between making sure as few people as possible have an unfettered ability to exploit it and letting everyone know there's a problem.

Here lemme fix that for ya.  hehe

Link to comment
Share on other sites

Link to post
Share on other sites

 

3 minutes ago, M.Yurizaki said:

I wasn't aware that the Linux Foundation was a publicly traded company.

They are not, I was generalizing...

Link to comment
Share on other sites

Link to post
Share on other sites

28 minutes ago, M.Yurizaki said:

From what I could gather, one of the research firms told the relevant stakeholders in private. The nice thing to do as a white hat researcher is to tell the affected parties in private and give them time to fix the problem before going public with it. It's a compromise between making sure as few people as possible have an unfettered ability to exploit it and letting everyone know there's a problem.

I know, but unless I misunderstood something I thought MS and the Linux foundation had only started working on it very recently. If that's not the case I wonder why they didn't wait for everyone to have a fix before making it public.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Sauron said:

I know, but unless I misunderstood something I thought MS and the Linux foundation had only started working on it very recently. If that's not the case I wonder why they didn't wait for everyone to have a fix before making it public.

The same reason Google said to Microsoft "You have 90 days to fix this before we go public with it."

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, M.Yurizaki said:

The same reason Google said to Microsoft "You have 90 days to fix this before we go public with it."

Fair enough I guess... then I wonder what's taking the others so long.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Sauron said:

Interesting; did they somehow know about it in advance or did they unintentionally fixed part of the issue while adding a different feature? If they knew it already I wonder why they didn't tell Intel... it would be weird, I'm leaning towards the second case.

 

Still, good news for mac users.

All the major companies involved all knew at the same time, insider preview build of Windows had the patch in Dec. Microsoft just has a lot more bases to cover and were also busy deploying the patch to the Azure platform and validation testing it. They and Google were fully patched before the news about it became public.

Link to comment
Share on other sites

Link to post
Share on other sites

If you want to split hairs about it (not like it really matters who had it 'first'), Microsoft had a KPTI in place back in November beginning with the Insider builds (17035).

 

So yeah, Meltdown has been mitigated in most OSes now. Spectre is the one people should actually worry about, since it can be exploited via Javascript in the web browser (though it's harder to exploit than Meltdown).

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Matu20 said:

Shit on Apple all you want, but their focus on single OS and product line has it's benefits.

Who knew patching and maintaining a system that you know 100% for sure what the system has in it is easy?

 

While windows has to make a patch that is compatible with millions of configurations....

Link to comment
Share on other sites

Link to post
Share on other sites

My question would be, is it only High Sierra (10.13) that received the patch, or did they roll it out to previous versions?  When we've been reinstalling on Macs at work lately, we've avoided HS because of several bugs in it.  If 10.12 (Sierra) doesn't get this patch, that's going to force us to install 10.13 or leave customer's computers vulnerable.

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, Sauron said:

Fair enough I guess... then I wonder what's taking the others so long.

Sheer volume of varience in end user systems.  Apple are only patching one OS (with a few variants), MS are patching 7, 8, 10, several different servers, embedded and probably even XP.   Who knows how much they have to do for each OS given they could be running any CPU from the last 15 years.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

They were bound to get something right with HS eventually.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

Maybe I should finally update from El Capitan. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×