Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Is it true there's NO sec. upd. vs. Shellshock virus for SL?

Sorry, but if this is true then I have little time to waste for either getting back offline or (apparently) upgrading as noted below. I've intentionally been staying offline for several weeks - waiting for a security update from Apple.


Today, I spoke over the phone to an employee at an Apple Store. He said that there is a sec. upd. for the new malware/virus which reportedly can penetrate Mac OSX, but that it's only good for Lion, Mountain Lion & Mavericks. Therefore, I must assume that Apple is forcing SL users to either upgrade or swim in the 'shark infested internet of things'.


So the bottom line is (apparently) that Mac is leaving it's Snow Leopard users unsupported on this? If this is true, then it's an EPIC FAIL for a good # of users who still use SL.


My best wishes to all of the other faithful Snow Leopard users who are left to fend for themselves.


Thanks in Advance

~mm


MacArthur's Park is melting in the dark

All the sweet green icing flowing down

Someone left the cake out it the rain

I don't think that I can take it

Cause it took so long to bake it

And I'll never have that recipe again

Oh noooooooo

~ Sung by Richard Harris on the 1968 album 'A Tramp Shining'

iMac (20-inch Early 2008), Mac OS X (10.6.8), iTunes 11.3.1

Posted on Oct 14, 2014 5:29 PM

Reply
17 replies

Oct 14, 2014 6:03 PM in response to Michael Murphy3

Michael Murphy3 wrote:


...

MacArthur's Park is melting in the dark

All the sweet green icing flowing down

Someone left the cake out it the rain

I don't think that I can take it

Cause it took so long to bake it

And I'll never have that recipe again

Oh noooooooo

~ Sung by Richard Harris on the 1968 album 'A Tramp Shining'

Nice song written by James Layne Webb "Jimmy Webb"😉.

Oct 14, 2014 6:34 PM in response to Michael Murphy3

Are you running a web server?


Re: Shellshock


I still have an external partition with a bootable Snow Leopard; however, I no longer expect support as it was discontinued more than 3 years ago, so one can't expect support indefinitely. Some companies cease support as soon as a new version is introduced - well, there was Lion, Mountain Lion, Mavericks, and the soon to be released Yosemite and Apple issued updates for about 2+ years. That's pretty good.

Oct 14, 2014 8:06 PM in response to Michael Murphy3

There have not been any Security updates (other than XProtect updates) for Snow Leopard for over a year now, so it's not a big surprise that they aren't offering a bash update. They have not pushed this update to users of any newer OS's, so they certainly must feel that it isn't necessarily required for all users and to quote an Apple source here:

The vast majority of OS X users are not at risk to recently reported bash vulnerabilities," an Apple spokesperson told iMore. "Bash, a UNIX command shell and language included in OS X, has a weakness that could allow unauthorized users to remotely gain control of vulnerable systems. With OS X, systems are safe by default and not exposed to remote exploits of bash unless users configure advanced UNIX services.

Oct 15, 2014 4:25 PM in response to babowa

Thank you so, so much Babowa 🙂


No, I don't run a web server, I just love my Snow Leopard 😍 and so I will do whatever it takes to keep it purring.


The link that you posted looks quite promising!


Yes, as you say that is pretty good - all things considered.


I guess it just boils down to my responsibility to do as much due diligence as it takes; that I may come to understand (more comprehensively than I do right now) the seemingly daunting technical complexities that currently have me in such a quandary.


Nonetheless, I thank you and all of your compatriots here at the ASC for your thoughtful and elegant guidance.


Peace Out (for now)

~mm

Oct 15, 2014 4:58 PM in response to Matt Clifton

Thanks for getting back to me Matt.


Please pardon my naiveté; but what about the proverbial 'ten thousand' websites that are out there in cyberspace. Wouldn't landing on a shellshock compromised site be somewhat or potentially akin to something like a man-in-the-middle attack or a cross site scripting attack?


Best Regards

~mm


'ten thousand' things was popularized by Lao-tzu in his seminal work, Tao-te-Ching

Oct 15, 2014 5:06 PM in response to Michael Murphy3

Michael Murphy3 wrote:


You mean that if I were running - let's say Mountain Lion, that when I run a Software Update check, that the bash-shell/shellshock security update is Not offered to the typical desktop user?

Exactly. It is not offered to any user, typical desktop or otherwise. It is only available by downloading and installing it manually using the correct URL for the Lion, Mountain Lion or Mavericks Update.

Oct 15, 2014 5:13 PM in response to Michael Murphy3

Not Matt, but as long as I'm here.


Installing the Bash Update on your Mac will do nothing to protect you against a compromised web site that has the vulnerability. Bash would run on the server only, not on your Mac and the only rumored vector back to your computer might be associated with a DHCP server, not a web site. As to that rumor, this is what Apple is quoted as saying about it on Saturday:

The issue that remains, while it raises interesting questions, is not a security issue in and of itself.

We'll all just have to wait and see how that one goes.

Is it true there's NO sec. upd. vs. Shellshock virus for SL?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.