https://eclecticlight.co/2022/11/06/last-week-on-my-mac-home-truths-about-macos/ Skip to content [eclecticlight] The Eclectic Light Company Macs, painting, and more Main navigation Menu * Downloads * M1 & M2 Macs * Mac Problems * Mac articles * Art * Macs * Painting hoakley November 6, 2022 Macs, Technology Last Week on My Mac: Home truths about macOS Deciding whether and when to upgrade macOS is one of the more difficult choices we face. If your Mac isn't capable of running the current release of macOS, or you're dependent on key hardware or software which is incompatible, then the decision is made for you. For most of us, though, there's nothing really holding us back except our own decision, which should be informed by facts rather than false hopes or assumptions. Let me question some common perceptions. Apple supports macOS for three years For several years, I've been searching for the document in which Apple might have stated this common assumption, and so far I have been unable to find it. Just over a year ago, I examined this in detail, concluding that "over a period of eight years, Apple has followed what most believe to be its policy on macOS support: major versions enjoy full support for the year that they are the current release, then receive approximately two years of security updates." To bring this up to date I have analysed the Monterey cycle, between its release in October 2021 and that of Ventura last month. Over that period of exactly a year, Apple released non-security updates for Monterey only, with a single exception: on 9 June, one severe bug affecting the opening of mail attachments was fixed in Big Sur 11.6.7, an extremely unusual event. All support for Catalina ceased on 20 July, with Security Update 2022-005, and Monterey's last non-security bug fixes were released that same day in 12.6. By the time that the new version of macOS is released in the autumn/ fall, the previous version typically hasn't had any fixes to bugs that don't affect security vulnerabilities for at least two months, making its period of full support less than ten months. Apple's security updates are sufficient When the current version of macOS loses its general support, and starts its two years of security-only fixes, there are still many bugs left in it, which are only likely to be fixed in the new version. Those residual bugs are often severe: El Capitan continued to cause many Macs to grind to a halt through its entire cycle, the cause not being addressed until Sierra. Sierra in turn was abandoned with a serious bug in its backup scheduling system that caused automatic backups to fail completely after a few days, and that was only fixed in High Sierra. More recently, Monterey initially suffered from three serious memory leaks, of which two were fixed early, but the third has only just been addressed in Ventura. What I've not seen considered by anyone are updates to APFS. For the year that it's supported, each version of macOS gets a new version of APFS with each minor update, and sometimes in intermediate security patches too. Apple hardly ever mentions bugs or fixes to APFS, but some known problems have come and gone, only in the latest version of macOS, of course. We have no idea what bugs in old versions of APFS are known to Apple, nor of their consequences. Just at the moment, though, I'm concerned that I've heard of a few users whose APFS Encrypted external disks have suddenly become unusable; as most have been storing Time Machine backups, those users have lost all their backups. APFS is but one example of a critical sub-system that loses all support once Apple releases a new version of macOS. Apple hasn't provided detailed lists of more significant bugs fixed in updates for many years now, but does provide itemised release notes for fixes addressing identified security vulnerabilities. Many of us had suspected that, during those two security-only maintenance years, older macOS didn't get all the fixes it could have. I wrote that those security updates "address many of the more significant vulnerabilities which are found in it". That was examined in detail a year ago by Joshua Long, who concluded on Intego's Mac Security Blog that "unless you're running the very latest major version of macOS (now macOS Monterey), Apple's updates provide only selective fixes along with a false sense of security." Most recently, Apple has confirmed this: "Because of dependency on architecture and system changes to any current version of macOS (for example, macOS 13), not all known security issues are addressed in previous versions (for example, macOS 12)." (Oddly, that latest revision may not appear yet on all localised versions of that guide, including the UK version.) This is visible when you simply count the number of vulnerabilities fixed according to Apple's release notes. SecUpd2122 Over the 2021-22 cycle, the current version of macOS, Monterey, received a total of 342 security updates, Big Sur only 202, and Catalina just 146. The graph above shows how those three versions diverged over that time. Monterey started with an advantage, in arriving with all the fixes accomplished during its development. Its overall gradient is greater than either Big Sur or Catalina, and towards the end of the cycle their rate of fixes slowed, in Catalina to flatline after July, when it was abandoned altogether. This will soon be amplified by Ventura's new Rapid Security Response, which will deliver smaller security patches several weeks before they're likely to be incorporated into full macOS updates. Those Macs upgraded to Ventura will thus be patched long before those still running Monterey or Big Sur even stand a chance of those being incorporated into their next security update. New versions of macOS are full of bugs macOS is vast, and I don't think anyone can hazard a guess at how many identified bugs might exist in any version. What is more feasible is discovering whether there are any serious bugs, such as those causing kernel panics, major memory leaks, etc., that many users are likely to encounter. Although the risk of those is likely to be highest in the first version of any release cycle, they can be introduced in any update after that. One of the most serious and frequently encountered in recent years appeared in Catalina 10.15.6, for instance. One factor that makes recent memory an unreliable indicator is the series of changes to macOS to prepare for Apple silicon Macs. Those started in earnest with High Sierra and the introduction of APFS, continued in Catalina with the loss of 32-bit support and the new Boot Volume Group, followed by Big Sur's signed and sealed system volume (SSV). In contrast, upgrades from Big Sur to Monterey, and from Monterey to Ventura, have generally been far less traumatic. Indeed, with the new mechanism for updating and the demonstrable integrity of the SSV, those versions enjoy more reliable updates and robust System volumes. At least malfunction is now likely to be a bug rather than the result of damage to the system. It's safer to delay upgrading Much as I respect Andrew Cunningham in Ars Technica, I question his conclusion that "most people running an up-to-date Big Sur or Monterey installation with an up-to-date Safari browser should be safe from most high-priority threats, especially if you also keep the other apps on your Mac updated." Even if security threats were the only concern, this begs the question as to how to tell whether you are among those "most people", and the only threats you'll ever encounter are among the "most high-priority threats" that you should be safe from. It's a similar argument to that concerning vaccination of younger people against Covid or other generally non-fatal conditions. Most people under the age of 70 who are in reasonably good health should be safe from serious or prolonged illness or death. But the only way to tell whether you are most people is in retrospect. Mark Josh Long's words: "macOS Mojave is -- and presumably always will be -- vulnerable to the "FORCEDENTRY" bug that has been actively exploited by the Pegasus spyware." What other actively exploited bugs are Big Sur and Monterey now vulnerable to? What bugs remain in their old versions of APFS, Time Machine, or anything else in the system that could result in data loss? Making these decisions is always a gamble. Although I well understand you might feel more reassured by waiting a couple of weeks to ensure there are no showstoppers that might make upgrading unwise, delaying beyond the first update brings ever-increasing risk. That's no longer a risk I'm prepared to take: I put my production Mac where my mouth is, and upgraded it to Ventura on the day of its release, followed rapidly by my other Macs. Share this: * Twitter * Facebook * Reddit * Pinterest * Email * Print * Like this: Like Loading... Related Posted in Macs, Technology and tagged APFS, Apple, macOS, macOS 13, security, update, Ventura. Bookmark the permalink. 8Comments Add yours 1. 1 [070d89fa6e75] Tim R on November 6, 2022 at 10:23 am Reply The worst part of Apple leaving macOS versions as "broken" for lack of a better word is that some machines simply won't get the next macOS. One would certainly hope Apple would change course on unfixed flaws in the final revision of a major release, but they've been doing that for so long that it's very unlikely. As for Time Machine backups being lost, between that and Time Machine being extremely long in the tooth I've moved everything except my Library folder off of Time Machine and onto NAS-syncing that I can then backup from there. The initial Monterey Time Machine bug got me interested in other solutions, and it turns out that they're generally better (if not faster) than Time Machine for most types of files (small files such as those in the Library folder being an exception). LikeLiked by 2 people + 2 [6986a746f627] hoakley on November 6, 2022 at 9:58 pm Reply Thank you. Time Machine is no longer long in the tooth: the current version is totally different when making backups to APFS volumes. It makes extensive use of snapshots, and the backups don't use hard links at all, but create a series of synthetic snapshots. I have several articles here explaining those differences. I'm astonished that you find TM backups to a NAS better and faster - having conducted tests with a range of NAS systems, I can assure you that they're considerably slower, and using sparse bundles they're also more liable to problems and failure. Three of my Macs back up using TM to local SSDs; when I had the chance to keep a NAS of my choice, I was only too happy to let it pass. Howard. LikeLike 2. 3 [ec859d707747] Sab Gigo on November 6, 2022 at 3:44 pm Reply Thank you, Howard, for a most informative article. I have always been an early adopter of macOS updates, and occasionally have been bitten by a serious bug. I always have a current backup that I can use to return to a previous and healthier state, for which the time and effort to accomplish is not usually excessive. Tim R makes a valid point, and so I have used OpenCore Legacy Patcher to bring my Mac mini 2014 up-to-date with Ventura using this incredible software package -- thank you, Dortania! I had not heard or encountered the "...APFS Encrypted external disks have suddenly become unusable..." issue, but because of the chance of this, or other hardware failure, I maintain multiple backups of my systems on different drives and NAS volumes, including Carbon Copy Cloner data volume backups (but not clones anymore). As a physician, I could not agree with you more regarding medical conditions like Covid, having lost a close associate at an age much younger than what was anticipated -- "An ounce of prevention..." seems to apply equally to the health of people and computer systems. Thank you for your learned observations and other work; your contributions are without compare. LikeLiked by 1 person + 4 [6986a746f627] hoakley on November 6, 2022 at 10:01 pm Reply Thank you. I don't think the problem with APFS Encrypted is at all common, but I have heard of several cases just recently which make me concerned, as it's something that should never happen. Howard. LikeLike 3. 5 [8d53fc15eb97] Simon on November 6, 2022 at 4:56 pm Reply I think the wait-a-few-weeks strategy at this point is a given since regular users can avoid a lot of suffering (few would argue Apple's QC/QA has improved the last few years) without incurring notable risk -- assuming most users are not multi-billion-$ CEOs or revolutionary leaders and as such the type to have state-sponsored intelligence agencies actively trying to hack them (and yes there's all the ransomware BS that affects regular people, but when was the last time that affected Macs due to an exploit Apple had allowed before patching? -there's no patch against social engineering). I also realize nobody can broadly encourage the wait-a-few-weeks strategy because ultimately, if everybody waits a couple weeks then the waiting won't fulfill its purpose (let the early adopters get bitten so Apple is forced to either release a fix or face public humiliation and ideally both). But on a longer time scale, I suppose the question rather boils down to *psychology*: do I prefer to live with the bugs and risks I'm not aware of, or do I want to take my chances with known pitfalls. I suspect many users who see their computers more like a tool than a hobby are starting to side with the former ("never touch a running system"). They know there's risk, but as long as you don't get bitten (and you haven't gotten bitten so far) why take any chances? Apple's software lately has been perceived (not saying it's actually the case) as ridden with bugs, unwelcome changes, undocumented adjustments etc. Why would you take your chances with any of that? At the end of the day, macOS exploits in the wild are rare and have known to affect only few people, usually celebs or activists. Most people are neither. But let's instead assume we want to put easy/careless behind us and instead decide to really be smart and not take any chances. We'll try to stay as current as we can: after waiting 2-3 weeks to make sure there's no serious bugs and similar, we do go ahead and stringently update. But what strategies exist for hedging our bet? Things like downgrading to prior snapshots, restoring previous backups ("clones" [that are no longer truly clones] or TM backups), maintaining older installers, repositories to older app versions, etc. I'd personally like to hear more about that because my hunch is, the experts at the end of the day will come down on the side of "always keep up with Apple's updates" and going against that mantra will become more and more untenable. OTOH going along with that will at times also come with pain and suffering. The question is what insurance, fallback strategies, and coping mechanisms people can prepare to minimize the brunt of it when that keeping-up strategy does end up biting you big time. This site has had many articles dealing with those strategies. Thank you. I look forward to reading many more. LikeLiked by 1 person + 6 [6986a746f627] hoakley on November 6, 2022 at 10:05 pm Reply Thank you. Ventura was released two weeks ago. I've been using it on my M1 MacBook Pro since it was first released to developers in June. I have yet to discover anything sinister about it, and as I've recorded here, have been discovering longstanding bugs which it fixes. Upgrading now to Ventura is hardly throwing caution to the winds. Howard. LikeLike 4. 7 [3bf90edf88f4] Blivit on November 6, 2022 at 8:29 pm Reply All that being said above, I have been 'doing Macs' for 37 years now, and Macs have been getting better and the OS's getting better with every release. Maybe a few small bumps along the way, but I remember when backing up was almost ALWAYS a disaster, even with CCC. I haven't worried about crashes or backups in YEARS, and that includes iOS too. So, I'm extremely happy about the current 'state-of-the-art' and I will never look back. LikeLiked by 1 person + 8 [6986a746f627] hoakley on November 6, 2022 at 10:07 pm Reply Thank you. I started with Macs in 1989, and concur. Howard. LikeLike Leave a Reply Cancel reply Enter your comment here... [ ] Fill in your details below or click an icon to log in: * * * * Gravatar Email (required) (Address never made public) [ ] Name (required) [ ] Website [ ] WordPress.com Logo You are commenting using your WordPress.com account. ( Log Out / Change ) Twitter picture You are commenting using your Twitter account. ( Log Out / Change ) Facebook photo You are commenting using your Facebook account. ( Log Out / Change ) Cancel Connecting to %s [ ] Notify me of new comments via email. [ ] Notify me of new posts via email. [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] This site uses Akismet to reduce spam. Learn how your comment data is processed. Quick Links * Downloads * Mac Troubleshooting Summary * M1 & M2 Macs * Mac problem-solving * Painting topics * Painting * Long Reads Search Search for: [ ] [Search] Monthly archives * November 2022 (15) * October 2022 (76) * September 2022 (72) * August 2022 (75) * July 2022 (76) * June 2022 (73) * May 2022 (76) * April 2022 (71) * March 2022 (77) * February 2022 (68) * January 2022 (77) * December 2021 (75) * November 2021 (72) * October 2021 (75) * September 2021 (76) * August 2021 (75) * July 2021 (75) * June 2021 (71) * May 2021 (80) * April 2021 (79) * March 2021 (77) * February 2021 (75) * January 2021 (75) * December 2020 (77) * November 2020 (84) * October 2020 (81) * September 2020 (79) * August 2020 (103) * July 2020 (81) * June 2020 (78) * May 2020 (78) * April 2020 (81) * March 2020 (86) * February 2020 (77) * January 2020 (86) * December 2019 (82) * November 2019 (74) * October 2019 (89) * September 2019 (80) * August 2019 (91) * July 2019 (95) * June 2019 (88) * May 2019 (91) * April 2019 (79) * March 2019 (78) * February 2019 (71) * January 2019 (69) * December 2018 (79) * November 2018 (71) * October 2018 (78) * September 2018 (76) * August 2018 (78) * July 2018 (76) * June 2018 (77) * May 2018 (71) * April 2018 (67) * March 2018 (73) * February 2018 (67) * January 2018 (83) * December 2017 (94) * November 2017 (73) * October 2017 (86) * September 2017 (92) * August 2017 (69) * July 2017 (81) * June 2017 (76) * May 2017 (90) * April 2017 (76) * March 2017 (79) * February 2017 (65) * January 2017 (76) * December 2016 (75) * November 2016 (68) * October 2016 (76) * September 2016 (78) * August 2016 (70) * July 2016 (74) * June 2016 (66) * May 2016 (71) * April 2016 (67) * March 2016 (71) * February 2016 (68) * January 2016 (90) * December 2015 (96) * November 2015 (103) * October 2015 (119) * September 2015 (115) * August 2015 (117) * July 2015 (117) * June 2015 (105) * May 2015 (111) * April 2015 (119) * March 2015 (69) * February 2015 (54) * January 2015 (39) Tags APFS Apple AppleScript Apple silicon backup Big Sur Blake bug Catalina Consolation Console Cezanne diagnosis Disk Utility Dore El Capitan extended attributes Finder firmware Gatekeeper Gerome HFS+ High Sierra history history of painting iCloud Impressionism iOS landscape LockRattler log logs M1 Mac Mac history macOS macOS 10.12 macOS 10.13 macOS 10.14 macOS 10.15 macOS 11 macOS 12 malware Metamorphoses Mojave Monet Monterey Moreau MRT myth narrative OS X Ovid painting Pissarro Poussin privacy realism riddle Rubens Sargent scripting security Sierra SilentKnight SSD Swift symbolism Time Machine Turner update upgrade xattr Xcode XProtect Statistics * 13,047,035 hits Blog at WordPress.com. Footer navigation * About & Contact * Macs * Painting * Language * Tech * Life * General * Downloads * Mac problem-solving * Extended attributes (xattrs) * Painting topics * Hieronymus Bosch * English language * LockRattler: 10.12 Sierra * LockRattler: 10.13 High Sierra * LockRattler: 10.11 El Capitan * Updates: El Capitan * Updates: Sierra, High Sierra, Mojave, Catalina, Big Sur * LockRattler: 10.14 Mojave * SilentKnight, silnite, LockRattler, SystHist & Scrub * DelightEd & Podofyllin * xattred, Metamer, Sandstrip & xattr tools * 32-bitCheck & ArchiChect * T2M2, Ulbow, Consolation and log utilities * Cirrus & Bailiff * Taccy, Signet, Precize, Alifix, UTIutility, Sparsity, alisma * Revisionist & DeepTools * Text Utilities: Nalaprop, Dystextia and others * PDF * Keychains & Permissions * LockRattler: 10.15 Catalina * Updates * Spundle, Cormorant, Stibium, Dintch, Fintch and cintch * Long Reads * Mac Troubleshooting Summary * LockRattler: 11.0 Big Sur * M1 & M2 Macs * Mints: a multifunction utility * LockRattler: 12.x Monterey * VisualLookUpTest * Virtualisation on Apple silicon * LockRattler: 13.x Ventura Secondary navigation * Search Post navigation Fools and jesters in paintings Painting the Ship of Fools Search for: [ ] [Search] Begin typing your search above and press return to search. Press Esc to cancel. * Follow Following + [croppe] The Eclectic Light Company Join 3,040 other followers [ ] Sign me up + Already have a WordPress.com account? Log in now. * + [croppe] The Eclectic Light Company + Customize + Follow Following + Sign up + Log in + Copy shortlink + Report this content + View post in Reader + Manage subscriptions + Collapse this bar Loading Comments... Write a Comment... [ ] Email (Required) [ ] Name (Required) [ ] Website [ ] [Post Comment] %d bloggers like this: [b]