Weekly News Summary for Admins — 2023-05-05

WWDC starts in one month. Do you feel that you and macOS Ventura are ready for the next version of macOS?

This week Apple published the first Rapid Security Response (RSR) for macOS, iOS, and iPadOS. Even though RSRs were tested during the beta phase, there were some hiccups. Overall, the actual release seems to have gone as planned by Apple.

The reception in the MacAdmins community was… not enthusiastic.

The support article for the RSR contains no information on which software or CVEs was patched and the Apple security updates page has no entry for the RSR either. It is not unprecedented or even unusual for security documentation to be published or amended after the release of updates. Since the point of RSRs is to be released quickly, there might still be embargoes in place, CVEs might not even exist, or documentation simply takes second priority. We should expect to see documentation with the release of the macOS 13.4 and iOS 16.5 updates, which will include the issues fixed in the RSR. (It would be nice if Apple pointed out which were fixed in the RSR.)

Because they can be removed, RSRs introduce a new “extra” addition to the version number. This one is 13.3.1 (a). Even though RSRs were announced at WWDC and could be tested during the beta phase, not all management systems, security and monitoring tools are ready to gather the information. Even when your tools are ready, most admins have not yet adjusted or even prepared their workflows for this new piece of information.

There are also (of course) some issues with the management of RSRs. Configuration profiles and MDM commands don’t quite work as advertised. Tools that exist to work around the many shortcomings of the software update workflow will need to be adapted to incorporate RSRs

For a change, Apple announced this well ahead of time. But then, why are (some) MacAdmins still reacting with so much frustration?

I believe, there was some expectation that RSRs might be a fix, or at least a bandaid, for macOS software update. It was implied they wouldn’t require reboots, but most will. You cannot update directly from an older version of macOS to the RSR version, so a user may need two successive installations and reboots to get ‘fully patched.’

Instead of replacing (security) updates, it now looks as if RSRs will happen in addition to the traditional update cycle, increasing the number of updates users and admins have to manage.

RSRs do not solve any of the multitude of issues prevalent with software update. Whether that hope was overly optimistic, misguided, or misinformed, MacAdmins were hoping for some relief with managing software updates. Instead, we are now are facing yet another thing to manage; more and new workflows to build, fix, and adapt.

The burden was increased, rather than reduced. The lack of detailed information, even though it has good reasons, obscures their benefit. We can’t even tell why we have to do this, except for a nebulous “trust us, this is important!”

At Apple, the rollout of RSRs might justifiably be considered a success. They solve a problem they had internally that kept them from responding swiftly to security issues. RSRs improve the overall security of the platforms, which is something Apple obviously and correctly cares about. You have to appreciate that.

This mismatch in the requirements and expectations from the MacAdmins community and Apple isn’t new and there will always be friction here. Nevertheless, Apple needs to directly address the issues with software update in a way that does not increase the workload of users and MacAdmins.

Maybe at WWDC? (ever the optimist)

