> You are sneering at Apple, and yet there's a Linux snafu published...
Hardly the same level of borkage.. RTFA on the regresshion bug you linked - it's inherently rate-limited with an incredibly low chance of success - so no "proof of concept" beyond a denial of service, because it would take forever to successfully run remote code. Very few are affected anyway, since it doesn't affect older distros, and newer ones had already patched by the time the article went out.
> Despite the regreSSHion bug, Qualys had nothing but positive things to say about the OpenSSH project, saying that the discovery is "one slip-up in an otherwise near-flawless implementation."
> "Its defense-in-depth design and code are a model and an inspiration, and we thank OpenSSH's developers for their exemplary work," it added.
Whereas this CocoaPods thing seems to be a very, very severe security flaw which had apparently gone unnoticed by Crapple for years.
So why, in two separate posts, are you saying "but but.. Linux has a security flaw too!!"
Desperate to defend your cult membership?
Not to mention of course.. OpenSSH isn't even Linux! It's just OpenSSH and it runs on lots of platforms. It's no doubt running right now on your beloved cackbook.