{"id":31884,"date":"2021-03-15T16:24:07","date_gmt":"2021-03-15T20:24:07","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=31884"},"modified":"2023-10-25T09:34:11","modified_gmt":"2023-10-25T13:34:11","slug":"mac-software-updates-open-up-sshd","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/03\/15\/mac-software-updates-open-up-sshd\/","title":{"rendered":"Mac Software Updates Open Up sshd"},"content":{"rendered":"<p><a href=\"https:\/\/rachelbythebay.com\/w\/2021\/03\/10\/sealed\/\">Rachel Kroll<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=26418191\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/rachelbythebay.com\/w\/2021\/03\/10\/sealed\/\"><p>A couple of weeks ago, I read a\n<a href=\"https:\/\/eclecticlight.co\/2021\/02\/28\/last-week-on-my-mac-users-are-losing-out-against-big-surs-sealed-system\/\">post<\/a>\nabout how the &ldquo;sealed system&rdquo; on Big Sur was hurting people.  I kind of \nskimmed through it and figured it was mostly complaining about the \nsize of the download.  For whatever reason, that hadn&rsquo;t been a problem \nfor me and my machines, so I kind of wrote it off.<\/p><p>Last night, I applied the latest security patches to arrive at Big Sur version 11.2.3, and realized that I should have paid more attention to that thing. It explained something that I had been noticing for a while: my Apache config would keep reverting.<\/p><p>[&#8230;]<\/p><p>Why would it matter if the sshd config got reverted? Simple: it&rsquo;s because the stock Mac sshd install includes password-based auth, and that means someone can brute-force their way onto your machine if they can connect to it on port 22 for long enough.<\/p><\/blockquote>\n\n<p>I don&rsquo;t understand how this would be caused by the SSV, and there&rsquo;s a report that it&rsquo;s actually been happening <a href=\"https:\/\/news.ycombinator.com\/item?id=26295849\">since Catalina<\/a>. Big Sur updates are also <a href=\"https:\/\/mjtsai.com\/blog\/2021\/03\/08\/macos-11-2-3#macos-11-2-3-update-2021-03-14\">removing the command-line developer tools<\/a>, although this is also not due to the SSV, as far as I know.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/03\/15\/larger-and-slower-updates-with-big-sur\/\">Larger and Slower Updates With Big Sur<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/03\/09\/apple-platform-security-february-2021\/\">Apple Platform Security (February 2021)<\/a><\/li>\n<\/ul>\n\n<p id=\"mac-software-updates-open-up-sshd-update-2021-03-16\">Update (2021-03-16): <a href=\"https:\/\/twitter.com\/tjluoma\/status\/1371692296849260545\">TJ Luoma<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/tjluoma\/status\/1371692296849260545\">\n<p>This has been happening for a long time, and not just on Big Sur. Apple resets 1) sshd_config, 2) ssh_config, 3) the config file that speeds up Time Machine, and 4) the setting that allows you to use Touch ID for sudo auth.<\/p>\n<p>I now have scripts to re-apply those settings.<\/p>\n<p>Also, after every point-update, macOS asks me if I want to turn on Siri (a setting I&rsquo;ve never enabled on any Mac, ever&#8230;take a hint, Apple).<\/p>\n<p>I recently turned off Document &amp; Desktop sync via iCloud, and after a point-update, I was asked if I wanted to re-enable that too.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2016\/03\/16\/massively-speed-up-time-machine-backups\/\">Massively Speed Up Time Machine Backups<\/a><\/li>\n<\/ul>\n\n<p id=\"mac-software-updates-open-up-sshd-update-2023-10-25\">Update (2023-10-25): <a href=\"https:\/\/rachelbythebay.com\/w\/2021\/10\/27\/macssh\/\">Rachel Kroll<\/a>:<\/p>\n<blockquote cite=\"https:\/\/rachelbythebay.com\/w\/2021\/10\/27\/macssh\/\"><p>They&rsquo;ve changed the way the config works [in Monterey] to add a &ldquo;.d&rdquo; directory scheme which sets some defaults. There is now \/etc\/ssh\/sshd_config.d, and in it, 100-macos.conf.<\/p><p>Editing that file would likely get reverted upon the next patch (12.0.2?), so that&rsquo;s right out. You can&rsquo;t go past it with a higher number, since as the sshd_config points out, the <em>first<\/em> instance of a setting is kept, and subsequent instances of the same setting are ignored.<\/p><p>Instead, you have to get in front of them, and use a LOWER number. Try something like &ldquo;000-yourname.conf&rdquo;[&#8230;]<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Rachel Kroll (Hacker News): A couple of weeks ago, I read a post about how the &ldquo;sealed system&rdquo; on Big Sur was hurting people. I kind of skimmed through it and figured it was mostly complaining about the size of the download. For whatever reason, that hadn&rsquo;t been a problem for me and my machines, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-03-15T20:24:10Z","apple_news_api_id":"8518dd94-4067-408f-8984-eb45d79747f4","apple_news_api_modified_at":"2023-10-25T13:34:14Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABA==","apple_news_api_share_url":"https:\/\/apple.news\/AhRjdlEBnQI-JhOtF15dH9A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[544,131,30,1891,2077,48,2087,506,216],"class_list":["post-31884","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apache","tag-bug","tag-mac","tag-macos-11-0","tag-macos-12","tag-security","tag-software-update","tag-ssh","tag-timemachine"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=31884"}],"version-history":[{"count":4,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31884\/revisions"}],"predecessor-version":[{"id":40888,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31884\/revisions\/40888"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=31884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=31884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=31884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}