Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

121–130 of 193 posts

Re: OS X sudoers exploit found in the wild

#121

Earlier quoted context omitted.

> helping out a company that takes part in the usual tax and labor law evasion tactics Irrelevant. The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour, not about helping Apple itself. Just because Apple does it (by sitting on the problem) does not make it right for other people to put the public at risk as well. Both parties can be in the wrong at the same time, t…

> The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record? > anonymously informing the controlling party With government surveillance could he have…

> Why do users knowingly use an OS with this track record?

Knowingly might be a stretch there. Many don't know any better either through lack of education on such matters or deliberate ignorance.

> The real villain here is the European Commission for such a brain-dead policy.

I'd argue that this means there are three villains, rather than the bad law being the one and only problem!

Re: OS X sudoers exploit found in the wild

#122
post #55

Earlier quoted context omitted.

> Stefan Esser for flinging the vulnerability into the breeze for anyone to catch Then let me help you with this one. The former is responsibility of the worlds most profit corporation with tens of thousands of employees, and the latter is under the responsibility of a random guy on the internet.

Both are in the wrong. The behaviour of neither is a valid defence for the behaviour of the other. Apple are irresponsible for not addressing the issue in good time (they have known about it for long enough). This fellow is irresponsible for not following decent "responsible disclosure" procedure. He released information of a serious exploitable problem without first making any attempt to inform the people who could…

You can pin responsibility onto a huge corporation. They can be liable for it. But you cannot control the behavior of random people on the internet without seriously impinging upon the general freedom of people everywhere. So the question of liability and responsibility is irrelevant if placed upon a random individual (unless you want a police state). It's best to hold the huge corporation liable.

Re: OS X sudoers exploit found in the wild

#123
post #64

Earlier quoted context omitted.

I think you put far too much trust in one of thousands of clone VPN services. There's no reputation to taint, there's stock standard scripts running on commodity VPS boxes they rented from somewhere else. I would be shocked if at least some of the most commonly used ones weren't run by people looking to sniff credentials. You're paying to pipe all of your sensitive information through some random persons box, which i…

Oh, wait. Were you suggesting VPNing into your home connection or similar instead?

you should trust your end points. assuming you trust the machine you are using, the other end of the tunnel should be just as trustworthy. that's great if you trust a company; but what incentive do you have to trust them?

Re: OS X sudoers exploit found in the wild

#124

Earlier quoted context omitted.

I'm saying taxation is extortion, and just as immoral as when a mafia does it. You're trying to justify extortion with things that are built with extorted money, but could be built without extorting people too. > You can't just ask some to pay for the road and the rest not to use it. You could just build a road and then ask people to pay for using it, much like you can build an iPhone and ask people to pay for one if…

> I'm saying taxation is extortion, and just as immoral as when a mafia does it. This is a ridiculous comment. I realise the social contract has broken down somewhat in recent years but if you can't see the difference between Mafia extortion and government taxation there's something wrong. Here's just one difference: we can vote for the government.

> Here's just one difference: we can vote for the government.

So what? Go ahead and tell me how and why that matters with regard to taxation itself.

Again, if a mafia let you vote for the new mafia boss, would that make extortion alright? Would it be good to be bossed around by a mafia boss you voted for? Would getting elected make it alright for him to extort you?

You do realize they're still taking your money by force, don't you? What difference does it make that you drop a piece of paper into a box once every few years?

Re: OS X sudoers exploit found in the wild

#125

Earlier quoted context omitted.

I'm saying taxation is extortion, and just as immoral as when a mafia does it. You're trying to justify extortion with things that are built with extorted money, but could be built without extorting people too. > You can't just ask some to pay for the road and the rest not to use it. You could just build a road and then ask people to pay for using it, much like you can build an iPhone and ask people to pay for one if…

And the police? Fire departments? Social security? Town planning/maintenance/social policy/etc etc etc. Essentially the only system without tax is anarchy, and if you are bona fide advocating that - well I wish you the best of luck in your brave new world.

> And the police? Fire departments? Social security?

I know, it's like.. how could supermarkets sell you ice-cream without 330 million people getting extorted?! It's ridiculous!

Re: OS X sudoers exploit found in the wild

#126

Earlier quoted context omitted.

Spurious reasoning. You can't negotiate with the mafia, they do not represent your will and they offer no services. If you want to argue that governments do none of these things, then by all means do so via the democratic process. If you want to argue that the mafia DOES, my cousin Vinny would like to meet you for a coffee.

> You can't negotiate with the mafia, they do not represent your will and they offer no services. Oh, right. Kind of like how SOPA, PIPA, CISPA, TPP, TPPIP and so on ad infinitum represent your will? They know people don't want onerous legislation. That's why they make it behind closed doors. So much for "representation".

These laws and agreements in your list were heavily lobbied by big corporations including Apple. One of the main reasons why their influence on politics is so big is that they are undertaxed.

Concentration of capital in the possession of one agent is bad because of positive feedback loop. This is why progressive taxation must be applied to corporations like it's applied to people. This is why government's budget must be balanced.

Re: OS X sudoers exploit found in the wild

#127

Earlier quoted context omitted.

> helping out a company that takes part in the usual tax and labor law evasion tactics Irrelevant. The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour, not about helping Apple itself. Just because Apple does it (by sitting on the problem) does not make it right for other people to put the public at risk as well. Both parties can be in the wrong at the same time, t…

> The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record? > anonymously informing the controlling party With government surveillance could he have…

>The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record?

Perhaps because ever since 2001 there are 5-6 new stories like this with huge scaremongering headlines and "sky is falling" implications, and then NOTHING absolutely happens, at worse a tiny miniscule of OS X boxes are ever affected, and there are absolutely no implications for 99.9% of users. In the meantime, Apple, even if slow to respond to stuff like this, does improve OS X security infrastructure steadily.

Meanwhile, in the same real world, people have to constantly fight viruses off of Windows boxes (slightly better after 8, but still a real concern).

Btw, no it's not just about "small market share" either. Mac OS had even smaller market share in the late 90s (even 1/10 as small as OSX), but it still had lots of malware and viruses people caught.

Re: OS X sudoers exploit found in the wild

#128
Would it make sense for the kernel to use a fresh, empty environment when executing a setuid binary?

Or perhaps a fresh environment with a few of the most important variables sanitised and copied over? And perhaps with the old variables available with a prefix (_UNPRIVILEGED_DYLD_PRINT_TO_FILE etc)?

What would this break?

Re: OS X sudoers exploit found in the wild

#129
post #128

Would it make sense for the kernel to use a fresh, empty environment when executing a setuid binary? Or perhaps a fresh environment with a few of the most important variables sanitised and copied over? And perhaps with the old variables available with a prefix (_UNPRIVILEGED_DYLD_PRINT_TO_FILE etc)? What would this break?

The kext at https://github.com/sektioneins/SUIDGuard does something like that. For privileged processes, it neuters DYLD_* variables completely.

Re: OS X sudoers exploit found in the wild

#130
post #128

Would it make sense for the kernel to use a fresh, empty environment when executing a setuid binary? Or perhaps a fresh environment with a few of the most important variables sanitised and copied over? And perhaps with the old variables available with a prefix (_UNPRIVILEGED_DYLD_PRINT_TO_FILE etc)? What would this break?

[deleted]
Post reply on HN