Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

141–150 of 193 posts

Re: OS X sudoers exploit found in the wild

#141

Earlier quoted context omitted.

> Here's just one difference: we can vote for the government. So what? Go ahead and tell me how and why that matters with regard to taxation itself. Again, if a mafia let you vote for the new mafia boss, would that make extortion alright? Would it be good to be bossed around by a mafia boss you voted for? Would getting elected make it alright for him to extort you? You do realize they're still taking your money by fo…

How do you intend to have money without a central bank? Should we all swap gold bars? What if I have a different view of the value of gold/bitcoin? Also, I'll play along if that's what you want. > You could just build a road and then ask people to pay for using it 1. I'm going to use your road and not pay. What are you going to do about it? 2. I don't believe you have rights to the land the road is on. How do you pro…

He’s one of the anarcho-capitalist hardcore bitcoin defenders that hang out in #bitcoin-assets, too.

Just ignore him, I wasted a week trying to talk to these kind of people, it’s of no use.

Re: OS X sudoers exploit found in the wild

#142

Earlier quoted context omitted.

> Here's just one difference: we can vote for the government. So what? Go ahead and tell me how and why that matters with regard to taxation itself. Again, if a mafia let you vote for the new mafia boss, would that make extortion alright? Would it be good to be bossed around by a mafia boss you voted for? Would getting elected make it alright for him to extort you? You do realize they're still taking your money by fo…

How do you intend to have money without a central bank? Should we all swap gold bars? What if I have a different view of the value of gold/bitcoin? Also, I'll play along if that's what you want. > You could just build a road and then ask people to pay for using it 1. I'm going to use your road and not pay. What are you going to do about it? 2. I don't believe you have rights to the land the road is on. How do you pro…

You didn't actually address any of my questions, so I'll just refrain from addressing yours.

Re: OS X sudoers exploit found in the wild

#143

Earlier quoted context omitted.

> You can't negotiate with the mafia, they do not represent your will and they offer no services. Oh, right. Kind of like how SOPA, PIPA, CISPA, TPP, TPPIP and so on ad infinitum represent your will? They know people don't want onerous legislation. That's why they make it behind closed doors. So much for "representation".

These laws and agreements in your list were heavily lobbied by big corporations including Apple. One of the main reasons why their influence on politics is so big is that they are undertaxed. Concentration of capital in the possession of one agent is bad because of positive feedback loop. This is why progressive taxation must be applied to corporations like it's applied to people. This is why government's budget must…

So you think big corporations control the government, but you want the government to tax them so hard that they won't have the money to control the government anymore?

Don't you think they'd bribe politicians not to tax them too hard?

Also, if you tax those hundreds-of-thousands-of-jobs-providing nasty corporations into the ground, lots of people will lose their jobs. How's that for the common good?

Re: OS X sudoers exploit found in the wild

#145
post #5
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

As a general rule, I don't use public wifi and council people to use VPN if they must. No flash, disable java in the browser, prefer chrome to safari, AdBlock and NoScript if you don't need JS.

I have removed Flash from my machines but using Chrome over Safari is like kissing your battery goodbye. It does not put the CPU to sleep properly for some tabs. It is sad.

Re: OS X sudoers exploit found in the wild

#146
post #37

Earlier quoted context omitted.

Just giving the benefit of the doubt here, a lot of the time it's unclear if your disclosure even made it to the right people in a company or not. No response is the norm for security disclosures, as is claims of "we didn't get this", even if you have a receipt for their ticketing system that says they did. I've sometimes spent far longer attempting to contact a company than doing research into something that seems t…

Stefan is not just some random guy on the Internet. I can assure you the relevant folks at Apple know him and most likely he knows them.

oh, well as long as you can assure us of that orthogonal point, I guess it's all good mr anonymous internet person

Re: OS X sudoers exploit found in the wild

#147
post #73

Earlier quoted context omitted.

I'm getting at the fact a shell script with this exploit can be made to look like an "app" and be "double-clickable", and doesn't require any code signing.

Gatekeeper also watches over shell scripts, so when you double click the shell script it will tell you that you can't open it because it is from an unidentified developer.

You're thinking of quarantine. You'll get a warning saying the script was downloaded from the Internet, asking if you're sure you want to open it. Again, nothing to do with code signing.

Re: OS X sudoers exploit found in the wild

#148

Earlier quoted context omitted.

> The logical next step is that Apple have been intermittently flippant about security (of late they have improved but their approach is still wholesale unacceptable). Why do users knowingly use an OS with this track record? Perhaps because ever since 2001 there are 5-6 new stories like this with huge scaremongering headlines and "sky is falling" implications, and then NOTHING absolutely happens, at worse a tiny mini…

> "sky is falling" implications, and then NOTHING absolutely happens Sure, just brush off a sudo vulnerability. > fight viruses off of Windows boxes Virus != vulnerability. Furthermore, while a rootkit is still a virus it's a long-shot from the relatively benign things running around on Windows machines (not that I mentioned Windows at first, but there ya' go - were on to that now). Just to avoid a Windows shitstorm,…

Viruses are not going to go poof unless your antivirus knows about them And in the typical case a vulnerability is a prerequisite for a virus.

But local vulns are only a concern if someone already has access to your system. In which case your usually fucked anyway. Which is why Apple introduced developer certs and gatekeeper.

Re: OS X sudoers exploit found in the wild

#149
post #91
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Eset now has security software for Mac. They were always my go to products on Windows.

There really is no good anti-virus software for Macs at the moment. Have a look at recent vulnerabilities in ESET and Sophos, for example:

http://googleprojectzero.blogspot.com/2015/06/analysis-and-e...

https://lock.cmpxchg8b.com/sophailv2.pdf

Re: OS X sudoers exploit found in the wild

#150
post #84

I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…

> I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. One party makes billions off their users, and will most likely continue their practice of not supporting 3 year old systems even if they are still in wide use for the next time. This should pretty much clear up who is worse. > Esser has his reasons - "Sh…

>> I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch.

> One party makes billions off their users, and will most likely continue their practice of not supporting 3 year old systems even if they are still in wide use for the next time. This should pretty much clear up who is worse.

I don't agree. I have a six year old Macbook. In those six years I've updated to a new OS about three or four times. One time it has cost me 20 euros, the others were free. Not only that, but updating is a breeze, it's painless and never was a problem. I never had to do a complete reinstall. My mother could have done this. It's clicking a few buttons and that's it.

On top of that, there is no serious degradation in speed. They claim it's even faster, but that probably isn't true for the older hardware. So even if they don't support their three year old OS, you can update your six year old system to the most current one without problem. They could have served these updates as minor ones, but that wouldn't be fun, nothing to show, no new names, no big shows.

Now tell me - what is it that they don't support?

Post reply on HN