About the security content of Security Update 2017-001
11–20 of 158 posts
Re: About the security content of Security Update 2017-001
#12Earlier today I set a root password. Can anyone confirm what the steps are to get back to the original state of a disabled root account with no password?
Re: About the security content of Security Update 2017-001
#13Re: About the security content of Security Update 2017-001
#14Earlier quoted context omitted.
It's a massive global security vulnerability with huge amounts of public exposure (so any malicious user is well aware they can take advantage). If they did, wouldn't be surprised and I'd be glad they did.
If they did for this, great. But the fact that they could for any other update, too, is what's scary.
Click AppleMenu > About this mac > System Report, and scroll down to Software > Installations, and click on the "Install Date" column header twice to sort by install date descending, and you will discover apple pushing updates very frequently for things like "MRTConfigData", "XProtectPlistConfigData", "Voice Update - Samantha", "Gatekeeper Configuration Data", "Chinese word list update" etc etc.
It's not without flaws; at least once they slipped up and pushed a blacklist for their own ethernet adapter driver (cutting off their own patch life-line, I guess, for those affected) : https://www.digitaltrends.com/computing/mac-update-breaks-et...
Re: About the security content of Security Update 2017-001
#15Re: About the security content of Security Update 2017-001
#16Kinda aggressive. I don't even clicked on update and they already did that for me.
Is it possible that "Automatically check for updates" and "Install system data files and security updates" are set in your system preferences? I have that enabled because this is exactly the kind of thing I want patched ASAP.
Re: About the security content of Security Update 2017-001
#17Kinda aggressive. I don't even clicked on update and they already did that for me.
They force-pushed code to your box without you agreeing to this? Can anyone else confirm?
”Q. Automatic Updates. The Apple Software will periodically check with Apple for updates to the Apple Software. If an update is available, the update may automatically download and install onto your computer and, if applicable, your peripheral devices. _By using the Apple Software, you agree that Apple may download and install automatic updates onto your computer and your peripheral devices_. You can turn off automatic updates altogether at any time by changing the automatic updates settings found within System Preferences.”
Re: About the security content of Security Update 2017-001
#18"Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS.
When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8:00 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.
We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again."
(posted to https://news.ycombinator.com/item?id=15808164 if separate discussion is preferred)
Re: About the security content of Security Update 2017-001
#19Re: About the security content of Security Update 2017-001
#20Earlier today I set a root password. Can anyone confirm what the steps are to get back to the original state of a disabled root account with no password?
Open Directory Utility.app, click the lock to make changes, then Edit -> Disable Root User.