Earlier quoted context omitted.
They force-pushed code to your box without you agreeing to this? Can anyone else confirm?
The update didn't auto-install for me. I suppose it only does that when "Install system data files and security updates" is enabled in System Preferences -> App Store.
About the security content of Security Update 2017-001
21–30 of 158 posts
Re: About the security content of Security Update 2017-001
#22See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
Re: About the security content of Security Update 2017-001
#23I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password.
I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !password { createEmptySuper()}" line written by mistake.
Re: About the security content of Security Update 2017-001
#24See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?
Re: About the security content of Security Update 2017-001
#25Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??
Re: About the security content of Security Update 2017-001
#26"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…
Re: About the security content of Security Update 2017-001
#27"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…
Re: About the security content of Security Update 2017-001
#28"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…
Re: About the security content of Security Update 2017-001
#29Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??
Re: About the security content of Security Update 2017-001
#30Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??
From what i understood it's not a remote vulnerability until someone actually activates the "root user with empty password" locally using the vulnerability.