Live data from Hacker News

About the security content of Security Update 2017-001

support.apple.com

21–30 of 158 posts

Re: About the security content of Security Update 2017-001

#21

Earlier quoted context omitted.

They force-pushed code to your box without you agreeing to this? Can anyone else confirm?

The update didn't auto-install for me. I suppose it only does that when "Install system data files and security updates" is enabled in System Preferences -> App Store.

right, for me neither. I can choose.

Re: About the security content of Security Update 2017-001

#22

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Original source of Buzzfeed article, if you'd like to avoid giving them traffic:

https://twitter.com/lemiorhan/status/935578694541770752

Demo: https://twitter.com/0xAmit/status/935607313368481793

Re: About the security content of Security Update 2017-001

#23
"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation."

I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password.

I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !password { createEmptySuper()}" line written by mistake.

Re: About the security content of Security Update 2017-001

#24

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

> We are auditing our development processes to help prevent this from happening again.

That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?

Re: About the security content of Security Update 2017-001

#25
post #19

Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??

From what i understood it's not a remote vulnerability until someone actually activates the "root user with empty password" locally using the vulnerability.

Re: About the security content of Security Update 2017-001

#26
post #23

"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…

That's kind of what it was: https://objective-see.com/blog/blog_0x24.html

Re: About the security content of Security Update 2017-001

#27
post #23

"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…

[deleted]

Re: About the security content of Security Update 2017-001

#28
post #23

"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…

[deleted]

Re: About the security content of Security Update 2017-001

#29
post #19

Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??

It's from any login prompt, and it gives root, so it's an elevation vulnerability that could be leveraged by a local or remote process with limited privileges to gain elevated privileges.

Re: About the security content of Security Update 2017-001

#30
post #25
post #19

Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??

From what i understood it's not a remote vulnerability until someone actually activates the "root user with empty password" locally using the vulnerability.

You could exploit it with remote desktop. If it's enabled on the client, you can just connect with root/no password.
Post reply on HN