"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…
About the security content of Security Update 2017-001
31–40 of 158 posts
Re: About the security content of Security Update 2017-001
#32Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??
I've seen rumors otherwise, but until someone with experience verifies those pathways I can only guess.
Re: About the security content of Security Update 2017-001
#33See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
> We are auditing our development processes to help prevent this from happening again. That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?
From "brainstorming" and new feature development, to development, to testing, to QA, to deployment.
Re: About the security content of Security Update 2017-001
#34See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
Re: About the security content of Security Update 2017-001
#35Re: About the security content of Security Update 2017-001
#36Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??
Re: About the security content of Security Update 2017-001
#37Earlier quoted context omitted.
> We are auditing our development processes to help prevent this from happening again. That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?
It sound to me like the "development process" points to the whole soup-to-nuts system. From "brainstorming" and new feature development, to development, to testing, to QA, to deployment.
Re: About the security content of Security Update 2017-001
#38Re: About the security content of Security Update 2017-001
#39See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.
Yesterday I had a back-and-forth with a boss over "login", "log in", "log in to" and "log into". That might seem silly but little things really do matter. (fyi, login = noun. Log in = verb. We never settled on 'into' or 'in to'.)
Re: About the security content of Security Update 2017-001
#40See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.