Live data from Hacker News

About the security content of Security Update 2017-001

support.apple.com

41–50 of 158 posts

Re: About the security content of Security Update 2017-001

#42
post #2

Kinda aggressive. I don't even clicked on update and they already did that for me.

They force-pushed code to your box without you agreeing to this? Can anyone else confirm?

They do have this capability, and have for years, although they rarely use it. They're force-pushing this update later today. It says so right in their statement:

"the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra"

Re: About the security content of Security Update 2017-001

#43

Earlier quoted context omitted.

It sound to me like the "development process" points to the whole soup-to-nuts system. From "brainstorming" and new feature development, to development, to testing, to QA, to deployment.

If so, that's going to be a big undertaking :)

Or a big lip service.

Re: About the security content of Security Update 2017-001

#44

Earlier quoted context omitted.

Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.

The ability to write is largely ignored at tech firms these days. Grammar is viewed as a bunch of stodgy rules to be ignored at will. Some are indeed silly throwbacks, but the basic structures are what allow us to communicate effectively. Drop them and errors in understanding creep into nearly every email. Yesterday I had a back-and-forth with a boss over "login", "log in", "log in to" and "log into". That might seem…

Surely:

    log into -> write to a specific log
    log in to -> access a certain host
no?

Re: About the security content of Security Update 2017-001

#45
post #4

Earlier quoted context omitted.

It's a massive global security vulnerability with huge amounts of public exposure (so any malicious user is well aware they can take advantage). If they did, wouldn't be surprised and I'd be glad they did.

If they did for this, great. But the fact that they could for any other update, too, is what's scary.

It's an option that this person enabled. Nothing scary.

Re: About the security content of Security Update 2017-001

#46

Does their patch also disable root accounts that were enabled using the exploit?

That last sentence [0] suggests that the patch will disable every single activated root account.

[0]

> If you require the root user account on your Mac, you will need to re-enable the root user and change the root user's password after this update.

Re: About the security content of Security Update 2017-001

#47

Earlier quoted context omitted.

Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.

The ability to write is largely ignored at tech firms these days. Grammar is viewed as a bunch of stodgy rules to be ignored at will. Some are indeed silly throwbacks, but the basic structures are what allow us to communicate effectively. Drop them and errors in understanding creep into nearly every email. Yesterday I had a back-and-forth with a boss over "login", "log in", "log in to" and "log into". That might seem…

[deleted]

Re: About the security content of Security Update 2017-001

#48

Does their patch also disable root accounts that were enabled using the exploit?

I just installed the patch on a system where I had logged into root with a blank to confirm the issue. Root login no longer works in the unlock dialog. I didn't try a more sophisticated test.

Re: About the security content of Security Update 2017-001

#49
post #36
post #19

Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??

I read that it worked even with Remote Management and Screen Sharing. https://twitter.com/voretaq7/status/935609138725425153

Which means that by default, a Mac would not by vulnerable remotely, but you'd only have to click one checkbox to become exposed remotely.

Re: About the security content of Security Update 2017-001

#50
post #12

Earlier quoted context omitted.

Open Directory Utility.app, click the lock to make changes, then Edit -> Disable Root User.

Ah, looks like it was automatically disabled again by the patch, so nothing to do.

That's interesting, it seems to have disabled mine as well, even on the computer that already had a root user enabled from before. I'd guess they can't distinguish between root accounts deliberately enabled by the user and accidentally enabled because of this bug. Fun stuff. No trouble for me, at least, I'm not even sure why I had it enabled in the first place.
Post reply on HN