Earlier quoted context omitted.
Where are all the unit/integration tests for the APIs that this damned button is calling? Hindsight being 20/20, but I cannot imagine not asserting that a newly created/re-enabled root user has a non-empty password.
Exactly, testing the UI may be hard, but whatever API that UI is calling is amazingly horribly broken.
About the security content of Security Update 2017-001
91–100 of 158 posts
Re: About the security content of Security Update 2017-001
#92Earlier quoted context omitted.
Apple says "Not impacted: macOS Sierra 10.12.6 and earlier" in their security advisory for the patch.
My fear is that Apple doesn't know that it still affects El Capitan, though the poster I linked to could have just been lying.
Re: About the security content of Security Update 2017-001
#93Earlier quoted context omitted.
Actually entering blank passwords and automated password entry should be Test Cases #0 and #1 for any thing that has a login. OS and other critical infrastructure vendors should go beyond that and explore the vast space to make sure nothing like this ever happens.
And I'm sure they've had privilege escalation vulns before and a workflow already in place for catching a lot of them. I mean, it's not like Apple's totally asleep at the wheel here. OSX may not be a front-burner project anymore, but they're still supporting it better than Microsoft manages to support Windows. But that's the nasty thing about InfoSec. It's a never-ending process. There's always realms you haven't con…
I’m a longtime NeXT-then-MacOSX user with an experience in commercial UNICES ante-2000 and a predilection for Linux and DragonFlyBSD for my server needs. That said, I am gaining a begrudging respect for Microsoft. They make you pay for your nose, and their stuff looks and feels clunky, but the solidity and backwards-compatibility is utterly amazing.
Re: About the security content of Security Update 2017-001
#94See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
Why is all communication from Apple on this case, both yesterday and today, being channeled via screenshots of text appended to random twitter users posts or blogs? It's weird that there's no official page on apple.com for these statements. (Beyond the actual "security update 2017-001" announcement webpage, which wasn't published until the patch was available)
answered your own question?
They knew the patch would be quick and was in progress, why bring extra attention to it. A few tech blogs and devs on twitter is good enough.
Re: About the security content of Security Update 2017-001
#95See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…
Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.
hey, your preposition is auditing process is broken
Re: About the security content of Security Update 2017-001
#96> it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra So uh... where are all those people who lost their mind about Windows 10 forcing updates? http://i2.kym-cdn.com/photos/images/newsfeed/001/042/619/4ea...
I realise that this is a facile topic for engendering scandal amongst our geek demographic (and rightly so), but given the gravity of the underlying issue it’s actually entirely reasonable and indeed preferable to the alternative scenario of N hundred million insouciant users lagging behind with a gaping security hole.
You could argue that severity plays a role in the level opposition to such a feature however severity is an arbitrary assessment applied by the person issuing the update.
> the alternative scenario of N hundred million insouciant users lagging behind with a gaping security hole.
Last I checked macOS hadn't crossed the 50 million user mark. The combined iOS/macOS user base only just surpasses Windows.
Re: About the security content of Security Update 2017-001
#97Real problem is that if you are nobody then your private bug reports mean nothing. Only public shaming helps here. https://medium.com/@lemiorhan/the-story-behind-anyone-can-lo... Author of this tweet said that Apple was informed at least week before tweet, but zero response.
Usually there's a long chain of people involved in creating tickets, allocating resources, finding the bug, fixing the bug, QA, release processes, documenting the problem, making security bulletins, translating security bulletins, etc.
Each of those people communicates via internal processes the reporter doesn't have access to, and none of them think to ping the original reporter saying 'yo - bugfix complete, qa next, then release'
Re: About the security content of Security Update 2017-001
#98Does their patch also disable root accounts that were enabled using the exploit?
That last sentence [0] suggests that the patch will disable every single activated root account. [0] > If you require the root user account on your Mac, you will need to re-enable the root user and change the root user's password after this update.
Re: About the security content of Security Update 2017-001
#99Earlier quoted context omitted.
Where are all the unit/integration tests for the APIs that this damned button is calling? Hindsight being 20/20, but I cannot imagine not asserting that a newly created/re-enabled root user has a non-empty password.
Following and furthering your logic, what the hell could they have been doing in the codebase to revert a control mechanism that was effective up to and including 10.12.6, but unsafe as of 10.13.0 onwards???
Re: About the security content of Security Update 2017-001
#100Earlier quoted context omitted.
Why is all communication from Apple on this case, both yesterday and today, being channeled via screenshots of text appended to random twitter users posts or blogs? It's weird that there's no official page on apple.com for these statements. (Beyond the actual "security update 2017-001" announcement webpage, which wasn't published until the patch was available)
> which wasn't published until the patch was available answered your own question? They knew the patch would be quick and was in progress, why bring extra attention to it. A few tech blogs and devs on twitter is good enough.