Live data from Hacker News

About the security content of Security Update 2017-001

support.apple.com

91–100 of 158 posts

Re: About the security content of Security Update 2017-001

#91
post #85

Earlier quoted context omitted.

Where are all the unit/integration tests for the APIs that this damned button is calling? Hindsight being 20/20, but I cannot imagine not asserting that a newly created/re-enabled root user has a non-empty password.

Exactly, testing the UI may be hard, but whatever API that UI is calling is amazingly horribly broken.

And fascinatingly wasn’t broken until very recently...

Re: About the security content of Security Update 2017-001

#92

Earlier quoted context omitted.

Apple says "Not impacted: macOS Sierra 10.12.6 and earlier" in their security advisory for the patch.

My fear is that Apple doesn't know that it still affects El Capitan, though the poster I linked to could have just been lying.

I can't reproduce it on El Capitan. Doesn't prove others can't, but I'm pretty sure Apple would patch it on El Capitan too if the bug was that old - they issued other security patches less than a month ago.

Re: About the security content of Security Update 2017-001

#93

Earlier quoted context omitted.

Actually entering blank passwords and automated password entry should be Test Cases #0 and #1 for any thing that has a login. OS and other critical infrastructure vendors should go beyond that and explore the vast space to make sure nothing like this ever happens.

And I'm sure they've had privilege escalation vulns before and a workflow already in place for catching a lot of them. I mean, it's not like Apple's totally asleep at the wheel here. OSX may not be a front-burner project anymore, but they're still supporting it better than Microsoft manages to support Windows. But that's the nasty thing about InfoSec. It's a never-ending process. There's always realms you haven't con…

(I am not a developer, nor a sysadmin, but a casual programmer and intensive power user, and I get the instant bleah factor when I come across consumers or enterprises using it.)

I’m a longtime NeXT-then-MacOSX user with an experience in commercial UNICES ante-2000 and a predilection for Linux and DragonFlyBSD for my server needs. That said, I am gaining a begrudging respect for Microsoft. They make you pay for your nose, and their stuff looks and feels clunky, but the solidity and backwards-compatibility is utterly amazing.

Re: About the security content of Security Update 2017-001

#94
post #58

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Why is all communication from Apple on this case, both yesterday and today, being channeled via screenshots of text appended to random twitter users posts or blogs? It's weird that there's no official page on apple.com for these statements. (Beyond the actual "security update 2017-001" announcement webpage, which wasn't published until the patch was available)

> which wasn't published until the patch was available

answered your own question?

They knew the patch would be quick and was in progress, why bring extra attention to it. A few tech blogs and devs on twitter is good enough.

Re: About the security content of Security Update 2017-001

#95

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.

> worldwide computer vulnerability

hey, your preposition is auditing process is broken

Re: About the security content of Security Update 2017-001

#96
post #88

> it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra So uh... where are all those people who lost their mind about Windows 10 forcing updates? http://i2.kym-cdn.com/photos/images/newsfeed/001/042/619/4ea...

I realise that this is a facile topic for engendering scandal amongst our geek demographic (and rightly so), but given the gravity of the underlying issue it’s actually entirely reasonable and indeed preferable to the alternative scenario of N hundred million insouciant users lagging behind with a gaping security hole.

I don't disagree about the necessity of being able to force updates for bugs of this severity. I'm simply pointing out that, when Microsoft does forced updates, people lose their minds with outrage.

You could argue that severity plays a role in the level opposition to such a feature however severity is an arbitrary assessment applied by the person issuing the update.

> the alternative scenario of N hundred million insouciant users lagging behind with a gaping security hole.

Last I checked macOS hadn't crossed the 50 million user mark. The combined iOS/macOS user base only just surpasses Windows.

Re: About the security content of Security Update 2017-001

#97
post #79

Real problem is that if you are nobody then your private bug reports mean nothing. Only public shaming helps here. https://medium.com/@lemiorhan/the-story-behind-anyone-can-lo... Author of this tweet said that Apple was informed at least week before tweet, but zero response.

Lots of companies are quite good at handling security vulnerabilities, but somehow still neglect to reply to the original reporter.

Usually there's a long chain of people involved in creating tickets, allocating resources, finding the bug, fixing the bug, QA, release processes, documenting the problem, making security bulletins, translating security bulletins, etc.

Each of those people communicates via internal processes the reporter doesn't have access to, and none of them think to ping the original reporter saying 'yo - bugfix complete, qa next, then release'

Re: About the security content of Security Update 2017-001

#98
post #46

Does their patch also disable root accounts that were enabled using the exploit?

That last sentence [0] suggests that the patch will disable every single activated root account. [0] > If you require the root user account on your Mac, you will need to re-enable the root user and change the root user's password after this update.

Which could lock some users out permanently if the root user was the only user they knew the password to.

Re: About the security content of Security Update 2017-001

#99
post #90

Earlier quoted context omitted.

Where are all the unit/integration tests for the APIs that this damned button is calling? Hindsight being 20/20, but I cannot imagine not asserting that a newly created/re-enabled root user has a non-empty password.

Following and furthering your logic, what the hell could they have been doing in the codebase to revert a control mechanism that was effective up to and including 10.12.6, but unsafe as of 10.13.0 onwards???

A graceful upgrade mechanism towards a new password hashing algorithm.

Re: About the security content of Security Update 2017-001

#100
post #58

Earlier quoted context omitted.

Why is all communication from Apple on this case, both yesterday and today, being channeled via screenshots of text appended to random twitter users posts or blogs? It's weird that there's no official page on apple.com for these statements. (Beyond the actual "security update 2017-001" announcement webpage, which wasn't published until the patch was available)

> which wasn't published until the patch was available answered your own question? They knew the patch would be quick and was in progress, why bring extra attention to it. A few tech blogs and devs on twitter is good enough.

Exactly. They don't want this in the MSM and the MSM is usually a few days or even weeks behind the internet when it comes to things that aren't relocatable to the vast majority of people.
Post reply on HN