Live data from Hacker News

About the security content of Security Update 2017-001

support.apple.com

131–140 of 158 posts

Re: About the security content of Security Update 2017-001

#131
Not to be confused with the other 2017-001 update they released one month ago: https://support.apple.com/en-gb/HT208221

The App Store Updates page on my mum's Macbook Air now shows that she has installed two updates called "Security Update 2017-001", and she started to worry that she didn't have the correct update installed today.

They both link to the same page (https://support.apple.com/en-gb/HT201222), so it took me a while to figure out what was going on, and that she really had installed two distinct security patches (one before upgrading to High Sierra, one after).

Re: About the security content of Security Update 2017-001

#132

Apparently this forced update breaks file-sharing(!): https://forums.macrumors.com/threads/security-update-2017-00... (SMB still works)

NFS is still working for me. I thought "file sharing" was SMB. AFP is deprecated. What other kind of file sharing is there?

I think they're talking about AFP, which is still in use in a lot of places (you can't share ADFS over AFP, but you can connect to/share non-ADFS disks)

Re: About the security content of Security Update 2017-001

#133
post #124

Earlier quoted context omitted.

Which could lock some users out permanently if the root user was the only user they knew the password to.

It's impossible to have full-disk encryption with that config, right? (i.e., does FileVault work for the root user?) If you can get in from an install CD, you can reset passwords as needed. If I were writing this patch, I'd probably check to see if the root user's password was indeed blank, but given that use of the root account only is extremely unsupported I cannot get too upset about Apple breaking that use case a…

The issue wasn’t actually specific to a blank password. You could try to log in as root using any password, and as long as root had never had a password set, it would fail but set root’s password to whatever you entered.

Re: About the security content of Security Update 2017-001

#134
post #127

Earlier quoted context omitted.

I don't know how you could expect QA to be able to have a rigorous process to catch security problems of this type. It's one thing to audit the strength of crypto protocols, quite another to rigorously test every conceivable attack surface for privilege escalation. That space is vast.

I worked on mobile games few years back. Our tester always did everything that was sane and most things that were not sane. For every version. He tried to break the game. He was randomly and wildly tapping the screen. He was repeatedly going through menus. The most things he did us developers thought: who would do that? We caught lots of bugs this way. It was a company that you never heard of. It's a normal thing for…

Do you realize for all the unexpected bugs your manual tester caught, an equal number were simply never found?

Re: About the security content of Security Update 2017-001

#135

Earlier quoted context omitted.

Apple still allows users to control their system's update behavior. "Install system data files and security updates" is turned on by default in the App Store Control panel, but the user can turn it off if they (unwisely) wish to. In Windows XP, for example, Windows Update had a similar option, but that was removed in Windows 10.

AIUI the expectation is that Apple is going to force all 10.13.1 machines to automatically upgrade themselves regardless of settings. This is something they've apparently done once before, with an ntpd remote vulnerability. Given the nature of this bug, forcing all machines to automatically apply this patch seems like the right move. (BTW the patch doesn't require restarting the machine, so it's not going to interrup…

No, the poster you replied to is correct. If you turn that setting off you will not automatically get this update.

Re: About the security content of Security Update 2017-001

#136
post #58

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Why is all communication from Apple on this case, both yesterday and today, being channeled via screenshots of text appended to random twitter users posts or blogs? It's weird that there's no official page on apple.com for these statements. (Beyond the actual "security update 2017-001" announcement webpage, which wasn't published until the patch was available)

Apple's answer is on that page:

"For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available."

Re: About the security content of Security Update 2017-001

#137
post #23

"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…

> I hope they won't stop to this brief summary

Why Gets You Root: https://objective-see.com/blog/blog_0x24.html

Re: About the security content of Security Update 2017-001

#138
post #58

Earlier quoted context omitted.

Why is all communication from Apple on this case, both yesterday and today, being channeled via screenshots of text appended to random twitter users posts or blogs? It's weird that there's no official page on apple.com for these statements. (Beyond the actual "security update 2017-001" announcement webpage, which wasn't published until the patch was available)

Apple's answer is on that page: "For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available."

I'd say that works against the purpose of protecting customers. Every blackhat in the world had probably heard about it last night, but if Apple had announced details earlier, even without a patch, informed customers could take preventive action (such as not connecting to public wifi, disabling screen sharing, etc).

Re: About the security content of Security Update 2017-001

#139

Earlier quoted context omitted.

People weren't upset about windows installing security updates. If this update adds nagware to OSX or forces people to restart their computer in the middle of whatever they are working on, your comment will be a fair point. Until then, it is an stupid comparison.

As of the latest update macOS has started to nag me to allow automatic updates, so I think the comparison is probably valid. FWIW I told it No, for the same reason my Win10 laptop has been nagging me to update but I've not let it install for a month - until I've finished whatever work I'm doing I'm not going to let a possibly badly written patch stack the OS and leave me rebuilding the machine from scratch (yes - I'm…

Oh geez. Have you ever tried to skip iCloud setup? Or Cloud Keychain? Or two factor authentication?

It's like trying to leave a time share presentation.

Re: About the security content of Security Update 2017-001

#140
post #127

Earlier quoted context omitted.

I worked on mobile games few years back. Our tester always did everything that was sane and most things that were not sane. For every version. He tried to break the game. He was randomly and wildly tapping the screen. He was repeatedly going through menus. The most things he did us developers thought: who would do that? We caught lots of bugs this way. It was a company that you never heard of. It's a normal thing for…

Do you realize for all the unexpected bugs your manual tester caught, an equal number were simply never found?

No one said that you can't do automatic tests. Manual tests do not exclude automatic tests. But I dare to say that manual tests are essential, because that's how the software will really be used. Especially for release candidates. Apple has resources to do both repeatedly.

In this big corporation I mentioned tests were also done automatically. A device receives via infrared programmed set of commands in a loop for 24h. The test simulates a user with a remote.

Even so called gravitational tests are useful. A test where "only" gravitation acts on a device for 24h.

Those may seem dumb, but bugs can be hunted this way, that no automatic test could find. Because real hardware and release environment is messy.

Post reply on HN