Live data from Hacker News

macOS lock screen: “I just sent my session pass to my whole team”

twitter.com

161–170 of 276 posts

Re: macOS lock screen: “I just sent my session pass to my whole team”

#161
post #95
post #71

Earlier quoted context omitted.

Let's all sit and reflect for a moment that Apple was the first (and for a long time, the only) company that used to get sleep/wake "right".

what did other companies not get right?

Linux specifically has a horrible track record for sleep/battery management in laptops, and worse recovery. Windows used to be far more buggy, but the long XP era a lot of that was fixed by XP SP3.

Aside:

I just wish there was an option in Mac to use "PC Shortcuts" in all my apps... it's the only place where some of the key combinations feel truly alien in most apps. I use a "PC" keyboard, but remap CMD to CTRL, ALT to SUPER/WIN, and CTRL to ALT... but in the end, terminal is awkward, and some other shortcuts are hard.

May take the time to figure out how to get VSCode how I like it with the windows/linux shortcuts, but my key bindings.. find/replace are particularly awkward to remember, and usually resort to mouse menus.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#162
post #66
post #3

How about people stop releasing this sh*t on twitter?

What's the threat model here? That someone malicious with physical access to the computer somehow shifts focus to a program they know you have running such that, when you type your password, you send it to the malicious person. That's a very tenuous exploit, seeing as it relies on physical access and knowledge that the victim is already running a program which would hand the password to the attacker were the password…

You don't need physical access to the computer at all. All you need is to make your malware program steal focus the same way Slack does it and then you can have the users password for that computer.

It's good practice to always assume bugs aren't innocuous even if you can't think of a way to exploit it.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#163
post #100
post #31

Not to pile on, but my MBP (with "TouchBar" which will assuredly not exist in another year) is always in clamshell mode and connected to two external LG 4K displays. Whether, on which screen(s), or in what state the Mac wakes each morning is completely random. Sometimes it doesn't wake at all. Sometimes I have artifacts on one screen and a desktop on another screen. The sleep/wake sequence is a complete mess, and it…

Sleep / wake in this kind of setup has always been an issue with my 2013 rmbp. I'm not even on high Sierra. USB stuff doesn't wake up the computer. Opening the lid doesn't wake it up. Sometimes typing on the laptop itself doesn't work and it requires a hard reboot. It's been four years now and I've given up hope that Apple will ever get sleep / wake right. The reality is that Apple's software is absolute shit. OS X w…

my usb hub and/or keyboard and/or mouse will often not be working when trying to come out of sleep.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#164

So, Apple has the most available cash resource of any company out there (or at least close to). Yet, bugs galore, and strange product decisions. The obvious conclusion is that their management is failing to staff accordingly to the work that needs to be done. This could be because they are not aware that work needs to be done, which means engineers are not telling them, or that the management is not succeeding in hir…

I'm guessing that it's going to be pretty difficult to hire an engineer who is: - Very good - Wants to live near Palo Alto - Is able to live in the US - Wants to be subjected to Apple's privacy rules - Wants to work on fixing bugs instead of making new features In the software engineering game, money only goes so far.

I'm pretty sure you'd find a LOT of people to do that work for $300k/year... Apple has lots of money to go as far as they like.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#165
post #35

Earlier quoted context omitted.

Because of the short delay between waking the Mac and the display lighting up, I always either use spacebar or command key, or click the trackpad/mouse a couple times to wake. Return is a dangerous key!

I hit the shift key

Same here.. modifier keys are the safest to use.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#166
post #123

Earlier quoted context omitted.

No -- I don't know him personally -- but I would guess that he thinks it's a pile of amoral greed-heads and ignorant children.

amoral greed-heads and ignorant children. Basically HN is him when he worked for Netscape and he doesn't like the reminder...

Pretty much that, I reckon. He’s warned anyone who would listen not to work as hard as he did while at Netscape. But at the same time, he did win the startup lottery, so there’s that.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#167
post #136

FWIW this is a known security bug at Apple. I filed a bug about similar behavior where you can see the desktop briefly without logging in. Apple marked it as a duplicate. https://imgur.com/YxXtU2y Here are the steps to reproduce: - Start Mac - Login - Turn on Screen Lock: System Preferences > Security > General > Check "Require Password" and Select 5 Seconds. - Turn on Hot Corner Sleep Display: System Preferences > M…

Just FYI, this works on 10.10 (Mavericks).

Re: macOS lock screen: “I just sent my session pass to my whole team”

#168

These lock screen issues go back further than 10.13, I believe it was 10.10 or 10.11 my child was able to bypass the lock screen by mashing on the keyboard while the screensaver was fading out the login dialog. I witnessed it. I was not able to reproduce it in 10-15 minutes of testing. She did NOT type in the password. Just banging on the keyboard, playing with the screensaver.

I have a computer on 10.10. Has this issue.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#169
post #7
post #3

How about people stop releasing this sh*t on twitter?

Most people not in tech or infosec have never heard of and are totally uneducated about the concept of responsible disclosure. Maybe it needs to be added to high school computer class?

I've said it before and I'll say it again: You don't need to have heard of "responsible disclosure" to understand that publicly pointing out a bug before it's fixed can lead to people who did not previously know about the bug hearing about it and exploiting it maliciously. That just seems like common sense to me and (I'm willing to bet) many others.
Post reply on HN