Live data from Hacker News

AppStore Preferences can be unlocked by a local admin with any bogus password

openradar.appspot.com

21–30 of 190 posts

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#21

sorry if this is a dumb question, but: why is it unreasonable for a local admin to have the power to change AppStore preferences? without knowing much about the osx security model, this sounds like not a big deal?

I don't believe it is, necessarily. The issue is that doing this action requires the admin to re-enter their credentials.

In this case, any credentials work, meaning that if a "guest" user (semi-trusted by the account owner, obviously using the owner's credentials. ) were attempting to change these settings, they could bypass the prompt with a bogus password instead of the alternative which requires the guest to ask the owner to enter their password.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#22
post #8

I'm on 10.12.6 and a local admin account, and it only unlocks to my actual password. That might mean it's a recently-introduced bug (assuming someone else can reproduce my result).

It doesn't reproduce for me on 10.12.6 either. It only works on High Sierra (10.13).

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#24

sorry if this is a dumb question, but: why is it unreasonable for a local admin to have the power to change AppStore preferences? without knowing much about the osx security model, this sounds like not a big deal?

For certain features, they want you to reconfirm that the user presently at the keyboard is the real admin at the moment that you do it. This prevents a situation where the actual admin logs in, their attention is taken away from the computer, and someone sits at their chair and does awful things with the computer.

> For certain features, they want you to reconfirm that the user presently at the keyboard is the real admin at the moment that you do it.

If that's the case, no-one told the `sudo` command...

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#26

sorry if this is a dumb question, but: why is it unreasonable for a local admin to have the power to change AppStore preferences? without knowing much about the osx security model, this sounds like not a big deal?

You have the power, but the system would like to check that it is actually you and not a malicious script. It is the compromise between running as non-admin and running sudo for ever friggin’ thing and running wide open to the world as admin.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#28
post #8

I'm on 10.12.6 and a local admin account, and it only unlocks to my actual password. That might mean it's a recently-introduced bug (assuming someone else can reproduce my result).

yea, it says 10.13.2. I can't reproduce it on 10.13.1.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#29
post #8

I'm on 10.12.6 and a local admin account, and it only unlocks to my actual password. That might mean it's a recently-introduced bug (assuming someone else can reproduce my result).

It doesn't reproduce for me on 10.12.6 either. It only works on High Sierra (10.13).

I can't reproduce it on 10.13.3 Beta (17D29a). So it might have been fixed already.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#30

Earlier quoted context omitted.

For certain features, they want you to reconfirm that the user presently at the keyboard is the real admin at the moment that you do it. This prevents a situation where the actual admin logs in, their attention is taken away from the computer, and someone sits at their chair and does awful things with the computer.

> For certain features, they want you to reconfirm that the user presently at the keyboard is the real admin at the moment that you do it. If that's the case, no-one told the `sudo` command...

Sudo requires a password, so I’m confused. Do you mean the period of time before it requires entering creds again?
Post reply on HN