Though it is "queer", it doesn't seem to be that much a security issue, or - more probably - I am failing to understand the risk implied. Can anyone describe a possible scenario where this would pose a security risk?
AppStore Preferences can be unlocked by a local admin with any bogus password
31–40 of 190 posts
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#32I have a feeling this isn't actually that High Sierra is that much worse, but more that people are now actively pen-testing macOS to find the next embarrassing bug. And that scares me even more because of the unknown of how long such bugs must've existed in the system. Is this Apple's Windows XP moment? (Like when MS stopped everything and did massive security training that resulted in XP SP 2 being worlds more secur…
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#33Earlier quoted context omitted.
> For certain features, they want you to reconfirm that the user presently at the keyboard is the real admin at the moment that you do it. If that's the case, no-one told the `sudo` command...
Sudo requires a password, so I’m confused. Do you mean the period of time before it requires entering creds again?
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#34This does not help at all for the drubbing that macOS High Sierra has been getting recently. Long term OS X users have been waiting for a Snow Leopard like release, but it seems like Apple isn’t taking as much care as required on security and stability on the Mac. Something has to give — either Apple’s organizational structure needs a change or Apple needs to abandon certain things completely instead of releasing sub…
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#35The interesting implication from this is that while it works for the App Store preferences, it doesn't work for the others, showing that there is a manual check that each pane is doing. Why aren't all of these calls identical? If each has to be handled manually, it's no wonder that there are bugs like this appearing.
If you try the same thing with say "Time & date prefs", it pauses with an incorrect password for a few seconds, then visually shakes indicating it's a wrong password. With the App Store prefs, it just instantly closes the authentication dialog, even with a blank password.
I don't really understand the logic as to why some panels in preferences have padlocks and others don't... Why does date/time need admin rights whereas Network (delete/add/reconfigure networking), Internet Accounts (delete/add any accounts?), iCloud (do all manner of things), Time Machine (back a machine up elsewhere?) don't require it?
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#36Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#37Though it is "queer", it doesn't seem to be that much a security issue, or - more probably - I am failing to understand the risk implied. Can anyone describe a possible scenario where this would pose a security risk?
A user with access to a mac could enable the option to automatically install macOS updates, which given recent trends, could impose a security risk.
How?
Installing a Mac OS update could be considered a security risk? That makes little sense since the security risks you're alluding to were solved by updates. 10.13.2 partially fixed the Intel problem in December and 10.13.3 will have more fixes. If you were still running 10.13.1, you'd have both the root login bug and the Intel security issues.
If you were still running Sierra, keeping Sierra updated results in solving the following security issues: https://support.apple.com/en-us/HT207483
The Mac OS version out right now is more secure than the previous minor or major version. There really isn't any credible evidence to the contrary.
It's irresponsible to not update your system. I understand not moving up to a new version of an OS because of compatibility issues (i.e. audio interfaces often are sluggish to update, libraries you need might not work, etc.,) but not updating because of security fears -- that's just ridiculous. 10.13.3 is more secure than 10.12.2.
Also, in order to "exploit" the reported bug, you would have to already be signed into the computer AS AN ADMIN. Which means that you could already change the updating behavior. So unless you are sharing your admin login/account with non admin users, the risk you cite is pretty trivial.
If you are in a higher risk computing environment, it would be logical that you would sign out of your account after you've finished using the system -- you would essentially have to provide an unauthorized person access to your Mac while you were signed in before this would be an actual threat. That doesn't make the bug less "real," but it does make the real-world security ramifications much less dire than being implied.
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#38Earlier quoted context omitted.
Sudo requires a password, so I’m confused. Do you mean the period of time before it requires entering creds again?
Yes, exactly. It requires a password, then doesn't require a password on subsequent attempts for a certain period of time.
Maybe you already saw this but I see they also made the same security/ease of use tradeoff for the (non-buggy) locks in the other preference panes. After unlocking, it stays unlocked for a period of time while you are in preferences, even if you visit different areas within preferences and come back.
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#39Earlier quoted context omitted.
A user with access to a mac could enable the option to automatically install macOS updates, which given recent trends, could impose a security risk.
> could impose a security risk How? Installing a Mac OS update could be considered a security risk? That makes little sense since the security risks you're alluding to were solved by updates. 10.13.2 partially fixed the Intel problem in December and 10.13.3 will have more fixes. If you were still running 10.13.1, you'd have both the root login bug and the Intel security issues. If you were still running Sierra, keepi…
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#40Earlier quoted context omitted.
Sudo requires a password, so I’m confused. Do you mean the period of time before it requires entering creds again?
Yes, exactly. It requires a password, then doesn't require a password on subsequent attempts for a certain period of time.
[0] https://askubuntu.com/questions/636092/how-to-get-sudo-to-pr...