Earlier quoted context omitted.
I would imagine it's because changing the system date/time could be used nefariously whereas iCloud, Internet Accounts, and Network would all require passwords for the individual accounts/networks to do anything with them.
Date time manipulation can be used to bypass expired certificates.
AppStore Preferences can be unlocked by a local admin with any bogus password
51–60 of 190 posts
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#52I'm on 10.12.6 and a local admin account, and it only unlocks to my actual password. That might mean it's a recently-introduced bug (assuming someone else can reproduce my result).
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#53This does not help at all for the drubbing that macOS High Sierra has been getting recently. Long term OS X users have been waiting for a Snow Leopard like release, but it seems like Apple isn’t taking as much care as required on security and stability on the Mac. Something has to give — either Apple’s organizational structure needs a change or Apple needs to abandon certain things completely instead of releasing sub…
The thing that I don't understand, as a developer, is how these types of bugs even make it in to these releases. Was the "lock" functionality in System Preferences changed at all in any meaningful way for the App Store panel. It doesn't seem like anything about that functionality is sufficiently different so how did this break? Did they bypass the check in order to work on the panel and forget to re-enable it or some…
QA and dev approach software with different mindsets, and I've noticed in Agile projects where QA is mostly or entirely missing, there is a skill gap.
Edit: People - I'm not trying to be flippant. I really have seen a decrease in quality in the transition to Agile. We use Scrum or Kanban where I work, and while overall the approach to estimation and the smaller scheduling and estimating increment is better, in many projects where I work there is no _separate_ QA group. A few project do retain it (though re-branded as "Performance, Stability, Reliability" - PSR) and it does help, but generally this PSR doesn't cover everything our old QA groups used to cover.
In any case, I have no insight in to what is happening inside Apple. I'm really just suggesting that given the prevalence of Agile methodologies these day, perhaps a non-ideal transition to Agile is a contributing factor to their quality issues.
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#54Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#55This does not help at all for the drubbing that macOS High Sierra has been getting recently. Long term OS X users have been waiting for a Snow Leopard like release, but it seems like Apple isn’t taking as much care as required on security and stability on the Mac. Something has to give — either Apple’s organizational structure needs a change or Apple needs to abandon certain things completely instead of releasing sub…
Edit: El Capitain doesn't have the padlock on that pane Other panes validate the password correctly
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#56The interesting implication from this is that while it works for the App Store preferences, it doesn't work for the others, showing that there is a manual check that each pane is doing. Why aren't all of these calls identical? If each has to be handled manually, it's no wonder that there are bugs like this appearing.
My guess is that the App Store preferences isn't even meant to have the padlock. iCloud prefs doesn't have it, so I can only assume it's there by mistake. If you try the same thing with say "Time & date prefs", it pauses with an incorrect password for a few seconds, then visually shakes indicating it's a wrong password. With the App Store prefs, it just instantly closes the authentication dialog, even with a blank pa…
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#57I have a feeling this isn't actually that High Sierra is that much worse, but more that people are now actively pen-testing macOS to find the next embarrassing bug. And that scares me even more because of the unknown of how long such bugs must've existed in the system. Is this Apple's Windows XP moment? (Like when MS stopped everything and did massive security training that resulted in XP SP 2 being worlds more secur…
Most of the recently discussed High Sierra bugs were not there on Sierra, while the features were there, like this one. So it's not that much pen tensting, but Apple making changes and not validating them correctly. Maybe they have their Vista moment with High Sierra, maybe we forgot previous buggy versions.
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#58Earlier quoted context omitted.
My guess is that the App Store preferences isn't even meant to have the padlock. iCloud prefs doesn't have it, so I can only assume it's there by mistake. If you try the same thing with say "Time & date prefs", it pauses with an incorrect password for a few seconds, then visually shakes indicating it's a wrong password. With the App Store prefs, it just instantly closes the authentication dialog, even with a blank pa…
Most OS's require admin rights to change the date/time because of the ability to mess with things like kerberos ticket TTL's, and other security issues.
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#59This does not help at all for the drubbing that macOS High Sierra has been getting recently. Long term OS X users have been waiting for a Snow Leopard like release, but it seems like Apple isn’t taking as much care as required on security and stability on the Mac. Something has to give — either Apple’s organizational structure needs a change or Apple needs to abandon certain things completely instead of releasing sub…
It's even worse than that according to[0] Mark Gurman[1]:
In another sign that the company has prioritized the iPhone, Apple re-organized its software engineering department so there's no longer a dedicated Mac operating system team. There is now just one team, and most of the engineers are iOS first, giving the people working on the iPhone and iPad more power.
[0] https://www.bloomberg.com/news/articles/2016-12-20/how-apple...
[1] https://www.recode.net/2016/6/1/11835514/bloomberg-mark-gurm...
Re: AppStore Preferences can be unlocked by a local admin with any bogus password
#60This does not help at all for the drubbing that macOS High Sierra has been getting recently. Long term OS X users have been waiting for a Snow Leopard like release, but it seems like Apple isn’t taking as much care as required on security and stability on the Mac. Something has to give — either Apple’s organizational structure needs a change or Apple needs to abandon certain things completely instead of releasing sub…
Snow leopard wasn’t all that till it got a few updates either