Live data from Hacker News

Mac OS X Lion accepts any password when authenticating via LDAP

forums.macrumors.com

51–60 of 89 posts

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#51
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

This is how bullying works.

If the victim is small and accessible, with their reputation on the line, you can put them in their place.

When DropBox broke, the community pounced.

Apple can't be bullied.

With DropBox I can just cancel my membership and sign-up somewhere else.

I'm not going to throw out my $1000+ Mac with $1000+ in software on it out the Window, right along with my livelihood of creating software for iOS. I'm not going to cancel my iPhone contract and pay hundreds in penalties too, and throw out all my apps and games and switch to Android. Not happening.

They've got us by the balls here, we just have to let them fix this and move on.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#53
post #51
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

This is how bullying works. If the victim is small and accessible, with their reputation on the line, you can put them in their place. When DropBox broke, the community pounced. Apple can't be bullied. With DropBox I can just cancel my membership and sign-up somewhere else. I'm not going to throw out my $1000+ Mac with $1000+ in software on it out the Window, right along with my livelihood of creating software for iO…

It's not bullying to tell people to fix security bugs.

It's not bullying to use your own resources to entice (or force) them to do so in a timely manner.

You're right that no one can threaten Apple and get action, but you're wrong in characterizing the threat as bullying.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#54
post #39

What alarms me is that on both of my computers with Lion, about half of the time just clicking on a name on the login screen works without entering the password. Happens on my friend's Lion install as well.

There is an option "Require password after sleep or screen saver begins" in the Security preferences, general tab. I'll bet yours is set to something other than "immediately".

This happens after I explicitly log out of my user account, though.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#56
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

The dropbox bug only affected 100 people? Or it affected everyone but only 100 people logged in with it? That's a big difference.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#57
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

The dropbox bug only affected 100 people? Or it affected everyone but only 100 people logged in with it? That's a big difference.

"According to our records, there were fewer than a hundred affected users and neither account settings nor files were modified in any of these accounts."

http://blog.dropbox.com/?p=821

Everyone was vulnerable for 4 hours.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#59

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Being affected by 3 serious regressions in Lion (all filed as bugs and Apple closed them as duplicates, btw) - I get the feeling that Apple could do better at software engineering. (Alarms on iOS if you are still not convinced :) Just the fact that they release software that allows authentication without corre…

> Say what you will about Microsoft but in my several years of using Windows I rarely had these type of glaring issues even with the awful amount of hardware it supports.

I'm an ex-MS employee. One thing that really impressed me about my team at MS is the depth and quality of testing that was done. Unit tests, integration, fuzz, load, UI, regression, etc. All done in extreme depth, extremely efficiently, and across every supported SKU (and when you consider every possible OS, culture and .NET combinations out there, that's a lot)

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#60
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

The News.YC "community" is not homogenous. I find this just as odious as Dropbox's security issues, and just as indicative of a broken software development process.

Then again, it's Apple. I wouldn't normally even bother commenting here, because nobody from Apple cares. My finest rant would have epsilon impact on anyone at Apple, so why bother?

Dropbox, on the other hand, is present here. Someone might be able to convince them to change their practices for the better by getting on their case here.

That doesn't justify meanness, but a different response from this community over an issue from BigIvoryTowerCo versus OneOfOurOwn shouldn't be surprising.

Post reply on HN