Live data from Hacker News

Mac OS X Lion accepts any password when authenticating via LDAP

forums.macrumors.com

71–80 of 89 posts

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#71

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Being affected by 3 serious regressions in Lion (all filed as bugs and Apple closed them as duplicates, btw) - I get the feeling that Apple could do better at software engineering. (Alarms on iOS if you are still not convinced :) Just the fact that they release software that allows authentication without corre…

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Yep, I agree. I've been very disappointed with Lion, even taking into account the common "Don't buy an x.0 Apple product", there were some terrible bugs (I was personally bitten by the inability to look up DNS servers after waking from sleep, which I can't believe was missed in testing). Apple's software quali…

Apple's software quality has been markedly going down

People have said the same thing about nearly every OS X release (with the possible exception of 10.1). At least Lion doesn't erase your firewire hard drives [1], or delete your entire home folder [2] etc etc. The comparative severity of these really bad bugs can be debated, but I think in terms of general quality OS X 10.0 − 10.2 really were quite a lot worse than the more recent releases.

I don't disagree with your general point though, the Mac is obviously not their priority anymore, and hasn't been for a while.

[1] http://www.wired.com/gadgets/mac/news/2003/10/61031

[2] http://macs.about.com/b/2009/10/13/snow-leopard-may-delete-u...

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#72

Earlier quoted context omitted.

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Yep, I agree. I've been very disappointed with Lion, even taking into account the common "Don't buy an x.0 Apple product", there were some terrible bugs (I was personally bitten by the inability to look up DNS servers after waking from sleep, which I can't believe was missed in testing). Apple's software quali…

Apple's software quality has been markedly going down People have said the same thing about nearly every OS X release (with the possible exception of 10.1). At least Lion doesn't erase your firewire hard drives [1], or delete your entire home folder [2] etc etc. The comparative severity of these really bad bugs can be debated, but I think in terms of general quality OS X 10.0 − 10.2 really were quite a lot worse than…

Yeah, this is true. Those ones were pretty bad.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#73
post #39

Earlier quoted context omitted.

There is an option "Require password after sleep or screen saver begins" in the Security preferences, general tab. I'll bet yours is set to something other than "immediately".

This happens after I explicitly log out of my user account, though.

Apologies, I totally missed the phrase "login screen" in your post.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#74

Earlier quoted context omitted.

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Yep, I agree. I've been very disappointed with Lion, even taking into account the common "Don't buy an x.0 Apple product", there were some terrible bugs (I was personally bitten by the inability to look up DNS servers after waking from sleep, which I can't believe was missed in testing). Apple's software quali…

Apple's software quality has been markedly going down People have said the same thing about nearly every OS X release (with the possible exception of 10.1). At least Lion doesn't erase your firewire hard drives [1], or delete your entire home folder [2] etc etc. The comparative severity of these really bad bugs can be debated, but I think in terms of general quality OS X 10.0 − 10.2 really were quite a lot worse than…

Possible, but having gone from 8.6->Linux->10.4 myself, I think it's worth noting that 10.6, their previous release, was without question one of the most solid, stable, usable desktop OSes ever released by anyone. 10.7's instability and rough edges seem extraordinarily out of place by comparison.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#75
post #46

Earlier quoted context omitted.

It wasn't your bug to find, it was Apple's , and they should have found it far sooner.

Who are you talking to? Me? Did you read the comment thread? I'm not sure who you're arguing with, or why you picked me for this reply.

Yeah, you're right, I misposted. Sorry.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#76
post #74

Earlier quoted context omitted.

Apple's software quality has been markedly going down People have said the same thing about nearly every OS X release (with the possible exception of 10.1). At least Lion doesn't erase your firewire hard drives [1], or delete your entire home folder [2] etc etc. The comparative severity of these really bad bugs can be debated, but I think in terms of general quality OS X 10.0 − 10.2 really were quite a lot worse than…

Possible, but having gone from 8.6->Linux->10.4 myself, I think it's worth noting that 10.6, their previous release, was without question one of the most solid, stable, usable desktop OSes ever released by anyone. 10.7's instability and rough edges seem extraordinarily out of place by comparison.

Did you look at the linked articles? The second one is titled: "Snow Leopard May Delete User Accounts: Are You At Risk?"

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#77
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

> And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug also only affected 100 accounts.

  - The dropbox issue was not initially reported as 100 exposed accounts, it was
    reported as "Dropbox vulnerable", that's something that alarms about 99% of 
    the HN readership.  
  - Dropbox is a YC company.
  - Dropbox is exposed to the world and the issue was seemingly 
    out of users control (until the facts were known).
By comparison, the OSX issue was initially reported as being LDAP specific which probably means it's not an issue for 99% of HN readership. The OSX issue can also be disabled, at great inconvenience I'm sure, but the point is you can protect yourself.

The OSX issue is a big screwup, but I see no mystery as to the response.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#78

Why are they not using Kerberos and SSL though? Does this affect those users who actually do take security seriously or just the bare bones implementations that aren't safe anyways?

Not entirely relevant, but Lion's Kerberos is pretty funky as well. Apple switched to Heimdal from MIT, supposedly marked the Heimdal API 'private' and provided a worse than broken shim between the MIT API and Heimdal.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#79
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

It's because it's only for enterprise setups that use LDAP in the particular way described here. It's not every Mac OS X user, it's not every enterprise Mac OS X setup. If they had been using AD it would have worked. So really it's not as wide spread as DropBox's issue that was for every single user.

No. AD is fucked too, just in a different way. 5 minute logins anyone? And don't restart or you'll have to re-bind to AD.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#80
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

The dropbox bug only affected 100 people? Or it affected everyone but only 100 people logged in with it? That's a big difference.

[deleted]
Post reply on HN