Live data from Hacker News

Mac OS X Lion accepts any password when authenticating via LDAP

forums.macrumors.com

81–89 of 89 posts

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#81

Earlier quoted context omitted.

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Yep, I agree. I've been very disappointed with Lion, even taking into account the common "Don't buy an x.0 Apple product", there were some terrible bugs (I was personally bitten by the inability to look up DNS servers after waking from sleep, which I can't believe was missed in testing). Apple's software quali…

Apple's software quality has been markedly going down People have said the same thing about nearly every OS X release (with the possible exception of 10.1). At least Lion doesn't erase your firewire hard drives [1], or delete your entire home folder [2] etc etc. The comparative severity of these really bad bugs can be debated, but I think in terms of general quality OS X 10.0 − 10.2 really were quite a lot worse than…

It's nothing to do with how the Mac ranks in Apple's priorities. Apple security has been a joke, compared to Windows, for a very long time.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#82
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

That's because lots of people here have dropbox accounts. Very few authenticate via LDAP to a Lion server.

People are a lot more emotional about problems when they're personally affected.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#83
post #59

Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Being affected by 3 serious regressions in Lion (all filed as bugs and Apple closed them as duplicates, btw) - I get the feeling that Apple could do better at software engineering. (Alarms on iOS if you are still not convinced :) Just the fact that they release software that allows authentication without corre…

> Say what you will about Microsoft but in my several years of using Windows I rarely had these type of glaring issues even with the awful amount of hardware it supports. I'm an ex-MS employee. One thing that really impressed me about my team at MS is the depth and quality of testing that was done. Unit tests, integration, fuzz, load, UI, regression, etc. All done in extreme depth, extremely efficiently, and across e…

I always thought that an interesting thing about Vista was that although it was widely seen as a horrible failure it wasn't actually highly buggy. It had horrible problems with performance and hardware compatibility, but the software itself didn't seem to contain glaring issues - at least if you calibrated your expectations to the perception of its quality by the market and end users.

On the other hand, Apple always nails the user experience - a release like Vista just wouldn't get out the door. But they let other horrendous quality problems through that would and should be caught by better process.

So it sort of illustrates two fairly orthogonal axes of quality and how different companies excel in different directions along those axes.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#85
post #13

This looks both real and a pretty serious issue (I wonder how it went by almost a month without getting picked up by the security community). There's an discussion about it on Apple's own forums, linked below, but the gist of it is that users can authenticate over LDAP using any password using the login screen, and can't authenticate at all using su: https://discussions.apple.com/message/15887083

Not many people in the security community use Mac servers in such a way that they need LDAP, and of those people, very few are running Lion on their servers.

Agreed that few are relying on Lion servers. But the security flaw is at the side of the Mac client, not the server. If you have Lion clients authenticating against OpenLDAD hosted on, say, a Linux server, then only the username is checked and any password is accepted. IMHO this is a serious security flaw that should be fixed as soon as possible by Apple.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#86
post #43
post #12

Can someone give a quick lowdown on what's really happening here? I am assuming the Lion client is connecting to an LDAP server using the provided password, and regardless of the response from LDAP, Lion proceeds with the login?

No-if you try to submit a blank password it is (rightly) rejected. If you submit a non-blank password, the login succeeds. This (to me) points to the LDAP server responding with a login success message and the OS allowing the user in. This bug appears to only effect Lion clients talking to OpenLDAP (not the LDAP server shipped with Lion Server) or Active Directory.

I played with a Lion client bound to OpenLDAP running on a Linux server. I could login with my username and any password (empty or not). I used a packet sniffer and it appeared to me, that the Lion client is not even sending the password to the server, but simply logging the user in. At least in my case, the server didn't send any login success message, and the Lion still let the user in. It clearly seems to be an issue on the side of the Mac OS X client, not the server.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#87
post #48

News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…

>News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs

My old HN account got shaddowbanned after I talked shit about Dropbox when that happened. The post got a big number of points (more than anything else I had ever posted) and sparked interesting discussion, but I now know better than to question the Hacker News community's Sacred Cows.

>or ranting how this lapse is unforgivable.

I ranted against Dropbox because of the amount of people downplaying the severity, I'm not seeing that with this OS X issue (yet?). With the dropbox password thing, I saw a frequent argument, also used in their encryption scandal, one that really pissed me off. People were defending them with what boiled down to "you're stupid for expecting them to provide any level of service, as reasonable as it may be, unless their underlying tech doesn't force them to provide it".

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#88

Earlier quoted context omitted.

We just got some Lion iMacs and have not been able to keep them connected to the AD. It doesn't work as expect unfortunately.

Are you talking about the "Network accounts unavailable" red light? If you wait ~20secs, it generally resolves itself. Definitely a bug, but just an annoying one.

Yep, that's the one. We've tried waiting and even increased the timeout from 2 seconds to something higher and it's still not working.

Re: Mac OS X Lion accepts any password when authenticating via LDAP

#89
post #63

Earlier quoted context omitted.

which is possibly quite a few university macs in libraries and computer labs.

Really? Can you name even one university that uses LDAP but not Kerberos for their computer labs?

Well, I could name one that almost certainly doesn't, but I'll refrain.
Post reply on HN