Earlier quoted context omitted.
Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Yep, I agree. I've been very disappointed with Lion, even taking into account the common "Don't buy an x.0 Apple product", there were some terrible bugs (I was personally bitten by the inability to look up DNS servers after waking from sleep, which I can't believe was missed in testing). Apple's software quali…
Apple's software quality has been markedly going down People have said the same thing about nearly every OS X release (with the possible exception of 10.1). At least Lion doesn't erase your firewire hard drives [1], or delete your entire home folder [2] etc etc. The comparative severity of these really bad bugs can be debated, but I think in terms of general quality OS X 10.0 − 10.2 really were quite a lot worse than…
Mac OS X Lion accepts any password when authenticating via LDAP
81–89 of 89 posts
Re: Mac OS X Lion accepts any password when authenticating via LDAP
#82News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…
People are a lot more emotional about problems when they're personally affected.
Re: Mac OS X Lion accepts any password when authenticating via LDAP
#83Tells you something about Apple's testing methodology. QA team at Apple must be playing real fast and loose. Being affected by 3 serious regressions in Lion (all filed as bugs and Apple closed them as duplicates, btw) - I get the feeling that Apple could do better at software engineering. (Alarms on iOS if you are still not convinced :) Just the fact that they release software that allows authentication without corre…
> Say what you will about Microsoft but in my several years of using Windows I rarely had these type of glaring issues even with the awful amount of hardware it supports. I'm an ex-MS employee. One thing that really impressed me about my team at MS is the depth and quality of testing that was done. Unit tests, integration, fuzz, load, UI, regression, etc. All done in extreme depth, extremely efficiently, and across e…
On the other hand, Apple always nails the user experience - a release like Vista just wouldn't get out the door. But they let other horrendous quality problems through that would and should be caught by better process.
So it sort of illustrates two fairly orthogonal axes of quality and how different companies excel in different directions along those axes.
Re: Mac OS X Lion accepts any password when authenticating via LDAP
#84Re: Mac OS X Lion accepts any password when authenticating via LDAP
#85This looks both real and a pretty serious issue (I wonder how it went by almost a month without getting picked up by the security community). There's an discussion about it on Apple's own forums, linked below, but the gist of it is that users can authenticate over LDAP using any password using the login screen, and can't authenticate at all using su: https://discussions.apple.com/message/15887083
Not many people in the security community use Mac servers in such a way that they need LDAP, and of those people, very few are running Lion on their servers.
Re: Mac OS X Lion accepts any password when authenticating via LDAP
#86Can someone give a quick lowdown on what's really happening here? I am assuming the Lion client is connecting to an LDAP server using the provided password, and regardless of the response from LDAP, Lion proceeds with the login?
No-if you try to submit a blank password it is (rightly) rejected. If you submit a non-blank password, the login succeeds. This (to me) points to the LDAP server responding with a login success message and the OS allowing the user in. This bug appears to only effect Lion clients talking to OpenLDAP (not the LDAP server shipped with Lion Server) or Active Directory.
Re: Mac OS X Lion accepts any password when authenticating via LDAP
#87News.YC community is being much kinder towards Apple than it acted towards Dropbox for identical security bugs. Dropbox even had the issue resolved in hours. I don't see anyone threatening to switch away from Apple or demanding an immediate personal response from Steve Jobs or ranting how this lapse is unforgivable. And you can't say it's because this bug only affects a small portion of Lion users as the Dropbox bug…
My old HN account got shaddowbanned after I talked shit about Dropbox when that happened. The post got a big number of points (more than anything else I had ever posted) and sparked interesting discussion, but I now know better than to question the Hacker News community's Sacred Cows.
>or ranting how this lapse is unforgivable.
I ranted against Dropbox because of the amount of people downplaying the severity, I'm not seeing that with this OS X issue (yet?). With the dropbox password thing, I saw a frequent argument, also used in their encryption scandal, one that really pissed me off. People were defending them with what boiled down to "you're stupid for expecting them to provide any level of service, as reasonable as it may be, unless their underlying tech doesn't force them to provide it".
Re: Mac OS X Lion accepts any password when authenticating via LDAP
#88Earlier quoted context omitted.
We just got some Lion iMacs and have not been able to keep them connected to the AD. It doesn't work as expect unfortunately.
Are you talking about the "Network accounts unavailable" red light? If you wait ~20secs, it generally resolves itself. Definitely a bug, but just an annoying one.