Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

91–100 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#91

> Apple indicated that this issue required a substantial amount of changes on their side, and that they will not back port the fix to 10.9.x and older. What ? So all OS X boxes are simply broken, privileges-wise, if they're not on 10.10?

Looks like they've released patches for Mavericks and Mountain Lion as well:

https://support.apple.com/kb/DL1803 https://support.apple.com/kb/DL1802

Re: Hidden backdoor API to root privileges in Apple OS X

#92
post #91

> Apple indicated that this issue required a substantial amount of changes on their side, and that they will not back port the fix to 10.9.x and older. What ? So all OS X boxes are simply broken, privileges-wise, if they're not on 10.10?

Looks like they've released patches for Mavericks and Mountain Lion as well: https://support.apple.com/kb/DL1803 https://support.apple.com/kb/DL1802

Unfortunately this fix is apparently not included.

Re: Hidden backdoor API to root privileges in Apple OS X

#93

Earlier quoted context omitted.

Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

sounds like macs are only in homes from your perspective.

Re: Hidden backdoor API to root privileges in Apple OS X

#95

Earlier quoted context omitted.

Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

[citation needed]

Re: Hidden backdoor API to root privileges in Apple OS X

#96
post #11

With physical access, one has been able to create admin accounts for as long as I can remember. - Start up the Mac whilst holding down ⌘-S. This boots the Mac into Single-User Mode and provides a method of interacting with OS X via the command-line, with full root privileges. - Then check the filesystem to ensure there are no problems: "/sbin/fsck -fy" - Then mount the filesystem for it to be accessible: "/sbin/mount…

About two months or three ago I stupidly changed my password to my only account to a password I promptly forgot. I was losing it when I realized what I had done. To make matters worse, I did this change a day before our office was scheduled to move to automated backups via Time Machine.

Luckily after some digging I came across this fix and was back in to my computer, albeit a little shaken up by the back door.

Re: Hidden backdoor API to root privileges in Apple OS X

#97
post #92
post #91

Earlier quoted context omitted.

Looks like they've released patches for Mavericks and Mountain Lion as well: https://support.apple.com/kb/DL1803 https://support.apple.com/kb/DL1802

Unfortunately this fix is apparently not included.

What makes you say that?

Re: Hidden backdoor API to root privileges in Apple OS X

#98
post #52
post #50

Earlier quoted context omitted.

Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.

In that case, I think "backdoor" is hyperbolic. That word is usually uses to indicate intentional secret security holes.

What do you call something that grants root access without authentication, but wasn't intended to let arbitrary people or programs use it?

"Backdoor" isn't quite right, since that implies that the intent was to allow unauthorized use.

"Security vulnerability" isn't quite right either, since that usually implies getting code to exhibit some sort of behavior it was never supposed to have.

I can't think of any other term. Of the two, "backdoor" seems closer. Maybe "unintentional backdoor"?

Re: Hidden backdoor API to root privileges in Apple OS X

#100
post #69

OT but I have to say that the amount of Apple apologists in these comments is mind blowing. HN reader of all people should be the ones urging Apple to issue a fix for a very serious bug such as this one. Yet many comments here are saying that people should just upgrade while it might solve the problem for some, there are ones who can't upgrade machines at will.

Same devs who just say "users should just upgrade their browsers" perhaps?

If only it were that easy. Yosemite just seems to "break" some things and I've still been waiting it out.

Post reply on HN