Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

131–140 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#131
post #69

OT but I have to say that the amount of Apple apologists in these comments is mind blowing. HN reader of all people should be the ones urging Apple to issue a fix for a very serious bug such as this one. Yet many comments here are saying that people should just upgrade while it might solve the problem for some, there are ones who can't upgrade machines at will.

What apologists? Were the comments deleted or something, because I really don't see anyone defending Apple in this thread.

> Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.

> To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

> While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.

> Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken.

> Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.

> Referring to Snow Leopard now not secure > Still pretty much the best OSX.

> Among other things upgrading (to 10.10.3) will do, it'll fix the issue in the article.

Re: Hidden backdoor API to root privileges in Apple OS X

#133
post #3

Related to this, how have people found running Yosemite compared to Mavericks, performance and compatibility-wise? Are you sorry you upgraded? (I'm asking for a friend.)

If you're seriously concerned, why not use an external drive of some sort and install Yosemite to it? (Bonus points: clone your internal disk to it first, and upgrade that.) Boot it up, test out your critical functions, and then update your main volume if it works out for you.

You need to do the Bonus points version of your recommendation. Running an OS off an external will just make everything feel sluggish (unless you have a lightning enclosure and spare SSD laying around).

Re: Hidden backdoor API to root privileges in Apple OS X

#134

Earlier quoted context omitted.

What apologists? Were the comments deleted or something, because I really don't see anyone defending Apple in this thread.

> Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility. > To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version. > While this is a sign…

Do you legitimately see these comments are being apologetic towards apple?

Re: Hidden backdoor API to root privileges in Apple OS X

#136
post #50

Earlier quoted context omitted.

Smells like an oversight to me. Some new developer got assigned to implement or tweak the SSH enabling switch (or whatever), and this was their solution, which never got reviewed.

Not closing the hole in old versions of the OS isn't an oversight, however.

It's a business decision.

Re: Hidden backdoor API to root privileges in Apple OS X

#137
post #105

Earlier quoted context omitted.

What kind of issues? I've literally noticed no differences besides UI.

Random bugginess. When I came into office, plugged my machine into TB display (have one at home, so should be no issue), I got nothing but black. Could get a login prompt, and even closing lid kept backlight on. Only solution was a hard reboot.

Oh true. I just realized I have the same issue. I connect my macbook to my hengedock which has 3 monitors attached. If I disconnect my macbook and hook up my tv via hdmi, I plug it into my hengedock and my 3rd monitor is just black while plugged into that hdmi port. I always restart it after watching tv and then plugging my monitors to get it to work.

Re: Hidden backdoor API to root privileges in Apple OS X

#138

Earlier quoted context omitted.

What apologists? Were the comments deleted or something, because I really don't see anyone defending Apple in this thread.

> Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility. > To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version. > While this is a sign…

Most of those are people giving fairly reasonable benefit of the doubt, no apologism. But I suspect you're probably about as biased against Apple as the people you're assuming are biased towards Apple.

Re: Hidden backdoor API to root privileges in Apple OS X

#139
post #69

OT but I have to say that the amount of Apple apologists in these comments is mind blowing. HN reader of all people should be the ones urging Apple to issue a fix for a very serious bug such as this one. Yet many comments here are saying that people should just upgrade while it might solve the problem for some, there are ones who can't upgrade machines at will.

Yeah, imagine if the same was true of say, Rails 4.0.

Re: Hidden backdoor API to root privileges in Apple OS X

#140

While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.

This is a hole that exists because an Apple-written application needed a method to gain elevated access. This was done through unpublished APIs which, when used by another application in a similar way, also resulted in elevated access. So, this was clearly intentional, because it's used by Apple directly. And it allows illicit access, because any program can use it to gain access.

I'm not so sure. Unless I'm missing something, he doesn't demonstrate that this 'backdoor' is in use. It looks like they were using an escalation backdoor in `systemsetup`, but quickly patched a fix after 10.8.5. He just found a way around it.

Now, the fact that 'it takes too much effort' to backport would suggest that it was still in use. I don't see any other evidence, though. I'd be interested if someone found it!

Post reply on HN