Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

171–180 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#171

Earlier quoted context omitted.

What apologists? Were the comments deleted or something, because I really don't see anyone defending Apple in this thread.

> Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility. > To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version. > While this is a sign…

So, it's my comment you quoted questioning whether this can be called a backdoor.

I don't intend that to be apologetic for Apple. I called it a 'significant vulnerability' but at the end of the day, it's a privilege escalation like those that have come before and will likely continue to be found occasionally, regardless of OS. I don't see what's apologetic about acknowledging a significant vulnerable while questioning whether it should be called a backdoor.

If you want to talk about Apple's response - I find it concerning that they aren't backporting the fix.

Re: Hidden backdoor API to root privileges in Apple OS X

#172
post #165

Earlier quoted context omitted.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

> To be fair, OS X updates are free and usually run well even on 5+ years old hardware Unless your hardware has been made "incompatible" by Apple (not for any technical reason, but simply because they wish you'd buy new hardware).

What hardware have they dropped support for without a technical reason? To my knowledge, the only Intel Macs they've dropped support for are ones with 32-bit processors, 32-bit firmware (requiring a 32-bit kernel and drivers even if the processor is 64-bit), or really old GPUs that can't support recent versions of OpenGL.

Re: Hidden backdoor API to root privileges in Apple OS X

#173
post #105

Earlier quoted context omitted.

What kind of issues? I've literally noticed no differences besides UI.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

> Windows is out of the question after seeing what a factory OEM image comes with nowadays. I'm not giving them money and spending 2 days formatting/reinstalling/seeking out drivers on slow Taiwanese servers just to make a half-usable computer. And then, after all that, spend another 2 days installing various adware infested shitware to get a fricking PDF viewer.

Microsoft Signature PCs solve this problem. :)

http://www.microsoftstore.com/store/msusa/en_US/cat/Signatur...

Re: Hidden backdoor API to root privileges in Apple OS X

#174
post #67

Earlier quoted context omitted.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

I'm currently running 10.10.3 on a Mac Pro 1,1, at almost 9 years of use. Of course 10.10 isn't supported by Apple, but it works just fine, and with the combination of an SSD and cheap RAM, I imagine I can get another 3-4 years out of this desktop barring a hardware failure that pushes me to a new system.

... and now that you've posted that, I fully expect a mysterious hardware failure to suddenly manifest....

Re: Hidden backdoor API to root privileges in Apple OS X

#175
post #160

Earlier quoted context omitted.

A large chunk of this is due to business use of Windows. Microsoft would not be able to get away with the shenanigans that Apple are pulling here.

Don't worry, my company uses plenty of Macs, and they're plenty upset. As does the U.S. government. I wouldn't count on this "oh, we're just not going to backport the update" sticking around. Unless they want to loose all of their government and commercial sales.

Alupis, I support federal government scientists (biologists, chemists, entomologists, etc.), and many of them use Macs. Naturally, there are more Windows PCs than there are Macs, but there are plenty of Macs in our labs.

Re: Hidden backdoor API to root privileges in Apple OS X

#176

Of course this exploits XPC. I really hate all the desktop IPC bullshit. IPC frameworks are pure fucking evil. COM, D-Bus, XPC, everything SUCKS. If you want completely separate programs on one machine to talk, use UNIX domain sockets (with something like ZeroMQ or HTTP), FIFOs (named pipes), anything that you can chmod and chown, not a daemon that reinvents access control, badly.

[deleted]

Re: Hidden backdoor API to root privileges in Apple OS X

#177
post #165

Earlier quoted context omitted.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

> To be fair, OS X updates are free and usually run well even on 5+ years old hardware Unless your hardware has been made "incompatible" by Apple (not for any technical reason, but simply because they wish you'd buy new hardware).

I am not sure why you were downvoted. I'd think it is in Apple's vested interest to actually not treat the older hardware so you buy new one. I am no talking about really old hardware. Example: I have seen my iPhone 5S get substantially slower after update to ios 8+.

Re: Hidden backdoor API to root privileges in Apple OS X

#178

While this is a significant vulnerability, I don't think the article is correct when it calls it a 'backdoor.' The term backdoor typically implies something that was intentionally left to allow illicit access, and while this is a significant bug, I don't see anything to indicate that's the case here.

There's no way to tell for sure if something like this is intentional or not. Also, waiting to fix it until a researcher makes it public may have been intentional.

> There's no way to tell for sure if something like this is intentional or not.

Right, so the simplest explanation is that it's an unintentional bug. The absence of evidence that it was unintentional isn't evidence that it was intentional. If there were some magic string or default password or something, that'd be an obvious backdoor, but to me this looks like a pretty typical privesc bug, albeit in an undocumented api.

It was found through a chain of events that started with looking at the patch related to another privilege escalation vulnerability, one which no one seems to be claiming was a backdoor.

> Also, waiting to fix it until a researcher makes it public may have been intentional.

I'm guessing it's more likely the the researcher waiting to go public until it was fixed.

This is evidenced both by the fact that it was patched alongside other vulns (ie. not a rushed out one-off patch) and from the article's disclosure timeline, which shows 'Full disclosure' occurring 04/09, while the 'Release of OS X 10.10.3' occurred 04/08. This is a pretty typical disclosure timeline; they couldn't begin to fix it until it was tracked as a bug, after all.

Re: Hidden backdoor API to root privileges in Apple OS X

#179
post #134

Earlier quoted context omitted.

Do you legitimately see these comments are being apologetic towards apple?

> To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

Which was a response to:

>Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.

He was rebutting that regular upgrades are somehow a type of revenue to apple since they are free and work on some previous generation hardware. How is that apologetic?

Re: Hidden backdoor API to root privileges in Apple OS X

#180
post #105

Earlier quoted context omitted.

What kind of issues? I've literally noticed no differences besides UI.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

>Linux is almost there. It's a crap shoot for me

Just get Ubuntu Certified Hardware. They have over 500 models of laptops they certify. I have never had a kernel update break wifi. I don't know about all the other stuff, but most distributions store old kernels and allow you to boot back into the old kernel pretty easily. Don't know if this is an option on OS X.

Post reply on HN