Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

251–260 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#251
post #105

Earlier quoted context omitted.

What kind of issues? I've literally noticed no differences besides UI.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

FWIW, my wifi had similar problems on 10.9. Not every time, but occasionally when it goes to sleep, it doesn't wake up and you have to reset the whole TCP/IP stack to make it work. And lockups after wakeup requiring hard boot are not unheard of either. So it may not be exclusive for 10.10.

Re: Hidden backdoor API to root privileges in Apple OS X

#252

Earlier quoted context omitted.

To be even more fair, there's been a number of issues with Yosemite that make some of us want to stick with Mavericks. Just because something is free doesn't make it better.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> Yep. JWZ used to say that Linux is only free if you don't value your time.

Yeah, like installing drivers for all your peripherals on Windows never takes time, right?

Re: Hidden backdoor API to root privileges in Apple OS X

#253

Earlier quoted context omitted.

>Windows is out of the question after seeing what a factory OEM image comes with nowadays. Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. >I'm not giving them money and spending 2 days formatting/reinstalling/seeking out drivers on slow Taiwanese servers just to make a half-usable computer. When's the last time you actually installed dri…

My Dad got himself a brand new laptop (i7, 8gb ram, ssd, etc). And a brand new printer HP OfficeJet (big black shiny machine with all the bells and whistles). He couldn't print his stuff for work. He called me up. After over an hour I gave up. Windows 8 couldn't figure out which drivers to use. The CDs attached with printer didn't help too. I mean the installation went smoothly, but then nothing was printed. Check yo…

And on our network the Windows PC prints fine, but the Macs have no idea what's going on.

TL;DR: Printers still suck.

Re: Hidden backdoor API to root privileges in Apple OS X

#254

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> Yep. JWZ used to say that Linux is only free if you don't value your time. Yeah, like installing drivers for all your peripherals on Windows never takes time, right?

He uses OS X. Rantilly.

http://www.jwz.org/blog/tag/mac/

Re: Hidden backdoor API to root privileges in Apple OS X

#255
post #238

Earlier quoted context omitted.

>Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. I can build my own desktop, but I can't build my own laptop. I use laptops exclusively for work. >When's the last time you actually installed drivers on a fresh Windows install? Less than year ago on my girlfriend's VAIO laptop, actually. Windows 7. >Microsoft has made progress on supportin…

None of your complaints are about Windows. They're all, almost universally, about OEM and third-party shovelware. You want to avoid OEMs trashing your computer? Don't pretend this is about a lack of choice, or about Microsoft being stuck in the past. It's about you being ignorant of your options, or ignorant of the ecosystem. Buy a Signature Series machine from Microsoft.[1] No crapware, no bundled "features" or "tri…

All of the GP's complaints are about Windows. You are attempting to divorce "this PDF viewer" from "Microsoft Windows" while the GP's complaints are about the laptop running Microsoft Windows with a bunch of Windows software installed on it.

I love how you point at "unchecky" as a great service when it is a piece of software you use to deal with problems that shouldn't exist in other software.

How manu Windows users wailed and gnashed their teeth over iTunes insisting on installing Quicktime? Is that because Windows users are lazy or that they didn't want Quicktime installed just to use iTunes?

"You are all too lazy for your own good," is classic victim blaming.

Is it perhaps possible that Sony, Dell, Toshiba et al have poisoned the well?

Re: Hidden backdoor API to root privileges in Apple OS X

#256
post #217

Earlier quoted context omitted.

What hardware have they dropped support for without a technical reason? To my knowledge, the only Intel Macs they've dropped support for are ones with 32-bit processors, 32-bit firmware (requiring a 32-bit kernel and drivers even if the processor is 64-bit), or really old GPUs that can't support recent versions of OpenGL.

To my knowledge no Linux distro packages install media supporting 32-bit firmware and 64-bit kernel+CPU, but it's definitely possible to built a 32-bit GRUB EFI binary and have it load and execute a 64-bit kernel on a 64-bit CPU. I've done it on such a Mac. And there are a number of tablets built this way also (unfortunately).

Intel only contributed the code for that a year ago, so while we now know it can be done, there's no particular reason to believe that it's easy to get working properly. The messy mix of EFI 1.x and UEFI 2.x that Apple uses could make things even trickier.

Re: Hidden backdoor API to root privileges in Apple OS X

#257
post #44
post #11

With physical access, one has been able to create admin accounts for as long as I can remember. - Start up the Mac whilst holding down ⌘-S. This boots the Mac into Single-User Mode and provides a method of interacting with OS X via the command-line, with full root privileges. - Then check the filesystem to ensure there are no problems: "/sbin/fsck -fy" - Then mount the filesystem for it to be accessible: "/sbin/mount…

Local privilege escalation is always bad because it means you're one malware payload or RCE away from being rooted and conscripted into someone's botnet (or worse). This isn't just a physical access concern.

What about without local privilege escalation? Is there no way for a malware payload or RCE to turn your computer into a botnet without root privileges?

Re: Hidden backdoor API to root privileges in Apple OS X

#258
post #26

Earlier quoted context omitted.

If I understood the article correctly, this can be exploited remotely by anybody who has managed to get a shell on the system.

Just to clarify, this is _not_ a remote vulnerability. If it was a means to create a remote shell, then it would be. An attacker would need to first find some way to gain remote access and then could use this bug to gain root privilege.

[deleted]

Re: Hidden backdoor API to root privileges in Apple OS X

#259

Earlier quoted context omitted.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

on the "run well even on 5+ years old hardware" bit. Sure, the OS will boot and work, but that doesn't mean things will work well . My late 2011 13-in MacBook Pro became unbearably slow after doing a clean upgrade to Mavericks. Only upgrading the memory to 8GB (which was not supported by Apple for that model) fixed the issue. Yosemite works, but looks like crap on anything without a retina display. Newer versions of…

I'm currently running the latest version of Yosemite. I have a 2010 MacBook Pro 15 inch with eight gigs of RAM and an SSD.

I've had little bugs and fiddly bugs with Safari and a few other things, but I really thinks it has worked fine for years and years on the machine. It noticeably improved when they added RAM compression (was that Mavericks?).

I don't find the graphics a problem at all, although they do look better on my Retina iMac. I got used to them pretty quickly.

I've been happy with most OS updates as they sped Safari up or fixed small bugs in it. Photos for OS X is a MASSIVE speed improvement over iPhoto.

I know some people run into pretty catastrophic bugs from time to time, I haven't had that experience personally. The idea that the OS doesn't run well on five-year-old hardware is bunk. I have no need to replace my MacBook Pro, The only thing it's not good at is 3D (and it was never very good at that).

If you have enough RAM and replace the spinning disk old Macs feel fantastic with a if you have enough RAM and replace the spinning hard drive old Mac still feel fantastic with a recent OS.

If you're on a 5400rpm drive with 2GB I'm sure it's painful. But I know even 4GB machines fair very well. SSDs just make an insanely big difference.

Re: Hidden backdoor API to root privileges in Apple OS X

#260
post #98
post #52

Earlier quoted context omitted.

In that case, I think "backdoor" is hyperbolic. That word is usually uses to indicate intentional secret security holes.

What do you call something that grants root access without authentication, but wasn't intended to let arbitrary people or programs use it? "Backdoor" isn't quite right, since that implies that the intent was to allow unauthorized use. "Security vulnerability" isn't quite right either , since that usually implies getting code to exhibit some sort of behavior it was never supposed to have. I can't think of any other te…

Unintentional backdoor is better, wouldn't be my choice though.

To me the term backdoor implies malevolence and purposeful decision to allow you to remotely access someone's system without their permission later.

And purposeful decision to allow you to remotely access someone's system without their permission later.

This seems more like a mistake, although a pretty big one. It seems like it was designed as a small escaped out to make some of Apple's scripts cleaner it wasn't locked down to the degree that should've been.

It's a big security hole, but I'm not sure backdoor fits.

Post reply on HN