Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

261–270 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#261

Earlier quoted context omitted.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

>Windows is out of the question after seeing what a factory OEM image comes with nowadays. Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. >I'm not giving them money and spending 2 days formatting/reinstalling/seeking out drivers on slow Taiwanese servers just to make a half-usable computer. When's the last time you actually installed dri…

http://www.nliteos.com helps massively when installing all the Java / Flash / browsers / anti-malware / other stuff you need on Windows. The Taiwanese driver thing is still real; windows may ship drivers and have some via windows update, but they probably won't be the newest (or even newest certified).

Don't forget about the 4 hours, 10 reboots, 3 blue screens, and reinstalling your video card drivers twice of windows updates!

Re: Hidden backdoor API to root privileges in Apple OS X

#262
post #94

Could anyone summarize the implications of this finding in plain English?

Any code running as any user on an unpatched version can become root (and do whatever it wants, E.g. install keyloggers) Sandboxed apps (from the app storr) may be blocked from doing this, I'm not sure.

>Sandboxed apps (from the app storr) may be blocked from doing this, I'm not sure.

Just tried. Sandbox lets this through. (As long as you pass nil to authenticateUsingAuthorizationSync:).

Re: Hidden backdoor API to root privileges in Apple OS X

#263
post #44

Earlier quoted context omitted.

Local privilege escalation is always bad because it means you're one malware payload or RCE away from being rooted and conscripted into someone's botnet (or worse). This isn't just a physical access concern.

What about without local privilege escalation? Is there no way for a malware payload or RCE to turn your computer into a botnet without root privileges?

There are advertising networks that use JavaScript on client machine do distributed computing. Is that a botnet or not?

Re: Hidden backdoor API to root privileges in Apple OS X

#264

Earlier quoted context omitted.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

>Linux is almost there. It's a crap shoot for me Just get Ubuntu Certified Hardware. They have over 500 models of laptops they certify. I have never had a kernel update break wifi. I don't know about all the other stuff, but most distributions store old kernels and allow you to boot back into the old kernel pretty easily. Don't know if this is an option on OS X.

One problem with Ubuntu's hardware certification is that it's always for a specific Ubuntu version. I use Ubuntu and would really like it if they would pick at least a few common laptops and commit to ensuring that a certain number of future Ubuntu updates will continue to work perfectly on those laptops. It would help a lot in knowing what to buy.

Re: Hidden backdoor API to root privileges in Apple OS X

#265
post #56

> Apple indicated that this issue required a substantial amount of changes on their side, and that they will not back port the fix to 10.9.x and older. What ? So all OS X boxes are simply broken, privileges-wise, if they're not on 10.10?

They even released "Security Update 2015-004" at the same time, including many updates for 10.8 and 10.9, but not the admin framework. https://support.apple.com/en-us/HT204659

The first item on their list of patches is this vulnerability.

Re: Hidden backdoor API to root privileges in Apple OS X

#266

Earlier quoted context omitted.

To be even more fair, there's been a number of issues with Yosemite that make some of us want to stick with Mavericks. Just because something is free doesn't make it better.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> maybe I should go back to Snow Leopard; I can't think of a single valuable change to OS X since then...

I wish I had that option, but I'm an iOS developer, so I upgrade when Apple forces me to, and right now their forcing Mavericks and up.

> Linux is only free if you don't value your time.

Amazing how the largest server farms on earth are all run by administrators who don't value their time...

Re: Hidden backdoor API to root privileges in Apple OS X

#267
post #266

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> maybe I should go back to Snow Leopard; I can't think of a single valuable change to OS X since then... I wish I had that option, but I'm an iOS developer, so I upgrade when Apple forces me to, and right now their forcing Mavericks and up. > Linux is only free if you don't value your time. Amazing how the largest server farms on earth are all run by administrators who don't value their time...

There's a large difference between linux on the server and on your (personal) desktop.

Re: Hidden backdoor API to root privileges in Apple OS X

#268

Earlier quoted context omitted.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

>Windows is out of the question after seeing what a factory OEM image comes with nowadays. Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. >I'm not giving them money and spending 2 days formatting/reinstalling/seeking out drivers on slow Taiwanese servers just to make a half-usable computer. When's the last time you actually installed dri…

> When's the last time you actually installed drivers on a fresh Windows install?

On this very box, I bought a 8.1 pro license, and had to install drivers for my GPU (ATI r9), along with various other tidbits, which I've now forgotten. Oh, yeah, my usb sound card.

Granted, I needed to install the closed source drivers on the Linux side, but it was easier (enable non-free, aptitude install ...) -- and the soundcard worked out of the box.

At least the network card worked this time around on Windows (at least as far as I remember). So the only real hassle was that I needed a windows install from which to build the usb install stick. Thankfully I still dual-boot my laptop, so I could make the install image there.

Re: Hidden backdoor API to root privileges in Apple OS X

#269

Earlier quoted context omitted.

To be even more fair, there's been a number of issues with Yosemite that make some of us want to stick with Mavericks. Just because something is free doesn't make it better.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> JWZ used to say that Linux is only free if you don't value your time.

Used to say? How long ago was that?

Ubuntu and many other distros are incredibly easy and effortless to use. I know devs using apple products who spend more time mucking about with brew and other tools trying to accomplish things that are very easy to do on the most popular linux distros.

Re: Hidden backdoor API to root privileges in Apple OS X

#270
post #3

Related to this, how have people found running Yosemite compared to Mavericks, performance and compatibility-wise? Are you sorry you upgraded? (I'm asking for a friend.)

I recently got a mac mini that shipped with Yosemite. It has the nice feature of completely killing the WiFi interface when you attach a USB hub - googling around it seems a Yosemite bug. I have been told that also using bluetooth devices (such as the apple mouse) can trigger the same behaviour. So I'd say I'm sorry that the mac shipped with Yosemite, except that at least I received the fix for the privilege escalati…

It isn't just Yosemite... I had exactly this behavior with Mavericks on a new MacBook last year. Fired up a Bluetooth mouse, and next time I opened the lid wireless had completely gone.

I've managed to get it working after a fashion, although not reliably, and have come to the conclusion that Apple just don't do wireless well.

Post reply on HN