Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

281–290 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#281
post #238

Earlier quoted context omitted.

>Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. I can build my own desktop, but I can't build my own laptop. I use laptops exclusively for work. >When's the last time you actually installed drivers on a fresh Windows install? Less than year ago on my girlfriend's VAIO laptop, actually. Windows 7. >Microsoft has made progress on supportin…

None of your complaints are about Windows. They're all, almost universally, about OEM and third-party shovelware. You want to avoid OEMs trashing your computer? Don't pretend this is about a lack of choice, or about Microsoft being stuck in the past. It's about you being ignorant of your options, or ignorant of the ecosystem. Buy a Signature Series machine from Microsoft.[1] No crapware, no bundled "features" or "tri…

> This annoys me so much because you are essentially arguing that problems caused by refusing to read are problems caused by operating systems, and this really isn't the case. This isn't something Apple has done a better job with either, it's just that the marketshare for Apple wasn't high enough for the malware vendors to bother with them.

If you have to carefully uncheck a bunch of options to avoid killing your computer with malware, then yes, the operating system is at fault. These sort of dark design patterns shouldn't exist, and the OS should be designed so that it's harder to implement shady things like this.

Yes, there is Mac malware out there, but Mac apps tend to have no installer at all, which is where most of the malware and crapware come from. It's harder to install some OS daemon when "installing" is just copying a file into your Applications folder. Mac apps almost never ask for permissions so I think users are more wary when the OS is asking weird stuff.

And Malware is practically unheard of in the Linux/Free Software world. I trust "apt-get install" implicitly when dealing with the main Debian archives.

> See, you're doing it again. You're not dealing with "Windows issues", you're dealing with issues on Windows boxes, caused by non-Windows problems.

That's a reasonable distinction, I suppose. How about this: The Windows software community sucks. The product may be fine if you know your way around the horrible alleys where malware and crapware lie in wait, but for normal people, the whole external environment is designed to screw you and mangle your computer.

Windows itself may be great, but the whole ecosystem is a wretched hive of scum and villainy.

Re: Hidden backdoor API to root privileges in Apple OS X

#282
post #239

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> JWZ used to say that Linux is only free if you don't value your time. My reply to that has always been that Windows is only $300 if you don't value your time. (Preserving archaic cost of Windows to match JWZ quote.) The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false. At the time, for many requirements, configuring and administeri…

The point is when you include your time your comparing ~10k products and there purchase price is a rounding error, not that Linux is inferior because it's free.

Re: Hidden backdoor API to root privileges in Apple OS X

#283

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> JWZ used to say that Linux is only free if you don't value your time. Used to say? How long ago was that? Ubuntu and many other distros are incredibly easy and effortless to use. I know devs using apple products who spend more time mucking about with brew and other tools trying to accomplish things that are very easy to do on the most popular linux distros.

I prefer and run Linux. However, troubleshooting Linux issues, even on Ubuntu is a pain in the ass. The fact that Google's page rank favors older stable pages in search results is a factor. A forum post from 2004 is not the best source of information in regards to dual monitors (and xrandr). 2007 instructions for changing the default boot will be based around Grub. I shouldn't adjust ~/.bash_login in 14.10 despite what the internet says. I should use the configuration tool.

My point is that Ubuntu is complex [as is Windows] and when something doesn't run quite right, the right answer is usually hard to find and hard to recognize because it will be embedded in a culture of highly technical cross referencing. The tradeoff for going down the rabbit hole is that Linux is really powerful and flexible.

I'm loving me some Xmonad this week, but I had to root around in xkb and xmodmap and write a little haskell and read about out how to switch layout engines in Ubuntu [and then translate that into xfce based Ubuntu Studio]. It's non-trivial and requires reading stuff on the Arch Linux Wiki. Ubuntu isn't really self contained in the way Windows is.

Re: Hidden backdoor API to root privileges in Apple OS X

#284

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> Yep. JWZ used to say that Linux is only free if you don't value your time. Yeah, like installing drivers for all your peripherals on Windows never takes time, right?

I don't think I've ever had to install a driver manually on Windows 7.

Re: Hidden backdoor API to root privileges in Apple OS X

#286

> Apple indicated that this issue required a substantial amount of changes on their side, and that they will not back port the fix to 10.9.x and older. What ? So all OS X boxes are simply broken, privileges-wise, if they're not on 10.10?

Apple's model customer is one who upgrades often. If you want solid support for old products, stick with Microsoft, and accept that their products can be clunkier because of deliberate choices to maintain backwards-compatibility.

Holy Apple can't be wrong. Microsoft bad bad and clunky.

We're talking about a security issue!

Re: Hidden backdoor API to root privileges in Apple OS X

#287

Earlier quoted context omitted.

>Windows is out of the question after seeing what a factory OEM image comes with nowadays. Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. >I'm not giving them money and spending 2 days formatting/reinstalling/seeking out drivers on slow Taiwanese servers just to make a half-usable computer. When's the last time you actually installed dri…

>If you absolutely need to read a PDF, Foxit Reader is free, as in beer. You're actually proving his point : on Windows something as basic as reading PDFs (yes you "absolutely" need that in 2015) requires specific knowledge of obscure names like "Foxit Reader". I'm not even going into annotating that PDF or adding your signature to it then. The same goes for : an office suite, a file manager with decent previewing+sm…

Or maybe it requires specific knowledge of obscure names like Adobe Reader. Or did I miss something and Adobe started charging for Reader once there were double - digit numbers of free alternatives including those built into the browsers?

Heck, do Chrome or Firefox actually register with the system to handle PDFs? Wouldn't surprise me if they did.

Re: Hidden backdoor API to root privileges in Apple OS X

#288

Earlier quoted context omitted.

> Yep. JWZ used to say that Linux is only free if you don't value your time. Yeah, like installing drivers for all your peripherals on Windows never takes time, right?

I don't think I've ever had to install a driver manually on Windows 7.

So you don't have a GPU card I guess?

Re: Hidden backdoor API to root privileges in Apple OS X

#289
post #239

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> JWZ used to say that Linux is only free if you don't value your time. My reply to that has always been that Windows is only $300 if you don't value your time. (Preserving archaic cost of Windows to match JWZ quote.) The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false. At the time, for many requirements, configuring and administeri…

Linux desktop is and has been second rate for a long long time. Turns out unless there are corporate sponsors paying for development, open source software sucks. The OSS community is pretty much in denial about that.

Re: Hidden backdoor API to root privileges in Apple OS X

#290

Earlier quoted context omitted.

> There's no way to tell for sure if something like this is intentional or not. Right, so the simplest explanation is that it's an unintentional bug. The absence of evidence that it was unintentional isn't evidence that it was intentional. If there were some magic string or default password or something, that'd be an obvious backdoor, but to me this looks like a pretty typical privesc bug, albeit in an undocumented a…

There's no way to tell for sure if something like this is intentional or not. Yes, there is. Sue Apple for willful negligence and subpoena the development logs.

Sigh. No practical way…
Post reply on HN