Live data from Hacker News

Hidden backdoor API to root privileges in Apple OS X

truesecdev.wordpress.com

291–300 of 367 posts

Re: Hidden backdoor API to root privileges in Apple OS X

#291
post #105

Earlier quoted context omitted.

What kind of issues? I've literally noticed no differences besides UI.

FWIW, 10.10.0 for me was perfect. 10.10.1 broke my wifi. Anytime the computer woke up from sleep, I'd have to reset the wifi card so it could find my access point. After 10.10.2 came out, I got my second-ever full computer lock-up. I've had the same OS image since 10.5 (migrated and upgraded multiple time, obviously) and this was the second time my computer required a hard reboot. And this was while watching a video…

> Windows is out of the question after seeing what a factory OEM image comes with nowadays. I'm not giving them money and spending 2 days formatting/reinstalling/seeking out drivers on slow Taiwanese servers just to make a half-usable computer.

"Dude, get a Dell!"[1] Seriously, one of the selling points of a Dell system is rock solid components, and a centralized place to find drivers (at least for the business line of systems). Keep in mind, Dell sells hundreds of thousands (or more?) systems to corporate America, all with support contracts. Everything they can streamline and make more stable and reliable is money in their pocket. I mean, they wrote their own RAID drivers for the AMI and LSI Megaraid chipsets which they resold under the PERC brand, and in my experience, they were better than the manufacturer drivers. That takes dedication.

1: http://en.wikipedia.org/wiki/Ben_Curtis_%28actor%29#The_Dell...

Re: Hidden backdoor API to root privileges in Apple OS X

#293
post #266

Earlier quoted context omitted.

Yep. JWZ used to say that Linux is only free if you don't value your time. OS X has many merits on this front, but since 10.3 I've found that the first few dot releases of OS X have the same caveats often enough (both in terms of bugs/hazards and in terms of gratuitous UI "progress") that it usually seems better to wait past .x.4/5. Now there's this, of course. Since the problem showed up in 2011, maybe I should go b…

> maybe I should go back to Snow Leopard; I can't think of a single valuable change to OS X since then... I wish I had that option, but I'm an iOS developer, so I upgrade when Apple forces me to, and right now their forcing Mavericks and up. > Linux is only free if you don't value your time. Amazing how the largest server farms on earth are all run by administrators who don't value their time...

The largest server farms on earth are all run by administrators who are extremely well paid for their time. Linux isn't free for the companies who hire them.

Re: Hidden backdoor API to root privileges in Apple OS X

#294

Earlier quoted context omitted.

Alrighty.... I can't think of a better way to undermine your credibility, so I think we're done here.

A biased person isn't credible? What did I say that was factually wrong or personal opinion. I don't like Apple products (Locked down and no fun for a hacker and expensive) I have no credibility since I don't like a company? What about the opposite people who like the company? Credible people are always upfront with their biases. I never trust anyone that says they are neutral.

Of course not. You're admitting and prideful that you aren't going to look at things fairly, and your complaints are therefore unhelpful, naive and very likely wrong to boot. People who simply like Apple are not uncredible, though a fanboy would be, for similar but opposite reasons. Credible people are aware of their biases and strive to overcome them. When you embrace your biases like you have, you're just offering some bullshit with a disclaimer that it's bullshit. At least you have honesty going for you.

Re: Hidden backdoor API to root privileges in Apple OS X

#295
post #289
post #239

Earlier quoted context omitted.

> JWZ used to say that Linux is only free if you don't value your time. My reply to that has always been that Windows is only $300 if you don't value your time. (Preserving archaic cost of Windows to match JWZ quote.) The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false. At the time, for many requirements, configuring and administeri…

Linux desktop is and has been second rate for a long long time. Turns out unless there are corporate sponsors paying for development, open source software sucks. The OSS community is pretty much in denial about that.

Funny, I'm watching a talk about issues with software quality on free software right now. Perhaps some members of the community are in denial, but not all of them.

https://media.libreplanet.org/u/libby/m/mako/

Re: Hidden backdoor API to root privileges in Apple OS X

#296
post #289
post #239

Earlier quoted context omitted.

> JWZ used to say that Linux is only free if you don't value your time. My reply to that has always been that Windows is only $300 if you don't value your time. (Preserving archaic cost of Windows to match JWZ quote.) The implication that the one system is free and time-consuming and the other moderately in price but not time-consuming is entirely false. At the time, for many requirements, configuring and administeri…

Linux desktop is and has been second rate for a long long time. Turns out unless there are corporate sponsors paying for development, open source software sucks. The OSS community is pretty much in denial about that.

I used to find Linux desktop second rate a few years ago but adopting it again recently I've found Gnome 3 better than OSX in many ways, at the very least comparable. Plus Arch Linux has been incredibly stable whereas in the past it also used to break often.

Re: Hidden backdoor API to root privileges in Apple OS X

#297
post #4

Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken. I do think its too bad that setuid binaries don't have additional restrictions, like 100% must be code-signed or must be run in a sandbox-exec[1] based on that signing. [1] - https://developer.apple.com/library/mac/documentation/Darwin...

Code signing is not interesting. If normal people can get their code signed then so can the attacker and if they can't then it locks you out of your own computer. The only thing code signing is really good for is to verify that an update to a program the machine's owner installed was signed by the same author as the original program, and unfortunately it's rarely implemented that way.

But that's not really what you're asking for anyway. You can assign granular permissions to binaries regardless of code signing.

The real problem is there are so many things that aren't literally root but are effectively equivalent because if you can do them then you have easy privilege escalation. That's why the Windows security model is so silly. An administrator is not allowed to 'su' to another user without the user's password but any reasonable subset of the administrator's privileges can be used to silently cause any user to execute arbitrary code, e.g. by setting their login script or putting executables in the All Users startup folder or just loading a kernel driver that will let them do whatever they want.

Re: Hidden backdoor API to root privileges in Apple OS X

#298
post #238

Earlier quoted context omitted.

>Fair play. Research the manufacturer's policy if you're buying pre-built. If you build your own desktops, this is not an issue. I can build my own desktop, but I can't build my own laptop. I use laptops exclusively for work. >When's the last time you actually installed drivers on a fresh Windows install? Less than year ago on my girlfriend's VAIO laptop, actually. Windows 7. >Microsoft has made progress on supportin…

None of your complaints are about Windows. They're all, almost universally, about OEM and third-party shovelware. You want to avoid OEMs trashing your computer? Don't pretend this is about a lack of choice, or about Microsoft being stuck in the past. It's about you being ignorant of your options, or ignorant of the ecosystem. Buy a Signature Series machine from Microsoft.[1] No crapware, no bundled "features" or "tri…

I had been an avid Windows user for two years from 2010-2012 and I had fun with Windows, surprisingly, I did not have the "Windows sucks" feelings back then because I hadn't started using Linux full time, and now I am a full time Linux user.

I don't use Windows on my laptop, but I don't "hate" it, I totally concur on your point about people hating the platform for the wrong reasons, historically the maretshare of Windows has been high and that is the reason for malware stuff.

What irritates me more than people hating windows for no reason is they don't realize that they are not using the platform properly, for eg when I tell fellow developers to switch to or use Linux for development they "stick" to windows even if they can't change the brightness of the screen! Yes some stupid driver error, they say they are "comfortable" with Windows, but irnonically they can't even give folder permission to users, this basic thing!

I feel people are too resistant to change and they want to blame something/someone and that is the problem with the hate stuff that spreads like a flu over the Internet

Re: Hidden backdoor API to root privileges in Apple OS X

#299

Earlier quoted context omitted.

To be fair, OS X updates are free and usually run well even on 5+ years old hardware. OS X has kinda gone the way of Chrome, with most users on the newest version.

To be even more fair, there's been a number of issues with Yosemite that make some of us want to stick with Mavericks. Just because something is free doesn't make it better.

I miss 10.6.8.

Re: Hidden backdoor API to root privileges in Apple OS X

#300
post #4

Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken. I do think its too bad that setuid binaries don't have additional restrictions, like 100% must be code-signed or must be run in a sandbox-exec[1] based on that signing. [1] - https://developer.apple.com/library/mac/documentation/Darwin...

Code signing is not interesting. If normal people can get their code signed then so can the attacker and if they can't then it locks you out of your own computer. The only thing code signing is really good for is to verify that an update to a program the machine's owner installed was signed by the same author as the original program, and unfortunately it's rarely implemented that way. But that's not really what you'r…

>then so can the attacker

Maybe, but the attacker can also get their certificate revoked when their activities are discovered.

Post reply on HN