Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

111–120 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#111

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

this is too serious to hide. better to tell users how to fix it than wait until apple releases something

That's not how responsible disclosure works.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#112
post #94

For those who can't make it happen, it requires that the root account is disabled, which is the default. If you already enabled the root account for some other reason (which apparently I had on one of my Macs, although I don't know why) then that prevents it from working. It seems like the best mitigation for the moment might be to enable the root user and set a password for it.

Once you disable the root account you can log in without a password again :/

Yep. If you keep it enabled and set a good password then you should be OK. I think.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#114
To workaround this before Apple have had a chance to patch it(thanks @lemiorhan), it seems you can:

- Open Directory Utility (/System/Library/CoreServices/Applications/Directory Utility.app)

- Authenticate with the lock icon

- From the Edit menu you can enable the root user and set a proper password (it would already be enabled if you had tried out the exploit)

Having that root user enabled isn't great overall, so it would be best to set a reminder to disable it using the same Directory Utility app once the security hole is patched.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#115
post #99

Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.

Exactly my thoughts. I remember this, I think even early versions of WinXP had this feature.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#116
post #75

Earlier quoted context omitted.

Only if the laptop is locked (as the encryption key is already in memory).

Any chance that self clears after an interval? Might be a bad day to leave the laptop at the table at the coffeeshop when ordering.

By default no as most people expect things to keep running when they lock their laptop.

There is a setting to immediately destroy the key when the laptop sleeps. It might be outdated but [1] should give you a starting point for setting it up.

[1] http://mattwashchuk.com/articles/2016/01/08/maximizing-filev...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#118
post #56

In the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password

Standalone iMac here - the 'Join' button is disabled. So is this vulnerability only for Macs on a network? EDIT: My bad - editing was locked on that screen. Got it now... EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?

Mine is currently enabled and since i've set a password, the bug seems to be gone. I can't authenticate by just typing root anymore.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#119
post #88

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

Probably could still get 15 minutes of fame if you disclosed privately then blogged about the back and forth and a picture of the $10,000 cheque from Apple.

Apple doesn't pay bounties for this sort of report, even if direct to their team. They have a private bounty program, for a select few.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#120
post #99

Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.

I believe hitting "cancel" was enough. https://www.youtube.com/watch?v=DE5PRW-AR7Q

Also reminds me of https://youtu.be/BVL8_ne4WZo?t=19s

Post reply on HN