Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
this is too serious to hide. better to tell users how to fix it than wait until apple releases something
macOS High Sierra: Anyone can login as “root” with empty password
111–120 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#112For those who can't make it happen, it requires that the root account is disabled, which is the default. If you already enabled the root account for some other reason (which apparently I had on one of my Macs, although I don't know why) then that prevents it from working. It seems like the best mitigation for the moment might be to enable the root user and set a password for it.
Once you disable the root account you can log in without a password again :/
Re: macOS High Sierra: Anyone can login as “root” with empty password
#113Re: macOS High Sierra: Anyone can login as “root” with empty password
#114- Open Directory Utility (/System/Library/CoreServices/Applications/Directory Utility.app)
- Authenticate with the lock icon
- From the Edit menu you can enable the root user and set a proper password (it would already be enabled if you had tried out the exploit)
Having that root user enabled isn't great overall, so it would be best to set a reminder to disable it using the same Directory Utility app once the security hole is patched.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#115Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#116Earlier quoted context omitted.
Only if the laptop is locked (as the encryption key is already in memory).
Any chance that self clears after an interval? Might be a bad day to leave the laptop at the table at the coffeeshop when ordering.
There is a setting to immediately destroy the key when the laptop sleeps. It might be outdated but [1] should give you a starting point for setting it up.
[1] http://mattwashchuk.com/articles/2016/01/08/maximizing-filev...
Re: macOS High Sierra: Anyone can login as “root” with empty password
#117Re: macOS High Sierra: Anyone can login as “root” with empty password
#118In the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password
Standalone iMac here - the 'Join' button is disabled. So is this vulnerability only for Macs on a network? EDIT: My bad - editing was locked on that screen. Got it now... EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#119Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
Probably could still get 15 minutes of fame if you disclosed privately then blogged about the back and forth and a picture of the $10,000 cheque from Apple.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#120Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
Also reminds me of https://youtu.be/BVL8_ne4WZo?t=19s