Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
macOS High Sierra: Anyone can login as “root” with empty password
121–130 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#122Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#123Re: macOS High Sierra: Anyone can login as “root” with empty password
#124Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#125Even on El Capitan, I was able to unlock with "root" on my first try. From there, I could add a new admin user. This seems... not good.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#126Come on Apple you have a quarter trillion dollars in the bank why don't you spend some on improving your software.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#127Earlier quoted context omitted.
As a programmer, the thought terrifies me.
As someone who tries to do risk analysis, the prospect of sticking with human drivers because of fear of software bugs (which inevitably will kill, just in much smaller numbers) terrifies me.
If ISIS was able to hack a major fleet through one such bug, do you think for a single moment they wouldn't make use of it to kill many people?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#128Can't reproduce on multiple High Sierra machines.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#129Earlier quoted context omitted.
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#130It is really ironic that a company, making billions of dollars and branding itself as the leaders of quality, stability and so on, to have this kind of vulnerability.
I have truly lost faith in Apple.