Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

121–130 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#121

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Is it likely it's just an error due to the discoverer not being immersed in the Infosec space? "Don't disclose a 0-day publicly" is good 'common' sense, but only among the 'common' of people who are steeped in security issues and the ramifications of publicizing them.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#122

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

There must be some kind of scale 1-10 of how serious the issue is. This one goes up to 11 as hilarious, not sure if proper reporting ethics apply here anymore.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#124

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

I get it, I really do, but it's not like he was complaining about a bad Uber driver. Disclosure in this way has real-world impacts up to and including harming people and we shouldn't ever consider it as something which is remotely acceptable. Is it acceptable to publicly disclose that an airport has a self-destruct switch which can be accessed near the NW mens bathroom? No. You contact someone who can fix the problem, then publicly disclose.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#125
post #6

Even on El Capitan, I was able to unlock with "root" on my first try. From there, I could add a new admin user. This seems... not good.

Especially not good is Apple likely won't fix it in El Cap. They'll tell all of us to upgrade. I don't want that buggy HS mess.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#126
Apple has a serious software quality problem. Last night I was helping a friend with their computer. Safari couldn't even render apples website correctly. Nor could Safari connect to any site with HTTPS. Installed FireFox and HTTPS sites worked and apples's site renders. But the submit button on their developer site is broken[1]. Mail on my Mom's fully updated laptop crashes every time it's opened. Once I reported a bug in ptrace like 4 years ago and no response yet. Also the archive utility fails often to extract tar files that the tar command has no problem extracting at all. Quicktime can't play most videos, etc, etc. And now shipping an operating system with a root account with no password by default.

Come on Apple you have a quarter trillion dollars in the bank why don't you spend some on improving your software.

[1]: https://forums.developer.apple.com/thread/60763

Re: macOS High Sierra: Anyone can login as “root” with empty password

#127

Earlier quoted context omitted.

As a programmer, the thought terrifies me.

As someone who tries to do risk analysis, the prospect of sticking with human drivers because of fear of software bugs (which inevitably will kill, just in much smaller numbers) terrifies me.

The fear is not of bugs killing people. The fear is of bugs allowing people to kill people.

If ISIS was able to hack a major fleet through one such bug, do you think for a single moment they wouldn't make use of it to kill many people?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#128

Can't reproduce on multiple High Sierra machines.

Can't repro on a 2012 retina MBP running 10.13.1, attempting the original repro and others suggested here. Until the wife walks away from hers, it's the only machine I have available. I'm curious as to the difference, given the high number of repros.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#129
post #102

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#130
This is comical at this point. I have no idea how such vulnerable software makes it to production.

It is really ironic that a company, making billions of dollars and branding itself as the leaders of quality, stability and so on, to have this kind of vulnerability.

I have truly lost faith in Apple.

Post reply on HN