Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

131–140 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#131

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

... And means that others can utilize this to cause damage.

The idea of responsible disclosure is to minimize harm for you, the user. Not to minimize bad publicity.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#133
post #102

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

Wrong. This is Apple -- not the homeowners -- leaving everyone's key in everyone's door without them knowing.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#135
post #102

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

The problem with that analogy is that the probability that the "bad guys" already know about this vulnerability is vastly higher than the probability that thieves know about how well some random house in the neighborhood is secured.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#136

Confirming this works, both from preferences, as well as from the main login screen It seems like root has no password by default. Setting one is enough to close the hole. This is unbelievable! Curious to see what's in /var/db/dslocal/nodes/Default/users/root.plist before trying this.

These are the contents of the file, after converting them from binary plist to plain xml: https://gist.github.com/shoghicp/2b529b54b9d70daf192b68e3564...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#137
post #97

Fix this by setting a password for root (or disable). Instructions here: https://support.apple.com/en-us/HT204012

Doesn't help to disable it, you have to change the password. UPDATE: if you disable the account after setting a password, a login without a password is possible again ..

Yeah, confirmed it myself too. Enable root with a strong password works though.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#138

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Is it likely it's just an error due to the discoverer not being immersed in the Infosec space? "Don't disclose a 0-day publicly" is good 'common' sense, but only among the 'common' of people who are steeped in security issues and the ramifications of publicizing them.

Indeed, discovering this bug wouldn't take any security skill (I imagine it could be harmful since you might skip really dumb stuff like this) and could easily happen by accident. Responsible disclosure is standard for security researchers but I don't think this person was one, and it's not very fair to blame him for not doing it right.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#139
post #88

Earlier quoted context omitted.

Probably could still get 15 minutes of fame if you disclosed privately then blogged about the back and forth and a picture of the $10,000 cheque from Apple.

Apple doesn't pay bounties for this sort of report, even if direct to their team. They have a private bounty program, for a select few.

That this would be the prevailing understanding is exactly why a bug like this would live in the wild at all. There are plenty of other orgs out there who would have paid big money for this.
Post reply on HN