Earlier quoted context omitted.
I will take malicious improper analogy for 100
Please point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM
macOS High Sierra: Anyone can login as “root” with empty password
141–150 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#142Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#143Re: macOS High Sierra: Anyone can login as “root” with empty password
#144Classical click and bait title. First promises that you'll become a hacker, and then when you actually click the tweet is deleted.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#145Re: macOS High Sierra: Anyone can login as “root” with empty password
#146While this true, please keep in mind that rebooting your Mac into single user mode also allows anybody to login as root
Re: macOS High Sierra: Anyone can login as “root” with empty password
#147Earlier quoted context omitted.
Probably could still get 15 minutes of fame if you disclosed privately then blogged about the back and forth and a picture of the $10,000 cheque from Apple.
Apple doesn't pay bounties for this sort of report, even if direct to their team. They have a private bounty program, for a select few.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#148Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs.
Let's hope Apple gets sued for the damage they'll cause by including this bug in High Sierra so they make sure that next release of macOS won't be another bug filled mess.
[1] https://arstechnica.com/information-technology/2017/09/passw...
[2] https://www.macrumors.com/2017/10/05/macos-high-sierra-disk-...
Re: macOS High Sierra: Anyone can login as “root” with empty password
#149Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#150Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure
To whom does he owe that obligation? Apple? The public? Both? Why?