Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

141–150 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#141
post #51

Earlier quoted context omitted.

I will take malicious improper analogy for 100

Please point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM

[deleted]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#142

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's not local if you have Remote Desktop enabled. Works over that too. From there you can enable ssh and all bets are off.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#147
post #88

Earlier quoted context omitted.

Probably could still get 15 minutes of fame if you disclosed privately then blogged about the back and forth and a picture of the $10,000 cheque from Apple.

Apple doesn't pay bounties for this sort of report, even if direct to their team. They have a private bounty program, for a select few.

Source? I've heard of iPhone vulnerabilities getting high six figures from Apple (for root access via sms). Why wouldn't Apple pay for something like this?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#148

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple.

This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs.

Let's hope Apple gets sued for the damage they'll cause by including this bug in High Sierra so they make sure that next release of macOS won't be another bug filled mess.

[1] https://arstechnica.com/information-technology/2017/09/passw...

[2] https://www.macrumors.com/2017/10/05/macos-high-sierra-disk-...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#149

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue?

I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#150

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

Where is Joe Random's obligation to responsibly disclose?

To whom does he owe that obligation? Apple? The public? Both? Why?

Post reply on HN