Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464
It's worse than that. You're enabling the root user EVERY time you use this vulnerability. Even if you disable the root user in Directory Utility, logging in with root and no password will re-enable the root user.
macOS High Sierra: Anyone can login as “root” with empty password
151–160 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#152Earlier quoted context omitted.
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.
The main question that should be asked is, how did this get overlooked? How is it that your average website has better password security than the OS of one of the richest tech companies in the world?
To be fair to Apple, Microsoft had similar issues back in the 1990s. Perhaps it takes a string of security blunders for some tech companies to take security seriously.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#153Re: macOS High Sierra: Anyone can login as “root” with empty password
#154Re: macOS High Sierra: Anyone can login as “root” with empty password
#155Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#156Earlier quoted context omitted.
The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.
Wrong. This is Apple -- not the homeowners -- leaving everyone's key in everyone's door without them knowing.
You would hope the self-described twitter bio "Agile Software Craftsman" might have thought about this a little before tweeting.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#157Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#158Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
Exactly my thoughts. I remember this, I think even early versions of WinXP had this feature.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#159Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464
It's worse than that. You're enabling the root user EVERY time you use this vulnerability. Even if you disable the root user in Directory Utility, logging in with root and no password will re-enable the root user.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#160Earlier quoted context omitted.
I will take malicious improper analogy for 100
Please point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM
By your logic, we should not fly any modern commercial or military aircraft or spacecraft, live within a certain radius of any power or hazardous chemical plant, place any dependency on any first world country's health care network, including life support, or invest in any company or stock.
Like most things in life it comes down to a security/convenience risk/benefit compromise.