Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

161–170 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#161
post #102

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

Your analogy makes no sense. He's just as vulnerable as you are.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#162
post #99

Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.

I believe hitting "cancel" was enough. https://www.youtube.com/watch?v=DE5PRW-AR7Q Also reminds me of https://youtu.be/BVL8_ne4WZo?t=19s

from the only top-level comment on that video:

> That isn't a login screen for Windows 98, it's a login for Microsoft Networking (which the box shows). If you had any shared mapped drives, network privileges, etc they wouldn't work if you cancelled. If you had multiple profiles set up, you wouldn't get those either. Win98 wasn't intended to have password security.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#164

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms.

This vulnerability is ridiculous, unacceptable, and braindead to execute.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#167
post #8
post #6

Even on El Capitan, I was able to unlock with "root" on my first try. From there, I could add a new admin user. This seems... not good.

I wasn't able to do it on 10.12.6 (Sierra) though, so perhaps there's something else odd here?

Doesn't work for me either on 10.12.6.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#168

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

I get it, I really do, but it's not like he was complaining about a bad Uber driver. Disclosure in this way has real-world impacts up to and including harming people and we shouldn't ever consider it as something which is remotely acceptable. Is it acceptable to publicly disclose that an airport has a self-destruct switch which can be accessed near the NW mens bathroom? No. You contact someone who can fix the problem…

It's as remotely acceptable as "root" with no password, apparently.

The question is large and complicated, and people can agree to disagree. There's nothing wrong with tweeting vulns: The company is at fault, we can defend ourselves now that we know about the vuln, and it's a big PR disaster for Apple.

A past conversation: https://news.ycombinator.com/item?id=14009937

No, no it's not strictly more ethical. It's not even strictly safer, which should be an even easier question to answer. The baked-in assumption in your logic is that users have no options other than waiting to patch. But, obviously, they do, and keeping vulnerabilities secret deprives them of those options.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#169

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

You can't expect everybody who uses a computer to be aware of that.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#170
post #27

This is deeply troubling. How does this even happen?

All too easily. There's so much to keep track of in modern systems engineering. We should all have a healthy dose of awareness that we could be/create that weakest link even on our best days.
Post reply on HN