Earlier quoted context omitted.
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.
macOS High Sierra: Anyone can login as “root” with empty password
161–170 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#162Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
I believe hitting "cancel" was enough. https://www.youtube.com/watch?v=DE5PRW-AR7Q Also reminds me of https://youtu.be/BVL8_ne4WZo?t=19s
> That isn't a login screen for Windows 98, it's a login for Microsoft Networking (which the box shows). If you had any shared mapped drives, network privileges, etc they wouldn't work if you cancelled. If you had multiple profiles set up, you wouldn't get those either. Win98 wasn't intended to have password security.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#163Even on El Capitan, I was able to unlock with "root" on my first try. From there, I could add a new admin user. This seems... not good.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#164Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
This vulnerability is ridiculous, unacceptable, and braindead to execute.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#165While this true, please keep in mind that rebooting your Mac into single user mode also allows anybody to login as root
Re: macOS High Sierra: Anyone can login as “root” with empty password
#166Does this effect people who already have a root user with a password set up?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#167Re: macOS High Sierra: Anyone can login as “root” with empty password
#168Earlier quoted context omitted.
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
I get it, I really do, but it's not like he was complaining about a bad Uber driver. Disclosure in this way has real-world impacts up to and including harming people and we shouldn't ever consider it as something which is remotely acceptable. Is it acceptable to publicly disclose that an airport has a self-destruct switch which can be accessed near the NW mens bathroom? No. You contact someone who can fix the problem…
The question is large and complicated, and people can agree to disagree. There's nothing wrong with tweeting vulns: The company is at fault, we can defend ourselves now that we know about the vuln, and it's a big PR disaster for Apple.
A past conversation: https://news.ycombinator.com/item?id=14009937
No, no it's not strictly more ethical. It's not even strictly safer, which should be an even easier question to answer. The baked-in assumption in your logic is that users have no options other than waiting to patch. But, obviously, they do, and keeping vulnerabilities secret deprives them of those options.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#169Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#170This is deeply troubling. How does this even happen?