Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

181–190 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#181

Earlier quoted context omitted.

Please point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM

These companies have completely different operating systems, network ACLs, software update policies and subsystems that affect certain mechanical features. By your logic, we should not fly any modern commercial or military aircraft or spacecraft, live within a certain radius of any power or hazardous chemical plant, place any dependency on any first world country's health care network, including life support, or inve…

> These companies have completely different operating systems, network ACLs, software update policies and subsystems that affect certain mechanical features.

Are you claiming that this could not have happened with Tesla? If so, please explain why.

> By your logic, we should not fly any modern commercial or military aircraft or spacecraft, live within a certain radius of any power or hazardous chemical plant, place any dependency on any first world country's health care network, including life support, or invest in any company or stock.

Up until now the benefits have clearly outweighed the risks, but that does not mean it will continue to do so.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#182
post #51

Earlier quoted context omitted.

I will take malicious improper analogy for 100

Please point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM

This is a much more interesting comment than your initial quip. Next time, consider leading with this rather than unnecessarily antagonizing people.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#185
Looks like changing root’s password blocks the exploit but if you disable the root user, it re-enables the exploit.

Protect yourself by changing root’s password: ⌘ (Command) + Space, Directory Utility, click the lock and enter your password, Edit -> Change Root Password…, then do NOT disable Root User.

Or open a terminal and do:

    sudo passwd

Re: macOS High Sierra: Anyone can login as “root” with empty password

#186

Are we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM

As a programmer, the thought terrifies me.

Could a programmer be held liable for any bad outcomes?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#187

Are we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM

I think the question you're fundamentally asking is "are we ready for imperfect systems with potential vulnerabilities?", and the answer to that question has been the same since the advent of software.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#189

Earlier quoted context omitted.

I believe hitting "cancel" was enough. https://www.youtube.com/watch?v=DE5PRW-AR7Q Also reminds me of https://youtu.be/BVL8_ne4WZo?t=19s

from the only top-level comment on that video: > That isn't a login screen for Windows 98, it's a login for Microsoft Networking (which the box shows). If you had any shared mapped drives, network privileges, etc they wouldn't work if you cancelled. If you had multiple profiles set up, you wouldn't get those either. Win98 wasn't intended to have password security.

Good point. Been a while. Windows 7 also has/had an interesting one https://www.youtube.com/watch?v=zwO4YqSc4XE but it's much more involved.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#190
post #102

Earlier quoted context omitted.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.

Let's say keys were hidden around the neighborhood. Would you rather everyone in the whole town know about it or quietly and quickly go pick up all the keys before someone notices and breaks into one of the houses?

Personally I think if you report through the proper channels and nothing is changed THEN broadcast, but not as an opener.

Post reply on HN