macOS High Sierra: Anyone can login as “root” with empty password
21–30 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#22Can this be used remotely? Edit: Yes, after turning on Remote Management on my second mac I was able to log into it using Remote Desktop, account root and no pw. It only works after getting physical access once.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#23Re: macOS High Sierra: Anyone can login as “root” with empty password
#24Edit: changing the login method to "Name and password" under login options, then logout and login with "root" with empty password also works.
Fortunately, it doesn't work on cold boot with FileVault enabled, at least it doesn't appear so. `sudo su root` also doesn't work with an empty password.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#25Confirmed that root with no password unlocks the preferences pane. But, changing the require password after screen saver setting doesn't take effect. So, it seems to be a bug in the UI not an actual vulnerability. edit: I stand corrected. The 'require password' setting under Security Preferences didn't change, but other settings do. Yikes
Re: macOS High Sierra: Anyone can login as “root” with empty password
#26Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure
Re: macOS High Sierra: Anyone can login as “root” with empty password
#27Re: macOS High Sierra: Anyone can login as “root” with empty password
#28Fellow Linux users, please keep the snark in this thread to a minimum. Here's just one recent example why, there are more: http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-log...
Linux didn't have that problem, a single vendor did. You could say the same for Apple except they are the single vendor. That stupid security trick in Ubuntu only impacts subset of a subset of Linux _desktop_ users which is a pretty small subset of computer users as a whole. When Apple does something like this, it impacts a much larger share of the world population.
So how about we keep the snark to an appropriate level based on the impact to the world population? ;)
Re: macOS High Sierra: Anyone can login as “root” with empty password
#29I guess they were more focused in introducing bugs and less performant filesystem than security in High Sierra.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#30Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure