Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

21–30 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#22
post #13

Can this be used remotely? Edit: Yes, after turning on Remote Management on my second mac I was able to log into it using Remote Desktop, account root and no pw. It only works after getting physical access once.

Been wondering that myself since it seems that this also happens with the login screen.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#24
wat. confirmed on 10.13.1 (17B48). I was even able to add another super user.

Edit: changing the login method to "Name and password" under login options, then logout and login with "root" with empty password also works.

Fortunately, it doesn't work on cold boot with FileVault enabled, at least it doesn't appear so. `sudo su root` also doesn't work with an empty password.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#25
post #2

Confirmed that root with no password unlocks the preferences pane. But, changing the require password after screen saver setting doesn't take effect. So, it seems to be a bug in the UI not an actual vulnerability. edit: I stand corrected. The 'require password' setting under Security Preferences didn't change, but other settings do. Yikes

10.13.1 can't make it happen

Re: macOS High Sierra: Anyone can login as “root” with empty password

#26

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

Someone notices that they can log in as root with no password. In 2017, reflexively tweeting about it seems pretty unsurprising.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#28

Fellow Linux users, please keep the snark in this thread to a minimum. Here's just one recent example why, there are more: http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-log...

Linux != Ubuntu

Linux didn't have that problem, a single vendor did. You could say the same for Apple except they are the single vendor. That stupid security trick in Ubuntu only impacts subset of a subset of Linux _desktop_ users which is a pretty small subset of computer users as a whole. When Apple does something like this, it impacts a much larger share of the world population.

So how about we keep the snark to an appropriate level based on the impact to the world population? ;)

Re: macOS High Sierra: Anyone can login as “root” with empty password

#30

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

I think the difference is if the problem is discovered by Joe Schmoe or a security researcher.
Post reply on HN