Earlier quoted context omitted.
this is too serious to hide. better to tell users how to fix it than wait until apple releases something
Yeh, except for the millions of MacOS users out there, like my parents who don't read Twitter, or HN or any of the other sites people think that everyone stays up on. They are the targets.
macOS High Sierra: Anyone can login as “root” with empty password
201–210 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#202Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
Enables root access in what way?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#203Looks like changing root’s password blocks the exploit but if you disable the root user, it re-enables the exploit. Protect yourself by changing root’s password: ⌘ (Command) + Space, Directory Utility, click the lock and enter your password, Edit -> Change Root Password…, then do NOT disable Root User. Or open a terminal and do: sudo passwd
> click the lock and enter your password or just enter root with no password
Re: macOS High Sierra: Anyone can login as “root” with empty password
#204Re: macOS High Sierra: Anyone can login as “root” with empty password
#205I can't seem to reproduce it locally. 10.13.1… Anyone else having issues? I've upgraded a through a couple versions of OS X on this machine - maybe that makes a difference?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#206Fellow Linux users, please keep the snark in this thread to a minimum. Here's just one recent example why, there are more: http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-log...
Linux != Ubuntu Linux didn't have that problem, a single vendor did. You could say the same for Apple except they are the single vendor. That stupid security trick in Ubuntu only impacts subset of a subset of Linux _desktop_ users which is a pretty small subset of computer users as a whole. When Apple does something like this, it impacts a much larger share of the world population. So how about we keep the snark to a…
So lets keep the snark to an appropriate level, shall we?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#207Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
Enables root access in what way?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#208Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
I was wondering about that. I'm going to change this.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#209Does this effect people who already have a root user with a password set up?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#210Earlier quoted context omitted.
Wrong. This is Apple -- not the homeowners -- leaving everyone's key in everyone's door without them knowing.
Responsible Disclosure is widely regarded as a good practice in these situations. Blame isn't the key issue - fixing the problem quickly and safely is. Widespread disclosure before Apple have even a chance to respond in a timely fashion is inherently unsafe. You would hope the self-described twitter bio "Agile Software Craftsman" might have thought about this a little before tweeting. > https://en.wikipedia.org/wiki/…
Since we're just making up statements, I guarantee that Apple would never voluntarily disclose this issue if it was reported privately. So Full Disclosure is the only way to put Apple's feet to the fire, as it's the only way in which this issue would have had any visibility whatsoever.
https://en.wikipedia.org/wiki/Full_disclosure_(computer_secu...