Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

211–220 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#213
post #102

Earlier quoted context omitted.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

The problem with that analogy is that the probability that the "bad guys" already know about this vulnerability is vastly higher than the probability that thieves know about how well some random house in the neighborhood is secured.

But do they? And what portion of them do? And are they using it? There's a lot of speculation here. But surely the average person doesn't know and with this being public knowledge, AND easy to execute there is a bigger chance for crime of opportunity.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#214

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

Maybe he didn't know about the proper procedures to handle a security vulnerability. You wouldn't have to be a security researcher to discover this bug, and I don't see any indication that he is one.

Maybe. Look at his twitter page though: https://twitter.com/lemiorhan

Not impossible to believe he's unaware of the right way of handling this kind of issue, but that banner photo (Enthralling My F-ing Audience) [1] and stats there suggest he should be aware that there probably are sensible and polite procedures for this, even if he didn't immediately know what they were.

[1] http://jesuschristsiliconvalley-blog.tumblr.com/post/4653787...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#216
post #51

Earlier quoted context omitted.

I will take malicious improper analogy for 100

Please point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM

How much of that code is safety critical? I occasionally see misbehavior from my Tesla's center screen, like the network connection failing, or audio glitches, or even the occasional spontaneous reboot. This can be mildly annoying but it doesn't worry me because I know that the center screen is separate from the stuff where bugs can actually get me killed.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#218

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

I was wondering about that. I'm going to change this.

Thanks :)

Re: macOS High Sierra: Anyone can login as “root” with empty password

#219
post #214

Earlier quoted context omitted.

Maybe he didn't know about the proper procedures to handle a security vulnerability. You wouldn't have to be a security researcher to discover this bug, and I don't see any indication that he is one.

Maybe. Look at his twitter page though: https://twitter.com/lemiorhan Not impossible to believe he's unaware of the right way of handling this kind of issue, but that banner photo (Enthralling My F-ing Audience) [1] and stats there suggest he should be aware that there probably are sensible and polite procedures for this, even if he didn't immediately know what they were. [1] http://jesuschristsiliconvalley-blog.tumb…

How do the banner or stats suggest he should have known about this?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#220

I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.

> I still can't believe more people complain about this being publicly disclosed than this being possible in the first place.

I think the problem is due to the fact that they are fans. In this case, it's Apple, but there's no reason it couldn't be Linux or Go or whatever. Regardless, any bad news about their hero is irresponsible to disseminate. We see this same phenomenon in politics, in sports and elsewhere — I daresay it's regrettable human nature.

Post reply on HN