Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

221–230 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#223

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway.

What should be done is that Apple releases fix to this problem.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#224
I wonder who they're going to ask to write a public letter of apology this time.

This isn't just a snarky comment. They have just released the most awfull iOS upgrade for a long time, and now this. Something's messed up, and they better fix it soon.

I've think i've read somewhere they merged the iOS and macOS teams, i suppose the wrong people were promoted during the operation.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#225

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue? I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.

That was my first thought. Based on some bounty reports I've seen recently I would assume at least high five figures.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#226

Are we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM

> Are we really ready for self-driving cars?

Firstly, car automation is machine learning, not programming. Completely incomparable.

Finally, we've known how to prove the absence of bugs for decades. It's not a matter of not knowing how, it's about incentives to do it right.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#227
post #217

Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.

It works remotely if remote login is enable.

edit: Screen sharing is is vulnerable not ssh. Either way its bad.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#228
Fortunately, I'm OK. The latest OS upgrade failed to install and bricked my computer so that no one could log in, let alone root. I was able to restore it using Time Machine but I don't think I'll go through that exercise again for a while yet.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#229

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

Maybe he didn't know about the proper procedures to handle a security vulnerability. You wouldn't have to be a security researcher to discover this bug, and I don't see any indication that he is one.

I would say it's pretty basic common sense, not to publicly announce ANYTHING that could immediately affect millions of people. Unless he's just a sociopath.

From his Twitter account, he's not just some layman stumbling across it.

Agile Software Craftsman, iyzicoder @ http://www.iyzico.com , Founder of Software Craftsmanship Turkey @scturkey, The community guy http://bit.ly/lemiorhan

Re: macOS High Sierra: Anyone can login as “root” with empty password

#230

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.

Yeah that was my thought initially too but there may be invisible ways to leverage an existing root user that we're not aware of. After all, this bug exists...
Post reply on HN