Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.
macOS High Sierra: Anyone can login as “root” with empty password
221–230 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#222Re: macOS High Sierra: Anyone can login as “root” with empty password
#223Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
What should be done is that Apple releases fix to this problem.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#224This isn't just a snarky comment. They have just released the most awfull iOS upgrade for a long time, and now this. Something's messed up, and they better fix it soon.
I've think i've read somewhere they merged the iOS and macOS teams, i suppose the wrong people were promoted during the operation.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#225Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue? I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#226Are we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM
Firstly, car automation is machine learning, not programming. Completely incomparable.
Finally, we've known how to prove the absence of bugs for decades. It's not a matter of not knowing how, it's about incentives to do it right.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#227Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.
edit: Screen sharing is is vulnerable not ssh. Either way its bad.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#228Re: macOS High Sierra: Anyone can login as “root” with empty password
#229Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
Maybe he didn't know about the proper procedures to handle a security vulnerability. You wouldn't have to be a security researcher to discover this bug, and I don't see any indication that he is one.
From his Twitter account, he's not just some layman stumbling across it.
Agile Software Craftsman, iyzicoder @ http://www.iyzico.com , Founder of Software Craftsmanship Turkey @scturkey, The community guy http://bit.ly/lemiorhan
Re: macOS High Sierra: Anyone can login as “root” with empty password
#230Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.