Live data from Hacker News

macOS lock screen: “I just sent my session pass to my whole team”

twitter.com

241–250 of 276 posts

Re: macOS lock screen: “I just sent my session pass to my whole team”

#241
post #238

Earlier quoted context omitted.

> isn't immune Why all-or-nothing? The fact is that free software has transparency as one of its advantages. When software is closed-source, its users must rely on the developers to maintain that software.

I completely agree it is an advantage and I'm very happy there are options that are mostly Open Source (I say mostly because I'm not a fan of binary drivers, which are often a necessity for decent performance or features). > Why all-or-nothin? The parent was citing the existence of a few specific bugs in macOS and Open Source as an alternative (implying it wasn't vulnerable). I really think the "given enough eyeballs…

> too much comfort

That may be true, but the alternative is certainly worse.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#242
post #215

Earlier quoted context omitted.

No, I mean complete GUI heads: completely separate GUI login sessions which use the same screen and can be switched between. Also called 'virtual framebuffers,' I think. Very awesome. I'm sure that Macs support something similar.

macOS has something called Fast User Switching, which is completely separate login sessions, but you access it through a menu on the right side of the menubar, not with keys. macOS also has Spaces, which is just virtual desktops, but again, it doesn't use the F-keys to switch between them.

I'm strongly reading GP comments as trolling, given indirect context, but I respect your approach of taking the high road by assuming simple ignorance.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#243

Earlier quoted context omitted.

Yeah, but if you can make $300k a year, you're likely not dedicating your software engineering career to fixing bugs. Also, you can go a few miles south to Los Gatos and work at Netflix and make $400k/year.

$400k/year? is that for Principal Engineers and Directors? What would a senior eng make there?

I think that's for Sr. Engineers++. What I heard is that they do an all in compensation plan so your equity, bonus, and salary are all rolled into your salary and then you decide what you want to do with it. On Glassdoor that doesn't seem to match what I was told though.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#244

Earlier quoted context omitted.

If someone is good and can't get a Visa to move to the U.S. more money won't help that either.

Money can buy a new engineering office in a more immigration-friendly country.

You're right, but Apple doesn't work like that. They just spent 5 billion dollars on Apple Park attempting to put everyone under one roof. I don't think it's in Apples corporate DNA to outsource core components of their operating system to a more immigration-friendly country.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#245
post #126

Earlier quoted context omitted.

No -- I don't know him personally -- but I would guess that he thinks it's a pile of amoral greed-heads and ignorant children.

Well, he isn't exactly wrong. But redirecting like that is pretty immature in itself.

I agree. He could just redirect to a blank page but this puts him in a really bad light. I wouldn't care except I frequently browse HN at work when I'm getting settled in in the morning.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#246
post #205

Earlier quoted context omitted.

This topic is about keyboard input focus. Yes, and the SAS guarantees that after you enter it, nothing else can have keyboard focus. I don't see why this is such a controversial point. You will never come to unlock your NT workstation and find that the keyboard focus is somewhere you don't expect, because you need to enter the SAS first.

> I don't see why this is such a controversial point. Because It's untrue. The SAS is a sanity check. If something is spoofing a login screen on your desktop and you press CTRL+ALT+DEL, you will get a system menu instead of a password prompt. If you are in the login screen, which is able to hook CTRL+ALT+DEL, it will switch to the password prompt. Here's the clincher: even if you have the SAS disabled (which it is by…

Normal apps can't, but it is possible to access other desktops, such as the login screen, from a system service. I work on software that does it

Re: macOS lock screen: “I just sent my session pass to my whole team”

#247

Earlier quoted context omitted.

Responsible disclosure is about preventing the bug from being exploited before it can be fixed. Knowing about this bug doesn't help me compromise someone else, but it does help me avoid getting compromised.

> but it does help me avoid getting compromised Only by casual hackers. The pros will probably have been exploiting the flaw for weeks or months against gainful targets. If there is a reasonable end-user workaround against the vulnerability then I'd argue it's more responsible to publish early and widely than to wait for the vendor. It becomes greyer if there is no workaround. I'm not sure what I'd support in that ca…

The compromise is that I accidentally type my password into Slack and send it out to everyone in the building. There is no hacker involved in this one, and I can fully protect myself by ensuring that my password is going into the password field.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#248

Earlier quoted context omitted.

Responsible disclosure is about preventing the bug from being exploited before it can be fixed. Knowing about this bug doesn't help me compromise someone else, but it does help me avoid getting compromised.

So, security through obscurity. No thanks. I'd rather know about the exploit ASAP so I can implement a workaround, rather than wait months for the vendor to get off their ass while my systems are getting hacked by the hundreds if not thousands of hackers that have 0-day knowledge. Calling what you describe as "Responsible" is intellectually dishonest.

What do you think it is that I'm calling responsible? I'm in favor of the public disclosure for this particular bug, and that seems to be your position too.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#249

Earlier quoted context omitted.

Especially here, where it’s (probably?) not remotely exploitable.

Having your password in some IRC channel gets remotely exploitable quickly.

No, because if you type in your pw, it will show as stars ;-)

Re: macOS lock screen: “I just sent my session pass to my whole team”

#250
post #188

Earlier quoted context omitted.

Yes because I'm sure those same people are also able to work on security.

Someone made the decision, this year we will hire X number of security engineers and Y number of poop animators. Ultimately that guy is Tim Cook.

[deleted]
Post reply on HN