Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

251–260 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#251
post #217

Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.

an unlocked computer, or:

* a computer with remote login enabled

* a computer with the main login screen set to "username and password" mode

* a computer with a guest account

Re: macOS High Sierra: Anyone can login as “root” with empty password

#253

I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.

Most likely another from of bikeshedding; people don't have real input on the main matter, so they comment on circumstantial matters just so they can throw in their 2c

Re: macOS High Sierra: Anyone can login as “root” with empty password

#254
post #222

Now that this is public, it's likely worth passing this message on to non-technical folks too (e.g. share this or write a similar post - this is my only public post): https://www.facebook.com/amar.sood/posts/10209545863036116

Important error in your instructions. They should set a very strong password and keep the root account enabled. Disabling the root account opens up the vulnerability again.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#255

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

I get it, I really do, but it's not like he was complaining about a bad Uber driver. Disclosure in this way has real-world impacts up to and including harming people and we shouldn't ever consider it as something which is remotely acceptable. Is it acceptable to publicly disclose that an airport has a self-destruct switch which can be accessed near the NW mens bathroom? No. You contact someone who can fix the problem…

But everyone can fix this problem by setting a root password. So telling everyone is the right call. Otherwise people would be sitting vulnerable while Apple comes up with a patch.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#257
post #217

Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.

It requires the attacker to be able to type a few characters into a logged in session. If the session is not an administrative one, it's not fair to say all bets were off. If I give you a Mac logged in with an unprivileged account and you can use only the keyboard and mouse to gain root access, the security has failed. I think you've conflated this with the attacker having (full) physical access to the machine, which…

Fair point, if that works with a guest account.

I was thinking along the lines of, if I have write access to your .bashrc (or a multitude of other config files that you as an unprivileged user have write access to, and can be used to trick you later into running code of my choosing), all bets are off.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#258

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Let's wait until Apple release their patch so we know just how long they left everyone's machines vulnerable for. That will be a factor in determining whether this disclosure was irresponsible or not. It's been two and a half hours so far.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#259
Reminds me of an exploit back in 10.7 where you could create a new admin privileged user from a non-admin account using some bash commands. Used that to add Xcode to my work computer at college so I could fool around with learning how to code when I was at work.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#260
post #225

Earlier quoted context omitted.

Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue? I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.

That was my first thought. Based on some bounty reports I've seen recently I would assume at least high five figures.

Ouch. This guy's going to kick himself pretty hard. The 15 minutes of infamy seems like a pretty bad tradeoff.
Post reply on HN