I initially saw this thinking it didn't affect Sierra or High Sierra.
macOS High Sierra: Anyone can login as “root” with empty password
271–280 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#272Earlier quoted context omitted.
This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.
This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…
Somebody in Turkey has no expectation that they will be treated with respect. It's much more likely they will be attacked as in "shoot the messenger." (So, please don't attack the person who brought this to our attention.)
I think they made a reasonable decision, due to the critical nature of this bug, and tweeted about it.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#273Re: macOS High Sierra: Anyone can login as “root” with empty password
#274Should I leave my Mac unattended until this is resolved?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#275Earlier quoted context omitted.
Yeah that was my thought initially too but there may be invisible ways to leverage an existing root user that we're not aware of. After all, this bug exists...
The issue is that the bug leaves a password-less root account available through other means as well. Once you try to reproduce the bug, an attacker could potentially do a remote root login without password. As such, it's very dangerous for people to try to verify and should be strongly discouraged.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#276Earlier quoted context omitted.
I would say it's pretty basic common sense, not to publicly announce ANYTHING that could immediately affect millions of people. Unless he's just a sociopath. From his Twitter account, he's not just some layman stumbling across it. Agile Software Craftsman, iyzicoder @ http://www.iyzico.com , Founder of Software Craftsmanship Turkey @scturkey, The community guy http://bit.ly/lemiorhan
If that were true, then the security community wouldn't have spent years fighting about whether responsible disclosure was the right approach. That's for people who actually understand this stuff. It's unreasonable to expect an outsider to derive it all on their own from first principles.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#277Re: macOS High Sierra: Anyone can login as “root” with empty password
#278Re: macOS High Sierra: Anyone can login as “root” with empty password
#279Why is this so far down the front page? Are people flagging it for some reason?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#280Title should be changed to 'macOS' I initially saw this thinking it didn't affect Sierra or High Sierra.