Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

291–300 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#291

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I disagree. Being unaware of the flaw doesn't make you more secure.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#293

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

Full disclosure is also a form of responsible disclosure.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#295
post #217

Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.

>In which case all bets are off anyways How are all bets off if they don't have access to a root user? This isn't Windows we're talking about.

If they have access to the account that is being used normally, they can modify the (user-accessible) settings to trick the user into running malicious code and giving them access (or causing trouble even without access to the root account).

Re: macOS High Sierra: Anyone can login as “root” with empty password

#297
post #277

I tried it anyway and it does not work! I'm running version 10.13.1

I'm using 10.13.1 and it did work for me. You have to first fail a login in one of these dialogs (did it with my current user and no password) before doing root with no password.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#298
post #225

Earlier quoted context omitted.

That was my first thought. Based on some bounty reports I've seen recently I would assume at least high five figures.

Ouch. This guy's going to kick himself pretty hard. The 15 minutes of infamy seems like a pretty bad tradeoff.

Do you honestly believe Apple will pay out the same to someone located in Turkey?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#299
post #217

Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.

nope. you can log in at the login screen, it creates a new root admin user

Missed that part in the text, thanks.

Yikes!

Re: macOS High Sierra: Anyone can login as “root” with empty password

#300
I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state.

But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

Post reply on HN