Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

31–40 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#32
Apple makes it pretty easy to report vulnerabilities to:

product-security@apple.com

They also respond to security@apple.com but prefer the product-security address.

Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed.

Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even if it is local: think of the impact to shared iMacs on university campuses.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#33
Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#35

Fellow Linux users, please keep the snark in this thread to a minimum. Here's just one recent example why, there are more: http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-log...

Number of mentions of "Linux" outside of your thread comment chain: 0

Re: macOS High Sierra: Anyone can login as “root” with empty password

#39

I just tested this on a Sierra (10.12.6) machine, and verified this bug isn't present in that earlier OSX version.

Same, I'm on 10.12.6, could not reproduce anywhere.

I think I'll hold off on that 10.13.1 "security update" it keeps bugging me about. Seems to let anyone use my computer...

Edit: After looking a little further, it seems staying on Sierra will always be a 10.12.* version, and High Sierra is 10.13.*?

Post reply on HN