Live data from Hacker News

About the security content of Security Update 2017-001

support.apple.com

31–40 of 158 posts

Re: About the security content of Security Update 2017-001

#31
post #23

"Description: A logic error existed in the validation of credentials. This was addressed with improved credential validation." I hope they won't stop to this brief summary, because a "logic error in the validation of credentials" shouldn't be able to allow the creation of a root super user with empty password. I'm hope they'll go deep in the gory details, to show us how it's in fact much more complicated than a "if !…

The user root always existed as a disabled user. The problem was that the logic error (whatever it was) resulted in the user being enabled.

Re: About the security content of Security Update 2017-001

#32
post #19

Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??

Once the exploit is done (clicking the unlock button w/ the user root on the settings pane), the root account is setup with a blank password. At this point any remote access methods that use the accounts on the system should allow access. Depending on SSH config, root may be disallowed.

I've seen rumors otherwise, but until someone with experience verifies those pathways I can only guess.

Re: About the security content of Security Update 2017-001

#33

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

> We are auditing our development processes to help prevent this from happening again. That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?

It sound to me like the "development process" points to the whole soup-to-nuts system.

From "brainstorming" and new feature development, to development, to testing, to QA, to deployment.

Re: About the security content of Security Update 2017-001

#34

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.

Re: About the security content of Security Update 2017-001

#36
post #19

Haven't seen this mentioned anywhere so far but this was not a remote vulnerability right? Only from login screen, right !! ??

I read that it worked even with Remote Management and Screen Sharing. https://twitter.com/voretaq7/status/935609138725425153

Re: About the security content of Security Update 2017-001

#37

Earlier quoted context omitted.

> We are auditing our development processes to help prevent this from happening again. That's great to hear even if it took multiple stumbles for them to finally admit - but surely they should be also audit their QA/testing processes? Or does development in AppleSpeak mean everything?

It sound to me like the "development process" points to the whole soup-to-nuts system. From "brainstorming" and new feature development, to development, to testing, to QA, to deployment.

If so, that's going to be a big undertaking :)

Re: About the security content of Security Update 2017-001

#39

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.

The ability to write is largely ignored at tech firms these days. Grammar is viewed as a bunch of stodgy rules to be ignored at will. Some are indeed silly throwbacks, but the basic structures are what allow us to communicate effectively. Drop them and errors in understanding creep into nearly every email.

Yesterday I had a back-and-forth with a boss over "login", "log in", "log in to" and "log into". That might seem silly but little things really do matter. (fyi, login = noun. Log in = verb. We never settled on 'into' or 'in to'.)

Re: About the security content of Security Update 2017-001

#40

See Apple's comment on this, given to BuzzFeed I assume: https://twitter.com/JohnPaczkowski/status/935909264362586112 / https://www.buzzfeed.com/josephbernstein/apple-released-a-pa... "Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS. When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes…

Off-topic, but it blows my mind how poorly proofread many articles are nowadays. In this example, there's a 3-word sentence fragment - "That login gave" - hanging out in between two other sentences. If the author even read what he'd written once before posting, he ought to have caught that.

I'm no journalist, but I guess that being first to report is more important than minor errors in the article.
Post reply on HN