Live data from Hacker News

Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

support.apple.com

31–40 of 49 posts

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#31

I seriously can't imagine how much pressure engineers at Apple were to ship this patch. Considering they tend to ship infrequently, I doubt they have the sort of QA turn-around that'd support emergency releases. Remember that: - They learned about this yesterday - They had as much heads up as the general public did - They are a large company. I don't disagree that the apparent QA quality from Apple software isn't wha…

The thing that really shocks me about this incident is that, basically checking that "root cannot be logged in under any unusual circumstances" is a fundamental, basic test of any OS development group, and there must have been at least 2 decades of this test running somewhere internally at Apple, and .. somehow .. thats not happening.

Like, I seriously hope this was just an oversight in the testing system somehow - but I'm really rather concerned that Apple is not testing these things as rigorously as it should be/used to be.

This is such a fundamentally corrupt security issue that we all have to increase our levels of suspicion over the QA team at Apple. Truly a shocking hole.

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#32
post #25
post #19

Earlier quoted context omitted.

High Sierra bricked my 2010 iMac. Haven’t even bothered to try and repair it. It shipped with one of those crappy slow HD’s Apple used to save money.

Expecting a 2010 Mac to work with 2017 software (which I infer from your bothering to post here) seems a bit of a stretch. And all hard drives were slow back then. Any variance between models then is lost in the noise when comparing against SSDs, which were not generally available in 2010. But it should definitely refrain from bricking the machine... that’s a bummer.

Apple list 2009 iMacs as compatible with High Sierra so I don’t think it’s a stretch to expect it to work, no.

https://www.apple.com/macos/how-to-upgrade/#hardware-require...

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#33
post #29

The article says “ if file sharing doesn’t work”, but is it ok to just run this command line fix anyway? I’m not sure if file sharing is broken for me. I don’t use it right now . But I’m afraid I might run into this bug in the future when I eventually use file sharing, and then I will have forgotten about this fix, and end up spending hours scratching my head and head-desking.

My thoughts exactly. I executed it just in case.

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#34
post #24

Earlier quoted context omitted.

I feel bad for the engineers, but seriously screw Apple on this. They have an overcomplicated setup with little internal Kerberos implementations on every Mac to make peer to peer networking easier. If it’s like everything else, it’s probably ancient and crufty. The dude who wrote it probably cashed out years ago. Some engineer rushed through and made the original worst-case-scenario error, and the guys cleaning up t…

I designed and implemented quite lot of the LocalKDC mechanism - um, roughly about 11-12 years ago now I think. At the time it was based on the MIT version of Kerberos. When Apple switched to using Heimdal, the LocalKDC implementation was updated and it has been maintained since then - I am no longer the maintainer of this software. I haven't cashed out. As to why the LocalKDC exists? How can you do secure peer-to-pe…

> Apple iOS Security Guide

that goes perfectly with the trending feeling that iOS gets all the love while OSX sits on the back burner.

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#35
post #24

Earlier quoted context omitted.

I designed and implemented quite lot of the LocalKDC mechanism - um, roughly about 11-12 years ago now I think. At the time it was based on the MIT version of Kerberos. When Apple switched to using Heimdal, the LocalKDC implementation was updated and it has been maintained since then - I am no longer the maintainer of this software. I haven't cashed out. As to why the LocalKDC exists? How can you do secure peer-to-pe…

> Apple iOS Security Guide that goes perfectly with the trending feeling that iOS gets all the love while OSX sits on the back burner.

I personally see that the mac is getting lots and lots of love! Not my place to say more than that.

I pointed to this resource due to the concern expressed about iOS.

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#36
post #25
post #19

Earlier quoted context omitted.

High Sierra bricked my 2010 iMac. Haven’t even bothered to try and repair it. It shipped with one of those crappy slow HD’s Apple used to save money.

Expecting a 2010 Mac to work with 2017 software (which I infer from your bothering to post here) seems a bit of a stretch. And all hard drives were slow back then. Any variance between models then is lost in the noise when comparing against SSDs, which were not generally available in 2010. But it should definitely refrain from bricking the machine... that’s a bummer.

I've got Windows 10 installed and working on a 2006 MacBook 1,1. It just got an update to 1709 Fall Creators Update, and still gets the usual weekly security patches. Something is awry when Microsoft is able to provide support & security patches for Apple devices longer than Apple itself.

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#37
post #17

Earlier quoted context omitted.

The fact they learned this only yesterday is amazingly stupid to start with. People were talking about this weeks ago on the Apple Forums, as a "neat trick" : https://twitter.com/fristle/status/935670476214378496 . Surely a moderator should have noticed something was wrong at that point. This is a major fuckup the kind of which should be illegal.

> People were talking about this weeks ago on the Apple Forums, as a "neat trick" Aren't Apple forums mostly meant as self-help forums, with minimal monitoring by Apple? It looks like one person posted it two weeks ago, not as a bug or security problem but as a solution to the problem that the original poster had, not realizing it was a bug. People didn't seem to notice it and start talking about it there until yeste…

I agree with you, but I'm also curious if the techniques that are making progress in other areas (e.g. machine learning) could be used to extract meaningful data from these forums. Most bugs won't be as obvious as "login as root without password" but I imagine there is substantial signal within the noise.

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#38
post #25
post #19

Earlier quoted context omitted.

High Sierra bricked my 2010 iMac. Haven’t even bothered to try and repair it. It shipped with one of those crappy slow HD’s Apple used to save money.

Expecting a 2010 Mac to work with 2017 software (which I infer from your bothering to post here) seems a bit of a stretch. And all hard drives were slow back then. Any variance between models then is lost in the noise when comparing against SSDs, which were not generally available in 2010. But it should definitely refrain from bricking the machine... that’s a bummer.

It’s supported so it’s not a bit of a stretch.

SSD’s were generally available but extremely expensive from Apple so I went for the extra space on the desktop. For some reason Apple makes it difficult to upgrade their hard drives. I bought an SSD MacBook Pro at the same time. It was much faster with only a Core i5 vs the iMac’s i7. Barely used now because I bought another laptop in 2013.

Now, I wanted to wait for the next Intel refresh. No point in getting less than 32GB in a laptop in 2018 when I got 16gb in 2013. Because of the slow change in Intel revs, I’m probably better off cracking open my 2010 iMac and putting in an SSD.

Hey, thanks for taking me back and explaining how it was “back then”. I miss the late 90’s back then when I spent $800 on several hundred megabytes of 10,000 rpm Cheetah SCSI drive, and had that thing screwed in within 5 minutes.

The bottom line is you will basically live with your Apple hardware as you bought it for 5-10 years. Better buy at the proper Intel revision and get the upgrades at purchase. That 1 port on your new MacBook Pro won’t go far

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#39
post #29

The article says “ if file sharing doesn’t work”, but is it ok to just run this command line fix anyway? I’m not sure if file sharing is broken for me. I don’t use it right now . But I’m afraid I might run into this bug in the future when I eventually use file sharing, and then I will have forgotten about this fix, and end up spending hours scratching my head and head-desking.

According to configureLocalKDC(1):

"The script is non-destructive and can be run multiple times."

Re: Repair file sharing after Security Update 2017-001 for macOS High Sierra 10.13.1

#40
post #17

Earlier quoted context omitted.

The fact they learned this only yesterday is amazingly stupid to start with. People were talking about this weeks ago on the Apple Forums, as a "neat trick" : https://twitter.com/fristle/status/935670476214378496 . Surely a moderator should have noticed something was wrong at that point. This is a major fuckup the kind of which should be illegal.

> People were talking about this weeks ago on the Apple Forums, as a "neat trick" Aren't Apple forums mostly meant as self-help forums, with minimal monitoring by Apple? It looks like one person posted it two weeks ago, not as a bug or security problem but as a solution to the problem that the original poster had, not realizing it was a bug. People didn't seem to notice it and start talking about it there until yeste…

On one part, I agree. On another, Average DevJoe on the Apple dev forums knew about it two weeks ago. It's scary to think about how many bad actors have known about it, and might have weaponized it given it is wormable, during that timeframe.
Post reply on HN