Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

311–320 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#312

Earlier quoted context omitted.

If that were true, then the security community wouldn't have spent years fighting about whether responsible disclosure was the right approach. That's for people who actually understand this stuff. It's unreasonable to expect an outsider to derive it all on their own from first principles.

So someone stumbles upon a lost cache of chemical weapons. Rather than reporting to the authorities, they post its location on Twitter. That's called just using your brain.

Security though obscurity is no security at all. Don't you think the people living around the chemical weapons should be informed too so they can take precautions to protect themselves?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#314

Apple has a serious software quality problem. Last night I was helping a friend with their computer. Safari couldn't even render apples website correctly. Nor could Safari connect to any site with HTTPS. Installed FireFox and HTTPS sites worked and apples's site renders. But the submit button on their developer site is broken[1]. Mail on my Mom's fully updated laptop crashes every time it's opened. Once I reported a…

Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

> Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

In my personal experience Windows has been much better than MacOS for me. I've been using Windows 7 for the last year at work and I'm having significantly less problems with Windows then MacOS. But Windows and MacOS both give me more problems then a FreeBSD or Linux box ever has.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#315
How can one of the most wealthy companies on the planet, that every single software engineer would kill to work for, manage to have a bug like this?

Maybe they need to re-think their hiring process, because clearly something is not working as it should.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#316

Apple has a serious software quality problem. Last night I was helping a friend with their computer. Safari couldn't even render apples website correctly. Nor could Safari connect to any site with HTTPS. Installed FireFox and HTTPS sites worked and apples's site renders. But the submit button on their developer site is broken[1]. Mail on my Mom's fully updated laptop crashes every time it's opened. Once I reported a…

Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

Silverlight was EOL'd five years ago.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#317

Earlier quoted context omitted.

The issue is that the bug leaves a password-less root account available through other means as well. Once you try to reproduce the bug, an attacker could potentially do a remote root login without password. As such, it's very dangerous for people to try to verify and should be strongly discouraged.

If you have remote login enabled does root/no password not work already because of the bug? It apparently does from the login screen if you have username/password mode on, so I wouldn't be surprised if it worked over remote login by default.

Does not work via ssh or screen sharing based on my testing here. Seems to require physical access to the machine.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#318

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

iTunes had QA problems for more than 10 years, only the early versions were really solid. I am not sure that it is a recent problem.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#319

Earlier quoted context omitted.

this is too serious to hide. better to tell users how to fix it than wait until apple releases something

That's not how responsible disclosure works.

But it's how full disclosure works which is more responsible then coordinated disclosure.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#320

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

Yes, but the most secure thing to do at this point _is_ to recreate the bug and then set a password for the root user.

Otherwise the hole is still there for others to exploit.

Post reply on HN