Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

321–330 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#321
post #296

These bugs are getting ridiculous. With Apple's budget, finding such bugs in a security architecture review or just in QA should be as easy as 1+2+3.

> 1 + 2 + 3

https://www.macrumors.com/2017/10/24/ios-11-calculator-anima...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#322

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

> Anyone got any inside scoop?

I have a feeling that anyone who does would get fired for commenting here about it.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#323

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

You could let them know about the vulnerability and wait until it's been patched before commenting, with some timeout where if they don't patch in a reasonable amount of time you announce it anyway.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#324

Earlier quoted context omitted.

This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.

This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…

I run as a standard user and was able to reproduce the bug.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#325

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

I'm going back to Windows after a 10 year hiatus. Mac has definitely declined.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#326
AWS ReInvent 2017 is going right now in Las Vegas, the number of attendees is about 40000, and I'm wondering how many laptops can be attacked using this technique. The `root` user stays in the system, so one just need to create it and open SSH quickly, and later they can do whatever they please.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#327

Earlier quoted context omitted.

This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.

This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…

"responsible disclosure" isn't some morally unassailable high ground, but companies like apple sure want you to believe it is.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#328

Earlier quoted context omitted.

The issue is that the bug leaves a password-less root account available through other means as well. Once you try to reproduce the bug, an attacker could potentially do a remote root login without password. As such, it's very dangerous for people to try to verify and should be strongly discouraged.

If you have remote login enabled does root/no password not work already because of the bug? It apparently does from the login screen if you have username/password mode on, so I wouldn't be surprised if it worked over remote login by default.

No, it doesn't work for remote login.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#329
post #224

I wonder who they're going to ask to write a public letter of apology this time. This isn't just a snarky comment. They have just released the most awfull iOS upgrade for a long time, and now this. Something's messed up, and they better fix it soon. I've think i've read somewhere they merged the iOS and macOS teams, i suppose the wrong people were promoted during the operation.

  > They have just released the most awfull iOS upgrade for a
  > long time, and now this. Something's messed up, and they
  > better fix it soon.
I keep seeing this written after each major iOS release sinc at least iOS 7.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#330
post #298

Earlier quoted context omitted.

Ouch. This guy's going to kick himself pretty hard. The 15 minutes of infamy seems like a pretty bad tradeoff.

Do you honestly believe Apple will pay out the same to someone located in Turkey?

I wouldn't think they'd care about the geography of it - a good tip is a good tip, and they want to encourage responsible disclosure.
Post reply on HN