These bugs are getting ridiculous. With Apple's budget, finding such bugs in a security architecture review or just in QA should be as easy as 1+2+3.
macOS High Sierra: Anyone can login as “root” with empty password
321–330 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#322I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
I have a feeling that anyone who does would get fired for commenting here about it.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#323Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#324Earlier quoted context omitted.
This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.
This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#325I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#326Re: macOS High Sierra: Anyone can login as “root” with empty password
#327Earlier quoted context omitted.
This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.
This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#328Earlier quoted context omitted.
The issue is that the bug leaves a password-less root account available through other means as well. Once you try to reproduce the bug, an attacker could potentially do a remote root login without password. As such, it's very dangerous for people to try to verify and should be strongly discouraged.
If you have remote login enabled does root/no password not work already because of the bug? It apparently does from the login screen if you have username/password mode on, so I wouldn't be surprised if it worked over remote login by default.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#329I wonder who they're going to ask to write a public letter of apology this time. This isn't just a snarky comment. They have just released the most awfull iOS upgrade for a long time, and now this. Something's messed up, and they better fix it soon. I've think i've read somewhere they merged the iOS and macOS teams, i suppose the wrong people were promoted during the operation.
> They have just released the most awfull iOS upgrade for a
> long time, and now this. Something's messed up, and they
> better fix it soon.
I keep seeing this written after each major iOS release sinc at least iOS 7.Re: macOS High Sierra: Anyone can login as “root” with empty password
#330Earlier quoted context omitted.
Ouch. This guy's going to kick himself pretty hard. The 15 minutes of infamy seems like a pretty bad tradeoff.
Do you honestly believe Apple will pay out the same to someone located in Turkey?