Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.
It works remotely if remote login is enable. edit: Screen sharing is is vulnerable not ssh. Either way its bad.
macOS High Sierra: Anyone can login as “root” with empty password
331–340 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#332Should I leave my Mac unattended until this is resolved?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#333I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#334I didn't think the BSD's allowed a blank root password.
At least if it'd been open, maybe someone could have diffed it …
Re: macOS High Sierra: Anyone can login as “root” with empty password
#335Earlier quoted context omitted.
Not the case. Once you enable root access - by 'testing' this - others can remotely & silently access the system as root. GP is right - don't encourage people to test this, as there's nothing to gain from it. If you're on a shared machine you need to mitigate. If you're on your own dedicated machine you need to not share it until this is fixed.
> Once you enable root access - by 'testing' this - others can remotely & silently access the system as root. That's not accurate. The user appears to be there either way, but attempting to log in to a machine remotely using 'root' and no password does not work - even after doing the preference pane thing...
root account is 'there' all the time, yes. This process enables the account proper (rather than just sudo). Evidently some remote mechanisms using root work after the account is enabled.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#336I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
macOS and iOS updates at Apple are now inextricably tied to new iPhone releases. There is a strict yearly deadline that the teams sprint toward, a timeline imposed by marketing rather than readiness. This affects prioritization of which features are pursued, where they lie in the stack, and how polished they get. Insufficient testing at today's Apple is not limited to software. They bragged about their extensive inpu…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#337I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#338I tried it anyway and it does not work! I'm running version 10.13.1