Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

351–360 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#352
post #264

Earlier quoted context omitted.

Can't repro on a 2012 retina MBP running 10.13.1, attempting the original repro and others suggested here. Until the wife walks away from hers, it's the only machine I have available. I'm curious as to the difference, given the high number of repros.

Apparently you have to have the password field focused before you submit. Anything in the password field (including nothing) will be saved as the root password.

Does it work if you set the root password and try again?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#353

I asked this in the other thread, but... does anyone know how big of a bounty the guy missed by not disclosing this responsibly? I'm guessing it probably would've been a fairly big chunk of change.

Apparently there is no macOS bug bounty: https://twitter.com/i0n1c/status/935608248027303936

Re: macOS High Sierra: Anyone can login as “root” with empty password

#354

Earlier quoted context omitted.

This vulnerability lets users activate the root user without using their password. Once done, you have opened for root without password globally. That's bad. What they should do, as responsible disclosure dictates , is report it in secret to apple, and at most publicize a workaround (activate root user, set password) without reporting the details of the vulnerability . EDIT: It does not appear to be limited to admin…

"responsible disclosure" isn't some morally unassailable high ground, but companies like apple sure want you to believe it is.

Care to explain the comment about Apple? I can think of a few companies (DJI, for example) that try to screw over security researchers, but big IT companies usually don't go on the list.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#355
post #155
post #99

Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.

Did Windows98 even have administrator role? I mean FAT file systems don't even have file ownership right?

It did. But didn't have security tied to the fs.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#356
post #326

AWS ReInvent 2017 is going right now in Las Vegas, the number of attendees is about 40000, and I'm wondering how many laptops can be attacked using this technique. The `root` user stays in the system, so one just need to create it and open SSH quickly, and later they can do whatever they please.

I really hope there's an extra zero in your 40000.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#358

Anyone else think it was a bad idea to disclose this so publicly over Twitter? I thought that the usual practice was to let the development team know first.

Letting the development team know first is nice to the development team, but not so nice to the users (especially not-nice if there's a workaround, which there is in this case.)

My personal policy: If there's a workaround or mitigation, then full disclosure is more responsible. If there isn't then report to developers and CERT or similar. Never report only to developers, always have a deadline for full disclosure, and always have a third-party (CERT, Project Zero, etc) to disclose if you come under legal fire.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#360
post #308

Earlier quoted context omitted.

>In which case all bets are off anyways How are all bets off if they don't have access to a root user? This isn't Windows we're talking about.

If you lose physical control over the machine, all bets are off because an attacker can modify the hardware to do nefarious things.

I know the theory, but practically there's a huge difference between that type of physical access and "the victim left the room to go to the bathroom for 2 minutes" type of physical access
Post reply on HN