Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

371–380 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#371
post #239

Earlier quoted context omitted.

This bug exists regardless of user reproducing it or not. If there is anything good, reproducing it actually brings awareness to the user (make them change the password maybe). Hacker will "enable" the root user anyway. What should be done is that Apple releases fix to this problem.

Not the case. Once you enable root access - by 'testing' this - others can remotely & silently access the system as root. GP is right - don't encourage people to test this, as there's nothing to gain from it. If you're on a shared machine you need to mitigate. If you're on your own dedicated machine you need to not share it until this is fixed.

No, root is root and has always been there. It's the super user account and cannot be removed, I think, from any modern unix like os (well, you can rename it to whatever you want in linux but UID 0 will always be there). The difference might be that if you do log in for the first time you will have lots of stuff on /private/var/root (talking from memory but it was something like that in OSX) and lots of preferences will be set, maybe even a /Users/root folder I hope that the SSH server, which is disabled by default, will also handle root login in a sensible way, but given the size of the f* up, I'm not so sure.

Really bad stuff

Re: macOS High Sierra: Anyone can login as “root” with empty password

#372
post #222

Now that this is public, it's likely worth passing this message on to non-technical folks too (e.g. share this or write a similar post - this is my only public post): https://www.facebook.com/amar.sood/posts/10209545863036116

Important error in your instructions. They should set a very strong password and keep the root account enabled. Disabling the root account opens up the vulnerability again.

Edit: Okay so it seems that my shell based suggestion of `dsenableroot -d` prevents the bug from re-occurring, but not the GUI version. :facepalm:

I updated the post to include the word 'strong', although I would expect most users to simply set their own password, which should provide identical security to what they currently (should) have.

Disabling the root account does not open up the vulnerability again.

This vulnerability doesn't reset the root password, it only enables the root account and checks the password against that. The default root password out of the box on OSX is blank which is what allows this to work as-is.

By setting a root password, the next time you attempt this (and I tried it), the attempt fails since the 'root' account now has a password set.

Disabling simply puts the root account back in a dormant state, where it should be for most users, for after this vulnerability is fixed and it can't be enabled maliciously.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#373

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Is it likely it's just an error due to the discoverer not being immersed in the Infosec space? "Don't disclose a 0-day publicly" is good 'common' sense, but only among the 'common' of people who are steeped in security issues and the ramifications of publicizing them.

That is not the case among infosec professionals either. Many respected professionals believe that the right thing to do in many cases is full public disclosure. Google Project Zero are a notable example.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#374

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

It can already be activated remotely:

https://gfycat.com/gifs/detail/sentimentalnaiveantelopegroun...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#375

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

No clues from me, but the problem is undeniable. Their stuff just does not work well anymore, and it has been so for a while now.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#376
post #101

Earlier quoted context omitted.

It's worse than that. You're enabling the root user EVERY time you use this vulnerability. Even if you disable the root user in Directory Utility, logging in with root and no password will re-enable the root user.

You can simply set a root password with "sudo passwd" to close the hole.

Then you better remember the password you set, or be sure that you will always have sudo access.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#377
post #326

AWS ReInvent 2017 is going right now in Las Vegas, the number of attendees is about 40000, and I'm wondering how many laptops can be attacked using this technique. The `root` user stays in the system, so one just need to create it and open SSH quickly, and later they can do whatever they please.

Unlikely any AWS imaged employee MacBooks at least. AWS IT back in the beginning of October forbade employees to not upgrade to High Sierra.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#378
1. Ensure you always have FileVault enabled (you should regardless) and shutdown after work until the bug is fixed.

2. Add a complex root passphrase and clean this up after the fix is released.

3. Reflect on how irresponsibly this serious security bug was ‘reported’, he didn’t just potentially miss out on $200,000, he put an enormous number of people at risk of local intrusions when instead if it was properly reported there’s a good chance Apple would have released a bug fix for this quicker thus reducing the potential impact and spread of misinformation.

https://en.m.wikipedia.org/wiki/Responsible_disclosure

https://support.apple.com/en-au/HT201220 (See ‘Security and privacy researchers’)

Re: macOS High Sierra: Anyone can login as “root” with empty password

#379

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed.

Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the process.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#380
post #225

Earlier quoted context omitted.

Does anybody have any info on how much Apple would've been likely to pay for a responsible disclosure in this case, given the scope and severity of the issue? I'm just curious how much of a payday this guy missed out on by not disclosing responsibly.

That was my first thought. Based on some bounty reports I've seen recently I would assume at least high five figures.

For a local root with physical access? Not a chance. Maybe low 4 figures.
Post reply on HN