Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

41–50 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#41
post #13

Can this be used remotely? Edit: Yes, after turning on Remote Management on my second mac I was able to log into it using Remote Desktop, account root and no pw. It only works after getting physical access once.

Yes, I just had a coworker test it after I enabled remote management and they used screensharing.app. I didn't even get notified a user remoted in.. never used screen share, that seems awful. Had to look over and ask if he was in.

edit: I should say, I did test this locally first so I don't know if a fresh machine that hasn't done it will do the same thing and let a remote account enable root.. Would like to hear if anyone tested it remotely WITHOUT doing it locally first.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#44
I can't reproduce this on a clean 10.13.1 (17B48) system, either at the login window or an authentication dialog.

Update: And even after attempting it, checking Directory Utility the root user is still disabled. So I wonder if something 3rd party has enabled the root user and left it passwordless.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#46
post #26

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

Someone notices that they can log in as root with no password. In 2017, reflexively tweeting about it seems pretty unsurprising.

Seems like the guy just discovered this by accident. It's not like you'd have to be a security engineer to stumble upon this.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#50
post #38

Be careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464

The "root" superuser is always there, I'm not sure if it's possible to actually delete it.
Post reply on HN