Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

401–410 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#401

Earlier quoted context omitted.

Is it likely it's just an error due to the discoverer not being immersed in the Infosec space? "Don't disclose a 0-day publicly" is good 'common' sense, but only among the 'common' of people who are steeped in security issues and the ramifications of publicizing them.

That is not the case among infosec professionals either. Many respected professionals believe that the right thing to do in many cases is full public disclosure. Google Project Zero are a notable example.

Project Zero does full disclosure 90 days after informing the relevant organization. Full disclosure comes after there has been a chance to fix the problem. Otherwise everyone is put at risk until a fix is available.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#402

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

I'm more concerned that the "exploit" works "after a few tries" and not the first-time-every-time, or not at all. One would think that something as simple as a login would be deterministic.

My understanding is that the first attempt is creating/enabling the root account with a blank password and that the subsequent login is actually utilizing it (which is kind of bizarre and probably why this was missed in testing).

Re: macOS High Sierra: Anyone can login as “root” with empty password

#403

Earlier quoted context omitted.

People are already fixing their machines because he tweeted. this is too much of a huge blunder to wait for the official channels.

they are? Where's the fix?

Create a root password.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#404

Earlier quoted context omitted.

"responsible disclosure" isn't some morally unassailable high ground, but companies like apple sure want you to believe it is.

Care to explain the comment about Apple? I can think of a few companies (DJI, for example) that try to screw over security researchers, but big IT companies usually don't go on the list.

Most of the big companies will take their sweet time to fix something if it suits them. Not always, but sometimes they just won't feel like getting around to it, and they know that as a "responsible" researcher, you will keep your mouth shut about it. I'm talking like a year. I've seen this with the "researcher friendly" companies.

In my opinion, there's a point at which it becomes irresponsible to let them sit on issues for so long, but their newspeak for the disclosure policy tries to pre-empt that idea.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#405

Earlier quoted context omitted.

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.

We need to come up with a witty name to get it fixed faster.

AppleGate

Re: macOS High Sierra: Anyone can login as “root” with empty password

#406
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

Identity management is complex and boring.

Apples user management is even more complex than most Unixes.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#407

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Don't forget the Disk Utility password disclosure! https://www.macrumors.com/2017/10/05/macos-high-sierra-disk-...

Thanks, added!

Re: macOS High Sierra: Anyone can login as “root” with empty password

#408

Earlier quoted context omitted.

Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

> Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft. In my personal experience Windows has been much better than MacOS for me. I've been using Windows 7 for the last year at work and I'm having significantly less problems with Windows then MacOS.…

> I'm having significantly less problems with Windows then MacOS.

I'm interested.. What kind of problems?

> But Windows and MacOS both give me more problems then a FreeBSD or Linux box ever has.

I switched from linux on the desktop to MacOs precisely because of the problems linux had - driver support, even LTS updates breaking functionality, and overall clunkiness. I run linux on all my servers.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#409

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

Repressive collusion to fix salaries and restrict industry movement, doesn't really inspire your employees to try their best

Re: macOS High Sierra: Anyone can login as “root” with empty password

#410

Earlier quoted context omitted.

If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.

Let's say keys were hidden around the neighborhood. Would you rather everyone in the whole town know about it or quietly and quickly go pick up all the keys before someone notices and breaks into one of the houses? Personally I think if you report through the proper channels and nothing is changed THEN broadcast, but not as an opener.

holy shit, you people are fucking lame.
Post reply on HN