Earlier quoted context omitted.
Is it likely it's just an error due to the discoverer not being immersed in the Infosec space? "Don't disclose a 0-day publicly" is good 'common' sense, but only among the 'common' of people who are steeped in security issues and the ramifications of publicizing them.
That is not the case among infosec professionals either. Many respected professionals believe that the right thing to do in many cases is full public disclosure. Google Project Zero are a notable example.
macOS High Sierra: Anyone can login as “root” with empty password
401–410 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#402Earlier quoted context omitted.
I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…
I'm more concerned that the "exploit" works "after a few tries" and not the first-time-every-time, or not at all. One would think that something as simple as a login would be deterministic.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#403Re: macOS High Sierra: Anyone can login as “root” with empty password
#404Earlier quoted context omitted.
"responsible disclosure" isn't some morally unassailable high ground, but companies like apple sure want you to believe it is.
Care to explain the comment about Apple? I can think of a few companies (DJI, for example) that try to screw over security researchers, but big IT companies usually don't go on the list.
In my opinion, there's a point at which it becomes irresponsible to let them sit on issues for so long, but their newspeak for the disclosure policy tries to pre-empt that idea.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#405Earlier quoted context omitted.
If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.
We need to come up with a witty name to get it fixed faster.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#406I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?
Apples user management is even more complex than most Unixes.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#407Earlier quoted context omitted.
I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…
Don't forget the Disk Utility password disclosure! https://www.macrumors.com/2017/10/05/macos-high-sierra-disk-...
Re: macOS High Sierra: Anyone can login as “root” with empty password
#408Earlier quoted context omitted.
Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.
> Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft. In my personal experience Windows has been much better than MacOS for me. I've been using Windows 7 for the last year at work and I'm having significantly less problems with Windows then MacOS.…
I'm interested.. What kind of problems?
> But Windows and MacOS both give me more problems then a FreeBSD or Linux box ever has.
I switched from linux on the desktop to MacOs precisely because of the problems linux had - driver support, even LTS updates breaking functionality, and overall clunkiness. I run linux on all my servers.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#409I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#410Earlier quoted context omitted.
If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.
Let's say keys were hidden around the neighborhood. Would you rather everyone in the whole town know about it or quietly and quickly go pick up all the keys before someone notices and breaks into one of the houses? Personally I think if you report through the proper channels and nothing is changed THEN broadcast, but not as an opener.