Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

411–420 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#411

Earlier quoted context omitted.

Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

> Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft. In my personal experience Windows has been much better than MacOS for me. I've been using Windows 7 for the last year at work and I'm having significantly less problems with Windows then MacOS.…

Windows 7 has been on the market since 2009 while High Sierra has been out since June of this year. I feel like we're not comparing apples to apples here.. I'm sure both companies are releasing security fixes consistently and Win7 has clearly had more of them in 8 years.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#413

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

Mostly, they're just missing out on an up to $200,000 bug bounty.

https://www.theregister.co.uk/2016/08/05/apple_joins_the_bug...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#414
post #217

Am I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.

The 'attacker' could be someone like your 12 year old son or an employee, who already has access to the computer but not necessarily everything on it at all times.

This would have been a pain for me when i was using parental restrictions to lock a 12 year old out of 18 hour a day Minecraft.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#415
post #224

I wonder who they're going to ask to write a public letter of apology this time. This isn't just a snarky comment. They have just released the most awfull iOS upgrade for a long time, and now this. Something's messed up, and they better fix it soon. I've think i've read somewhere they merged the iOS and macOS teams, i suppose the wrong people were promoted during the operation.

They will use some clever words to make it sound like a trivial issue like they did when password was appearing instead of password hint couple of months ago.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#416
post #281

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

I agree. https://www.eff.org/deeplinks/2017/10/drms-dead-canary-how-w... Blame the DMCA. This guy is in Turkey - does GP really think he can expect fair treatment and equal compensation as a "western world" security researcher?

There's no reason why the person who discovered the bug would be safer publishing the vulnerability on Twitter than disclosing it to Apple directly. If nothing else, they could always post it on Twitter later. The link to the DMCA is a digression.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#417

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Responsible disclosure is pretty much a security industry concept, it's not something that most developers know about, complaining on Twitter is probably what an average person would do.

Although for what it's worth last time I reported a security vuln to Apple using their official process they took around 2 years to fix it (admittedly low priority security vuln, passwords being sent over http).

Re: macOS High Sierra: Anyone can login as “root” with empty password

#418

Earlier quoted context omitted.

I get it, I really do, but it's not like he was complaining about a bad Uber driver. Disclosure in this way has real-world impacts up to and including harming people and we shouldn't ever consider it as something which is remotely acceptable. Is it acceptable to publicly disclose that an airport has a self-destruct switch which can be accessed near the NW mens bathroom? No. You contact someone who can fix the problem…

It's as remotely acceptable as "root" with no password, apparently. The question is large and complicated, and people can agree to disagree. There's nothing wrong with tweeting vulns: The company is at fault, we can defend ourselves now that we know about the vuln, and it's a big PR disaster for Apple. A past conversation: https://news.ycombinator.com/item?id=14009937 No, no it's not strictly more ethical. It's not e…

> The question is large and complicated, and people can agree to disagree

> There's nothing wrong with tweeting vulns

Those two statements seem to be contradictory. It seems to me there is still quite a lot of debate about which disclosure policy is best,

Re: macOS High Sierra: Anyone can login as “root” with empty password

#419
post #318

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

iTunes had QA problems for more than 10 years, only the early versions were really solid. I am not sure that it is a recent problem.

Subjectively it feels like Apple bugs have become larger and more prevalent, over the last few years. That and IMO clean OSX/iOS installs don't quite feel as polished as they used to. (I stopped using Apple products, except for a MBP, for a few years and recently started using them again, and the MBP still runs 10.10 for precisely this reason) The last solid OSX release was Snow Leopard

Re: macOS High Sierra: Anyone can login as “root” with empty password

#420
post #408

Earlier quoted context omitted.

> Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft. In my personal experience Windows has been much better than MacOS for me. I've been using Windows 7 for the last year at work and I'm having significantly less problems with Windows then MacOS.…

> I'm having significantly less problems with Windows then MacOS. I'm interested.. What kind of problems? > But Windows and MacOS both give me more problems then a FreeBSD or Linux box ever has. I switched from linux on the desktop to MacOs precisely because of the problems linux had - driver support, even LTS updates breaking functionality, and overall clunkiness. I run linux on all my servers.

Really? What driver support on a desktop were you experiencing?

I've run Linux mint on my desktop at home for a few years now and have had zero problems at all (Intel i5, Nvidia gfx, wired connection).

The last time I had driver issues with Linux was ~10 years ago and it was for a laptop running Ubuntu.

Post reply on HN