Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

431–440 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#431
Anyone in a position to short AAPL? It's apparently 6bps up in after hours trading but that's very low liquidity.

https://finance.yahoo.com/quote/AAPL?p=AAPL

A higher risk, higher leverage bet: buy some put options the milisecond markets open:

http://www.nasdaq.com/symbol/aapl/option-chain

Re: macOS High Sierra: Anyone can login as “root” with empty password

#432

1. Ensure you always have FileVault enabled (you should regardless) and shutdown after work until the bug is fixed. 2. Add a complex root passphrase and clean this up after the fix is released. 3. Reflect on how irresponsibly this serious security bug was ‘reported’, he didn’t just potentially miss out on $200,000, he put an enormous number of people at risk of local intrusions when instead if it was properly reporte…

It's not irresponsible to make a bug public. He did not put people at risk, he showed people they are already at risk, so they would know to set a root password, and thereby not be at risk . Security by obscurity does not work !

It’s not an example of security by obscurity, it’s a straight out security flaw and bug.

If it’s not publicly known and is a security risk it is far more effective to directly contact the developers / companies security team so they can immediately work on actually protecting people by developing a patch. If they don’t respond quickly (subjective, I’d call it within 12 hours) or fail to issue a fix in a timely manor (subjective, I’d say 24 hours) then yes - go public, start by logging a bug report and link to that bug report or if you can’t - the bug number / reference.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#433
post #326

AWS ReInvent 2017 is going right now in Las Vegas, the number of attendees is about 40000, and I'm wondering how many laptops can be attacked using this technique. The `root` user stays in the system, so one just need to create it and open SSH quickly, and later they can do whatever they please.

I really hope there's an extra zero in your 40000.

Maybe closer to 35000, but yeah, that's the scale of ReInvent, last year AWS reported 24000 attendees. I was there last year, that's a lot of people

https://aws.amazon.com/blogs/apn/why-sponsor-aws-reinvent-20...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#434

Earlier quoted context omitted.

Take this for the anecdata that it is. I interviewed at Apple, referred by old Microsoft friends that worked there. As I was trying to get a feel for things before the interview, I asked about the software testing. I was told, "don't expect what you're used to at Microsoft". The reference there is from when Microsoft often had more testers on a team than devs (ah, the good ol' days). The summary of what I was told by…

> But since I don't work there, I have no good inside info Actually, I've been wondering why I hear less about people working at Apple than at other big tech companies. It seems everyone and their mother work at Google or Facebook, but no so much at Apple. Do they have less software engineers, or their employees are required to be more discrete?

> or their employees are required to be more discrete?

Yes, I believe so. I've heard there are strict requirements on even internal discussion. (Who you can talk to; about what; where.)

Re: macOS High Sierra: Anyone can login as “root” with empty password

#435

Are we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM

Possibly not, but the death & maiming stats everywhere show we're absolutely not ready for human-driven ones.

Thank you

I imagine a Twilight Zone episode... Go back in time to before cars were invented and imagine some Mephistopheles offering the bargain: "You'll fly like the wind over hills and mountains, making a journey of days in mere hours!" What the catch? "For each mile traveled a certain number of people chosen at random must be put to death or maimed."

He would go on about how the chances of someone you love being chosen for sacrifice were infinitesimal, and the benefits to all were so great and so obvious...

("Also, it will poison the air and water, and force you to become dependent on fuel sources that destroy life and engender wars.")

Re: macOS High Sierra: Anyone can login as “root” with empty password

#436

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

Unrelated to Mac OS but I used to wonder all the time why iTunes connect was so shoddy. I got my answer when I learned Apple had outsourced a ton of backend work including iTunes Connect, App Store backend to Infosys in India.

They’re now retreating from that strategy: https://factordaily.com/apple-to-pull-back-development-work-...

Re: macOS High Sierra: Anyone can login as “root” with empty password

#437

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

Not the attitude of the people reporting the issue have put "millions of apple customers" at risk, but the company which allowed to let issues like this one slip through their Q&A process.

IMO, this behaviour is part of the problem, the reason why tech companies take security only on a superfiscial level seriously.

Don't kill the Messenger.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#438
post #322

Earlier quoted context omitted.

> Anyone got any inside scoop? I have a feeling that anyone who does would get fired for commenting here about it.

You have to think that whoever was responsible for testing this is going to get fired. This is egregiously bad...

This is a management issue. It shouldn't be possible for such a mistake to slip into production code. It has happened more than once in recent times.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#439

Earlier quoted context omitted.

Take this for the anecdata that it is. I interviewed at Apple, referred by old Microsoft friends that worked there. As I was trying to get a feel for things before the interview, I asked about the software testing. I was told, "don't expect what you're used to at Microsoft". The reference there is from when Microsoft often had more testers on a team than devs (ah, the good ol' days). The summary of what I was told by…

> But since I don't work there, I have no good inside info Actually, I've been wondering why I hear less about people working at Apple than at other big tech companies. It seems everyone and their mother work at Google or Facebook, but no so much at Apple. Do they have less software engineers, or their employees are required to be more discrete?

Apple probably doesn't take too kindly to their employees talking about their work. I'd imagine it's a fire-able offense.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#440

Earlier quoted context omitted.

Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

Silverlight was EOL'd five years ago.

Tell that to Dish Network.
Post reply on HN