Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

471–480 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#471
post #423

Earlier quoted context omitted.

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

And Full disclosure is about protecting users of a software, not letting the vendor off the hook. Here, the hack and the fix are so trivial the responsible thing to do is to publicly call out Apple for its lack of QA and warn users directly. It affects everybody who runs High Sierra. > it puts millions of Apple customers at risk in the process. Nah, it's Apple which put millions of customers at risk, not the person w…

I would argue that releasing this vulnerability as irresponsibly as he did is showing he cares more about negative publicity than user security.

Yes, it's Apple's fault for poor QA that this was released, but this guy also put users at risk by telling the entire world about it without giving Apple a chance to fix it.

You're right, it's about user security before publicity. So make sure users are safe first.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#472

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

Where is Joe Random's obligation to responsibly disclose? To whom does he owe that obligation? Apple? The public? Both? Why?

In my opinion they don't "owe" anyone that obligation, unless it's a contractual obligation associated with using a Mac. But just because it's not owed to anyone, doesn't mean there isn't a nicer way to handle it just to be nice.

That said, I don't immediately see evidence that this gentleman is in the security field, and perhaps isn't aware of responsible disclosure. Full disclosure isn't the worst thing in the world.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#473
post #443

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Why does it need to create a lot of negative publicity for Apple? Is there something you don't like about them? Responsible disclosure needs to be valued given the number of macs out there in the wild that could potentially be susceptible to issues like this, and the impact it could have on people (including you) not just directly but indirectly. How would you feel if someone discovered a 0day at a company that expos…

Far too many people think of Apple as infallible. I often think even Apple thinks of themselves as infallible. The more people that are aware of the inherent risk involved with using computers - any computer - the better.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#474
post #225

Earlier quoted context omitted.

That was my first thought. Based on some bounty reports I've seen recently I would assume at least high five figures.

For a local root with physical access? Not a chance. Maybe low 4 figures.

If the mac has screen sharing enabled, physical access is not required

Re: macOS High Sierra: Anyone can login as “root” with empty password

#475
post #220

I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.

> I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. I think the problem is due to the fact that they are fans. In this case, it's Apple, but there's no reason it couldn't be Linux or Go or whatever. Regardless, any bad news about their hero is irresponsible to disseminate. We see this same phenomenon in politics, in sports and elsewhere — I dar…

I've not commented either way on the subject in this thread, but personally I would much rather have read this as a writeup 2 or 3 months from now after the discoverer had responsibly disclosed the vulnerability and Apple had a chance to patch it.

On the other hand, I'm glad that I have this information so I know not to install High Sierra on my work iMac (sitting on a desk in a WeWork behind a door whose lock would be very easy to force open) until this is fixed.

[Edit: I now see that there's a simple workaround (change the root password and keep root enabled), so I'm all for "irresponsible disclosure" in this case]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#477

This is comical at this point. I have no idea how such vulnerable software makes it to production. It is really ironic that a company, making billions of dollars and branding itself as the leaders of quality, stability and so on, to have this kind of vulnerability. I have truly lost faith in Apple.

Agreed.

iOS 11 was the tipping point for me (can't delete photos using trash icon, wrong orientation when unlocking phone, random lag/freezes etc).

Apple just doesn't care any more.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#478
post #417

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Responsible disclosure is pretty much a security industry concept, it's not something that most developers know about, complaining on Twitter is probably what an average person would do. Although for what it's worth last time I reported a security vuln to Apple using their official process they took around 2 years to fix it (admittedly low priority security vuln, passwords being sent over http).

> admittedly low priority security vuln, passwords being sent over http

Wait, what?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#479

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

A [?] don't know what you are talking about.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#480

Earlier quoted context omitted.

It’s not an example of security by obscurity, it’s a straight out security flaw and bug. If it’s not publicly known and is a security risk it is far more effective to directly contact the developers / companies security team so they can immediately work on actually protecting people by developing a patch. If they don’t respond quickly (subjective, I’d call it within 12 hours) or fail to issue a fix in a timely manor…

The fact is that the devs certainly do know about it by now, yet users do not have a fix yet. Users do, however, have a workaround, and knowledge that the security flaw exists in the first place. Waiting for a fix before disclosing a security flaw is security by obscurity, even if it is to be replaced soon. It is best for users to know that their system is vulnerable, and how to fix that without waiting for a system…

> "The fact is that the devs certainly do know about it by now, yet users do not have a fix yet."

Citation needed.

> "It is best for users to know that their system is vulnerable, and how to fix that without waiting for a system update."

Stepping outside the 'tech' social bubble, most general users likely won't create a root account and password from something they see on TV or their local news site or at least not before a patch would have been released.

--

Further to previously provided examples:

https://www.cloudflare.com/disclosure/

https://access.redhat.com/security/team/contact

https://www.xenproject.org/security-policy.html

https://about.gitlab.com/disclosure/

https://help.github.com/articles/responsible-disclosure-of-s...

https://www.kernel.org/doc/html/v4.10/admin-guide/security-b...

https://www.drupal.org/drupal-security-team/general-informat...

https://www.cisco.com/c/en/us/about/security-center/security...

https://www.juniper.net/us/en/security/report-vulnerability/

Post reply on HN