Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

501–510 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#501

Earlier quoted context omitted.

Not the attitude of the people reporting the issue have put "millions of apple customers" at risk, but the company which allowed to let issues like this one slip through their Q&A process. IMO, this behaviour is part of the problem, the reason why tech companies take security only on a superfiscial level seriously. Don't kill the Messenger.

I think this incorrectly interprets my comment. I am not defending apple or blaming the individual that disclosed the vulnerability on Twitter. I am simply pointing out that putting users at additional risk because you want to see Apple hurt may be misguided. We have responsible disclosures in place for a reason. EDIT: putting users at _additional_ risk

I dont understand the implied correlation between, what you call, irresponsible disclosure and "wanting to hurt apple". Where did you get this impression from?

edit: Typo.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#502

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

macOS and iOS updates at Apple are now inextricably tied to new iPhone releases. There is a strict yearly deadline that the teams sprint toward, a timeline imposed by marketing rather than readiness. This affects prioritization of which features are pursued, where they lie in the stack, and how polished they get. Insufficient testing at today's Apple is not limited to software. They bragged about their extensive inpu…

Haven't deadlines at Apple always been driven by marketing? I'm looking for a source but I remember a story where the product director for iPod was told by steve jobs "make it simple, fast, beautiful, and have it done by Christmas."

Re: macOS High Sierra: Anyone can login as “root” with empty password

#503
post #478
post #417

Earlier quoted context omitted.

Responsible disclosure is pretty much a security industry concept, it's not something that most developers know about, complaining on Twitter is probably what an average person would do. Although for what it's worth last time I reported a security vuln to Apple using their official process they took around 2 years to fix it (admittedly low priority security vuln, passwords being sent over http).

> admittedly low priority security vuln, passwords being sent over http Wait, what ?

Unfortunately it's still more common than you think.

The other day I actually ran across some AWS docs which suggest you send your AWS root key id in the url of http requests:

http://docs.aws.amazon.com/AlexaWebInfoService/latest/index....

Re: macOS High Sierra: Anyone can login as “root” with empty password

#504
post #484

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

I think there's a middle ground to this. Submit your report to Apple security, allow them time to develop a patch, and then in a week go ahead and tweet at the big media outlets about it. I'm a die-hard Apple user myself, but I agree that the long list of severe bugs in High Sierra is absurd, and a big public backlash might be enough to kick them into gear. On the other hand, I, a university student with next to no u…

The fact that you as the ordinary student can become root and create a lot of damage so easily is the only reason the public will care.

Us geeks have been complaining about the horrible QA in macOS for years, yet nothing has been done. The fact that this is so simple to do will probably/hopefully get ordinary people to start talking about it too ("Hey, have you heard that you can hack Macs without a password? Very insecure"), which would force Apple to improve.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#505

Earlier quoted context omitted.

It's not irresponsible to make a bug public. He did not put people at risk, he showed people they are already at risk, so they would know to set a root password, and thereby not be at risk . Security by obscurity does not work !

This is the most idiotic thing I've heard in a long time. Yes, they were already at risk, but with the way he disclosed the information, the risk increased exponentially. This guy's actions were either stupid or malicious.

Obviously this isn't the best way to disclose a security flaw.

That does not make it malicious.

Sure, there are more malicious people aware of this security flaw, but there are also more users aware of this security flaw, and the simple steps they can take to mitigate it.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#507
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

Like an illusionist hiding the truth, this bug too will have a logical explanation that will leave us in wonder for as long as we aren't told how it happened.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#508
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

Exactly, how can this happens and no one asks.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#509

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.

> Apple only responds reliably to PR storms

They've been quick (within 45 days) to patch every major bug I've reported to them and where the bugs were cross platform, impacting Windows, Android, etc., they've consistently been amongst the quickest to issue a patch so I'm not sure how you qualify that statement.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#510

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

"Disclosing a 0Day... isn't cool,..."

But it is not nearly as uncool as releasing software to millions of paying customers containing a 0Day. Who knows how many people already knew about this and other 0Days and have said nothing?

The carelessness in releasing software with 0Days is especially unforgivable when the company has more cash on hand to pay employees than any company in history. What is their excuse?

Apple can afford the very best. Their customers pay the most. But the software they release, no matter what their user may want to imagine, is most certainly not the very best.

It is not even as good as open source BSD from which OSX is derived, maintained by unpaid volunteers, which does not allow remote logins as root without a password.

Post reply on HN