Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

511–520 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#511

Earlier quoted context omitted.

This is the most idiotic thing I've heard in a long time. Yes, they were already at risk, but with the way he disclosed the information, the risk increased exponentially. This guy's actions were either stupid or malicious.

Obviously this isn't the best way to disclose a security flaw. That does not make it malicious . Sure, there are more malicious people aware of this security flaw, but there are also more users aware of this security flaw, and the simple steps they can take to mitigate it.

Yep, just saying that if he's not malicious (intending to maximize harm to users), then he's an idiot for disclosing it this way.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#512
post #464

Earlier quoted context omitted.

Do note that this doesn't fix the problem. The system (at least High Sierra) will happily re-enable the user for every attempt at logging in.

If you disable the root user using `dsenableroot -d` from the Terminal, this seems to disable the account in a way that leaves its password intact.

The bug isn't in the disabling, it's in the auto-enabling on attempt.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#513

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

This situation is much more akin to a fire rapidly spreading through a village at night. I would go outside and start hollering in the hopes of saving anyone.

A better analogy is that there's a fire somewhere in your village, but it's mostly contained (it's not spreading, because other people don't know about it yet). By hollering about it, you've made it possible for anyone to go to the fire, light a torch with it, and burn down the village. Instead, you could call up the fire department and they could put it out–and then you could tell everyone about it.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#514

Earlier quoted context omitted.

It seems apple's software has been trending down in quality since Snow Leopard.

I'll agree that Snow Leopard is the high water-mark.

3rded. I wish time stopped at 10.6.8.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#515

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I agree in general, but calling it uncool and laying any blame on the person reporting is not fair.

You may know the protocol, security researchers and people in the tech industry may know that, but why is an ordinary Joe expected to know, or research, that email address and/or the protocol regarding 0-day vulnerabilities.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#516
That twitter thread and lots of the comments are missing the point. MANY people don't know about what the ethics of reporting vulnerabilities are, they just want to say something and get it fixed. yes, it probably would have been better if this person had gone through proper channels, but there's no evidence they did it for the lulz/fame.

In this case the bug is so bad and egregious, that publicizing it with the fix might have been the best thing to do -- no telling how many people have already discovered this or how long it would take Apple to fix.

Yes, let's educate each other about what responsible disclosure WITH A DEADLINE TO FIX looks like, but don't assume this person just wanted internet points. And now that the report and a workaround are out there, at least it can be mitigated personally.

Though I imagine there will be some SERIOUS hijinks that result from this until Apple fixes it because it is so easy to do. :(

Re: macOS High Sierra: Anyone can login as “root” with empty password

#518

Fortunately, I'm OK. The latest OS upgrade failed to install and bricked my computer so that no one could log in, let alone root. I was able to restore it using Time Machine but I don't think I'll go through that exercise again for a while yet.

you might be able to fix that. I had that too, had to manually update the preboot. Details are somewhere in here https://forums.developer.apple.com/thread/80174

Re: macOS High Sierra: Anyone can login as “root” with empty password

#519

Earlier quoted context omitted.

Not the attitude of the people reporting the issue have put "millions of apple customers" at risk, but the company which allowed to let issues like this one slip through their Q&A process. IMO, this behaviour is part of the problem, the reason why tech companies take security only on a superfiscial level seriously. Don't kill the Messenger.

I think this incorrectly interprets my comment. I am not defending apple or blaming the individual that disclosed the vulnerability on Twitter. I am simply pointing out that putting users at additional risk because you want to see Apple hurt may be misguided. We have responsible disclosures in place for a reason. EDIT: putting users at _additional_ risk

I do get the impression that you do blame the individual, as you have attributed unsavory motivations to his behavior. Why do you care to make such a loose statement about this person having a petty motive of malice?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#520

Earlier quoted context omitted.

Closed disclosure does, to a large degree, prevent negative publicity. I don't think it is in dispute that this bug would receive vastly less media coverage if it were only revealed as a bug in outdated/patched versions of the OS. I don't want to see Apple hurt (I'm an Apple-guy myself, using Macs, iPhone, iPad and Apple Watch), I want to see them improve. I doubt they start will start caring about QA unless they're…

I actually do think it is in dispute. This is a tweet after all. This guy could totally tweet about it in much the same way after Apple released a patch. The negative publicity would still exist because the bug would be equally stupid and disastrous, just fewer people would be harmed along the way.

It wouldn't be as clear that the bug is widely reproducible after the patch is put out. And it certainly wouldn't gather as much attention.
Post reply on HN