Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

551–560 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#551

Earlier quoted context omitted.

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.

We need to come up with a witty name to get it fixed faster.

iRoot. uRoot. Everybody Root.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#552

Earlier quoted context omitted.

> But since I don't work there, I have no good inside info Actually, I've been wondering why I hear less about people working at Apple than at other big tech companies. It seems everyone and their mother work at Google or Facebook, but no so much at Apple. Do they have less software engineers, or their employees are required to be more discrete?

Do they have less software engineers, or their employees are required to be more discrete? I know but a few that work at Apple, and of those few they strike me as less forthcoming than the multitudes I've worked with and know at Microsoft. I've wondered if part of that is because Microsoft previews/pre-announces just about everything, whereas Apple (mostly, and not so much anymore) announces it when the shipping truc…

> Probably more so, last I looked, Apple has considerably fewer software employees than the other big companies.

I don't think this is true. Apple, Google, and Microsoft all have on the order of 100K employees.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#553
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

I'm reminded of: "Solaris Telnet 0-day vulnerability", 2007: https://m.slashdot.org/story/80056

But this does indeed seem to be an extra level of user-friendly stupid.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#554

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

... And means that others can utilize this to cause damage. The idea of responsible disclosure is to minimize harm for you, the user. Not to minimize bad publicity.

In a case like this, I think it would be best to maximize the bad publicity. Bad publicity is the minimum Apple deserves for a bug like this. In my idea world they'd get a lot of bad publicity, and a significant financial penalty.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#555
post #403

Earlier quoted context omitted.

Create a root password.

This isn't a fix, it's a hack. A computer with a root password is inherently more insecure than one without a root account at all.

If setting a root password is a hack, I'm Donald Duck.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#556

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Yeah, the guy is an attention whore, he just wants to buzz.

There is no justification for releasing a 0day publicly.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#557
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

I'm having a hard time understanding how this could happen too. It would have to be that looking up the root account enabled it, maybe users go dormant or something, and this was a way to readd them? then once it was enabled it defaulted to a blank password, but you would think that it needs sudo to enable root in the first place.

Login screen is probably already running as root in the first place, so it already had permission to enable shell/GUI access

Re: macOS High Sierra: Anyone can login as “root” with empty password

#558
post #99

Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.

AFAIK, its not really a security bug. Windows 98 didn't really have any concept of user security. With the default install you could always cancel out of the login dialog and use the guest account. Every account was an 'administrator'. The user name / pwd was mainly to store the OS customization settings like UI colors and such.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#559
post #434

Earlier quoted context omitted.

> But since I don't work there, I have no good inside info Actually, I've been wondering why I hear less about people working at Apple than at other big tech companies. It seems everyone and their mother work at Google or Facebook, but no so much at Apple. Do they have less software engineers, or their employees are required to be more discrete?

> or their employees are required to be more discrete? Yes, I believe so. I've heard there are strict requirements on even internal discussion. (Who you can talk to; about what; where.)

[deleted]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#560

Earlier quoted context omitted.

This situation is much more akin to a fire rapidly spreading through a village at night. I would go outside and start hollering in the hopes of saving anyone.

A better analogy is that there's a fire somewhere in your village, but it's mostly contained (it's not spreading, because other people don't know about it yet). By hollering about it, you've made it possible for anyone to go to the fire, light a torch with it, and burn down the village. Instead, you could call up the fire department and they could put it out–and then you could tell everyone about it.

You are comparing an arsonist to a fire department.
Post reply on HN