Earlier quoted context omitted.
Do they have less software engineers, or their employees are required to be more discrete? I know but a few that work at Apple, and of those few they strike me as less forthcoming than the multitudes I've worked with and know at Microsoft. I've wondered if part of that is because Microsoft previews/pre-announces just about everything, whereas Apple (mostly, and not so much anymore) announces it when the shipping truc…
> Probably more so, last I looked, Apple has considerably fewer software employees than the other big companies. I don't think this is true. Apple, Google, and Microsoft all have on the order of 100K employees.
macOS High Sierra: Anyone can login as “root” with empty password
561–570 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#562Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure
Re: macOS High Sierra: Anyone can login as “root” with empty password
#563Fellow Linux users, please keep the snark in this thread to a minimum. Here's just one recent example why, there are more: http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-log...
Re: macOS High Sierra: Anyone can login as “root” with empty password
#564Earlier quoted context omitted.
But everyone can fix this problem by setting a root password. So telling everyone is the right call. Otherwise people would be sitting vulnerable while Apple comes up with a patch.
But a tweet isn't really the most effective way to tell everyone. Technical people, including those who would use this vulnerability for malice, will find out far far sooner than my grandmother. It seems to me the right thing to do is to tell Apple privately, tell them to either push a fix or put out some kind of release letting all their customers know how to mitigate this in the next, say, 3 days, or I'll just twee…
Re: macOS High Sierra: Anyone can login as “root” with empty password
#565I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.
I wouldn't bash the guy. Someone already let him know about his technical faux pas in a professional manner on his twitter. My guess is he found this vulnerability on accident, freaked out, and tweeted about it. Probably has limited infosec experience.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#566Earlier quoted context omitted.
If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.
We need to come up with a witty name to get it fixed faster.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#567Earlier quoted context omitted.
A better analogy is that there's a fire somewhere in your village, but it's mostly contained (it's not spreading, because other people don't know about it yet). By hollering about it, you've made it possible for anyone to go to the fire, light a torch with it, and burn down the village. Instead, you could call up the fire department and they could put it out–and then you could tell everyone about it.
You are comparing an arsonist to a fire department.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#568Earlier quoted context omitted.
I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…
I agree. https://www.eff.org/deeplinks/2017/10/drms-dead-canary-how-w... Blame the DMCA. This guy is in Turkey - does GP really think he can expect fair treatment and equal compensation as a "western world" security researcher?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#569Re: macOS High Sierra: Anyone can login as “root” with empty password
#570Earlier quoted context omitted.
Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…
A bug like 'can log in with password "root"/""' just isn't going to get you a grace period no matter what security researchers might want. I mean, this bugs has been reported already - by every cheesy hacking movie ever, by every beginners book on social engineering and so-forth. Heck, it was "reported" by Richard Feynman talking about cracking safes during the Manhattan.