Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

561–570 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#561

Earlier quoted context omitted.

Do they have less software engineers, or their employees are required to be more discrete? I know but a few that work at Apple, and of those few they strike me as less forthcoming than the multitudes I've worked with and know at Microsoft. I've wondered if part of that is because Microsoft previews/pre-announces just about everything, whereas Apple (mostly, and not so much anymore) announces it when the shipping truc…

> Probably more so, last I looked, Apple has considerably fewer software employees than the other big companies. I don't think this is true. Apple, Google, and Microsoft all have on the order of 100K employees.

Keep in mind that Apple directly employs retail staff.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#562

Is social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure

Twitter's also the goto for banning trans people from military service, attacking freedom of the press, threatening to declare nuclear war, and all kinds of other things too.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#564

Earlier quoted context omitted.

But everyone can fix this problem by setting a root password. So telling everyone is the right call. Otherwise people would be sitting vulnerable while Apple comes up with a patch.

But a tweet isn't really the most effective way to tell everyone. Technical people, including those who would use this vulnerability for malice, will find out far far sooner than my grandmother. It seems to me the right thing to do is to tell Apple privately, tell them to either push a fix or put out some kind of release letting all their customers know how to mitigate this in the next, say, 3 days, or I'll just twee…

It's not the most effective, but that doesn't make it bad, or malicious.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#565

I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.

I wouldn't bash the guy. Someone already let him know about his technical faux pas in a professional manner on his twitter. My guess is he found this vulnerability on accident, freaked out, and tweeted about it. Probably has limited infosec experience.

Or he cares more about doing the right thing than about following best practices designed to protect the guilty under the guise of helping users.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#566

Earlier quoted context omitted.

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.

We need to come up with a witty name to get it fixed faster.

[deleted]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#567
post #560

Earlier quoted context omitted.

A better analogy is that there's a fire somewhere in your village, but it's mostly contained (it's not spreading, because other people don't know about it yet). By hollering about it, you've made it possible for anyone to go to the fire, light a torch with it, and burn down the village. Instead, you could call up the fire department and they could put it out–and then you could tell everyone about it.

You are comparing an arsonist to a fire department.

Uhh, no. How are you getting that impression? I'm simply saying that arsonists exist, and it's probably a good idea to make it harder for them to burn things down than to publicly advertise a way for them to do it.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#568
post #281

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

I agree. https://www.eff.org/deeplinks/2017/10/drms-dead-canary-how-w... Blame the DMCA. This guy is in Turkey - does GP really think he can expect fair treatment and equal compensation as a "western world" security researcher?

How does him being from Turkey matter in this case?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#570

Earlier quoted context omitted.

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

A bug like 'can log in with password "root"/""' just isn't going to get you a grace period no matter what security researchers might want. I mean, this bugs has been reported already - by every cheesy hacking movie ever, by every beginners book on social engineering and so-forth. Heck, it was "reported" by Richard Feynman talking about cracking safes during the Manhattan.

Grub's "backspace 28 times to a rescue shell" was also a stupid one, but it first got fixed, and then made it to the news.
Post reply on HN