Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

591–600 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#591
post #220

Earlier quoted context omitted.

> I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. I think the problem is due to the fact that they are fans. In this case, it's Apple, but there's no reason it couldn't be Linux or Go or whatever. Regardless, any bad news about their hero is irresponsible to disseminate. We see this same phenomenon in politics, in sports and elsewhere — I dar…

> I think the problem is due to the fact that they are fans. I think this is an unfair characterization. Sure, it's hard to hear that their "hero is irresponsible", but the real reason is that this kind of behavior puts everyone at risk while Apple tries to fix it.

They were already at risk. Now they can mitigate.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#592

Earlier quoted context omitted.

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.

We need to come up with a witty name to get it fixed faster.

My current favorite is I am Root.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#593

Earlier quoted context omitted.

> I think the problem is due to the fact that they are fans. I think this is an unfair characterization. Sure, it's hard to hear that their "hero is irresponsible", but the real reason is that this kind of behavior puts everyone at risk while Apple tries to fix it.

They were already at risk. Now they can mitigate.

*Significantly more risk

Re: macOS High Sierra: Anyone can login as “root” with empty password

#594
post #102

Earlier quoted context omitted.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.

I am going to ask, do you want to try this scenario on your own in real life? Because often we make general statements while we don’t actually practice what we say to others when the issue is going to hurt ourselves.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#595

Earlier quoted context omitted.

Take this for the anecdata that it is. I interviewed at Apple, referred by old Microsoft friends that worked there. As I was trying to get a feel for things before the interview, I asked about the software testing. I was told, "don't expect what you're used to at Microsoft". The reference there is from when Microsoft often had more testers on a team than devs (ah, the good ol' days). The summary of what I was told by…

> But since I don't work there, I have no good inside info Actually, I've been wondering why I hear less about people working at Apple than at other big tech companies. It seems everyone and their mother work at Google or Facebook, but no so much at Apple. Do they have less software engineers, or their employees are required to be more discrete?

[deleted]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#596

Earlier quoted context omitted.

If you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.

> Apple only responds reliably to PR storms They've been quick (within 45 days) to patch every major bug I've reported to them and where the bugs were cross platform, impacting Windows, Android, etc., they've consistently been amongst the quickest to issue a patch so I'm not sure how you qualify that statement.

I qualified it with "reliably". Major bugs reported by you, a security researcher, may be bucketed differently than those deemed less serious or filed by others. As a recent example, a minor bug like the iOS 11 calculator ignoring keypresses had reports filed since Beta 1, but only after it made headlines and caused Apple public embarrassment will it be addressed in the upcoming 11.2, six months later.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#597

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

[deleted]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#598
post #584

Earlier quoted context omitted.

> I think the problem is due to the fact that they are fans. I think this is an unfair characterization. Sure, it's hard to hear that their "hero is irresponsible", but the real reason is that this kind of behavior puts everyone at risk while Apple tries to fix it.

That may be true for cisco and juniper where upgrades must be carefully rolled out across globally distributed critical infrastructure, but this is APPLE. They need no such help. They can push to everyone, now, and it will be fine. Forcing their hand is safer than trying to hide a flaw a 3 year old could find on accident.

> They can push to everyone, now, and it will be fine.

I'm pretty sure any fix has to go through Build and Integration before being rolled out. Then you need to have people actually install the update…

Re: macOS High Sierra: Anyone can login as “root” with empty password

#599
post #583

Earlier quoted context omitted.

I'll agree that Snow Leopard is the high water-mark.

It's common among a small group of Mac users to hold Snow Leopard up as the peak of software quality, but only because of rose-colored glasses [1]. [1] https://www.computerworld.com/article/2528936/mac-os-x/snow-...

I should have specified I meant 10.6.8 I ran it on my main computer until 10.9.2 because of the problems I had experienced with Lion and Mountain Lion on other computers.

Also I think when most people think of Snow Leopard they're thinking of 10.6.8, at least that's the version number you always see get thrown around on the internet.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#600
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

Seems to be something related to a backwards-compatibility code path for upgraded systems. According to multiple posts on this thread it only affects systems upgraded to High Sierra, not fresh installs. See https://news.ycombinator.com/item?id=15802622 for example. Adding extra layers for compatibility complicates testing and debugging. With this many eyes on it hopefully someone will be able to deduce exactly what's…

My High Sierra is a fresh install, and it's affected.
Post reply on HN