Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

601–610 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#601

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

[deleted]

Re: macOS High Sierra: Anyone can login as “root” with empty password

#603

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

> there are any number of legit bug bounty programs

The thing about bug bounty programs are that they are not a negotiation. They decide how much your information is worth--take it or leave it.

If you thought this bug was worth $25,000 and you feared that Apple might offer a $100 discount coupon plus a lovely "I Love My Mac" coffee mug, is there any way to start a negotiation without being accused of extortion (if you imply that you might disclose it publicly)?

This is a serious question: Is there any way to negotiate for security bugs, before or after disclosing all the details, without running a legal risk?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#605

Earlier quoted context omitted.

The root account always exists. Playing around with disable/enable and the exploit: Root always has a /bin/sh shell "Disable root user" removes the ShadowHashData from the directory services entry for root The bug sets ShadowHashData to the hash of an empty string. Now, ShadowHashData is a complex DS entry. I've never seen passwords represented this way in other OSX versions. I think this password storage format is n…

Your comment suggests that it is related to users with older, pre-High Sierra directory entries. That is, upgraded rather than freshly installed machines that leave older, pre-ShadowHashData intact. Is this correct?

No, sorry, I did not mean that or mean to imply it.

I think the feature that caused this is related to upgrading pre-high-sierra user password hashes to high-sierra-style hashes.

The fact that it works for situations where the password is null is a/the bug.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#606

That twitter thread and lots of the comments are missing the point. MANY people don't know about what the ethics of reporting vulnerabilities are, they just want to say something and get it fixed. yes, it probably would have been better if this person had gone through proper channels, but there's no evidence they did it for the lulz/fame. In this case the bug is so bad and egregious, that publicizing it with the fix…

I’m not a security researcher and I don’t work for Apple. If I casually came across this I would totally tweet it out. Anyone asserting I should follow some sort of procedure has a misplaced sense of reality.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#607
post #13

Can this be used remotely? Edit: Yes, after turning on Remote Management on my second mac I was able to log into it using Remote Desktop, account root and no pw. It only works after getting physical access once.

You can get undetectble remote access on most machines given "physical access once", so I don't think this qualifies as "remotely exploitable".

If root was ever enabled without setting a password, the machine is then in a state that it can be remotely exploitable.

While it's unlikely, there are probably plenty of users who have done this for some reason or another.

Don't underestimate a user's ability to blindly do things like this by following arcane instructions in attempts to fix an unrelated problem.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#608
My computer automatically downloaded high sierra without me wanting it to. Whether I was tricked into clicking something I don’t know. And then I heard about the disk utility password bug and decided I should wait a while before installing this OS— it seems as though Apple wants me to do their QA for them. And now I hear about this. And I see that dumb ugly notch on the iPhone X (seriously who approved that design decision?). And the 2015 MacBook Pro is more pro than the 2016 model? Apple is officially a tribute band, riding on the fame of its previous self. And I say this as someone who owns a MacBook Pro, MacBook Air, iPad Pro, iPhone, and Apple Watch. This comes from a place of love. You’re trendy now, but don’t you forget that trendy people will leave you for the next shiny thing in an instant. Please fire everyone who is just there to milk the profits, actually put some focus back into QA, and remember who your base was.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#609

Earlier quoted context omitted.

If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.

I am going to ask, do you want to try this scenario on your own in real life? Because often we make general statements while we don’t actually practice what we say to others when the issue is going to hurt ourselves.

We all live with this scenario everyday, most consumer locks are ridiculously easy to open. https://en.wikipedia.org/wiki/Lock_bumping

Re: macOS High Sierra: Anyone can login as “root” with empty password

#610

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

There is nothing irresponsible about disclosing huge vulnerabilities in software by any means necessary.

Edit: as usual, downvotes but no response. I miss when this place was decent.

Post reply on HN