Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

651–660 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#651
post #484

Earlier quoted context omitted.

I think there's a middle ground to this. Submit your report to Apple security, allow them time to develop a patch, and then in a week go ahead and tweet at the big media outlets about it. I'm a die-hard Apple user myself, but I agree that the long list of severe bugs in High Sierra is absurd, and a big public backlash might be enough to kick them into gear. On the other hand, I, a university student with next to no u…

The fact that you as the ordinary student can become root and create a lot of damage so easily is the only reason the public will care. Us geeks have been complaining about the horrible QA in macOS for years, yet nothing has been done. The fact that this is so simple to do will probably/hopefully get ordinary people to start talking about it too ("Hey, have you heard that you can hack Macs without a password? Very in…

It sounds to me like you're arguing that full disclosure in this situation could lead to a worse outcome for users in the short term, but the negative publicity will force Apple to improve their security posture, leading to a better outcome for users in the long term. (Please let me know if I'm miss-characterizing your argument)

I think you have to be very careful about that line of argument. It's a single vulnerability researcher making a unilateral decision about the short term and long term security of an entire user base, based entirely on personal judgement. I personally think the researcher should make the decision that best protects users from that specific vulnerability. Making long-term changes to a company's QA should come second.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#652

Earlier quoted context omitted.

Closed disclosure does, to a large degree, prevent negative publicity. I don't think it is in dispute that this bug would receive vastly less media coverage if it were only revealed as a bug in outdated/patched versions of the OS. I don't want to see Apple hurt (I'm an Apple-guy myself, using Macs, iPhone, iPad and Apple Watch), I want to see them improve. I doubt they start will start caring about QA unless they're…

Closed disclosure is responsible disclosure. Moving past the terminology, I am an Apple user as well, I am pretty satisfied with how quickly Apple resolves issues. Now if every person started disclosing vulnerabilities via twitter without giving the company turn around time to resolve the issue based on their dissatisfaction with Apple based on standards they came up with personally, I don’t think it is nice or fair.

So, obscurity is responsible disclosure? Cause being "closed disclosure" is being obscure.

A root password solves this issue. Its seconds to implement and helps right now.... Not "later" as closed disclosure does.

I'd rather know every error and critical bug. I can bring up with our team and decide now to either sudo service * stop or continue.

Your closed options keep the fact I'm vulnerable away, along with any pathways I might have to fix.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#653
post #450

Earlier quoted context omitted.

For me, the most painful is that this time they managed to screw up the damn keyboard while bringing absolutely nothing new. I can't even use hangout or chat on my iPad Air , i have to wait 3 seconds for my words to appear. That's just wrong. There's no excuse for that. We're not talking about fancy animation or new features that we think aren't a great idea. Just a basic regression on one of the most fundamental thi…

> I can't even use hangout or chat on my iPad Air , i have to wait 3 seconds for my words to appear. Obviously, something's wrong with your keyboard, but how do you know it's iOS's fault instead of your app's?

Because i know many people with the same issue, and the apple forums are filled with people with the same issue. It's not just hangout, every apps has the same issue ( including the one i'm selling to my customers )

Re: macOS High Sierra: Anyone can login as “root” with empty password

#654

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

There is no "responsible disclosure". You will never get 7 billion humans to do things exactly the way you want it, so if there is a possibility of at least 1 person disclosing a zero day publicly, then you have to be prepared for it just as much as if it was everyone.

Instead of trying to control behaviour of every single human being in this world and demanding of them to do things in a certain way - which is, was and will always be impossible it is much more favourable to establish the expectation that a zero day vulnerability might be dropped every week and have businesses (vendors and clients) be prepared for it so it can be handled adequately.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#655
post #583

Earlier quoted context omitted.

I'll agree that Snow Leopard is the high water-mark.

It's common among a small group of Mac users to hold Snow Leopard up as the peak of software quality, but only because of rose-colored glasses [1]. [1] https://www.computerworld.com/article/2528936/mac-os-x/snow-...

It's the last release they made any significant updates to the BSD userland. I'd mark this as the release they ceased serious investment into the operating system itself. After this point it's almost nothing of note. If you look at the dates of the various tools etc., this release is when they were last updated. Many are now getting on for being a decade out of date. The only major change has been the switch to llvm, and they made that horribly painful.

It also marks the decline of the desktop UI to introduce increasing amounts of iOS-like behaviour and appearance to the detriment of a usable desktop. Like proper scrollbars etc.

While some nostalgia might account for holdouts, it was the peak of MacOS in the minds of many, including myself. As a developer, I've been quite disappointed by its direction and declining quality. For the amount we pay for this hardware, it's not much to ask for some basic maintenance work and testing to be done.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#656
post #99

Wow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.

it was a feature not a bug. something related to not DoSing yourself by forgetting your password /s

Re: macOS High Sierra: Anyone can login as “root” with empty password

#657
post #608

My computer automatically downloaded high sierra without me wanting it to. Whether I was tricked into clicking something I don’t know. And then I heard about the disk utility password bug and decided I should wait a while before installing this OS— it seems as though Apple wants me to do their QA for them. And now I hear about this. And I see that dumb ugly notch on the iPhone X (seriously who approved that design de…

Have you used an iPhone X? The notch actually makes a lot of sense once you've used the gestures associated with it, same with how it integrates into apps. I'll agree that they've made a lot of mistakes in their product lines recently but the iPhone X was not one of them.

Well, sparing software. I've had intermittent phantom screen input using the latest betas on the X, making it infuriatingly unusable at times.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#658
post #484

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

I think there's a middle ground to this. Submit your report to Apple security, allow them time to develop a patch, and then in a week go ahead and tweet at the big media outlets about it. I'm a die-hard Apple user myself, but I agree that the long list of severe bugs in High Sierra is absurd, and a big public backlash might be enough to kick them into gear. On the other hand, I, a university student with next to no u…

Maybe it's crazy that we give people physical access to machines and expect them not to be able to obtain root.

I don't have any experience with enterprise-grade IT, but it seems like shared computers should be thin clients or at least use UEFI to securely boot an image over the network and not keep anything sensitive locally.

If you give someone physical access to a box, they will be able to own it.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#659

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

Security experts and hobbiests know this, but not your average user. This doesn't look like an in-depth bug hunt. Maybe more average users should be educated about responsible disclosures when finding security problems. This tweeter might not realize they gave up some money.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#660

Earlier quoted context omitted.

osquery is not a built-in tool. You can get the same info with plutil(1): $ sudo plutil -p /private/var/db/dslocal/nodes/Default/users/root.plist If I understand OP correctly, if passwd is a lone asterisk, then you haven't been exploited. Edit: trying a little harder to dump accountPolicyData: $ sudo defaults read /private/var/db/dslocal/nodes/Default/users/root.plist accountPolicyData | grep -oE '[[:xdigit:]]+' | xx…

Bad news: I tried the exploit in my macOS Sierra installation and it didn't seem to work. However, the passwd entry on the output of your first command IS A LONE ASTERISK. However I still can't login as root. This leads me to believe this behavior has always been there, and maybe the login methods just didn't allow an empty password.

This is very normal in 'nix' systems. '' indicates a locked account. (I've given up figuring out how to escape an asterisk)

ex:

  daemon:*:1:1::0:0:Owner of many system processes:/root:/usr/sbin/nologin
  operator:*:2:5::0:0:System &:/:/usr/sbin/nologin
  bin:*:3:7::0:0:Binaries Commands and Source:/:/usr/sbin/nologin
  tty:*:4:65533::0:0:Tty Sandbox:/:/usr/sbin/nologin
If the OS is letting you in with a '*'in the encrypted password field, something is very very wrong.
Post reply on HN