Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

671–680 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#671
post #468

Earlier quoted context omitted.

How do the banner or stats suggest he should have known about this?

He is giving a technical talk to a large audience. Slides refer to development, and bio implies this means software development. Bio uses the phrase 'founder of software craftsmanship Turkey'. Following the link to his home page we find: "He has worked as software architect, software craftsman, technical leader, team leader, technical coordinator, Scrum Master and Agile coach in dozens of software projects at BYM, Gi…

Are you proposing that being an active programmer implies familiarity with responsible disclosure? That doesn't follow in my mind.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#672

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

Mostly, they're just missing out on an up to $200,000 bug bounty. https://www.theregister.co.uk/2016/08/05/apple_joins_the_bug...

"Invite only", "provides a full report and a proof of concept that is accepted by Apple engineers"

Re: macOS High Sierra: Anyone can login as “root” with empty password

#673
post #515

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I agree in general, but calling it uncool and laying any blame on the person reporting is not fair. You may know the protocol, security researchers and people in the tech industry may know that, but why is an ordinary Joe expected to know, or research, that email address and/or the protocol regarding 0-day vulnerabilities.

I'd argue that even to the ordinary Joe it should be quite logical that disclosing something publicly before the company has had a chance to fix it means that nefarious people could learn about the exploit and use it against victims.

It's the same logical line of thought that leads people into turning wallets into the lost and found (or an authority) instead of just pointing at it on the ground shouting "hey look, a wallet!" then walking away.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#674
post #484

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

I think there's a middle ground to this. Submit your report to Apple security, allow them time to develop a patch, and then in a week go ahead and tweet at the big media outlets about it. I'm a die-hard Apple user myself, but I agree that the long list of severe bugs in High Sierra is absurd, and a big public backlash might be enough to kick them into gear. On the other hand, I, a university student with next to no u…

> On the other hand, I, a university student with next to no understanding of computer security, can simply walk onto campus, sit down at a Mac, and within seconds have complete access to the computer.

its educational for the end user. You cannot trust Apple. Good reminder there are other OS available out there.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#675

Oh my goodness. I have a High Sierra MBP. I am scared right now BADLY

It can't be exploited remotely. Only by someone sitting at your computer.

I know. But I don’t want my roomies to access it while I’m in the toilet, for example.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#676
post #300

I've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?

I hope a judge will order Apple to make all source code of macOS to be readable by everyone. This does not necessarily mean open source: you will not be allowed to modify and re-release it.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#677

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

This is extremely naive.

Yes Apple shouldn't be having this issue but disclosing a 0-day issue can possibly hurt users far worse than hurting Apple. Apple may lose a tiny bit of money but users could lose far, far more especially if someone develops a good way to remotely deploy / take advantage of this defect.

Ignoring responsible disclosure also limits the ability to sue them for any damage resulting from it (or so I'm told by one of my lawyer friends who thinks this disclosure may make it almost impossible to successfully sue them over it unless it simply takes them too long to fix).

Re: macOS High Sierra: Anyone can login as “root” with empty password

#678
post #484

Earlier quoted context omitted.

I think there's a middle ground to this. Submit your report to Apple security, allow them time to develop a patch, and then in a week go ahead and tweet at the big media outlets about it. I'm a die-hard Apple user myself, but I agree that the long list of severe bugs in High Sierra is absurd, and a big public backlash might be enough to kick them into gear. On the other hand, I, a university student with next to no u…

Maybe it's crazy that we give people physical access to machines and expect them not to be able to obtain root. I don't have any experience with enterprise-grade IT, but it seems like shared computers should be thin clients or at least use UEFI to securely boot an image over the network and not keep anything sensitive locally. If you give someone physical access to a box, they will be able to own it.

yes. physical access should never be considered secure.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#679
post #655
post #583

Earlier quoted context omitted.

It's common among a small group of Mac users to hold Snow Leopard up as the peak of software quality, but only because of rose-colored glasses [1]. [1] https://www.computerworld.com/article/2528936/mac-os-x/snow-...

It's the last release they made any significant updates to the BSD userland. I'd mark this as the release they ceased serious investment into the operating system itself. After this point it's almost nothing of note. If you look at the dates of the various tools etc., this release is when they were last updated. Many are now getting on for being a decade out of date. The only major change has been the switch to llvm,…

I remember my Macbook's battery life being significantly extended by an OS upgrade; either Leopard or Snow Leopard.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#680
post #267

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

There’s no need to do this yourself to verify it. Doing so creates a “root” account that others may be able to take advantage of if you don’t disable it. That should be much higher up in the article.

I really wish it had been. I had no idea it was something that A) left droppings, and B) actually enables direct login from boot with root/no pw once you've done it.

Apple's going to have to nuke everyone's root account on an update. I don't see any other solution that won't leave a shitload of machines with open root accounts from trying the fun tweet and then never setting a pw.

Post reply on HN