Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

681–690 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#681
post #484

Earlier quoted context omitted.

I think there's a middle ground to this. Submit your report to Apple security, allow them time to develop a patch, and then in a week go ahead and tweet at the big media outlets about it. I'm a die-hard Apple user myself, but I agree that the long list of severe bugs in High Sierra is absurd, and a big public backlash might be enough to kick them into gear. On the other hand, I, a university student with next to no u…

The fact that you as the ordinary student can become root and create a lot of damage so easily is the only reason the public will care. Us geeks have been complaining about the horrible QA in macOS for years, yet nothing has been done. The fact that this is so simple to do will probably/hopefully get ordinary people to start talking about it too ("Hey, have you heard that you can hack Macs without a password? Very in…

I think only economic consequences would cause Apple to up its QA game. Like decreased sales or lawsuits with good prospects of winning serious money.

Unfortunately, I don't believe those will happen.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#682
post #239

Earlier quoted context omitted.

Not the case. Once you enable root access - by 'testing' this - others can remotely & silently access the system as root. GP is right - don't encourage people to test this, as there's nothing to gain from it. If you're on a shared machine you need to mitigate. If you're on your own dedicated machine you need to not share it until this is fixed.

> Once you enable root access - by 'testing' this - others can remotely & silently access the system as root. That's not accurate. The user appears to be there either way, but attempting to log in to a machine remotely using 'root' and no password does not work - even after doing the preference pane thing...

Wonder if people tried screen share/vnc with that theory. I'd suspect anything gui-driven.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#683

Earlier quoted context omitted.

If you leave keys in other people's doors all over the neighbourhood, I damn well have a rigtht, and possibly an obligation, to make it publicly known that such a thing is taking place. So that everyone may take their own precautions.

Let's say keys were hidden around the neighborhood. Would you rather everyone in the whole town know about it or quietly and quickly go pick up all the keys before someone notices and breaks into one of the houses? Personally I think if you report through the proper channels and nothing is changed THEN broadcast, but not as an opener.

These keys aren't exactly hidden. This is like trying the doorknob a second time.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#684
post #102

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

This situation seems more like a lock manufacturer selling millions of locks that can be opened with a toothpick.

I'd lay responsibility at the lockmaker's door, not the guy who told everybody they were at the mercy of anyone with a toothpick.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#685

Earlier quoted context omitted.

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

There is nothing irresponsible about disclosing huge vulnerabilities in software by any means necessary. Edit: as usual, downvotes but no response. I miss when this place was decent.

Why not? The end goal is protecting users. If disclosing a vulnerability before a company has a chance to fix it puts more users at risk than waiting how is that not irresponsible?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#686
post #102

Earlier quoted context omitted.

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

The blame lies squarely on Apple, not on the messenger. There is blame on both. If you leave your key in your front door lock and I blast out on twitter your address and tell people about it, I think I have some responsibility.

This is different though: the bug is so bad that random, inexpert users can discover it by accident. People that are not going to even be familiar with the term "responsible disclosure" at all. This may have been the case for the guy who tweeted this.

There is no realistic way to keep a lid on something like that and so in this case the blame is entirely on Apple.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#687
Temporary workaround (pasted from http://www.bbc.com/news/technology-42161823)

While Apple works on its fix, it offered a workaround for users concerned about the bug.

“Setting a root password prevents unauthorized access to your Mac,” the company explained.

"To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012.

---

Edit - for me those Apple instructions didn't work. This seemed to:

Search for 'Directory Utility' in Spotlight and click it.

Click the lock to make changes

Select 'Enable root user' from 'Edit' on the main menu and set a password.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#688

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

> there are any number of legit bug bounty programs The thing about bug bounty programs are that they are not a negotiation. They decide how much your information is worth--take it or leave it. If you thought this bug was worth $25,000 and you feared that Apple might offer a $100 discount coupon plus a lovely "I Love My Mac" coffee mug, is there any way to start a negotiation without being accused of extortion (if yo…

Not really; the issue is that you don't have a way to disclose how much the bug is worth without giving away the bug itself. You can kind of ask how much an exploit that gets a local user root access is worth, but that can give away enough to let them focus their own search.

In general, you have to rely on this being a repeated game - you and the pentester community at large submit lots of bugs to this company, and you rely on them to make it worth your time and talent. If they don't, you go test someone else's software. Reputation is everything.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#689
This post reminded me of why Twitter is a pretty awful place.

The replies to this tweets are all everyones snarky comments to the @AppleSupport account or their edgy 'hot takes' on the issue. @AppleSupport responded promptly - albeit obviously out of their depth, and a bunch of people couldn't help but make fun of this fact. It's almost like tweeting to Apple's customer support account is not the best way to report a vulnerability?

Responsible disclosure has a proven history of working. When the vulnerability is appropriately patched and disclosed to the public, there is still a lot of backlash. You only need to look at the recent responsibly disclosed vulnerabilities for proof of this. Instead, we have a bunch of armchair analysts—who don't at all seem to be driven by past occurrences / existing data in any way—claiming that it didn't work.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#690

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

> Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool no one is under any obligation to sweep company's security problems under the rug for them. If companies create incentives for people to share vulnerabilities with them first, great, but no one is under any obligation to participate in those programs. Don't ship broken software if you don't want pie in your face.

Forget the company. This harms users, who are not responsible for causing these issues; for all except the most technical 1% of Apple users, keeping the problem secret while Apple works on a quick patch is much more secure than telling the whole world immediately.
Post reply on HN