Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

691–700 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#691

Earlier quoted context omitted.

I really disagree - this needs to be reported as much as possible publicly to create a huge thunderstorm of negative publicity for Apple. This isn't the first extremely serious and dumb High Sierra password bug this year [1] [2], and unless Apple is severely hurt by it, so they're forced to change, it won't be the last. High Sierra is full of bugs and seemingly not just annoying bugs, but also security bugs. Let's ho…

Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed. Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the proce…

> Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the process.

Apple put millions of their customers at risk by skimping on QA. As an Apple user I'm OK with this getting out if it motivates Apple to improve their approach in the future.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#692
post #526

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

This is one of the sillier things I've read today. The only way something like this slips through is a culture of complacency, or incompetence. And the only way Apple gets motivated to fix either of those two things is massive Pr damage.

How long have you been working in software? Bugs like this get past competent developers in reasonable organizations all the time.

Human fallibility, yo.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#693
post #291

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

I disagree. Being unaware of the flaw doesn't make you more secure.

Attackers being unaware of the flaw does.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#696

Earlier quoted context omitted.

I qualified it with "reliably". Major bugs reported by you, a security researcher, may be bucketed differently than those deemed less serious or filed by others. As a recent example, a minor bug like the iOS 11 calculator ignoring keypresses had reports filed since Beta 1, but only after it made headlines and caused Apple public embarrassment will it be addressed in the upcoming 11.2, six months later.

A calculator bug is hardly in the same ballpark.

It's worse. It shows nobody at Apple even tried to use app they are shipping.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#697

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

People are already fixing their machines because he tweeted. this is too much of a huge blunder to wait for the official channels.

A very small percentage of particularly tech-savvy users. The benefits to this subset do not justify the harm to everyone else.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#698

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

> Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool no one is under any obligation to sweep company's security problems under the rug for them. If companies create incentives for people to share vulnerabilities with them first, great, but no one is under any obligation to participate in those programs. Don't ship broken software if you don't want pie in your face.

This isn’t about what’s best for Apple it’s about what is best for users. The way this was disclosed was bad for users.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#700

That twitter thread and lots of the comments are missing the point. MANY people don't know about what the ethics of reporting vulnerabilities are, they just want to say something and get it fixed. yes, it probably would have been better if this person had gone through proper channels, but there's no evidence they did it for the lulz/fame. In this case the bug is so bad and egregious, that publicizing it with the fix…

I’m not a security researcher and I don’t work for Apple. If I casually came across this I would totally tweet it out. Anyone asserting I should follow some sort of procedure has a misplaced sense of reality.

Yeah this is not like you have to craft special wireless packets to compromise the Broadcom network stack and then gain access. It's not that kind of vulnerability. This is really dumb and anybody can stumble across it. Hell, I work on network devices and non-production ones have root and blank as the password. I have tried the same in my laptop many times out of habit.

Responsible disclosure works when you are fairly certain you have found something nobody else knows about. Logging in with root must be known to many people.

Post reply on HN