Earlier quoted context omitted.
Mostly, they're just missing out on an up to $200,000 bug bounty. https://www.theregister.co.uk/2016/08/05/apple_joins_the_bug...
"Invite only", "provides a full report and a proof of concept that is accepted by Apple engineers"
macOS High Sierra: Anyone can login as “root” with empty password
741–750 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#742Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.
> people are under no obligation to
> report vulns privately
Legal obligation, no, you're right. Moral obligation? Why not?Re: macOS High Sierra: Anyone can login as “root” with empty password
#743In the Spotlight Search type "Terminal" and press enter.
At the terminal type "passwd" and press enter.
The terminal will prompt you to change the password for "root".
Re: macOS High Sierra: Anyone can login as “root” with empty password
#744Earlier quoted context omitted.
Why does it need to create a lot of negative publicity for Apple? Is there something you don't like about them? Responsible disclosure needs to be valued given the number of macs out there in the wild that could potentially be susceptible to issues like this, and the impact it could have on people (including you) not just directly but indirectly. How would you feel if someone discovered a 0day at a company that expos…
> Is there something you don't like about them? You mean, in addition to bad QA and complete disregard for their users' security? And being the richest and most profitable company ever, cutting corners and evading taxes? Their response on Twitter was amazing: "PM us so we can discuss this privately", not "thank you, we're looking into it NOW".
Apple is a Rorschach test writ large. What people see in it reflects more on the observer than the company in many cases.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#745I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…
The loss of people like Avie Tevanian and Bertrand Serlet took its toll. Are there any "(tech) household name" engineers doing system-level work on iOS/macOS these days? It seems like Google and Facebook have a slew of them.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#746Earlier quoted context omitted.
I’m not a security researcher and I don’t work for Apple. If I casually came across this I would totally tweet it out. Anyone asserting I should follow some sort of procedure has a misplaced sense of reality.
You would do that.. but you don’t consider what you should do.. surely responsible disclosure is the smarter strategy?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#747Earlier quoted context omitted.
You would do that.. but you don’t consider what you should do.. surely responsible disclosure is the smarter strategy?
Responsible vs irresponsible... how would I know? You’re assuming way too much.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#748No one else has mentioned it seems, digging through the twitter comments I found a tweet which states this was already known by Apple, and posted on the forums in the form of a solution... https://forums.developer.apple.com/thread/79235#277225
Re: macOS High Sierra: Anyone can login as “root” with empty password
#749Earlier quoted context omitted.
There is nothing irresponsible about disclosing huge vulnerabilities in software by any means necessary. Edit: as usual, downvotes but no response. I miss when this place was decent.
Why not? The end goal is protecting users. If disclosing a vulnerability before a company has a chance to fix it puts more users at risk than waiting how is that not irresponsible?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#750Besides for APFS what user visible killer features has Apple made to Mac OS since 10.6.8? I'm sure they have made internal non user visible improvements to their kernel and userland. But it seems most of the "changes" to Mac OS is just churning code, or at least it seems that way from the outside. To me personally 10.6.8 + Security Updates + APFS is extremely close to the ideal operating system.
Real answer, APFS (which changes the Filevault encryption model to no longer be full-disk-encryption...) and Metal2 graphics (which has brought a variety of new gfx bugs into play, even for 1st party applications) are the big technical draws
For a full list of changes, review the marketing page or the developer release docs
- https://www.apple.com/macos/high-sierra/
- https://developer.apple.com/library/content/releasenotes/Mac...
(yes Apple can't be bothered to update their dev docs with the point releases. Documentation quality has fallen off dramatically since the 10.6 days)
Given the stream of bug reports on various apple sites, I have not upgraded any of my personal machines, and my employer has stated they will not be upgrading our machines in the near term.