Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

741–750 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#741

Earlier quoted context omitted.

Mostly, they're just missing out on an up to $200,000 bug bounty. https://www.theregister.co.uk/2016/08/05/apple_joins_the_bug...

"Invite only", "provides a full report and a proof of concept that is accepted by Apple engineers"

what the f is the point of this being invite only... i will never understand apple.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#742

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger. The fact that we know about it means we can take steps to mitigate the damage.

    > people are under no obligation to
    > report vulns privately
Legal obligation, no, you're right. Moral obligation? Why not?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#744
post #639
post #443

Earlier quoted context omitted.

Why does it need to create a lot of negative publicity for Apple? Is there something you don't like about them? Responsible disclosure needs to be valued given the number of macs out there in the wild that could potentially be susceptible to issues like this, and the impact it could have on people (including you) not just directly but indirectly. How would you feel if someone discovered a 0day at a company that expos…

> Is there something you don't like about them? You mean, in addition to bad QA and complete disregard for their users' security? And being the richest and most profitable company ever, cutting corners and evading taxes? Their response on Twitter was amazing: "PM us so we can discuss this privately", not "thank you, we're looking into it NOW".

I suspect the response on Twitter was a typical reply from a tier 0 support person. No reason to extrapolate from that to the company's internal response.

Apple is a Rorschach test writ large. What people see in it reflects more on the observer than the company in many cases.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#745

I wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with App…

The loss of people like Avie Tevanian and Bertrand Serlet took its toll. Are there any "(tech) household name" engineers doing system-level work on iOS/macOS these days? It seems like Google and Facebook have a slew of them.

In the case of Facebook, all the “household named” developers do nothing to improve the quality of their output, be it their user-facing software or developer-facing open source.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#746

Earlier quoted context omitted.

I’m not a security researcher and I don’t work for Apple. If I casually came across this I would totally tweet it out. Anyone asserting I should follow some sort of procedure has a misplaced sense of reality.

You would do that.. but you don’t consider what you should do.. surely responsible disclosure is the smarter strategy?

Responsible vs irresponsible... how would I know? You’re assuming way too much.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#747

Earlier quoted context omitted.

You would do that.. but you don’t consider what you should do.. surely responsible disclosure is the smarter strategy?

Responsible vs irresponsible... how would I know? You’re assuming way too much.

The average person who has never heard these things may act as described, but the person should be criticized for it, and if they dont correct their mistake they should be criticized for that too. Thats the point of criticism.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#748

No one else has mentioned it seems, digging through the twitter comments I found a tweet which states this was already known by Apple, and posted on the forums in the form of a solution... https://forums.developer.apple.com/thread/79235#277225

Mentioned many times actually. And the forum is users self help. It is not monitored by Apple.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#749
post #685

Earlier quoted context omitted.

There is nothing irresponsible about disclosing huge vulnerabilities in software by any means necessary. Edit: as usual, downvotes but no response. I miss when this place was decent.

Why not? The end goal is protecting users. If disclosing a vulnerability before a company has a chance to fix it puts more users at risk than waiting how is that not irresponsible?

Considering the vulnerability was supposedly brought to Apple's attention a month earlier via the "proper" channels, and considering Apple's history of repeatedly ignoring and dismissing said disclosures, I'd say this was the only correct action to take.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#750

Besides for APFS what user visible killer features has Apple made to Mac OS since 10.6.8? I'm sure they have made internal non user visible improvements to their kernel and userland. But it seems most of the "changes" to Mac OS is just churning code, or at least it seems that way from the outside. To me personally 10.6.8 + Security Updates + APFS is extremely close to the ideal operating system.

There's the new poop emoji!! (unicode 10 emojis via 10.13.1 update)

Real answer, APFS (which changes the Filevault encryption model to no longer be full-disk-encryption...) and Metal2 graphics (which has brought a variety of new gfx bugs into play, even for 1st party applications) are the big technical draws

For a full list of changes, review the marketing page or the developer release docs

- https://www.apple.com/macos/high-sierra/

- https://developer.apple.com/library/content/releasenotes/Mac...

(yes Apple can't be bothered to update their dev docs with the point releases. Documentation quality has fallen off dramatically since the 10.6 days)

Given the stream of bug reports on various apple sites, I have not upgraded any of my personal machines, and my employer has stated they will not be upgrading our machines in the near term.

Post reply on HN