Does this bypass filesystem encryption?
macOS High Sierra: Anyone can login as “root” with empty password
81–90 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#82In the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password
EDIT: My bad - editing was locked on that screen. Got it now...
EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#83Earlier quoted context omitted.
The "root" superuser is always there, I'm not sure if it's possible to actually delete it.
It is disabled by default[1] (meaning you can't login as it), this vulnerability appears to enable the root user without setting a password. If the root user has already been enabled it doesn't work. Anyone who does this should probably set a password for now and then disable the root user account once it has been patched. [1] https://support.apple.com/en-us/HT204012
Re: macOS High Sierra: Anyone can login as “root” with empty password
#84Anyone else think it was a bad idea to disclose this so publicly over Twitter? I thought that the usual practice was to let the development team know first.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#85Are we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM
Re: macOS High Sierra: Anyone can login as “root” with empty password
#86Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#87Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…
The fact that we know about it means we can take steps to mitigate the damage.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#88Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#89Re: macOS High Sierra: Anyone can login as “root” with empty password
#90Set a good password there and disable the root account again.
Now people making use of this vulnerability will still be able to re-enable the root account (that's why it fail the first time - root is default off, but this bug enables it), but now there will at least be a useful password set.