Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

81–90 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#82
post #56

In the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password

Standalone iMac here - the 'Join' button is disabled. So is this vulnerability only for Macs on a network?

EDIT: My bad - editing was locked on that screen. Got it now...

EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#83
post #68

Earlier quoted context omitted.

The "root" superuser is always there, I'm not sure if it's possible to actually delete it.

It is disabled by default[1] (meaning you can't login as it), this vulnerability appears to enable the root user without setting a password. If the root user has already been enabled it doesn't work. Anyone who does this should probably set a password for now and then disable the root user account once it has been patched. [1] https://support.apple.com/en-us/HT204012

This is the best workaround for now. Enable the root user with a strong password till the bug is fixed by Apple.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#86

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

this is too serious to hide. better to tell users how to fix it than wait until apple releases something

Re: macOS High Sierra: Anyone can login as “root” with empty password

#87

Apple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even…

It's the neighborly thing to do, but people are under no obligation to report vulns privately. The blame lies squarely on Apple, not on the messenger.

The fact that we know about it means we can take steps to mitigate the damage.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#88

Excuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.

Probably could still get 15 minutes of fame if you disclosed privately then blogged about the back and forth and a picture of the $10,000 cheque from Apple.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#89
post #75

Does this bypass filesystem encryption?

Only if the laptop is locked (as the encryption key is already in memory).

Any chance that self clears after an interval?

Might be a bad day to leave the laptop at the table at the coffeeshop when ordering.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#90
A quick mitigation workaround: If you follow the steps here https://support.apple.com/en-us/HT204012 to disable the root account until the point where you open and authenticate the Directory Utility, in the Edit menu there's a "Change Root Password" option.

Set a good password there and disable the root account again.

Now people making use of this vulnerability will still be able to re-enable the root account (that's why it fail the first time - root is default off, but this bug enables it), but now there will at least be a useful password set.

Post reply on HN