Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

851–860 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#851

Earlier quoted context omitted.

Blank password is not necessary. Any password provided on initial attempt WILL BECOME the root password. Blank is being circulated simply because that's what was discovered first. Edit: Which also means it's possible to "secure" a vulnerable (unexploited) machine simply by attempting to log in as root with a long random password.

So by my logic - if you tried this exploit and it failed the first time, then worked the second time: No one else has tried it before you. Otherwise it would either have worked the first time (if you guessed the same pass) or not worked at all (if the first time it was tried a different pass was used). Or is this not a permanent password set?

If that's true (and certainly sounds plausible from what is known so far), that's a very valuable heuristic.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#852

Top 10 software blunders of all time: 1) (Apple) 1 + 2 + 3 = 24 https://news.ycombinator.com/item?id=15538666 2) (Apple) Blank root password https://news.ycombinator.com/item?id=15800676 3) ...

Sort of related:

- it is almost 2018 and copy pasting on an ipad/iphone is still a horrible, non-deterministic nightmare

Re: macOS High Sierra: Anyone can login as “root” with empty password

#853
post #828
post #817

Earlier quoted context omitted.

And seeing this I am wondering why people still trust closed-source software. My long term dream is using 100% free software on a HW with minimum binary blobs.

This also can happen in open software. So I don't think your comment is valid. Open software enables people to take a look inside to what is going on. It isn't a cure for bug free development.

It reminds me the KMail bug: https://www.ctrl.blog/entry/kmail-cve-2017-9604-openpgp

Some security bugs exist in the Linux/BSDs kernels for a loooong time before someone notice and fix it (e.g., https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20pre...)

Re: macOS High Sierra: Anyone can login as “root” with empty password

#854
post #838

I see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up th…

Surely they havent used up the pool of people that might/want switch to macOS. How can anyone make even such statement?

Some years ago, I was hearing about people switching from PCs to Macs all the time. Later, not so much, but macOS was still getting praise. Maybe Apple looked at the conversion numbers at that time and decided that the cost of keeping up the quality of macOS wasn’t worth the few PC converts they were still getting, and they figured that not enough people would switch back to PCs since the iOS system lock-in effects, etc. would present enough of a barrier.

So it’s not that there aren’t still people who could conceivably switch to Macs, it’s that Apple decided they didn’t need more converts quite as badly anymore.

Still, only my theory of course.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#855
post #838

I see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up th…

I really hope that's not true and this is just some extended blip.

That said, between this, the disk encryption bug, not being able to type "I" on an iphone you have to wonder what is going on. I recently upgrade my MacBook Pro to High Sierra and it's been plagued with problems (Weird red flash when displaying menus, hangs/crashes with external monitors etc.)

Then I look at switching away, and I lose all the OSX software I own, all the easy iOS integration, all those Pages documents etc.

Maybe I just need to build a cheap but upgradable Linux box and start trying to switch.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#856
post #838

I see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up th…

> not improving macOS won’t make anyone upset enough to switch back

I’m not so sure about this — although it may be due more to the hardware side of their business: after the recent, disappointing iteration of their MacBook Pros I’ve heard a lot of people considering to switch (and actually switching).

Taken together with software quality issues, I wouldn’t be surprised if at least a subgroup of users are leaving Apple gradually. That subgroup being professional users, of course: Apple is still unassailed as a status symbol, and casual (+ mobile) users seem more than happy.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#857

Top 10 software blunders of all time: 1) (Apple) 1 + 2 + 3 = 24 https://news.ycombinator.com/item?id=15538666 2) (Apple) Blank root password https://news.ycombinator.com/item?id=15800676 3) ...

Well I remember when the Ubuntu installer left your root password in a clear text file that was world readable on your FS.[1]

I would really like to see a top 10 list of software blunders, I think everyone on HN would.

1. https://launchpad.net/ubuntu/+source/shadow/+bug/34606

Re: macOS High Sierra: Anyone can login as “root” with empty password

#858

Top 10 software blunders of all time: 1) (Apple) 1 + 2 + 3 = 24 https://news.ycombinator.com/item?id=15538666 2) (Apple) Blank root password https://news.ycombinator.com/item?id=15800676 3) ...

0)(Apple) If macOS High Sierra shows your password instead of the password hint https://news.ycombinator.com/item?id=15410953

Re: macOS High Sierra: Anyone can login as “root” with empty password

#859
post #856
post #838

I see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up th…

> not improving macOS won’t make anyone upset enough to switch back I’m not so sure about this — although it may be due more to the hardware side of their business: after the recent, disappointing iteration of their MacBook Pros I’ve heard a lot of people considering to switch (and actually switching). Taken together with software quality issues, I wouldn’t be surprised if at least a subgroup of users are leaving App…

Nobody cares about what developers like in their computers, developers will go wherever the users are. And Apple now has a sizable chunk of computer users and an even larger chunk of smartphone users.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#860

Fortunately, I'm OK. The latest OS upgrade failed to install and bricked my computer so that no one could log in, let alone root. I was able to restore it using Time Machine but I don't think I'll go through that exercise again for a while yet.

That probably takes some major doublethink: convincing yourself that a bricked machine is less broken than a vulnerable one.
Post reply on HN