Earlier quoted context omitted.
Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.
It was partly a marketing thing, but Edge is not IE, and Edge has never supported any plugins (which Silverlight is).
macOS High Sierra: Anyone can login as “root” with empty password
861–870 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#862Top 10 software blunders of all time: 1) (Apple) 1 + 2 + 3 = 24 https://news.ycombinator.com/item?id=15538666 2) (Apple) Blank root password https://news.ycombinator.com/item?id=15800676 3) ...
There ARE areas more safety critical than desktop computing, you know.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#863Looks like changing root’s password blocks the exploit but if you disable the root user, it re-enables the exploit. Protect yourself by changing root’s password: ⌘ (Command) + Space, Directory Utility, click the lock and enter your password, Edit -> Change Root Password…, then do NOT disable Root User. Or open a terminal and do: sudo passwd
dsenableroot -d
does not re-enable the exploitRe: macOS High Sierra: Anyone can login as “root” with empty password
#864"We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section."
Re: macOS High Sierra: Anyone can login as “root” with empty password
#865I see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up th…
Of course all that changed when its only priority became to shift more iPhones, and everything became secondary to that.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#866Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
There’s no need to do this yourself to verify it. Doing so creates a “root” account that others may be able to take advantage of if you don’t disable it. That should be much higher up in the article.
1. Try logging in with root and a good password. It should not work (if it does, root with that password had been enabled before).
2. Now, try logging in again with root and that same password.
2a. If it works, your system was vulnerable to that bug, but you've now fixed the problem, as you've enabled root and set a good password (so nobody else can log in unless they find that password).
2b. If it doesn't work, it looks like root had been set up before with some other password (maybe empty), and it's conceivable that someone has exploited that bug on your machine before.
Is that understanding correct?
Re: macOS High Sierra: Anyone can login as “root” with empty password
#867Earlier quoted context omitted.
Blank password is not necessary. Any password provided on initial attempt WILL BECOME the root password. Blank is being circulated simply because that's what was discovered first. Edit: Which also means it's possible to "secure" a vulnerable (unexploited) machine simply by attempting to log in as root with a long random password.
So by my logic - if you tried this exploit and it failed the first time, then worked the second time: No one else has tried it before you. Otherwise it would either have worked the first time (if you guessed the same pass) or not worked at all (if the first time it was tried a different pass was used). Or is this not a permanent password set?
But, if you don't have Screen Sharing or Remote Management enabled and exposed to the WAN, you're probably safe unless someone untrusted had physical access.
It's hard to know how long this vulnerability was "known." The initial report on Nov 13th looks second hand, so it may have been circulating earlier.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#868Earlier quoted context omitted.
> not improving macOS won’t make anyone upset enough to switch back I’m not so sure about this — although it may be due more to the hardware side of their business: after the recent, disappointing iteration of their MacBook Pros I’ve heard a lot of people considering to switch (and actually switching). Taken together with software quality issues, I wouldn’t be surprised if at least a subgroup of users are leaving App…
Nobody cares about what developers like in their computers, developers will go wherever the users are. And Apple now has a sizable chunk of computer users and an even larger chunk of smartphone users.
Otherwise I don't care which browser you are using to look at my pages, or which Desktop to run my qt app.
There was a massive influx of developers switchting to mac laptops before it was popular with a majority of users (around 2008).
Re: macOS High Sierra: Anyone can login as “root” with empty password
#869Earlier quoted context omitted.
Surely they havent used up the pool of people that might/want switch to macOS. How can anyone make even such statement?
Some years ago, I was hearing about people switching from PCs to Macs all the time. Later, not so much, but macOS was still getting praise. Maybe Apple looked at the conversion numbers at that time and decided that the cost of keeping up the quality of macOS wasn’t worth the few PC converts they were still getting, and they figured that not enough people would switch back to PCs since the iOS system lock-in effects,…
At this state in the company's life there is a disconnect between those who make the software and those who make the business decisions.
I don't think it's likely that Apple's board just decided to give up attracting new customers, and any apparent decline in quality is likely attributed to bad management; ineptitude, rather than purpose.
Occam's Razor supports this hypothesis.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#870Earlier quoted context omitted.
> not improving macOS won’t make anyone upset enough to switch back I’m not so sure about this — although it may be due more to the hardware side of their business: after the recent, disappointing iteration of their MacBook Pros I’ve heard a lot of people considering to switch (and actually switching). Taken together with software quality issues, I wouldn’t be surprised if at least a subgroup of users are leaving App…
Nobody cares about what developers like in their computers, developers will go wherever the users are. And Apple now has a sizable chunk of computer users and an even larger chunk of smartphone users.