Live data from Hacker News

macOS High Sierra: Anyone can login as “root” with empty password

twitter.com

861–870 of 1001 posts

Re: macOS High Sierra: Anyone can login as “root” with empty password

#861

Earlier quoted context omitted.

Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.

It was partly a marketing thing, but Edge is not IE, and Edge has never supported any plugins (which Silverlight is).

Correction: Edge is Not-IE(-Not-At-All-Nooosir)

Re: macOS High Sierra: Anyone can login as “root” with empty password

#862

Top 10 software blunders of all time: 1) (Apple) 1 + 2 + 3 = 24 https://news.ycombinator.com/item?id=15538666 2) (Apple) Blank root password https://news.ycombinator.com/item?id=15800676 3) ...

0) Therac 25: https://hackaday.com/2015/10/26/killed-by-a-machine-the-ther...

There ARE areas more safety critical than desktop computing, you know.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#863

Looks like changing root’s password blocks the exploit but if you disable the root user, it re-enables the exploit. Protect yourself by changing root’s password: ⌘ (Command) + Space, Directory Utility, click the lock and enter your password, Edit -> Change Root Password…, then do NOT disable Root User. Or open a terminal and do: sudo passwd

Disabling the root user again with

  dsenableroot -d
does not re-enable the exploit

Re: macOS High Sierra: Anyone can login as “root” with empty password

#864
Apple released the following statement regarding this bug:

"We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section."

Re: macOS High Sierra: Anyone can login as “root” with empty password

#865
post #838

I see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up th…

I really don't think that to be the case. Quality on OS X was a priority in its own right and fundamental to everything at Apple, not just a by-product of a strategy to get people to move from Windows.

Of course all that changed when its only priority became to shift more iPhones, and everything became secondary to that.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#866
post #267

Encouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.

There’s no need to do this yourself to verify it. Doing so creates a “root” account that others may be able to take advantage of if you don’t disable it. That should be much higher up in the article.

Wouldn't it make sense to propose this combined diagnostic and workaround:

1. Try logging in with root and a good password. It should not work (if it does, root with that password had been enabled before).

2. Now, try logging in again with root and that same password.

2a. If it works, your system was vulnerable to that bug, but you've now fixed the problem, as you've enabled root and set a good password (so nobody else can log in unless they find that password).

2b. If it doesn't work, it looks like root had been set up before with some other password (maybe empty), and it's conceivable that someone has exploited that bug on your machine before.

Is that understanding correct?

Re: macOS High Sierra: Anyone can login as “root” with empty password

#867

Earlier quoted context omitted.

Blank password is not necessary. Any password provided on initial attempt WILL BECOME the root password. Blank is being circulated simply because that's what was discovered first. Edit: Which also means it's possible to "secure" a vulnerable (unexploited) machine simply by attempting to log in as root with a long random password.

So by my logic - if you tried this exploit and it failed the first time, then worked the second time: No one else has tried it before you. Otherwise it would either have worked the first time (if you guessed the same pass) or not worked at all (if the first time it was tried a different pass was used). Or is this not a permanent password set?

Well, I suppose if someone had exploited your system with this, they could probably install some remote access tool, and then disable the root account and unset the password, and remove all evidence they were there.

But, if you don't have Screen Sharing or Remote Management enabled and exposed to the WAN, you're probably safe unless someone untrusted had physical access.

It's hard to know how long this vulnerability was "known." The initial report on Nov 13th looks second hand, so it may have been circulating earlier.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#868
post #859
post #856

Earlier quoted context omitted.

> not improving macOS won’t make anyone upset enough to switch back I’m not so sure about this — although it may be due more to the hardware side of their business: after the recent, disappointing iteration of their MacBook Pros I’ve heard a lot of people considering to switch (and actually switching). Taken together with software quality issues, I wouldn’t be surprised if at least a subgroup of users are leaving App…

Nobody cares about what developers like in their computers, developers will go wherever the users are. And Apple now has a sizable chunk of computer users and an even larger chunk of smartphone users.

This only holds true if you consider lock-in IMO, e.g. you need a mac to develop iOS or mac apps, or you need a windows machine to develop windows apps.

Otherwise I don't care which browser you are using to look at my pages, or which Desktop to run my qt app.

There was a massive influx of developers switchting to mac laptops before it was popular with a majority of users (around 2008).

Re: macOS High Sierra: Anyone can login as “root” with empty password

#869
post #854

Earlier quoted context omitted.

Surely they havent used up the pool of people that might/want switch to macOS. How can anyone make even such statement?

Some years ago, I was hearing about people switching from PCs to Macs all the time. Later, not so much, but macOS was still getting praise. Maybe Apple looked at the conversion numbers at that time and decided that the cost of keeping up the quality of macOS wasn’t worth the few PC converts they were still getting, and they figured that not enough people would switch back to PCs since the iOS system lock-in effects,…

This goes against basically every corporate strategy ever, which is to always increase growth.

At this state in the company's life there is a disconnect between those who make the software and those who make the business decisions.

I don't think it's likely that Apple's board just decided to give up attracting new customers, and any apparent decline in quality is likely attributed to bad management; ineptitude, rather than purpose.

Occam's Razor supports this hypothesis.

Re: macOS High Sierra: Anyone can login as “root” with empty password

#870
post #859
post #856

Earlier quoted context omitted.

> not improving macOS won’t make anyone upset enough to switch back I’m not so sure about this — although it may be due more to the hardware side of their business: after the recent, disappointing iteration of their MacBook Pros I’ve heard a lot of people considering to switch (and actually switching). Taken together with software quality issues, I wouldn’t be surprised if at least a subgroup of users are leaving App…

Nobody cares about what developers like in their computers, developers will go wherever the users are. And Apple now has a sizable chunk of computer users and an even larger chunk of smartphone users.

There's a big difference between a developer grudgingly keeping a cheap headless mini-computer under a stack of papers somewhere that gets used only as needed, and a developer using your system as their "home base" and buying into your entire ecosystem.
Post reply on HN