Does this bypass filesystem encryption?
macOS High Sierra: Anyone can login as “root” with empty password
91–100 of 1001 posts
Re: macOS High Sierra: Anyone can login as “root” with empty password
#92Re: macOS High Sierra: Anyone can login as “root” with empty password
#93Re: macOS High Sierra: Anyone can login as “root” with empty password
#94It seems like the best mitigation for the moment might be to enable the root user and set a password for it.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#95I just tested this on a Sierra (10.12.6) machine, and verified this bug isn't present in that earlier OSX version.
Same, I'm on 10.12.6, could not reproduce anywhere. I think I'll hold off on that 10.13.1 "security update" it keeps bugging me about. Seems to let anyone use my computer... Edit: After looking a little further, it seems staying on Sierra will always be a 10.12.* version, and High Sierra is 10.13.*?
- Mavericks (10.9.x)
- Yosemite (10.10.x)
- El Capitan (10.11.x)
- Sierra (10.12.x)
- High Sierra (10.13.x)
Re: macOS High Sierra: Anyone can login as “root” with empty password
#96Re: macOS High Sierra: Anyone can login as “root” with empty password
#97Fix this by setting a password for root (or disable). Instructions here: https://support.apple.com/en-us/HT204012
Re: macOS High Sierra: Anyone can login as “root” with empty password
#98Anyone else think it was a bad idea to disclose this so publicly over Twitter? I thought that the usual practice was to let the development team know first.
Re: macOS High Sierra: Anyone can login as “root” with empty password
#99Re: macOS High Sierra: Anyone can login as “root” with empty password
#100Can this be used remotely? Edit: Yes, after turning on Remote Management on my second mac I was able to log into it using Remote Desktop, account root and no pw. It only works after getting physical access once.