42 ms·
macOS High Sierra: Anyone can login as “root” with empty password
- sizzzzlerz 9y agoFortunately, I'm OK. The latest OS upgrade failed to install and bricked my computer so that no one could log in, let alone root. I was able to restore it using Time Machine but I don't think I'll go through that exercise again for a while yet.
- anon1253 9y agoyou might be able to fix that. I had that too, had to manually update the preboot. Details are somewhere in here https://forums.developer.apple.com/thread/80174 https://forums.developer.apple.com/thread/80174
- Piskvorrr 9y agoThat probably takes some major doublethink: convincing yourself that a bricked machine is less broken than a vulnerable one.
- mcintyre1994 9y agoI'm sure many of us can often see how some kinds of bugs managed to slip through testing/QA, but this is crazy to me given it works on the login screen if it's happening for everyone on whatever version: is "user cannot log in as root when root account is disabled" not a test case? That seems.. insane?
- Xeoncross 9y agoThere are thousands of ways you could test this. Like most tests, having them isn't the same as having good ones.
- dasil003 9y agoWhy is this so far down the front page? Are people flagging it for some reason?
- jeffisabelle 9y agoI still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.
- deleted 9y ago[deleted]
- zeveb 9y ago> I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. I think the problem is due to the fact that they are fans. In this case, it's Apple, but there's no reason it couldn't be Linux or Go or whatever. Regardless, any bad news about their hero is irresponsible to disseminate. We see this same phenomenon in politics, in sports and elsewhere — I daresay it's regrettable human nature.
- eric_h 9y agoI've not commented either way on the subject in this thread, but personally I would much rather have read this as a writeup 2 or 3 months from now after the discoverer had responsibly disclosed the vulnerability and Apple had a chance to patch it. On the other hand, I'm glad that I have this information so I know not to install High Sierra on my work iMac (sitting on a desk in a WeWork behind a door whose lock would be very easy to force open) until this is fixed. [Edit: I now see that there's a simple workaround (change the root password and keep root enabled), so I'm all for "irresponsible disclosure" in this case]
- eric_h 9y agoAs an addendum apple released a fix for this less than 48 hours after it was reported (I think I've got the timeframe right), so there's something to be said for irresponsibly disclosing to light a fire under the ass of whomever is responsible for fixing a vulnerability.
- saagarjha 9y ago
- deleted 9y ago[deleted]
- josho 9y agoConfirmed that root with no password unlocks the preferences pane. But, changing the require password after screen saver setting doesn't take effect. So, it seems to be a bug in the UI not an actual vulnerability. edit: I stand corrected. The 'require password' setting under Security Preferences didn't change, but other settings do. Yikes
- jameskilton 9y agoOh this is a real vulnerability. It's possible to switch your user to System Administrator using "root" and no password.
- vladikoff 9y agoI have "Guest User" disabled normally. This allowed me to switch Guest User on, log out, login as `root` into OS X. lol
- nsnick 9y ago10.13.1 can't make it happen
- deleted 9y ago[deleted]
- afiler 9y agoEven on El Capitan, I was able to unlock with "root" on my first try. From there, I could add a new admin user. This seems... not good.
- cthalupa 9y agoI cannot reproduce this on Sierra or El Cap
- joshvm 9y agoI wasn't able to do it on 10.12.6 (Sierra) though, so perhaps there's something else odd here?
- uuuuuuuuuuuu 9y agoDoesn't work for me either on 10.12.6.
- jobu 9y agoWhen I tried to make a new user after unlocking as "root" it ended up making a group instead. (High Sierra 10.13.1)
- JustSomeNobody 9y agoEspecially not good is Apple likely won't fix it in El Cap. They'll tell all of us to upgrade. I don't want that buggy HS mess.
- eridius 9y agoThe bug does not exist on El Capitan. Your description tells me you already had the root user enabled with no password (which is something you can do with Directory Utility.app)
- joe_hills 9y agoI just tested this on a Sierra (10.12.6) machine, and verified this bug isn't present in that earlier OSX version.
- Cshelton 9y agoSame, I'm on 10.12.6, could not reproduce anywhere. I think I'll hold off on that 10.13.1 "security update" it keeps bugging me about. Seems to let anyone use my computer... Edit: After looking a little further, it seems staying on Sierra will always be a 10.12.* version, and High Sierra is 10.13.*?
- m11r 9y agoYes, that's correct. Recent macOS (nee OS X) versions: - Mavericks (10.9.x) - Yosemite (10.10.x) - El Capitan (10.11.x) - Sierra (10.12.x) - High Sierra (10.13.x)
- hartator 9y agoI guess they were more focused in introducing bugs and less performant filesystem than security in High Sierra.
- Twirrim 9y agoThose teams are extremely unlikely to be the same ones.
- Shank 9y agoWith user switching enabled as a username + password combo, I was able to login to the root account from the login screen with no password on 10.13.1. It's not just a UI bug, it's a full on authentication bypass.
- coreymayo 9y agoI'm able to do this as well, login as root with no password from the login screen.
- donatj 9y agoI can't seem to reproduce it locally. 10.13.1… Anyone else having issues? I've upgraded a through a couple versions of OS X on this machine - maybe that makes a difference?
- hrrsn 9y agoWorked fine for me on 10.13.1.
- drunken-serval 9y agoIt took 3 tries for me and then it worked.
- yxhuvud 9y agoPerhaps you have a root password set?
- notanai 9y agoCan this be used remotely? Edit: Yes, after turning on Remote Management on my second mac I was able to log into it using Remote Desktop, account root and no pw. It only works after getting physical access once.
- rcruzeiro 9y agoBeen wondering that myself since it seems that this also happens with the login screen.
- swozey 9y agoYes, I just had a coworker test it after I enabled remote management and they used screensharing.app. I didn't even get notified a user remoted in.. never used screen share, that seems awful. Had to look over and ask if he was in. edit: I should say, I did test this locally first so I don't know if a fresh machine that hasn't done it will do the same thing and let a remote account enable root.. Would like to hear if anyone tested it remotely WITHOUT doing it locally first.
- deleted 9y ago[deleted]
- pilif 9y agoIt only works after getting physical access once to enable the root user by gibing any password UI the root user with no password (which will enable the local root account, which is also why it fails the first time around)
- djrogers 9y agoI tested this by logging in as root at a preference pane then attempting to connect via ssh and screen sharing (both enabled) using root with no password. It did not work. Not sure if you'd get different results after logging in as root at the login screen...
- CGamesPlay 9y agoYou can get undetectble remote access on most machines given "physical access once", so I don't think this qualifies as "remotely exploitable".
- mratzloff 9y agoWow. As if I needed another reason to never "upgrade" to High Sierra...
- MentallyRetired 9y agoApparently El Capitan is vulnerable too.
- LeoPanthera 9y agoCan't reproduce on El Cap.
- tombrossman 9y agoFellow Linux users, please keep the snark in this thread to a minimum. Here's just one recent example why, there are more: http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-login-disabled http://www.omgubuntu.co.uk/2017/05/ubuntu-guest-sessions-log...
- igetspam 9y agoLinux != Ubuntu Linux didn't have that problem, a single vendor did. You could say the same for Apple except they are the single vendor. That stupid security trick in Ubuntu only impacts subset of a subset of Linux _desktop_ users which is a pretty small subset of computer users as a whole. When Apple does something like this, it impacts a much larger share of the world population. So how about we keep the snark to an appropriate level based on the impact to the world population? ;)
- arghwhat 9y agoAs Linux user who does kernel-mode development for a living, root escalation bugs come a dime a dozen. And, well, Linux runs everything but the average persons laptop, so the impact, while different, is much greater. So lets keep the snark to an appropriate level, shall we?
- igetspam 9y agoAre you arguing that privilege escalation is the equivalent to passwordless root login? I mean, I guess you squint just right you could say that a logged out user having zero privileges being able to login as a user with all privileges is an "escalation" but that's one hell of a stretch. We haven't even gotten to snark yet though. We can point to avenues for remote root all day but I don't recall any that are/were as simple as "just hit [enter] to get root" that impacts the shared attack surface that impacts all Linux systems. NOTE: I did not go and search NVD before writing this reply but I did stay at a Holiday Inn Express once.
- dsp1234 9y agoNumber of mentions of "Linux" outside of your thread comment chain: 0
- myth_buster 9y agoIs social media the goto for reporting security vulnerabilities in 2017? If I remember correctly, one is supposed to make it public once patched or in event of no response, no? Edit: What is "Responsible Disclosure"[0]? [0] https://en.wikipedia.org/wiki/Responsible_disclosure https://en.wikipedia.org/wiki/Responsible_disclosure
- ams6110 9y agoSomeone notices that they can log in as root with no password. In 2017, reflexively tweeting about it seems pretty unsurprising.
- fredsted 9y agoSeems like the guy just discovered this by accident. It's not like you'd have to be a security engineer to stumble upon this.
- donatj 9y agoI think the difference is if the problem is discovered by Joe Schmoe or a security researcher.
- cotillion 9y agoThis is one of those cases where responsible disclosure just means you're doing the job one of apples automated tests should be doing.
- FireBeyond 9y agoWhere is Joe Random's obligation to responsibly disclose? To whom does he owe that obligation? Apple? The public? Both? Why?
- TallGuyShort 9y agoIn my opinion they don't "owe" anyone that obligation, unless it's a contractual obligation associated with using a Mac. But just because it's not owed to anyone, doesn't mean there isn't a nicer way to handle it just to be nice. That said, I don't immediately see evidence that this gentleman is in the security field, and perhaps isn't aware of responsible disclosure. Full disclosure isn't the worst thing in the world.
- pmoriarty 9y agoHas no one been running password crackers against OSX this whole time?
- fixermark 9y ago<sarcasm>"OSX the more secure OS because nobody tries to hack it, CONFIRMED."</sarcasm> ;)
- notanai 9y agoYou can just type root in the login window to get System administrator access.
- jmuguy 9y agoTime to install Afterdark on all the computers in the Apple store. Confirmed here, 10.13.1.
- jrowley 9y agoAnd I just googled afterdark at work... haha thanks!
- michaelmcmillan 9y agoAre we really ready for self-driving cars? https://www.youtube.com/watch?v=4G1Boh-URIM https://www.youtube.com/watch?v=4G1Boh-URIM
- deleted 9y ago[deleted]
- ky738 9y agoI will take malicious improper analogy for 100
- michaelmcmillan 9y agoPlease point out the discrepancy. A Tesla has ~ 100.000.000 [1] lines of code. Considering this post, do you think we are sufficiently educated in software security to produce secure self-driving cars? Elon Musk: "I think one of the biggest risks for autonomous vehicles is somebody achieving a fleet wide hack" [2]. [1] https://bit.ly/KIB_linescode https://bit.ly/KIB_linescode [2] https://www.youtube.com/watch?v=4G1Boh-URIM https://www.youtube.com/watch?v=4G1Boh-URIM
- abestic9 9y agoThese companies have completely different operating systems, network ACLs, software update policies and subsystems that affect certain mechanical features. By your logic, we should not fly any modern commercial or military aircraft or spacecraft, live within a certain radius of any power or hazardous chemical plant, place any dependency on any first world country's health care network, including life support, or invest in any company or stock. Like most things in life it comes down to a security/convenience risk/benefit compromise.
- michaelmcmillan 9y ago> These companies have completely different operating systems, network ACLs, software update policies and subsystems that affect certain mechanical features. Are you claiming that this could not have happened with Tesla? If so, please explain why. > By your logic, we should not fly any modern commercial or military aircraft or spacecraft, live within a certain radius of any power or hazardous chemical plant, place any dependency on any first world country's health care network, including life support, or invest in any company or stock. Up until now the benefits have clearly outweighed the risks, but that does not mean it will continue to do so.
- mrkstu 9y agoverified on latest build of 10.13.1 (17B48).
- anon1253 9y agowat. confirmed on 10.13.1 (17B48). I was even able to add another super user. Edit: changing the login method to "Name and password" under login options, then logout and login with "root" with empty password also works. Fortunately, it doesn't work on cold boot with FileVault enabled, at least it doesn't appear so. `sudo su root` also doesn't work with an empty password.
- cortesoft 9y agowell, `sudo su root` would be using the user password for the logged in user, not for root. Does `su root` work, with no password at the prompt?
- anon1253 9y agoGood point. Force of habit. Unfortunately I can no longer try since I set the root password under the Directory Utility, which probably changed the state of the system. Apparently someone verified that it /does/ also work with `su - root`.
- valine 9y agoThis is deeply troubling. How does this even happen?
- andrewstuart2 9y agoAll too easily. There's so much to keep track of in modern systems engineering. We should all have a healthy dose of awareness that we could be/create that weakest link even on our best days.
- kowdermeister 9y agoErrr... umm... unit tests? Tests?
- andrewstuart2 9y agoYou can have 100% coverage and never check a single edge case. Much less remember every edge case.
- fredsted 9y agoThis is very, very bad.
- patcheudor 9y agoApple makes it pretty easy to report vulnerabilities to: product-security@apple.com They also respond to security@apple.com but prefer the product-security address. Further, there are any number of legit bug bounty programs out there like ZDI that would pay for a bug like this then immediately disclose to Apple for it to be fixed. Disclosing an 0Day root authentication bypass vulnerability on Twitter isn't cool, even if it is local: think of the impact to shared iMacs on university campuses.
- bangonkeyboard 9y agoIf you urgently want Apple to fix something, you do not file quiet bug reports. Apple only responds reliably to PR storms. This vulnerability is ridiculous, unacceptable, and braindead to execute.
- Scoundreller 9y agoWe need to come up with a witty name to get it fixed faster.
- bhhaskin 9y agoAppleGate
- neverartful 9y agoi0wned
- maephisto 9y agoiRoot. uRoot. Everybody Root.
- deleted 9y ago[deleted]
- plttn 9y agoMy current favorite is I am Root.
- overcast 9y agoExcuse my language, but this was a dick move to post this publicly, especially on Twitter. Go through private bug channels properly for something as serious as this. Of course doing it that way doesn't give you your 15 minutes of interweb fame.
- mikeash 9y agoMaybe he didn't know about the proper procedures to handle a security vulnerability. You wouldn't have to be a security researcher to discover this bug, and I don't see any indication that he is one.
- overcast 9y agoI would say it's pretty basic common sense, not to publicly announce ANYTHING that could immediately affect millions of people. Unless he's just a sociopath. From his Twitter account, he's not just some layman stumbling across it. Agile Software Craftsman, iyzicoder @ http://www.iyzico.com http://www.iyzico.com , Founder of Software Craftsmanship Turkey @scturkey, The community guy http://bit.ly/lemiorhan http://bit.ly/lemiorhan
- mikeash 9y agoIf that were true, then the security community wouldn't have spent years fighting about whether responsible disclosure was the right approach. That's for people who actually understand this stuff. It's unreasonable to expect an outsider to derive it all on their own from first principles.
- deleted 9y ago[deleted]
- Unknoob 9y agoConfirmed here on 10.13
- jcoby 9y agoBe careful testing this! It appears that you're creating a "root" superuser with no password. Be sure to clean up that user afterwords. https://twitter.com/a_hailes/status/935601901839806464 https://twitter.com/a_hailes/status/935601901839806464
- mschuster91 9y agoThe "root" superuser is always there, I'm not sure if it's possible to actually delete it.
- tempay 9y agoIt is disabled by default[1] (meaning you can't login as it), this vulnerability appears to enable the root user without setting a password. If the root user has already been enabled it doesn't work. Anyone who does this should probably set a password for now and then disable the root user account once it has been patched. [1] https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012
- srathi 9y agoThis is the best workaround for now. Enable the root user with a strong password till the bug is fixed by Apple.
- martinp 9y agoThis support article explains how to disable the root user: https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012
- jameskilton 9y agoDo note that this doesn't fix the problem. The system (at least High Sierra) will happily re-enable the user for every attempt at logging in.
- 9y ago
- sillysaurus3 9y agoThis is the first time I've felt happy I rarely upgrade.
- quicklime 9y agoAnyone else think it was a bad idea to disclose this so publicly over Twitter? I thought that the usual practice was to let the development team know first.
- deleted 9y ago[deleted]
- hobonumber1 9y agoHe just wants attention.
- SAI_Peregrinus 9y agoLetting the development team know first is nice to the development team, but not so nice to the users (especially not-nice if there's a workaround, which there is in this case.) My personal policy: If there's a workaround or mitigation, then full disclosure is more responsible. If there isn't then report to developers and CERT or similar. Never report only to developers, always have a deadline for full disclosure, and always have a third-party (CERT, Project Zero, etc) to disclose if you come under legal fire.
- 5ilv3r 9y agoTime and time again we have been shown that the way to a company's heart is through it's PR department. This is a dev complaining to Apple like a lunchgoer would complain to Mc D's about a bad burger. Expect more of it.
- kiliankoe 9y agoSeems to go for almost all issues regarding Apple. I've been reporting that calculator bug since iOS 9, with updates for several betas that it's still there. Two years later someone with a significant following on Twitter writes about it, gets enough retweets and Apple finally fixes something so miniscule.
- fastball 9y agoNah, Apple really needs to realize that they need to step up their game. This might hurt some users, but it sets a much needed fire under Apple's ass.
- cmurf 9y agoI can't reproduce this on a clean 10.13.1 (17B48) system, either at the login window or an authentication dialog. Update: And even after attempting it, checking Directory Utility the root user is still disabled. So I wonder if something 3rd party has enabled the root user and left it passwordless.
- srathi 9y agoConfirmed on 10.13. I was even able to add a user as an administrator after unlocking with root.
- tzakrajs 9y agoCan't reproduce on multiple High Sierra machines.
- mikestew 9y agoCan't repro on a 2012 retina MBP running 10.13.1, attempting the original repro and others suggested here. Until the wife walks away from hers, it's the only machine I have available. I'm curious as to the difference, given the high number of repros.
- nathancahill 9y agoFix this by setting a password for root (or disable). Instructions here: https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012
- kylehotchkiss 9y agoDoes this bypass filesystem encryption?
- satysin 9y agoIf it does then it means Apple's encryption implementation is fucked.
- tempay 9y agoOnly if the laptop is locked (as the encryption key is already in memory).
- kylehotchkiss 9y agoAny chance that self clears after an interval? Might be a bad day to leave the laptop at the table at the coffeeshop when ordering.
- tempay 9y agoBy default no as most people expect things to keep running when they lock their laptop. There is a setting to immediately destroy the key when the laptop sleeps. It might be outdated but [1] should give you a starting point for setting it up. [1] http://mattwashchuk.com/articles/2016/01/08/maximizing-filevault-security http://mattwashchuk.com/articles/2016/01/08/maximizing-filev...
- Someone1234 9y agoYou have a valid user as far as the OS is concerned, so you'd be able to access encrypted files and copy them off of the machine.
- ams6110 9y agoIt might, if you added "root" as a user able to unlock the disk. But you'd probably have needed to set a password for the root account to do that.
- adambull 9y agoConfirmed on 10.13.1. As a workaround, once you login as "root", you can change the password to something else, and the empty password will stop working.
- equivocates 9y agoSo — if you log out and log in as root without a password (EEK!), you can set your own password as root. Once you do, Mac os will no longer bypass the password.
- dyavuz 9y agoIn the meantime, if you'd like to protect your mac, you can set a password for root by going to: System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit > Change Root Password
- cyberferret 9y agoStandalone iMac here - the 'Join' button is disabled. So is this vulnerability only for Macs on a network? EDIT: My bad - editing was locked on that screen. Got it now... EDIT2: Root user is disabled on mine. Is that enough, given that this bug seems to create a new root user each time? Should I enable root user and set a password rather than leave it disabled?
- fredsted 9y agoAlternatively, there's `sudo passwd`.
- ianmcgowan 9y agoConfirming this works, both from preferences, as well as from the main login screen It seems like root has no password by default. Setting one is enough to close the hole. This is unbelievable! Curious to see what's in /var/db/dslocal/nodes/Default/users/root.plist before trying this.
- shoghicp 9y agoThese are the contents of the file, after converting them from binary plist to plain xml: https://gist.github.com/shoghicp/2b529b54b9d70daf192b68e3564b3f4f https://gist.github.com/shoghicp/2b529b54b9d70daf192b68e3564...
- ianmcgowan 9y agoAh, there's no ShadowHashData or KerberosKeys nodes. Presumably the code creating that plist is not aware that later on it's going to be accessed thru layers of other software and end up as a usable login. To quote Shrek: "Software is like an onion".
- deleted 9y ago[deleted]
- cortesoft 9y agoDoes this effect people who already have a root user with a password set up?
- Asmod4n 9y agoWorks with "su - root" too in a Terminal.
- zaro 9y agoClassical click and bait title. First promises that you'll become a hacker, and then when you actually click the tweet is deleted.
- Murrawhip 9y agoIsn't deleted for me.
- pilif 9y agoA quick mitigation workaround: If you follow the steps here https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012 to disable the root account until the point where you open and authenticate the Directory Utility, in the Edit menu there's a "Change Root Password" option. Set a good password there and disable the root account again. Now people making use of this vulnerability will still be able to re-enable the root account (that's why it fail the first time - root is default off, but this bug enables it), but now there will at least be a useful password set.
- Asmod4n 9y agoif you disable the root account you can log in again without a password, even when you set one.
- sccxy 9y agoI wouldn't have thought that NSA backdoors are so simple
- estevaovix 9y agoThe solution for now is to set a passwd for root... this is ridiculous
- mikeash 9y agoFor those who can't make it happen, it requires that the root account is disabled, which is the default. If you already enabled the root account for some other reason (which apparently I had on one of my Macs, although I don't know why) then that prevents it from working. It seems like the best mitigation for the moment might be to enable the root user and set a password for it.
- deleted 9y ago[deleted]
- zaro 9y agoWow. This is fun. I remember my Windows98 had the same feature. You just use Administrator with empty password and you're in. Apple is finally catching up.
- pkaye 9y agoDid Windows98 even have administrator role? I mean FAT file systems don't even have file ownership right?
- lerpa 9y agoIt did. But didn't have security tied to the fs.
- romanovcode 9y agoExactly my thoughts. I remember this, I think even early versions of WinXP had this feature.
- Grollicus 9y agoExactly early versions of Windows XP had this: They removed the Administrator user from their graphical login splash but when booted in rescue mode ("Safe mode") you could just type in "Administrator" with no password and were in. On Win98, you could just cancel the login.
- anon1253 9y agoI believe hitting "cancel" was enough. https://www.youtube.com/watch?v=DE5PRW-AR7Q https://www.youtube.com/watch?v=DE5PRW-AR7Q Also reminds me of https://youtu.be/BVL8_ne4WZo?t=19s https://youtu.be/BVL8_ne4WZo?t=19s
- dabernathy89 9y agofrom the only top-level comment on that video: > That isn't a login screen for Windows 98, it's a login for Microsoft Networking (which the box shows). If you had any shared mapped drives, network privileges, etc they wouldn't work if you cancelled. If you had multiple profiles set up, you wouldn't get those either. Win98 wasn't intended to have password security.
- dwighttk 9y agoI mean, I only tried 15 times, I don't know if that counts as "several" but this doesn't work for me. It looks to me like my root user is disabled. When I type "root" into the username field and click unlock (in System Preferences > Users & Groups) "root" is replaced with my username and the dialog shakes... I have to type root in each time, but it never unlocks. 10.13.1 Edit: trying it after logging out keeps "root" in the username field, but never logs me in... tried 20+ times
- the_economist 9y agoI was just able to reproduce it in 10.13.1. I had to click submit twice.
- deleted 9y ago[deleted]
- lanius 9y agoGood thing I haven't updated yet. I wonder how many machines are vulnerable?
- steeleduncan 9y agoTo workaround this before Apple have had a chance to patch it(thanks @lemiorhan), it seems you can: - Open Directory Utility (/System/Library/CoreServices/Applications/Directory Utility.app) - Authenticate with the lock icon - From the Edit menu you can enable the root user and set a proper password (it would already be enabled if you had tried out the exploit) Having that root user enabled isn't great overall, so it would be best to set a reminder to disable it using the same Directory Utility app once the security hole is patched.
- singularity2001 9y agoIs http://hckrnews.com/ http://hckrnews.com/ buckling from the tremendous traffic this issue generates?
- rubatuga 9y agoWhile this true, please keep in mind that rebooting your Mac into single user mode also allows anybody to login as root
- mikeash 9y agoNot if I use FileVault, surely?
- 2trill2spill 9y agoYou can set a firmware password to prevent this.
- 2trill2spill 9y agoApple has a serious software quality problem. Last night I was helping a friend with their computer. Safari couldn't even render apples website correctly. Nor could Safari connect to any site with HTTPS. Installed FireFox and HTTPS sites worked and apples's site renders. But the submit button on their developer site is broken[1]. Mail on my Mom's fully updated laptop crashes every time it's opened. Once I reported a bug in ptrace like 4 years ago and no response yet. Also the archive utility fails often to extract tar files that the tar command has no problem extracting at all. Quicktime can't play most videos, etc, etc. And now shipping an operating system with a root account with no password by default. Come on Apple you have a quarter trillion dollars in the bank why don't you spend some on improving your software. [1]: https://forums.developer.apple.com/thread/60763 https://forums.developer.apple.com/thread/60763
- minusSeven 9y agoIts not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft.
- 2trill2spill 9y ago> Its not just Apple though. Microsoft had the similar problems in the past. Edge did not support silverlight causing people to move to other browser. It was strange to see Microsoft's own software not supported by Microsoft. In my personal experience Windows has been much better than MacOS for me. I've been using Windows 7 for the last year at work and I'm having significantly less problems with Windows then MacOS. But Windows and MacOS both give me more problems then a FreeBSD or Linux box ever has.
- anko 9y ago> I'm having significantly less problems with Windows then MacOS. I'm interested.. What kind of problems? > But Windows and MacOS both give me more problems then a FreeBSD or Linux box ever has. I switched from linux on the desktop to MacOs precisely because of the problems linux had - driver support, even LTS updates breaking functionality, and overall clunkiness. I run linux on all my servers.
- swat535 9y agoThis is comical at this point. I have no idea how such vulnerable software makes it to production. It is really ironic that a company, making billions of dollars and branding itself as the leaders of quality, stability and so on, to have this kind of vulnerability. I have truly lost faith in Apple.
- gluestic 9y agoAgreed. iOS 11 was the tipping point for me (can't delete photos using trash icon, wrong orientation when unlocking phone, random lag/freezes etc). Apple just doesn't care any more.
- piyush_soni 9y agoUnless you buy Apple Care, of course. (Sorry, couldn't resist writing :) )
- gluestic 9y agoI chuckled.
- ag_47 9y agoFWIW, as a mostly Android user, the latest Oreo update was pretty terrible as well. Its all about adding new "features" just for new features sake isnt it.
- rimliu 9y ago> and branding itself as the leaders of quality, stability > and so on The days of Mac vs. PC guy are long over. Apple usualy compares their products only to their other products now (best iPhone ever, not best smartphone ever, etc.) Alas if you look around such vulnerable software makes it to production now and again, there is nothing new. Hindsight is 20/20.
- kayoone 9y agoi am not saying something like this will always happen, but it can happen. No matter what kind of testing and QA you employ (and i bet it's gigantic in Apples case), not having critical bugs in something as complex as an OS every few years is kind of impossible. Should it happen ? Obviously not. But even popular open source software used by millions and developed by hundreds is not free of issues like this, like Heartbleed showed.
- gaius 9y agoBut someone at Apple got their bonus for shipping the animated poop icon in time for this release.
- LeoPanthera 9y agoIf you think the team that makes animojis is the same team in charge of security or QA, I have news for you.
- romanovcode 9y agoWho needs security when we have animoji!
- mholt 9y agoThe HN title is wrong. This reportedly affects High Sierra, not Sierra.
- brucepucci 9y agoTo fix this with a workaround open Terminal.app and run the command "sudo passwd" to set a password. Can't believe this is happening.
- mirekrusin 9y agoMaybe NSA asked for an easy access. Apple is generally good at making things simple for users.
- nerflad 9y agoI didn't think the BSD's allowed a blank root password.
- zeveb 9y agoWell, if they don't then this is a clear indication of the improvements possible with closed-source software. At least if it'd been open, maybe someone could have diffed it …
- manwe150 9y agoI'm on Sierra and haven't been able to reproduce. But does anyone know if it respects pam.d "nullok" and I could just delete that option? /etc/pam.d$ grep -RI nullok /etc/pam.d /etc/pam.d/authorization:auth required pam_opendirectory.so use_first_pass nullok /etc/pam.d/checkpw:auth required pam_opendirectory.so use_first_pass nullok /etc/pam.d/screensaver:auth required pam_opendirectory.so use_first_pass nullok
- Asmod4n 9y agoTested it in the terminal with "su - root". Doesn't help. Or does one need to reboot after it? UPDATE: No effect after rebooting.
- tempodox 9y agoOn my system, the trick doesn't work. But then, I did explicitly set a non-empty root password.
- TonnyGaric 9y agoNot cool to disclose this kind of bug on Twitter.
- arghwhat 9y agoIt seems to activate the root user with an empty password if you try, as an admin user, to use "root"/"" as credentials in a System Preferences authentication prompt. It does not work if you are not admin. It does not work if your root user is enabled and has a password set. If you tried the vuln, you should set a password for the root user ("sudo passwd root").
- thesephist 9y agoEncouraging users to "try it" is dangerous here. Recreating the bug enables root user across the system, and most users won't know how to disable it. TechCrunch, if you're reading this... please discourage people from reproducing the bug.
- devindotcom 9y agoI was wondering about that. I'm going to change this.
- deleted 9y ago[deleted]
- eganist 9y agoThanks :)
- AdamJacobMuller 9y agoEnables root access in what way?
- selectodude 9y agoMac OS X doesn't have a real root account, it uses sudo exclusively. This enables a true root user shell.
- AdamJacobMuller 9y agoThe root account always exists. Playing around with disable/enable and the exploit: Root always has a /bin/sh shell "Disable root user" removes the ShadowHashData from the directory services entry for root The bug sets ShadowHashData to the hash of an empty string. Now, ShadowHashData is a complex DS entry. I've never seen passwords represented this way in other OSX versions. I think this password storage format is new. I strongly suspect the bug here is one related to OSX attempting to upgrade the password to the new storage format and when it does that, it inadvertently stores the password with a hash of null. This should be very trivial for Apple to fix that (and thus "disable" the root user) by just removing any ShadowHashData that is solvable by an empty string.
- AdamJacobMuller 9y agoWow, setting a root password seems to fix this...
- jonny_eh 9y agoLooks like changing root’s password blocks the exploit but if you disable the root user, it re-enables the exploit. Protect yourself by changing root’s password: ⌘ (Command) + Space, Directory Utility, click the lock and enter your password, Edit -> Change Root Password…, then do NOT disable Root User. Or open a terminal and do: sudo passwd
- AdamJacobMuller 9y ago> click the lock and enter your password or just enter root with no password
- jonny_eh 9y agoHa, ya. That way you know it's still needed!
- thomastjeffery 9y agosudo passwd Does that change the password for the current user without authentication, or does it change the password for root without authentication? I think it would be best to recommend an unambiguous sudo passwd root
- LeoPanthera 9y ago"sudo foo" with no other arguments runs "foo" as root. "passwd" with no other arguments changes the password of the user it is running as. "sudo passwd" unambiguously changes the password of root.
- davidkclark 9y agoDisabling the root user again with dsenableroot -d does not re-enable the exploit
- deleted 9y ago[deleted]
- nkrisc 9y agoI don't know much about OS development but isn't this just the sort of thing you'd automate testing for?
- nixpulvis 9y agoIf they are even a little smart, they'll now have a test for this ;)
- mikestew 9y agoIn order to create the test case that you would automate, you first must create the repro scenario. IOW, automation has nothing to do with this until the bug is found in the first place. Arguably, one could create a test model that might have found this but raise your hand if you even know what I'm talking about when I say "test model". The only mitigation that automation would bring is if the bug was found in earlier versions, and test case was subsequently written. IOW, and very much a generalization, automation is to find regressions. But if the bug is new... (To be clear, this bug still should have been found. But automation is unlikely to have found it.)
- couchand 9y agoRespectfully disagree. "User cannot log in as root if root user is disabled" is absolutely a test case that should be written regardless of previously seeing the bug.
- mikestew 9y agoMeh, you're probably right. If nothing else, I'd want to verify the result of trying to use a disabled account (text in the dialog is localized, et. al.) Run through the scenario before I formally write the case and...WTF? Yeah, I could see that.
- dandr01d 9y agoHave you seen iOS11? Apple doesn't seem to value testing too much
- 9y ago
- _jomo 9y agoCurrent workaround / fix: 1) open Directory Utility app (via Spotlight or other) 2) Click lock to make changes, log in with admin account 2) Click Edit -> Enable Root User 3) Click Edit -> Change Root Password… 4) Set a password 5) Do NOT disable root user! If you disable the root user, the admin prompt will create it again with an empty password.
- deleted 9y ago[deleted]
- saagarjha 9y agoOnce the fix for this issue is out, you should disable the root user.
- callesgg 9y agoIn what version did the issue appear?
- devindotcom 9y agowe've seen it only in 10.13.1 (17B48) so far
- mithr 9y agoIt also works on 10.13 (17A365)
- shavingspiders 9y agoI can confirm that, too. Took 2 attempts.
- fiatpandas 9y agoWorked for me on the second try (10.13.1)
- LeoPanthera 9y agoroot is disabled by default. The first try, somehow, enables it with no password. The second try will let you in.
- senko 9y agoAm I missing something or does this require the attacker to have access to an unlocked computer? In which case all bets are off anyways.
- valine 9y agoIt works remotely if remote login is enable. edit: Screen sharing is is vulnerable not ssh. Either way its bad.
- djrogers 9y agoNo it does not. I tested this rather carefully, and both ssh and screen sharing do not allow the user root with no password.
- ehntoo 9y agoI have not been able to trigger this with ssh, but certainly have been able to with Screen Sharing, even after explicitly re-disabling the root account.
- jonny_eh 9y agoWhat if it's a stolen laptop with an encrypted hard drive?
- jzwinck 9y agoIt requires the attacker to be able to type a few characters into a logged in session. If the session is not an administrative one, it's not fair to say all bets were off. If I give you a Mac logged in with an unprivileged account and you can use only the keyboard and mouse to gain root access, the security has failed. I think you've conflated this with the attacker having (full) physical access to the machine, which conventionally means access to its ports and perhaps a screwdriver. This is not that.
- senko 9y agoFair point, if that works with a guest account. I was thinking along the lines of, if I have write access to your .bashrc (or a multitude of other config files that you as an unprivileged user have write access to, and can be used to trick you later into running code of my choosing), all bets are off.
- tekacs 9y agoNow that this is public, it's likely worth passing this message on to non-technical folks too (e.g. share this or write a similar post - this is my only public post): https://www.facebook.com/amar.sood/posts/10209545863036116 https://www.facebook.com/amar.sood/posts/10209545863036116
- jtokoph 9y agoImportant error in your instructions. They should set a very strong password and keep the root account enabled. Disabling the root account opens up the vulnerability again.
- tekacs 9y agoEdit: Okay so it seems that my shell based suggestion of `dsenableroot -d` prevents the bug from re-occurring, but not the GUI version. :facepalm: I updated the post to include the word 'strong', although I would expect most users to simply set their own password, which should provide identical security to what they currently (should) have. Disabling the root account does not open up the vulnerability again. This vulnerability doesn't reset the root password, it only enables the root account and checks the password against that. The default root password out of the box on OSX is blank which is what allows this to work as-is. By setting a root password, the next time you attempt this (and I tried it), the attempt fails since the 'root' account now has a password set. Disabling simply puts the root account back in a dormant state, where it should be for most users, for after this vulnerability is fixed and it can't be enabled maliciously.
- deleted 9y ago[deleted]
- bsaul 9y agoI wonder who they're going to ask to write a public letter of apology this time. This isn't just a snarky comment. They have just released the most awfull iOS upgrade for a long time, and now this. Something's messed up, and they better fix it soon. I've think i've read somewhere they merged the iOS and macOS teams, i suppose the wrong people were promoted during the operation.
- davidkuhta 9y agoCue "incorrect elevation of privileges" joke. sudo laugh edit: spelling
- intelliot 9y agoCue
- davidkuhta 9y agodoh, thanks. Can you tell what abstract data type I've been working with lately?
- nolok 9y agoNah you don't need sudo for that anymore, now you're root
- rimliu 9y ago> They have just released the most awfull iOS upgrade for a > long time, and now this. Something's messed up, and they > better fix it soon. I keep seeing this written after each major iOS release sinc at least iOS 7.
- bsaul 9y agoFor me, the most painful is that this time they managed to screw up the damn keyboard while bringing absolutely nothing new. I can't even use hangout or chat on my iPad Air , i have to wait 3 seconds for my words to appear. That's just wrong. There's no excuse for that. We're not talking about fancy animation or new features that we think aren't a great idea. Just a basic regression on one of the most fundamental things you can do with this device (the other being displaying things). Another thing is that they usually fix slowdowns and stability with the following release soon after. Not this time, so my guess is that it'll be a "change your device" kind of upgrade.
- TrueSelfDao 9y agoSerious 0-day on Twitter. How exciting!
- bennyg 9y agoReminds me of an exploit back in 10.7 where you could create a new admin privileged user from a non-admin account using some bash commands. Used that to add Xcode to my work computer at college so I could fool around with learning how to code when I was at work.
- realworldstuff 9y agoPeople going on about responsible disclosure when this is such a gross violation of CUSSE: https://web.archive.org/web/20170712120031/http://www.cusse.org/ https://web.archive.org/web/20170712120031/http://www.cusse....
- aezell 9y agoShould I leave my Mac unattended until this is resolved?
- fulafel 9y agoYou can keep using it.
- oneeyedpigeon 9y agoEnable the root account and set a (obviously, strong) password for it. Keep calm and carry on.
- tomduncalf 9y agoI wonder what is going on with software quality and testing at Apple. It feels like recently there have been quite a few issues like this (the FileVault password bug, numerous issues with iOS 11, the issue that totally broke iOS Safari a couple of years ago) which should have been fairly easily caught, especially given the limited range of devices their software runs on. I know testing is hard, but a company with Apple’s resources shouldn’t be making slip ups like this. It suggests some real issues such as lack of unit/automated tests and/or sufficient release testing, which pretty urgently need addressing. Anyone got any inside scoop?
- bangonkeyboard 9y agomacOS and iOS updates at Apple are now inextricably tied to new iPhone releases. There is a strict yearly deadline that the teams sprint toward, a timeline imposed by marketing rather than readiness. This affects prioritization of which features are pursued, where they lie in the stack, and how polished they get. Insufficient testing at today's Apple is not limited to software. They bragged about their extensive input testing lab [0] when the new line of Magic accessories was released, but the Magic Keyboard with Numeric Keypad launched last summer had all of its inventory pulled from the channel last month because users discovered that the model was so thin that its midsection bowed over time. [0]: https://medium.com/backchannel/what-i-saw-inside-apple-s-top-secret-input-lab-6637e2e5492e https://medium.com/backchannel/what-i-saw-inside-apple-s-top...
- warent 9y agoEverything ends in tears when managers mix up targets/estimates with commitments
- nikofeyn 9y agoit is also that they pursue features just for the sake of it. things get moved arund in the iPad from release to release for no good reason, often going backwards in usability. every release i have to relearn simple things like how to manage the screen brightness. i really wonder what they are thinking internally other than “we need to shake things up to make it appear we’re doing something with stale products”.
- mrkd 9y agoTitle should be changed to 'macOS' I initially saw this thinking it didn't affect Sierra or High Sierra.
- davidkuhta 9y agoNow you have me confused, is it just High Sierra or Sierra as well?
- perryh2 9y agoIt does not work for me using Sierra.
- davidkuhta 9y agoAwesome, thanks.
- quotha 9y agoI tried it anyway and it does not work! I'm running version 10.13.1
- sugavaneshb 9y ago*macOS High Sierra
- FiveSquared 9y agoOh my goodness. I have a High Sierra MBP. I am scared right now BADLY
- LeoPanthera 9y agoIt can't be exploited remotely. Only by someone sitting at your computer.
- FiveSquared 9y agoI know. But I don’t want my roomies to access it while I’m in the toilet, for example.
- abritishguy 9y agoIf you have `osquery` deployed to your fleet you can detect compromise with this query: SELECT * FROM plist WHERE path = "/private/var/db/dslocal/nodes/Default/users/root.plist" AND key = "passwd" AND length(value) > 1;
- sounds 9y agoThat only detects enabled root users, which is a start but may include innocent people who have set a root password to protect their machines.
- deleted 9y ago[deleted]
- danra 9y agoThese bugs are getting ridiculous. With Apple's budget, finding such bugs in a security architecture review or just in QA should be as easy as 1+2+3.
- symlinkk 9y ago> 1 + 2 + 3 https://www.macrumors.com/2017/10/24/ios-11-calculator-animation-bug/ https://www.macrumors.com/2017/10/24/ios-11-calculator-anima...
- orbitur 9y agoI've been a developer for a long time. I understand bugs happen, even bugs with terrible consequences. A lot of bugs seem understandable, like I can see the chain of ifs/thens required to end up at some hilarious broken state. But I'm breaking my brain trying to figure out how in the hell a login attempt for "root" will enable it if it's disabled. Why is this is a possibility, to just enable root, no questions asked?
- tylerhou 9y agoAnother user suggested it may have to do with Apple’s new file system: https://news.ycombinator.com/item?id=15801643 https://news.ycombinator.com/item?id=15801643
- LeoPanthera 9y agoYou misunderstood. He's talking about a password hash storage system, not a filesystem.
- dec0dedab0de 9y agoI'm having a hard time understanding how this could happen too. It would have to be that looking up the root account enabled it, maybe users go dormant or something, and this was a way to readd them? then once it was enabled it defaulted to a blank password, but you would think that it needs sudo to enable root in the first place.
- pishpash 9y agoNot only enabled it but actually set an empty-string password. Usually the stored hash for a disabled account is not in the hash space, so it was either overwritten, or root account password was actually empty string out of the factory. That and the enabling of the account both point to debug code accidentally left in (or intentional backdoor by the disgruntled).
- inetknght 9y agoLogin screen is probably already running as root in the first place, so it already had permission to enable shell/GUI access
- alexwebb2 9y agoI asked this in the other thread, but... does anyone know how big of a bounty the guy missed by not disclosing this responsibly? I'm guessing it probably would've been a fairly big chunk of change.
- silencio 9y agoApparently there is no macOS bug bounty: https://twitter.com/i0n1c/status/935608248027303936 https://twitter.com/i0n1c/status/935608248027303936
- cm2187 9y agoIt really feels like the only thing that made Apple to be less prone to hacking and malware (and therefore more secure) than other OS is the lack of scrutiny by hackers and malware authors. This is a front door open kind of problem.
- Stephen-E 9y agoWhile reading this, my mac just prompted me to Upgrade to High Sierra. I think I'll hold off...
- thought_alarm 9y agoThis will be a fun fix. They'll not only have to patch the vulnerability but they'll also have to disable all of the root accounts that were inadvertently enabled. What a mess.
- Welytech 9y agoDope
- symlinkk 9y agoHow can one of the most wealthy companies on the planet, that every single software engineer would kill to work for, manage to have a bug like this? Maybe they need to re-think their hiring process, because clearly something is not working as it should.
- buryat 9y agoAWS ReInvent 2017 is going right now in Las Vegas, the number of attendees is about 40000, and I'm wondering how many laptops can be attacked using this technique. The `root` user stays in the system, so one just need to create it and open SSH quickly, and later they can do whatever they please.
- the_duke 9y agoI really hope there's an extra zero in your 40000.
- buryat 9y agoMaybe closer to 35000, but yeah, that's the scale of ReInvent, last year AWS reported 24000 attendees. I was there last year, that's a lot of people https://aws.amazon.com/blogs/apn/why-sponsor-aws-reinvent-2016/ https://aws.amazon.com/blogs/apn/why-sponsor-aws-reinvent-20...
- Washuu 9y agoUnlikely any AWS imaged employee MacBooks at least. AWS IT back in the beginning of October forbade employees to not upgrade to High Sierra.
- joshuaturner 9y agoThis reminds me of the jailbreaking scene a few years back. I was at an event centered around jailbreaking, and you were able to ssh into 80% of users iOS devices by using the default root password, alpine.
- mfrw 9y agoI may not be an apple fanboy, but I admit, I really miss Jobs, and his commitment to quality. Apple has just been minting money and forgot all about its core values.
- taurath 9y agoThis is near Windows-95 levels of bad - at the very least you need to already be logged in
- lostgame 9y ago#whyidontupgrade Until Apple forces me to with a required xCode update for the newest iOS SDK...>.>
- mrmondo 9y ago1. Ensure you always have FileVault enabled (you should regardless) and shutdown after work until the bug is fixed. 2. Add a complex root passphrase and clean this up after the fix is released. 3. Reflect on how irresponsibly this serious security bug was ‘reported’, he didn’t just potentially miss out on $200,000, he put an enormous number of people at risk of local intrusions when instead if it was properly reported there’s a good chance Apple would have released a bug fix for this quicker thus reducing the potential impact and spread of misinformation. https://en.m.wikipedia.org/wiki/Responsible_disclosure https://en.m.wikipedia.org/wiki/Responsible_disclosure https://support.apple.com/en-au/HT201220 https://support.apple.com/en-au/HT201220 (See ‘Security and privacy researchers’)
- thomastjeffery 9y agoIt's not irresponsible to make a bug public. He did not put people at risk, he showed people they are already at risk, so they would know to set a root password, and thereby not be at risk. Security by obscurity does not work!
- mrmondo 9y agoIt’s not an example of security by obscurity, it’s a straight out security flaw and bug. If it’s not publicly known and is a security risk it is far more effective to directly contact the developers / companies security team so they can immediately work on actually protecting people by developing a patch. If they don’t respond quickly (subjective, I’d call it within 12 hours) or fail to issue a fix in a timely manor (subjective, I’d say 24 hours) then yes - go public, start by logging a bug report and link to that bug report or if you can’t - the bug number / reference.
- thomastjeffery 9y agoThe fact is that the devs certainly do know about it by now, yet users do not have a fix yet. Users do, however, have a workaround, and knowledge that the security flaw exists in the first place. Waiting for a fix before disclosing a security flaw is security by obscurity, even if it is to be replaced soon. It is best for users to know that their system is vulnerable, and how to fix that without waiting for a system update.
- perfectstorm 9y agoWhat's going on with Apple's QA team ? Here's another serious bug that I came across: I've two factor authentication on my Apple account and now every time I use a new browser (or after clearing the Cache) and try to log into one of the Apple developer sites it sends me the authentication code to the same machine that I'm using. How is that two factor ? I've an iPhone which is connected to the same account but it's not my primary phone so it's most likely not ON when I do this. I guess Apple tries to send the code to my phone and when it fails sends to the next online device which happens to be the same machine I'm using to log in. So all I have to do is click Allow and enter the 6 digit code which is displayed in a different app.
- rgrove 9y ago> I've two factor authentication on my Apple account and now every time I use a new browser (or after clearing the Cache) and try to log into one of the Apple developer sites it sends me the authentication code to the same machine that I'm using. How is that two factor? Your password is something you know. Your computer (which is associated with your Apple ID) is something you have. If someone tries to log in using your password from another computer, your account is safe. If someone steals your computer but doesn't know your password, your account is safe. You're only in trouble if someone steals your computer _and_ knows your password.
- nkkollaw 9y agoThe new Apple is the old Microsoft, and the new Microsoft is the old Apple. After 8 months of living hell using their overpriced MacBook Pro, I'm moving to Surface Pro (running Xubuntu, though).
- k4ch0w 9y agoI just have no words, it seems intentional. They may want to review their build pipeline to check someone didn't manipulate the source code before it was signed. I haven't seen an easy root priv-esc like this in a long while.
- lolc 9y agoReminds me of the time Mac OS X would trust any NIS server in the local net to authenticate local root. Can't find the story though. Did that even happen?
- tribune 9y agoI would say I'm surprised such a serious bug made it out, but after the A � thing who knows what's going on at Apple
- thanatropism 9y agoAnyone in a position to short AAPL? It's apparently 6bps up in after hours trading but that's very low liquidity. https://finance.yahoo.com/quote/AAPL?p=AAPL https://finance.yahoo.com/quote/AAPL?p=AAPL A higher risk, higher leverage bet: buy some put options the milisecond markets open: http://www.nasdaq.com/symbol/aapl/option-chain http://www.nasdaq.com/symbol/aapl/option-chain
- thrusong 9y agoThere have been some really horrible bugs at Apple lately. I'm still waiting on them to patch the camera bug in iOS 11 where if you try to use the camera in a web app pinned to the home screen, it shows the camera UI on a black screen. This dates back to June. How can it be that hard to patch such a glaring and embarrassing problem?
- milesokeefe 9y agoHow many people are using the camera in pinned web apps? What's the app you use? I'd imagine most camera-related functions are already best served by native apps.
- thrusong 9y agoDoes that make it OK? I mean, something as important to the web as getUserMedia is broken on websites only if you pin it to the home screen. Forcing people into Apple's walled garden doesn't seem like an acceptable excuse.
- milesokeefe 9y agoIt's certainly not acceptable, I just think it hasn't been a priority for Apple since it's a relatively niche usecase. It could also be a security/privacy decision to leave it broken but safe until they can implement camera access through WebViews securely. The closest to any official reason I could find is a dev letting us know that mum's the word: >I asked about this internally and the answer is that, right now, WebRTC is only supported in Safari. No WKWebView, not even SFSafariViewController. https://forums.developer.apple.com/thread/88052#266901 https://forums.developer.apple.com/thread/88052#266901
- MagerValp 9y agoTo block this, set a random password for root: sudo dscl . -passwd /Users/root $(uuidgen)
- mcintyre1994 9y agoI guess Apple aren't the kind of company that would do it, but I'd love to read a frank post mortem about how this happened.
- mofino 9y agoNot a remote vuln, who gives a shit. Physical security >
- DonHopkins 9y agoThey could have at least used "rms" instead of a blank password. https://www.reddit.com/r/linux/comments/7hj6v/i_use_my_login_name_as_my_password_richard_m/ https://www.reddit.com/r/linux/comments/7hj6v/i_use_my_login...
- llamataboot 9y agoThat twitter thread and lots of the comments are missing the point. MANY people don't know about what the ethics of reporting vulnerabilities are, they just want to say something and get it fixed. yes, it probably would have been better if this person had gone through proper channels, but there's no evidence they did it for the lulz/fame. In this case the bug is so bad and egregious, that publicizing it with the fix might have been the best thing to do -- no telling how many people have already discovered this or how long it would take Apple to fix. Yes, let's educate each other about what responsible disclosure WITH A DEADLINE TO FIX looks like, but don't assume this person just wanted internet points. And now that the report and a workaround are out there, at least it can be mitigated personally. Though I imagine there will be some SERIOUS hijinks that result from this until Apple fixes it because it is so easy to do. :(
- ryanmarsh 9y agoI’m not a security researcher and I don’t work for Apple. If I casually came across this I would totally tweet it out. Anyone asserting I should follow some sort of procedure has a misplaced sense of reality.
- hateduser2 9y agoYou would do that.. but you don’t consider what you should do.. surely responsible disclosure is the smarter strategy?
- ryanmarsh 9y agoResponsible vs irresponsible... how would I know? You’re assuming way too much.
- hateduser2 9y agoThe average person who has never heard these things may act as described, but the person should be criticized for it, and if they dont correct their mistake they should be criticized for that too. Thats the point of criticism.
- migueh 9y agoIf I could just use Mavericks and develop apps for last iOS release, that will be great. But I should update to High Sierra. I hate this. High Sierra seems to be focused in Emojis. Urghh
- alpb 9y ago[meta] I think this thread is currently being downvoted, or dragged down by the mods somehow. It should be in the #1 right now. I suspect people are flagging/downvoting because there is no responsible disclosure in this case.
- 3131s 9y agoNot the first time I've noticed this with threads that are bad PR for Apple.
- dang 9y agoBe careful about noticing a few data points and then connecting the dots. You can get an image that way but it's usually just a reflection of your own bias, and people with opposite views will see opposite patterns in the same data. In this case the story hit a software penalty for a while, which we noticed and corrected as we usually do eventually. This software works well most of the time but unfortunately not always. Either way, it has nothing to do with our opinions about Apple, which is fortunate because we don't particularly have any.
- 3131s 9y agoI didn't mean to imply that it was manipulation on the part of HN. I am wary that Apple, like any large company, might try to bury stories like this. I know it's been asked before (by me, for one), but can you tell us anything about the protections HN has in place against astroturfing?
- DonHopkins 9y agoPyramid's OSx version of Unix (a dual-universe Unix supporting both 4.xBSD and System V) [1] had a bug in the "passwd" program, such that if somebody edited /etc/passwd with a text editor and introduced a blank line (say at the end of the file, or anywhere), the next person who changed their password with the setuid root passwd program would cause the blank line to be replaced by "::0:0:::" (empty user name, empty password, uid 0, gid 0), which then let you get a root shell with 'su ""', and log in as root by pressing the return key to the Login: prompt. (Well it wasn't quite that simple. The email explains.) https://en.wikipedia.org/wiki/Pyramid_Technology https://en.wikipedia.org/wiki/Pyramid_Technology Here's the email in which I reported it to the staff mailing list. Date: Tue, 30 Sep 86 03:53:12 EDT From: Don Hopkins <don@brillig.umd.edu> Message-Id: <8609300753.AA22574@brillig.umd.edu> To: chris@mimsy.umd.edu, staff@mimsy.umd.edu, Pete "Gymble Roulette" Cottrell <pete@mimsy.umd.edu> In-Reply-To: Chris Torek's message of Mon, 29 Sep 86 22:57:57 EDT Subject: stranger and stranger and stranger and stranger and stranger Date: Mon, 29 Sep 86 22:57:57 EDT From: Chris Torek <chris@mimsy.umd.edu> Gymble has been `upgraded'. Pyramid's new login program requires that every account have a password. The remote login system works by having special, password-less accounts. Fun. Pyramid's has obviously put a WHOLE lot of thought into their nifty security measures in the new release. Is it only half installed, or what? I can't find much in the way of sources. /usr/src (on the ucb side of the universe at lease) is quite sparse. On gymble, if there is a stray newline at the end of /etc/passwd, the next time passwd is run, a nasty little "::0:0:::" entry gets added on that line! [Ye Olde Standard Unix "passwd" Bug That MUST Have Been Put There On Purpose.] So I tacked a newline onto the end with vipw to see how much fun I could have with this.... One effect is that I got a root shell by typing: % su "" But that's not nearly as bad as the effect of typing: % rlogin gymble -l "" All I typed after that was <cr>: you don't hasword: New passhoose one new word: <cr> se a lonNew passger password. word: <cr> se a lonNew password:ger password. <cr> Please use a longer password. Password: <cr> Retype new password: <cr> Connection closed Yes, it was quite garbled for me, too: you're not seeing things, or on ttyh4. I tried it several times, and it was still garbled. But I'm not EVEN going to complain about it being garbled, though, for three reasons: 1) It's the effect of a brand new Pyramid "feature", and being used to their software releases, it seems only trivial cosmetic, comparitivly. 2) I want to be able to get to sleep tonight, so I'm just going to pretend it didn't happen. 3) There are PLEANTY of things to complain about that are much much much worse. [My guess, though, would be that something is writing to /dev/tty one way, and something else isn't.] Except for this sentence, I will also completely ignore the fact that it closed the connection after setting the password, in a generous fit of compassion for overworked programmers with ridiculous deadlines. So then there was an entry in /etc/passwd where the ::0:0::: had been: :7h37OHz9Ww/oY:0:0::: i.e., it let me insist upon a password it thought was too short by repeating it. (A somewhat undocumented feature of the passwd program.) ("That's not a bug, it's a feature!") Then instead of recognizing an empty string as meaning no password, and clearing out the field like it should, it encrypted the null string and stuck it there. PRETTY CHEEZY, PYRAMID!!!! That means grepping for entries in /etc/passwd that have null strings in the password field will NOT necessarily find all accounts with no password. So just because I was enjoying myself so much, I once again did: % rlogin gymble -l "" Password: <cr> [ message of the day et all ] # Wham, bam, thank you man! Instead of letting me in without prompting for a password [like it should, according to everyone but pyramid], or not allowing a null password and insisting I change it [like it shouldn't, according to everyone but pyramid], it asked for a password. I hit return, and sure enough the encrypted null string matched what was in the passwd entry. It was quite difficult to resist the temptation of deleting everyone's files and trashing the root partition. -Don P.S.: First one to forward this to Pyramid is a turd. P.P.S.: The origin story of Pete's "Gymble Roulette" nick-name is here: http://art.net/~hopkins/Don/text/gymble-roulette.html http://art.net/~hopkins/Don/text/gymble-roulette.html The postscript comment was an oblique reference to the fact that I'd previously gotten in trouble for forwarding Pete's hilarious "Gymble Roulette" email to a mailing list and somehow it found its was back to Pyramid. In my defense, he did say "Tell your friends and loved ones.")
- tbarbugli 9y agoSo far the best mitigation I could find out is to enable the root account and set a strong password for it. Hopefully we'll get a security update quickly so that I disable root access again. While checking on this I also realized I was running 10.13 instead of 10.13.1 which fixes another major security flaw (key chain saves in plain text)
- 2trill2spill 9y agoBesides for APFS what user visible killer features has Apple made to Mac OS since 10.6.8? I'm sure they have made internal non user visible improvements to their kernel and userland. But it seems most of the "changes" to Mac OS is just churning code, or at least it seems that way from the outside. To me personally 10.6.8 + Security Updates + APFS is extremely close to the ideal operating system.
- saagarjha 9y agoAPFS is not an example of something I would consider "user visible"–for the average user there's no difference between HFS+ and APFS.
- waz0wski 9y agoThere's the new poop emoji!! (unicode 10 emojis via 10.13.1 update) Real answer, APFS (which changes the Filevault encryption model to no longer be full-disk-encryption...) and Metal2 graphics (which has brought a variety of new gfx bugs into play, even for 1st party applications) are the big technical draws For a full list of changes, review the marketing page or the developer release docs - https://www.apple.com/macos/high-sierra/ https://www.apple.com/macos/high-sierra/ - https://developer.apple.com/library/content/releasenotes/MacOSX/WhatsNewInOSX/Articles/macOS_10_13_0.html https://developer.apple.com/library/content/releasenotes/Mac... (yes Apple can't be bothered to update their dev docs with the point releases. Documentation quality has fallen off dramatically since the 10.6 days) Given the stream of bug reports on various apple sites, I have not upgraded any of my personal machines, and my employer has stated they will not be upgrading our machines in the near term.
- spsful 9y agoworkaround: ENABLE ROOT USER AS FAST AS POSSIBLE https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012
- saagarjha 9y agoAs I had said above, this, in the long run, is actually less secure than not having a root account at all. If you do this, make sure to revert it once the issue is patched.
- mk89 9y agoApple proves they still care about UX: finally, I found a way to login without typing.
- api 9y agoBut there are new emojis, and emoji karaoke works!
- abritishguy 9y agoJust in case it is relevant for anyone here this is what our security team have established thus far: - Can be mitigated by enabling the root user with a strong password - Can be detected with `osquery` using `SELECT * FROM plist WHERE path = "/private/var/db/dslocal/nodes/Default/users/root.plist" AND key = "passwd" AND length(value) > 1;";` - You can see what time the root account was enabled using `SELECT * FROM plist WHERE path = "/private/var/db/dslocal/nodes/Default/users/root.plist" WHERE key = "accountPolicyData";` then base 64 decoding that into a file and then running `plutil -convert xml1` and looking at the `passwordLastSetTime` field. Note: osquery needs to be running with `sudo` but if you have it deployed across a fleet of macs as a daemon then it will be running with `sudo` anyway.
- submeta 9y agoExcellent! Thanks for sharing
- RJIb8RBYxzAMX9u 9y agoosquery is not a built-in tool. You can get the same info with plutil(1): $ sudo plutil -p /private/var/db/dslocal/nodes/Default/users/root.plist If I understand OP correctly, if passwd is a lone asterisk, then you haven't been exploited. Edit: trying a little harder to dump accountPolicyData: $ sudo defaults read /private/var/db/dslocal/nodes/Default/users/root.plist accountPolicyData | grep -oE '[[:xdigit:]]+' | xxd -r -p
- abritishguy 9y agoThat's correct.
- princekolt 9y agoBad news: I tried the exploit in my macOS Sierra installation and it didn't seem to work. However, the passwd entry on the output of your first command IS A LONE ASTERISK. However I still can't login as root. This leads me to believe this behavior has always been there, and maybe the login methods just didn't allow an empty password.
- butterisgood 9y agoDoesn't work for me on a freshly installed MacOS High Sierra, but does work on an upgraded laptop to High Sierra. Interesting... Also the UX is different. Typing root on the fresh installed one fails, then resets the user text box to my name, and if I type root again it doesn't let me it. On the upgraded laptop, if I type root, it sticks and clicking unlock twice gets me in.
- VeejayRampay 9y agoDoesn't matter, Apple gets an automatic pass.
- DonHopkins 9y agoI wonder if you can also defeat Face ID by wearing a white face mask? https://images-na.ssl-images-amazon.com/images/I/51I4nsyt9AL._UL1000_.jpg https://images-na.ssl-images-amazon.com/images/I/51I4nsyt9AL...
- rderewianko 9y agoMyself and others blogged about solutions: https://www.rderewianko.com/10-13-root-password-oh-my/ https://www.rderewianko.com/10-13-root-password-oh-my/ https://derflounder.wordpress.com/2017/11/28/blocking-logins-to-the-root-account-on-macos-high-sierra/ https://derflounder.wordpress.com/2017/11/28/blocking-logins...
- runesoerensen 9y agoApple suggests the workaround also discussed in this thread until the issue is fixed: "We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section." https://techcrunch.com/2017/11/28/astonishing-os-x-bug-lets-anyone-log-into-a-high-sierra-machine/ https://techcrunch.com/2017/11/28/astonishing-os-x-bug-lets-...
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- beedogs 9y agoWhen you're too busy as a company making sure the corners of your products are sufficiently rounded, you get things like this.
- mygo 9y agoMy computer automatically downloaded high sierra without me wanting it to. Whether I was tricked into clicking something I don’t know. And then I heard about the disk utility password bug and decided I should wait a while before installing this OS— it seems as though Apple wants me to do their QA for them. And now I hear about this. And I see that dumb ugly notch on the iPhone X (seriously who approved that design decision?). And the 2015 MacBook Pro is more pro than the 2016 model? Apple is officially a tribute band, riding on the fame of its previous self. And I say this as someone who owns a MacBook Pro, MacBook Air, iPad Pro, iPhone, and Apple Watch. This comes from a place of love. You’re trendy now, but don’t you forget that trendy people will leave you for the next shiny thing in an instant. Please fire everyone who is just there to milk the profits, actually put some focus back into QA, and remember who your base was.
- milesokeefe 9y agoHave you used an iPhone X? The notch actually makes a lot of sense once you've used the gestures associated with it, same with how it integrates into apps. I'll agree that they've made a lot of mistakes in their product lines recently but the iPhone X was not one of them. Well, sparing software. I've had intermittent phantom screen input using the latest betas on the X, making it infuriatingly unusable at times.
- mygo 9y agoI get that you can swipe down from the left or the right. But obscuring a chunk of the screen is not something to aspire to. The notch is clearly a compromise to make room for hardware. They should have found a way to fit the hardware such that it doesn’t cutaway the screen.
- setgree 9y agoIt seems as though buying a new apple product or upgrading one to new software implicitly signs you up to be a beta tester. It's pretty surprising from the world's most valuable company, no?
- j-pb 9y agoOh god, seriously what happened to apple? They are the richest company in the world and the quality of their software has kept declining every year. Right now there is no computer system that I can wholeheartedly recommend to non technical people... :(
- danjoc 9y agoThe person who found this is at greatest risk. Public disclosure keeps him safe. "Oh, good boy. Thanks for the responsible disclosure. You're sure you haven't told ANYONE else about this? Great! Keep it that way and we'll send you a big check real soon. Promise!" Coordinates acquired. Boom. Keep in mind, Apple was caught working directly with NSA in Snowden disclosures. The US government will drone strike people outside the US without trial or charges. Apple illegally SWATed a Gizmodo reporter over a leaked iPhone prototype. I don't blame this Turkish national, not one bit.
- sallyfour 9y agoI'm unsurprised, loginwindow is a piece of shit nobody wants to work on. Poor dude.
- jamesma 9y ago1
- uean 9y agoI haven't seen anyone mention this critical part of the flaw - if you disable the root account, then log out and log back in, the root account is active again. Password change is the only protection until it is patched.
- martell 9y agoSeems as though this tweet is not the first time it came up in public. Nov 13, 2017 12:48 PM https://forums.developer.apple.com/thread/79235 https://forums.developer.apple.com/thread/79235 Screenshot. http://oi67.tinypic.com/2h6embp.jpg http://oi67.tinypic.com/2h6embp.jpg
- tim333 9y agoTemporary workaround (pasted from http://www.bbc.com/news/technology-42161823 http://www.bbc.com/news/technology-42161823) While Apple works on its fix, it offered a workaround for users concerned about the bug. “Setting a root password prevents unauthorized access to your Mac,” the company explained. "To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012. --- Edit - for me those Apple instructions didn't work. This seemed to: Search for 'Directory Utility' in Spotlight and click it. Click the lock to make changes Select 'Enable root user' from 'Edit' on the main menu and set a password.
- KyeRussell 9y agoThis post reminded me of why Twitter is a pretty awful place. The replies to this tweets are all everyones snarky comments to the @AppleSupport account or their edgy 'hot takes' on the issue. @AppleSupport responded promptly - albeit obviously out of their depth, and a bunch of people couldn't help but make fun of this fact. It's almost like tweeting to Apple's customer support account is not the best way to report a vulnerability? Responsible disclosure has a proven history of working. When the vulnerability is appropriately patched and disclosed to the public, there is still a lot of backlash. You only need to look at the recent responsibly disclosed vulnerabilities for proof of this. Instead, we have a bunch of armchair analysts—who don't at all seem to be driven by past occurrences / existing data in any way—claiming that it didn't work.
- jaequery 9y agoif someone has discovered a way to wipe anyones paypal account, should he disclose it privately or let it trend on social media? and lets say the fix will take about a day at the earliest.
- myrandomcomment 9y agohttps://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012 How to set root password.
- deleted 9y ago[deleted]
- dailyvijeos 9y agoApple along with a decline in product utility, reliability and quality, their software has been getting buggier every year post-Jobs. The QA people should be fired and replaced with a team whom insists on perfection. Otherwise, these embarrassing incidents will repeat, errode their brand and encourage customers to seek other platforms.
- dtf 9y agoAmazingly, this was disclosed offhand on the Apple developer forums, two weeks ago (see final comment by chethan177): https://forums.developer.apple.com/thread/79235 https://forums.developer.apple.com/thread/79235 (spotted by https://twitter.com/fristle/status/935670476214378496 https://twitter.com/fristle/status/935670476214378496)
- pls2halp 9y agoThat’s absolutely terrible. Does Apple not monitor those forums at all?
- neotek 9y agoApple's support forums aren't a place where Apple provides their users with support, they're where Apple users seek support from other Apple users, mostly unhelpful and often inaccurate support. In fact, 99% of the time the only advice you'll get is "restore your iPhone", "restore your MacBook Pro", "restore your Apple TV" and so on into bitter infinity.
- deleted 9y ago[deleted]
- refulgentis 9y agoThose are the support forums, GP is asking about developer forums. Yes, Apple monitors them, but apparently not closely enough :/
- sarreph 9y agoYeah, I miss the days back at the start of the decade when I would brim with delight over an email notification that a senior engineer / moderator had chimed-in on my thread on the Apple dev forums. Checking the dev forums was my favourite thing to do in IT class at school :) These days, I get that (especially now that they're open) the forums are too saturated with content to have engineers on the ball all the time... But the Captain Hindsight in me thinks they could have done with some keyword notifications to nip instances like this in the bud...
- philliphaydon 9y agoNo one else has mentioned it seems, digging through the twitter comments I found a tweet which states this was already known by Apple, and posted on the forums in the form of a solution... https://forums.developer.apple.com/thread/79235#277225 https://forums.developer.apple.com/thread/79235#277225
- LeoNatan25 9y agoMentioned many times actually. And the forum is users self help. It is not monitored by Apple.
- philliphaydon 9y agoAhh the links weren’t on the first page of the HN comments when I posted. They are now. I didn’t click more. :)
- runesoerensen 9y ago"Perhaps nobody noticed two weeks ago when the root login vulnerability in macOS High Sierra was shared as a helpful tip on Apple’s own Developer forums. https://forums.developer.apple.com/thread/79235 https://forums.developer.apple.com/thread/79235 " https://twitter.com/fristle/status/935670476214378496 https://twitter.com/fristle/status/935670476214378496
- deleted 9y ago[deleted]
- temporary57657 9y agoThe only current solution is to leave root enabled and change the password to something strong until this is patched by Apple. Disabling root re-enables the blank password to root.
- Exuma 9y agoI wonder when/what Apple's response will be
- knodi 9y agoHigh Sierra has been one of the worst OSX upgrade.
- anachronicnomad 9y agoI was able to successfully fix this by using the ``` dsenableroot ``` utility; by first enabling the root user with a strong password, then disabling it with the ``` dsenableroot -d ``` option. It's heavily recommended to not leave the root user enabled.
- deleted 9y ago[deleted]
- ghaydarov 9y agoWow. Can't believe it. It's true.
- pwdisswordfish2 9y agoIf someone has physical access to the Apple computer in order to "log in", then even if the owner has set a strong root password, what stops anyone from rebooting, holding down Command+S and booting into single user mode? In single user mode, as all macOS users know, there will be no access limits. Anything can be changed. How are users preventing from rebooting into single user mode?
- deleted 9y ago[deleted]
- mthoodlum 9y agoPress "command" and the "space" keys at the same time. In the Spotlight Search type "Terminal" and press enter. At the terminal type "passwd" and press enter. The terminal will prompt you to change the password for "root".
- theoutlander 9y agoKudos for reporting this publicly! We need this kind of stuff exposed publicly so that companies fix the issue and force an update. At the same time, consumers should be made aware of what security holes look like and what the risks are. Apple has been getting away with this stuff for a while now. Do you think a hacker with ill-intent would have reported this issue at all?
- dawnerd 9y agoThere's no way this wasn't being used prior to being publicized on twitter. I'm sure the FBI/etc was on this day one.
- ddmma 9y agoApple is the new Internet Explorer
- lgxz 9y agothe MOST STUPID OS bug FOREVER?
- deleted 9y ago[deleted]
- stmw 9y agoImagine what Steve Jobs would've said in a meeting today at Apple HQ to discuss this incident. "Can someone here explain to me what is the login dialog supposed to do? ... Ok. Then why the !@#% doesn't it do that???"
- martins_irbe 9y agoThis clearly is a feature!
- cm2187 9y agoDoes it affect MacOS Server?
- oh-kumudo 9y agoLOL. Can we call this...front door?
- unlmtd 9y agoPeople still use this thing !?
- aosmith 9y agoDoes this work from single user mode?
- fastball 9y agoYeah, everyone seems to be forgetting that until very recent versions of MacOS you could just boot into SUM and make your own admin account to get access to a mac.
- fastball 9y agoI miss Snow Leopard. :/
- HugoDaniel 9y agoApple uses the slogan for High Sierra: "Your Mac. Elevated." Kind of ironic that you can easily get elevated privileges with it.
- abdullahi1 9y agoThis is hilarious. I wonder why it took so long for this bug to be discovered, I mean, wasn't High Sierra released back in September?
- api 9y agoWho types root in as a login name on a Mac?
- zargath 9y agoI guess we finally figured out what the "insanely" great products was all about.
- corecoder 9y agoHow come nobody has picked a name for this vulnerability?
- codeisawesome 9y agoWhat does this say about the state of iOS security? I don’t know how to hope that my phone isn’t 0wned already. I’m not saying this from my high horse - more as a disappointed user who invested a lot of money in my Apple phone.
- teddyh 9y agoI see a lot of comments here wondering why Apple seems to not care about software quality anymore. I don’t know if that’s true, but there’s a perfectly obvious answer: They don’t have to. Software quality in macOS was important back when they were trying to get people to switch from Windows-based PCs to Macs. Nowadays, most people who were going to switch have already switched, so Apple has no incentive to keep up the same level of software quality anymore. They just have to keep people locked into their ecosystem (with iPhone etc.) enough that the barrier to switch out again is high enough. There is no reason for Apple to improve macOS, since doing so won’t make anyone switch to Macs who hasn’t already switched, and not improving macOS won’t make anyone upset enough to switch back. Ergo, Apple leaves macOS to stagnate, and they will keep macOS at this bad-but-not-horrible-enough-to-switch level for the foreseeable future. That’s my theory, anyway.
- skygazer 9y agoWhile your theory is interesting, if deeply cynical, the thing I find most interesting is that it's the top comment on an 800+ comment discussion when it was less than a minute old. Do new comments start at the top? I've never noticed that before. Edit: By the way, regarding the vulnerability, ANY password you use when you first attempt to login as root BECOMES root's new password. (Blank is a red herring.) So if you're going to test this, maybe use something non-obvious. In a terminal, setting a strong password for root with "sudo passwd" is the quickest mitigation. Ill-advised, but in a pinch, you can apparently 'secure' a machine you don't otherwise have access to by attempting to log in as root with a long random password you fail to remember. An admin on that machine can later change root's password with a "sudo passwd". Also, it appears the "dseneableroot -d" command suggested elsewhere here fails in preventing root login.
- qualitytime 9y agoTop 10 software blunders of all time: 1) (Apple) 1 + 2 + 3 = 24 https://news.ycombinator.com/item?id=15538666 https://news.ycombinator.com/item?id=15538666 2) (Apple) Blank root password https://news.ycombinator.com/item?id=15800676 https://news.ycombinator.com/item?id=15800676 3) ...
- isoprophlex 9y agoSort of related: - it is almost 2018 and copy pasting on an ipad/iphone is still a horrible, non-deterministic nightmare
- INTPenis 9y agoWell I remember when the Ubuntu installer left your root password in a clear text file that was world readable on your FS.[1] I would really like to see a top 10 list of software blunders, I think everyone on HN would. 1. https://launchpad.net/ubuntu/+source/shadow/+bug/34606 https://launchpad.net/ubuntu/+source/shadow/+bug/34606
- lultimouomo 9y agoIn that case the bug was fixed in less than a day. Let's see how Apple fares.
- 0xnotsohex 9y ago0)(Apple) If macOS High Sierra shows your password instead of the password hint https://news.ycombinator.com/item?id=15410953 https://news.ycombinator.com/item?id=15410953
- manmal 9y ago0) Therac 25: https://hackaday.com/2015/10/26/killed-by-a-machine-the-therac-25/ https://hackaday.com/2015/10/26/killed-by-a-machine-the-ther... There ARE areas more safety critical than desktop computing, you know.
- erikbye 9y agohttps://en.wikipedia.org/wiki/Ariane_5 https://en.wikipedia.org/wiki/Ariane_5
- deleted 9y ago[deleted]
- TonnyGaric 9y agoApple released the following statement regarding this bug: "We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012 https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section."
- sanbor 9y agoThank you! I was looking for a workaround to avoid leaving my system vulnerable until the patch lands in App Store.
- SyneRyder 9y agoThat might not be enough. There's a tweet claiming it isn't limited to the root account, and applies to other similar Apple-default accounts on the system, such as the _applepay user account: https://twitter.com/unsynchronized/status/935656609140711426 https://twitter.com/unsynchronized/status/935656609140711426 That seems to match the technical explanation of the bug here: https://objective-see.com/blog/blog_0x24.html https://objective-see.com/blog/blog_0x24.html The tweet claims they've got Apple Remote Desktop access & screen sharing working via the _applepay user account. Why/how that's possible, I have no idea - I don't have High Sierra to confirm this, and I'm not sure I'd want to mess with the _applepay user account even if I did.
- therealmarv 9y agoIs this also in 10.13.2 beta?
- qubex 9y agoThis is why I use disk encryption.
- deleted 9y ago[deleted]
- gkanai 9y agoThis is indeed a bad black mark on Apple. With all the money they have, it's terrible that they let this one slip by. I'm still on 10.12 Sierra. Long ago I stopped major updating when those releases were new. I learned to wait months or many months for bugs to be dealt with and for older software to be updated to be compatible with the new release. High Sierra provides nothing critical that Sierra does not provide, and thus, I am happy in my position as late adopter.
- itsthejb 9y agoApple software quality has got very sloppy (again). I recall it was particularly bad around 2014, but then seemed to have improved. Seems the sloppiness is back again. It would seem Apple is no unique in the regard that its success has made it fat and lazy. My particular favourite one at the moment is that in iOS 11.1.2 navigation transition animations eventually break if the device is running long enough (a few days). Restarting the device fixes this. The fun part is trying to work out why on earth this would be? Transition animations are cached?
- Welytech 9y agoToo bad apple should care about the software quality.
- submeta 9y agoWent to the next Apple store. Tried it out. It works. Can't believe it. Thousands of Macs are vulnerable. I'm wondering how fast all of these devices will be patched. Even if there is an update next week: How many devices won't get updated for quite some time. Unbelievable.
- w0m 9y agoThe TC GIF is hilarious. https://tctechcrunch2011.files.wordpress.com/2017/11/ooooooh-dear.gif https://tctechcrunch2011.files.wordpress.com/2017/11/ooooooh...
- willyt 9y agoSecurity update just came out. Installed it and can no longer reproduce. Can anyone confirm?
- mackey 9y agohttps://support.apple.com/en-us/HT208315 https://support.apple.com/en-us/HT208315 Fixed.
- tolien 9y agoFix has been released: https://www.macrumors.com/2017/11/29/apple-fixes-root-password-bug-security-update/ https://www.macrumors.com/2017/11/29/apple-fixes-root-passwo...
- senthilnayagam 9y agopatch has been released in record time, I have update my mac https://support.apple.com/en-in/HT208315 https://support.apple.com/en-in/HT208315
- jason_slack 9y agoThere is also now a patch available.
- eevilspock 9y agoPatched: https://support.apple.com/kb/HT208315 https://support.apple.com/kb/HT208315
- rilex1 9y agokk