4 ms·
You don't find that true? Anyone with physical (or remote) access can type in root, with no password, and have full control? ????
by _arvin 9y ago
You don't find that true? Anyone with physical (or remote) access can type in root, with no password, and have full control?
????
- ryanlol 9y agoI think you have a very limited understanding of the state of software security in general if you think that is true. Bugs far worse than this are discovered on a weekly basis. This one is just easy to exploit so it’s been hyped up by people who would normally ignore slightly more technical descriptions of much worse vulnerabilities.
- _arvin 9y agoHow so? If you own a macOS device and you weren't freaking out about the root bug, or all the other blunders that have been happening recently, then I think it's you that has the limited understanding.
- ryanlol 9y agoBugs like this are discovered regularly. If you are “freaking out” about this it is solely because you have not been paying attention before. Describing this as “one of the biggest bugs of the decade” is insane when you see stuff like the Eternal* exploits released by TSB.
- zulln 9y agoI think it is valid to take exploitability into the equation.
- ryanlol 9y agoAnd the impact remains minuscule outside of the remote desktop scenario. The attacker must already have access to exploit this, and one would have to be utterly clueless to expect that an attacker wouldn't be able to get root some other way.
- fauigerzigerk 9y agoReally? Bugs that allow anyone with physical access to log into any Mac without any preparation or specialist knowledge are discovered regularly? How bad this is depends entirely on your circumstances. If your Mac is only accessible to people you fully trust then good for you. Otherwise this bug is potentially far worse than anything that could be launched over a network by anonymous attackers.
- ryanlol 9y ago>Bugs that allow anyone with physical access to log into any Mac without any preparation Not the case here. This bug only¹ allows you to log into an unencrypted Mac, which you should of course never leave unattended. >How bad this is depends entirely on your circumstances. If your Mac is only accessible to people you fully trust then good for you. Otherwise this bug is potentially far worse than anything that could be launched over a network by anonymous attackers. Are you equally worried about the DMA attacks which affect most computers and are not widely considered vulnerabilities? It feels to me that you're creating a rather unrealistic threat model here. >If your Mac is only accessible to people you fully trust then good for you. If this isn't the case then why does the device contain data which makes a compromise by an adversary with physical access problematic? >Otherwise this bug is potentially far worse than anything that could be launched over a network by anonymous attackers. Only in an absurd scenario where you store sensitive plaintext data on a publicly accessible machine and expect it to remain secure. At this point no software is going to save you. ¹ Worth noting here that it also affects some Remote Desktop configurations which is the only actually somewhat serious part of this bug.
- fauigerzigerk 9y ago>It feels to me that you're creating a rather unrealistic threat model here. I'm thinking of Macs placed on desks in living rooms, home offices and small companies around the world, accessible to spouses, flatmates, parents, coworkers, cleaners, etc. 99% of these "adversaries" will never have heard of various other ways of breaking into a computer and they might never do anything that actually feels like breaking in. But if all that stands between you and reading all of your spouse's emails is entering "root" into the username box, that may be too much of a temptation.