5 ms·
How so? If you own a macOS device and you weren't freaking out about the root bug, or all the other blunders that have been happening recently, then I think it'
by _arvin 9y ago
How so? If you own a macOS device and you weren't freaking out about the root bug, or all the other blunders that have been happening recently, then I think it's you that has the limited understanding.
- ryanlol 9y agoBugs like this are discovered regularly. If you are “freaking out” about this it is solely because you have not been paying attention before. Describing this as “one of the biggest bugs of the decade” is insane when you see stuff like the Eternal* exploits released by TSB.
- zulln 9y agoI think it is valid to take exploitability into the equation.
- ryanlol 9y agoAnd the impact remains minuscule outside of the remote desktop scenario. The attacker must already have access to exploit this, and one would have to be utterly clueless to expect that an attacker wouldn't be able to get root some other way.
- fauigerzigerk 9y agoReally? Bugs that allow anyone with physical access to log into any Mac without any preparation or specialist knowledge are discovered regularly? How bad this is depends entirely on your circumstances. If your Mac is only accessible to people you fully trust then good for you. Otherwise this bug is potentially far worse than anything that could be launched over a network by anonymous attackers.
- ryanlol 9y ago>Bugs that allow anyone with physical access to log into any Mac without any preparation Not the case here. This bug only¹ allows you to log into an unencrypted Mac, which you should of course never leave unattended. >How bad this is depends entirely on your circumstances. If your Mac is only accessible to people you fully trust then good for you. Otherwise this bug is potentially far worse than anything that could be launched over a network by anonymous attackers. Are you equally worried about the DMA attacks which affect most computers and are not widely considered vulnerabilities? It feels to me that you're creating a rather unrealistic threat model here. >If your Mac is only accessible to people you fully trust then good for you. If this isn't the case then why does the device contain data which makes a compromise by an adversary with physical access problematic? >Otherwise this bug is potentially far worse than anything that could be launched over a network by anonymous attackers. Only in an absurd scenario where you store sensitive plaintext data on a publicly accessible machine and expect it to remain secure. At this point no software is going to save you. ¹ Worth noting here that it also affects some Remote Desktop configurations which is the only actually somewhat serious part of this bug.
- fauigerzigerk 9y ago>It feels to me that you're creating a rather unrealistic threat model here. I'm thinking of Macs placed on desks in living rooms, home offices and small companies around the world, accessible to spouses, flatmates, parents, coworkers, cleaners, etc. 99% of these "adversaries" will never have heard of various other ways of breaking into a computer and they might never do anything that actually feels like breaking in. But if all that stands between you and reading all of your spouse's emails is entering "root" into the username box, that may be too much of a temptation.
- lukevdp 9y agoIs it normal for people to be scared of their spouse reading their emails? That blows my mind.
- fauigerzigerk 9y agoThe estimates of how many people have cheated on their spouses at some point vary betwen 15% and 70%. Many couples are going through conflicts, broken relationships and divorce. So yes I'm afraid these things are a normal, if undesirable, part of life. And then there are all the other groups I mentioned (flatmates, coworkers, parents, cleaners). Among the millions of Mac users, there will be many who don't want those around them to sift through their emails, browser history, bank account statements, etc.