3 ms·
Yes this is quite standard for an OS. You might want to create a user that has access to some things but isnt as annoying as you could log into it. The other w
by neximo64 3y ago
Yes this is quite standard for an OS. You might want to create a user that has access to some things but isnt as annoying as you could log into it.
The other way to look at it is its annoying to have an account show up on the screen that you want specifically for machine purposes or to restrict the user. Or to hide the Admin user if it is in an enterprise network.
I'm assuming your 'attack' requires admin privileges, to create the account? I dont think that can be considered a vulnerability, it is almost doing exactly as expected.
- snakeroot 3y agoNo, the attack does not require admin. I demonstrated that two Apple as well.
- tssva 3y agoCreating users and groups in macOS requires administrator permissions. In the demo video you posted before creating the account you unlock the User settings panel using credentials of someone with administrator privileges.
- snakeroot 3y agoMore details added to the post about creating without any account access.
- snakeroot 3y agoTo clarify, there are two stages. The video included in the comment is just a proof of concept that MacOS will hide the account beginning with a period. In that demo, I was admin. In the demo to Apple, I demonstrated creating a new admin account that was hidden while I did not have admin access, but did have physical access to the device.
- tssva 3y agoTechnically when you boot to single user mode you are operating with admin permissions. But it is a technicality which really isn't relevant to the discussion. If someone has physical access to your device and can access single user/recovery mode then you are screwed to start with. This applies across macOS, Linux and Windows. Adding a hidden account is one of a long laundry list of exploits which can be accomplished in these modes. If you are concerned about these then you should apply a boot time password. Apple recommends doing just this help prevent single mode exploits. If you are concerned about supply chain attacks prior to receiving the device then you should be wiping the machine and reinstalling the OS prior to use. This is exactly what many organizations do.
- snakeroot 3y agoI agree with you on this. I am curious what your thoughts are on Apple allowing a user to be created in the GUI beginning with a period and what the purpose of that might be.