4 ms·
To clarify, there are two stages. The video included in the comment is just a proof of concept that MacOS will hide the account beginning with a period. In th
by snakeroot 3y ago
To clarify, there are two stages. The video included in the comment is just a proof of concept that MacOS will hide the account beginning with a period. In that demo, I was admin. In the demo to Apple, I demonstrated creating a new admin account that was hidden while I did not have admin access, but did have physical access to the device.
- tssva 3y agoTechnically when you boot to single user mode you are operating with admin permissions. But it is a technicality which really isn't relevant to the discussion. If someone has physical access to your device and can access single user/recovery mode then you are screwed to start with. This applies across macOS, Linux and Windows. Adding a hidden account is one of a long laundry list of exploits which can be accomplished in these modes. If you are concerned about these then you should apply a boot time password. Apple recommends doing just this help prevent single mode exploits. If you are concerned about supply chain attacks prior to receiving the device then you should be wiping the machine and reinstalling the OS prior to use. This is exactly what many organizations do.
- snakeroot 3y agoI agree with you on this. I am curious what your thoughts are on Apple allowing a user to be created in the GUI beginning with a period and what the purpose of that might be.