Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmgycombinator
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
61.
▲
by
nmgycombinator
2y ago
Fascinating. I'll have to test that out!
62.
▲
by
nmgycombinator
2y ago
It seems I was not confused then? The secrets are the "keychain items". I got really mixed up there.
63.
▲
by
nmgycombinator
2y ago
Great article! Thanks for the link!
64.
▲
by
nmgycombinator
2y ago
> I understand the technical reasons for that, but it is technically supported by the spec and other clients work with it just fine. I am completely aware of that, but I am aware that other clients handle it just fine. The bug actually f
65.
▲
by
nmgycombinator
2y ago
Take a look at it yourself if you're curious. The kernel code is open source: https://github.com/apple-oss-distributions/xnu
66.
▲
by
nmgycombinator
2y ago
Oh fascinating. And it seems I had my terms confused. I didn't know the items themselves were called keychains.
67.
▲
by
nmgycombinator
2y ago
> manually unlocked a local Keychain Does the Keychain stay unlocked for a while? And do people actually do this?
68.
▲
by
nmgycombinator
2y ago
> grep any user's FileVault password from the page file I'm not sure if this necessitates physical access.
69.
▲
by
nmgycombinator
2y ago
The PoC code should work. You just need to install Kass as a dependency. If you have done that, are there any other issues you are facing? As far as risks are concerned: any app with the ability to get a send right to NetAuthAgent (pretty m
70.
▲
by
nmgycombinator
2y ago
A minor correction was made to the article: Entitlement checks are not in the Mach layer of the kernel. https://github.com/nmggithub/wts/commit/2bdce1c0c76c7adc360e... Just a one word change, fixing a factual
71.
▲
by
nmgycombinator
2y ago
I would argue that Mach was not the source of the bug here, but rather it was the lack of an entitlement check. Entitlements are honestly a very good security system, but they are opt-in. If a daemon doesn't check entitlements, then it
72.
▲
by
nmgycombinator
2y ago
Damn, that's honestly hilarious.
73.
▲
by
nmgycombinator
2y ago
Yeah, if you're writing user-facing apps, writing against Mach wouldn't be smart. But if you're a vulnerability researcher on the other hand... it's a neat trick and might just help you find a CVE! (even though most stuf
74.
▲
by
nmgycombinator
2y ago
I feel like that (innocence about security) might be a bit of the reason why this vulnerability existed in the first place. I'm sure the NetAuthAgent code is very old, and was probably written at a time before even Apple was serious
75.
▲
by
nmgycombinator
2y ago
> Interesting to see the port system mentioned - it's not a well known fact of Mach kernels. I'm surprised to hear someone say that, given that it's the fact about Mach to me. I'm not sure how people could know abou
76.
▲
by
nmgycombinator
2y ago
Oh there's quite a lot of lore. Mach goes back even further to even earlier CMU kernel called Accent: https://en.wikipedia.org/wiki/Accent_kernel .
77.
▲
Leaking Passwords and more on macOS
(wts.dev)
325 points
by
nmgycombinator
2y ago
|
62 comments