Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
snakeroot
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
snakeroot
3y ago
I agree with you on this. I am curious what your thoughts are on Apple allowing a user to be created in the GUI beginning with a period and what the purpose of that might be.
2.
▲
by
snakeroot
3y ago
df to get the volume list, then ... mount -uw /dev/[Machintosh HD Volume] (by the way, I'd only be doing this on a Mac that I could restore and not care about my files - always back up)
3.
▲
by
snakeroot
3y ago
True. However, if this is performed in the supply chain and made to appear after like it had never been configured (by removing the .applesetupdone), then the computer would be fully compromised before any encryption is applied.
4.
▲
by
snakeroot
3y ago
More details added to the post about creating without any account access.
5.
▲
by
snakeroot
3y ago
Notes added to demonstrate non-admin creation of the hidden account. 1. Force Mac to boot in "single user mode" (holding COMMAND-S at startup) 2. Command: df - to determine which volume is the system volume 3. Command: mount -u
6.
▲
by
snakeroot
3y ago
To clarify, there are two stages. The video included in the comment is just a proof of concept that MacOS will hide the account beginning with a period. In that demo, I was admin. In the demo to Apple, I demonstrated creating a new admin
7.
▲
by
snakeroot
3y ago
No, the attack does not require admin. I demonstrated that two Apple as well.
8.
▲
by
snakeroot
3y ago
This is a quick and dirty demo just to show proof of concept. https://youtu.be/oQw4x8Hn31I
9.
▲
Is a hidden account in macOS considered a feature?
2 points
by
snakeroot
3y ago
|
16 comments