Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Swordmaker
You might find this interesting:
macOS root login vulnerability was shared over two weeks ago as a troubleshooting tip on Apple's own developer forums

https://www.reddit.com/r/programming/comments/7gb191/macos_root_login_vulnerability_was_shared_over/

Note: it's Reddit, so caveat emptor.
11 posted on 11/29/2017 9:15:33 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies ]


To: dayglored
macOS root login vulnerability was shared over two weeks ago as a troubleshooting tip on Apple's own developer forums

I wouldn't even couch it in terms of a "vulnerability" being shared. . . but rather as a developer sharing a "cool way" for another developer to get to an Admin account who had screwed up their Admin user account. This particular developer seemed oblivious that what he had actually stumbled across was in fact a very serious vulnerability to the Mac's security.

Note: it's Reddit, so caveat emptor.

Yup, it's Reddit, so they paint it with the broadest, blackest brush they can find with the stickiest tar available.

I read through all 225 responses in the Apple Developers' Forum in question and discovered that the vulnerability in question was not actually reported to Apple but rather, as you pointed out, just "shared" as a cool "fixit tip" to access an admin account, presented to a user who had, it turned out, accidentally screwed up their Admin user's credentials. This particular tip was buried about four nest's deep in a series of "tips" for the user to try. The guy who offered it did not even realize that it provided Root access, but just thought it made the person signing on using this tip an Admin.

It is not, however, one of the Apple moderated forums. It is purely a developers' forum for seeking other developers' comments and their experiences in how developers have handled particular problems they may be having with a problem, not Apple's help. There is another area for that. As I understand it, Apple employed engineers do not participate because of potential liability in these forums due to the possibility that some developer is working on an App that Apple may also be developing an in house version.

Unless this was specifically brought TO Apple's attention, it is unlikely Apple would have seen it in this forum.

A couple of developers commented that it appeared to be a serious security concern that one could get to Root without a password and that shouldn't happen. . . but no one mentioned anything about bringing it properly to Apple's attention back in mid-November. I suspect they'd all forgotten that the forum was not an observed, moderated forum.

13 posted on 11/29/2017 2:46:25 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 11 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson