Page 1 of 2 12 LastLast
Results 1 to 16 of 18

Thread: Big security flaw in Apple MacOS High Sierra uncovered

  1. #1
    HEXUS.admin
    Join Date
    Apr 2005
    Posts
    31,709
    Thanks
    0
    Thanked
    2,073 times in 719 posts

    Big security flaw in Apple MacOS High Sierra uncovered

    Anyone with physical access to your machine can login as root with an empty password.
    Read more.

  2. #2
    Senior Member
    Join Date
    Aug 2003
    Location
    Wonderful Warwick!
    Posts
    3,919
    Thanks
    4
    Thanked
    183 times in 153 posts

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Epic epic fail... I've seen a few tech sites commenting on how it seems Apple has QA issues these days.... not the first password bug recently
    Old puter - still good enuff till I save some pennies!

  3. #3
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Looks as if the patch has been released - I've just downloaded it.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  4. #4
    RIP Peterb ik9000's Avatar
    Join Date
    Nov 2009
    Posts
    7,704
    Thanks
    1,840
    Thanked
    1,434 times in 1,057 posts
    • ik9000's system
      • Motherboard:
      • Asus P7H55-M/USB3
      • CPU:
      • i7-870, Prolimatech Megahalems, 2x Akasa Apache 120mm
      • Memory:
      • 4x4GB Corsair Vengeance 2133 11-11-11-27
      • Storage:
      • 2x256GB Samsung 840-Pro, 1TB Seagate 7200.12, 1TB Seagate ES.2
      • Graphics card(s):
      • Gigabyte GTX 460 1GB SuperOverClocked
      • PSU:
      • NZXT Hale 90 750w
      • Case:
      • BitFenix Survivor + Bitfenix spectre LED fans, LG BluRay R/W optical drive
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Dell U2414h, U2311h 1920x1080
      • Internet:
      • 200Mb/s Fibre and 4G wifi

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by HEXUS View Post
    Slow to the news Hexus... https://forums.hexus.net/apple-mac/3...erability.html

  5. Received thanks from:

    Troopa (30-11-2017)

  6. #5
    Registered+
    Join Date
    May 2009
    Location
    Warrington, Cheshire
    Posts
    41
    Thanks
    0
    Thanked
    3 times in 1 post

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Only 3 comments?! Oops, 4!

  7. #6
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by Eric F View Post
    Only 3 comments?! Oops, 4!
    Not much to comment on. Flaw discovered and published, workaround quickly issued, followed just as quickly by a patch to fix it. Job done. It would have been better if it hadn't occurred, but you can say that about any software bug.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  8. #7
    don't stock motherhoods
    Join Date
    Jun 2005
    Posts
    1,298
    Thanks
    809
    Thanked
    125 times in 108 posts
    • Millennium's system
      • Motherboard:
      • MSI X470 Gaming Plus
      • CPU:
      • AMD 3600x @ 3.85 with Turbo
      • Memory:
      • 4*G-Skill Samsung B 3200 14T 1T
      • Storage:
      • WD850 and OEM961 1TB, 1.5TB SSD SATA, 4TB Storage, Ext.
      • Graphics card(s):
      • 3070 FE HHR NVidia (Mining Over)
      • PSU:
      • ToughPouwer 1kw (thinking of an upgrade to 600w)
      • Case:
      • Fractal Design Define S
      • Operating System:
      • Windows 101 Home 64bit
      • Monitor(s):
      • HiSense 55" TV 4k 8bit BT709 18:10
      • Internet:
      • Vodafone 12 / month, high contentions weekends 2, phone backup.

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    The bug speaks volumes about software dev practices though R. I dunno what to say, it's good it was patched. Thanks for letting me now.
    hexus trust : n(baby):n(lover):n(sky)|>P(Name)>>nopes

    Be Careful on the Internet! I ran and tackled a drive by mining attack today. It's not designed to do anything than provide fake texts (say!)

  9. #8
    Senior Member
    Join Date
    Feb 2016
    Location
    Somerset
    Posts
    1,112
    Thanks
    84
    Thanked
    137 times in 110 posts
    • wazzickle's system
      • Motherboard:
      • Asus H470M-itx
      • CPU:
      • i5 10500
      • Memory:
      • 16Gb DDR4 HyperX Fury
      • Storage:
      • Barracuda 510 1TB M.2, WD Blue 2TB
      • Graphics card(s):
      • Zotac 3070 Twin Edge
      • PSU:
      • Corsair SFX 600
      • Case:
      • Ghost S1 V2
      • Operating System:
      • W10
      • Monitor(s):
      • LG IPS 27" 144Hz QHD
      • Internet:
      • three4g & nighthawk MR1100

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    You could say that about any software bug, but the idiocy of the exploit combined with the supposed trust placed in this company is what makes it remarkable.

  10. #9
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by peterb View Post
    Not much to comment on. Flaw discovered and published, workaround quickly issued, followed just as quickly by a patch to fix it. Job done. It would have been better if it hadn't occurred, but you can say that about any software bug.
    No, this is a clear failure of any kind of SDLC.

    You can have bugs that are bizarrely complex, this is the result of poor exceptional event handling, with frankly shoddy designs in the first place.

    If this came from a team who worked for me, I'd be able to fire them for gross incompetence.
    throw new ArgumentException (String, String, Exception)

  11. #10
    RIP Peterb ik9000's Avatar
    Join Date
    Nov 2009
    Posts
    7,704
    Thanks
    1,840
    Thanked
    1,434 times in 1,057 posts
    • ik9000's system
      • Motherboard:
      • Asus P7H55-M/USB3
      • CPU:
      • i7-870, Prolimatech Megahalems, 2x Akasa Apache 120mm
      • Memory:
      • 4x4GB Corsair Vengeance 2133 11-11-11-27
      • Storage:
      • 2x256GB Samsung 840-Pro, 1TB Seagate 7200.12, 1TB Seagate ES.2
      • Graphics card(s):
      • Gigabyte GTX 460 1GB SuperOverClocked
      • PSU:
      • NZXT Hale 90 750w
      • Case:
      • BitFenix Survivor + Bitfenix spectre LED fans, LG BluRay R/W optical drive
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Dell U2414h, U2311h 1920x1080
      • Internet:
      • 200Mb/s Fibre and 4G wifi

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by peterb View Post
    Not much to comment on. Flaw discovered and published, workaround quickly issued, followed just as quickly by a patch to fix it. Job done. It would have been better if it hadn't occurred, but you can say that about any software bug.
    But it is essentially the same problem as the old XP "administrator" account shipping with zero password to begin with. How many people back then never knew to boot into safe mode and set one? There were so many articles on that back in the day - even in lesser PC magazines, and eventually regular mainstream newspapers etc - how did no-one at Apple check that this root login didn't avoid this default vulnerability?

  12. #11
    Oh Crumbs.... Biscuit's Avatar
    Join Date
    Feb 2007
    Location
    N. Yorkshire
    Posts
    11,193
    Thanks
    1,394
    Thanked
    1,091 times in 833 posts
    • Biscuit's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD 2700X (Be Quiet! Dark Rock 3)
      • Memory:
      • 16GB Patriot Viper 2 @ 3466MHz
      • Storage:
      • 500GB WD Black
      • Graphics card(s):
      • Sapphire R9 290X Vapor-X
      • PSU:
      • Seasonic Focus Gold 750W
      • Case:
      • Lian Li PC-V359
      • Operating System:
      • Windows 10 x64
      • Internet:
      • BT Infinity 80/20

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Guess this cements the rumour that all the good developers at Apple are working on iOS.

  13. #12
    don't stock motherhoods
    Join Date
    Jun 2005
    Posts
    1,298
    Thanks
    809
    Thanked
    125 times in 108 posts
    • Millennium's system
      • Motherboard:
      • MSI X470 Gaming Plus
      • CPU:
      • AMD 3600x @ 3.85 with Turbo
      • Memory:
      • 4*G-Skill Samsung B 3200 14T 1T
      • Storage:
      • WD850 and OEM961 1TB, 1.5TB SSD SATA, 4TB Storage, Ext.
      • Graphics card(s):
      • 3070 FE HHR NVidia (Mining Over)
      • PSU:
      • ToughPouwer 1kw (thinking of an upgrade to 600w)
      • Case:
      • Fractal Design Define S
      • Operating System:
      • Windows 101 Home 64bit
      • Monitor(s):
      • HiSense 55" TV 4k 8bit BT709 18:10
      • Internet:
      • Vodafone 12 / month, high contentions weekends 2, phone backup.

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by ik9000 View Post
    But it is essentially the same problem as the old XP "administrator" account shipping with zero password to begin with. How many people back then never knew to boot into safe mode and set one? There were so many articles on that back in the day - even in lesser PC magazines, and eventually regular mainstream newspapers etc - how did no-one at Apple check that this root login didn't avoid this default vulnerability?
    I didn't know that!
    hexus trust : n(baby):n(lover):n(sky)|>P(Name)>>nopes

    Be Careful on the Internet! I ran and tackled a drive by mining attack today. It's not designed to do anything than provide fake texts (say!)

  14. #13
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by Biscuit View Post
    Guess this cements the rumour that all the good developers at Apple are working on iOS.
    Or it was enabled during testing for the convenience of the developers, and someone forgot to disable it before it was released.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  15. #14
    Senior Member
    Join Date
    Apr 2016
    Posts
    772
    Thanks
    0
    Thanked
    9 times in 9 posts

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Not really a supporter of Apple products myself other than some of the actual work horse stuff they got... but from my point of view it is unforgiveable also... in general if all only use one brand and such you leave the world more vulnerable to a full scale attack.

    Hope the responsible people has been fired and branded for life.

  16. #15
    RIP Peterb ik9000's Avatar
    Join Date
    Nov 2009
    Posts
    7,704
    Thanks
    1,840
    Thanked
    1,434 times in 1,057 posts
    • ik9000's system
      • Motherboard:
      • Asus P7H55-M/USB3
      • CPU:
      • i7-870, Prolimatech Megahalems, 2x Akasa Apache 120mm
      • Memory:
      • 4x4GB Corsair Vengeance 2133 11-11-11-27
      • Storage:
      • 2x256GB Samsung 840-Pro, 1TB Seagate 7200.12, 1TB Seagate ES.2
      • Graphics card(s):
      • Gigabyte GTX 460 1GB SuperOverClocked
      • PSU:
      • NZXT Hale 90 750w
      • Case:
      • BitFenix Survivor + Bitfenix spectre LED fans, LG BluRay R/W optical drive
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Dell U2414h, U2311h 1920x1080
      • Internet:
      • 200Mb/s Fibre and 4G wifi

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by QuorTek View Post
    and branded for life.
    A bit extreme. What would your policy be for more violent offenders?

  17. #16
    Oh Crumbs.... Biscuit's Avatar
    Join Date
    Feb 2007
    Location
    N. Yorkshire
    Posts
    11,193
    Thanks
    1,394
    Thanked
    1,091 times in 833 posts
    • Biscuit's system
      • Motherboard:
      • MSI B450M Mortar
      • CPU:
      • AMD 2700X (Be Quiet! Dark Rock 3)
      • Memory:
      • 16GB Patriot Viper 2 @ 3466MHz
      • Storage:
      • 500GB WD Black
      • Graphics card(s):
      • Sapphire R9 290X Vapor-X
      • PSU:
      • Seasonic Focus Gold 750W
      • Case:
      • Lian Li PC-V359
      • Operating System:
      • Windows 10 x64
      • Internet:
      • BT Infinity 80/20

    Re: Big security flaw in Apple MacOS High Sierra uncovered

    Quote Originally Posted by peterb View Post
    Or it was enabled during testing for the convenience of the developers, and someone forgot to disable it before it was released.
    Incompetence whichever way you look at it.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •