What's new

So, this is bad. (1 Viewer)

Walter Kittel

Senior HTF Member
Joined
Dec 28, 1998
Messages
9,807
Somebody has got some explaining to do.

That is a pretty incredible oversight. Allowing any user id to login with no password is a big deal, but the idea that the root account (and the privileges that accompany that account) is accessible with no password makes it exponentially worse.

Wow. Just wow.

- Walter.
 

Johnny Angell

Played With Dinosaurs Member
Senior HTF Member
Deceased Member
Joined
Dec 13, 1998
Messages
14,905
Location
Central Arkansas
Real Name
Johnny Angell
As I read it, this flaw still required physical access to the Mac to do the fraudulent login. Am I right?
 

Walter Kittel

Senior HTF Member
Joined
Dec 28, 1998
Messages
9,807
From the original link...

One user reported the ability to also access the computer using the root login remotely.

Not exactly definitive. There are procedures to disable remote root access, but I have no idea whether or not Apple configures their OS in that manner as a default. I'm guessing - probably not.

- Walter.
 

Clinton McClure

Rocket Science Department
Premium
Senior HTF Member
Joined
Jun 28, 1999
Messages
7,797
Location
Central Arkansas
Real Name
Clint
This is old news now, as Apple has already patched the hole with both a macOS update and a stand-alone patch. It is a bit troubling how Apple has experienced several glaring security, usability, and show-stopper bugs in the last few weeks with both macOS and iOS. There needs to definitely be a review of and adjustment to internal testing policies.

That being said, I still prefer macOS and iOS to anything else out there.
 

DaveF

Moderator
Senior HTF Member
Joined
Mar 4, 2001
Messages
28,771
Location
Catfisch Cinema
Real Name
Dave
Veddy veddy bad.

Tally another incident in the "Apple's software quality is dropping" column.
 

B-ROLL

Senior HTF Member
Joined
May 26, 2016
Messages
5,031
Real Name
Bryan
kaspersky-antivirus-for-macintosh-technical-presentation-11-728.jpg

Sounds like a class action lawsuit to me ...
 

Users who are viewing this thread

Sign up for our newsletter

and receive essential news, curated deals, and much more







You will only receive emails from us. We will never sell or distribute your email address to third party companies at any time.

Forum statistics

Threads
357,055
Messages
5,129,696
Members
144,283
Latest member
Joshua32
Recent bookmarks
0
Top