Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: [1] 2

Author Topic: Mac OS root login  (Read 3594 times)

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Mac OS root login
« on: November 29, 2017, 09:40:05 AM »

Posted in 'News', rather than 'Apple'  as I think it will be of interest/amusement to non Apple users too.

http://www.bbc.co.uk/news/technology-42161823

I just tried it, and it works.   Don't know why BBC say you have to "hit enter a few times" which makes it sound more subtle than it is,  hitting enter just the once suffices as with any other login. 

Ooooops.  ::)
Logged

broadstairs

  • Kitizen
  • ****
  • Posts: 3700
Re: Mac OS root login
« Reply #1 on: November 29, 2017, 09:51:14 AM »

I just saw this on Victoria Derbyshire with Rory Cellan-Jones. How on earth can this happen - have they not heard of testing before release? Does not happen on any of my Linux systems  ;D

Stuart
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Re: Mac OS root login
« Reply #2 on: November 29, 2017, 10:49:04 AM »

I just saw this on Victoria Derbyshire with Rory Cellan-Jones. How on earth can this happen - have they not heard of testing before release? Does not happen on any of my Linux systems  ;D

Good question!

I don't think Root ever had a password by default on Mac OS, it was just rendered inaccessible by default.  You couldn't login directly as Root and if you wanted to do something as Root from command line, you used 'sudo', and confirmed with your own user password.  You could manually enable Root, and assign a password, after which you could login from the GUI or su from the command line,  but enabling Root involved a few non-obvious steps.   High Sierra seems to have Root enabled by default (though interestingly, su from the command line does not seem to work with the default configuration).

Another thing that seems to have changed is, on the main login GUI, in addition to Icons for each configured user there is one called 'other' which allows you to login by typing a user name, including Root.   I don't think 'other' was present on the login GUI before, even with Root enabled, but not certain.

Pure speculation, but this new configuration would be very useful to Apple developers and testers pre-release, as it would allow them to sometimes rescue a damaged system.   Don't suppose it was enabled temporarily during dev, and they just forgot to disable it before release?     :-\

Thought some of you'd be amused though, including you, Stuart.    ;)
Logged

broadstairs

  • Kitizen
  • ****
  • Posts: 3700
Re: Mac OS root login
« Reply #3 on: November 29, 2017, 11:11:23 AM »

I am very reluctant to use or configure sudo. Ubuntu and its derivatives use sudo and have root disabled by default, IMHO a very bad way to go. Much better to have root available, maybe set it to not be available as a login user, and then make sure you set a password for root which is difficult to guess. Using sudo with users p/w by default is I think a bad way to go. Same applies to the wheel group I think because it only uses the user p/w.

Stuart

PS I actually think they probably made a change the result of which was allowing this root access and it is unlikely to be deliberate, however because of the power of root it is quite astonishing they dont test it thoroughly.
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

Bowdon

  • Content Team
  • Kitizen
  • *
  • Posts: 2395
Re: Mac OS root login
« Reply #4 on: November 29, 2017, 11:19:42 AM »

I like how the BBC tells everyone how to do it  ::)
Logged
BT Full Fibre 500 - Smart Hub 2

broadstairs

  • Kitizen
  • ****
  • Posts: 3700
Re: Mac OS root login
« Reply #5 on: November 29, 2017, 11:33:12 AM »

I like how the BBC tells everyone how to do it  ::)

Well it was on a public forum so not really a secret anyway.

Stuart
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Re: Mac OS root login
« Reply #6 on: November 29, 2017, 11:41:02 AM »

Worth bearing in mind, unless encryption is used, Unrestricted access to the filestore of any PC to which you have physical access is trivialially easy, be it Unix, Linux or Windows.  You just remove or copy the disks, and mount them elsewhere.

With that in mind,  I know a few knowledgeable experts who knowingly set Root password to ‘blank’ on Linux and Unix boxes, on the basis that the security it provides is just an illusion.   Personally I do set a password.
Logged

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Re: Mac OS root login
« Reply #7 on: November 29, 2017, 11:54:48 AM »

Interesting that the story seems to have broken as a result of a seemingly innocent character, casually offering it as a solution to a problem on a forum, blissfuly unaware of the gravity of his ‘discovery’.  ::)

https://forums.developer.apple.com/thread/79235#

Logged

petef

  • Reg Member
  • ***
  • Posts: 135
Re: Mac OS root login
« Reply #8 on: November 29, 2017, 11:59:23 AM »

Here is a revised suggestion for Apple to use
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Mac OS root login
« Reply #9 on: November 29, 2017, 12:33:47 PM »

Not amused.   Just shows that no system is infallible.  This one is a bit of a big oopsie though :(
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

jelv

  • Helpful
  • Kitizen
  • *
  • Posts: 2054
Re: Mac OS root login
« Reply #10 on: November 29, 2017, 01:26:23 PM »

Can you imagine what Apple would have had to say if it was Microsoft that made a similar error?
Logged
Broadband and Line rental: Zen Unlimited Fibre 2, Mobile: Vodaphone
Router: Fritz!Box 7530

licquorice

  • Reg Member
  • ***
  • Posts: 977
Re: Mac OS root login
« Reply #11 on: November 29, 2017, 01:48:15 PM »

I am very reluctant to use or configure sudo. Ubuntu and its derivatives use sudo and have root disabled by default, IMHO a very bad way to go. Much better to have root available, maybe set it to not be available as a login user, and then make sure you set a password for root which is difficult to guess. Using sudo with users p/w by default is I think a bad way to go. Same applies to the wheel group I think because it only uses the user p/w.

Stuart

With sudo the hacker needs to know 2 variables, username and password. With root, only the password is needed.
Logged

broadstairs

  • Kitizen
  • ****
  • Posts: 3700
Re: Mac OS root login
« Reply #12 on: November 29, 2017, 03:55:24 PM »

With sudo the hacker needs to know 2 variables, username and password. With root, only the password is needed.

Yes but a user name is easy to get. Guessing my root password at 20 characters is far more problematic.

Stuart
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

stevebrass

  • Reg Member
  • ***
  • Posts: 261
Re: Mac OS root login
« Reply #13 on: November 29, 2017, 04:37:01 PM »

Dear me. What a mess.

But on my machine on logging in from start up or sleep I don't get the chance to enter a username. I don't have the guest account enabled either.

So in this case would this only be exploitable if my machine was left logged on?



Logged
Netgear Orbi; BT FTTP with Smart Hub 2

licquorice

  • Reg Member
  • ***
  • Posts: 977
Re: Mac OS root login
« Reply #14 on: November 29, 2017, 05:05:31 PM »

Yes but a user name is easy to get. Guessing my root password at 20 characters is far more problematic.

Stuart

Yes, but no username is even easier and username + 20 character password is even harder.
Logged
Pages: [1] 2
 

anything