Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as "root" with empty password after clicking on login button several times. Are you aware of it @Apple?
-
-
Apple is going to sue someone for their own software flaws? That's rich. Exposing it publicly lights a fire under Apple, forcing them to prioritize a fix. Private disclosure lets them drag their feet.
-
No, there are ethical disclosure systems. This puts millions of computers at risk. You don't expose zero days like this. Apple will probably not sue them, but I would be fully supportive of it if they do so.
- 8 more replies
New conversation -
-
-
Oh please. Do you know how long bugs sit in Bug reporter without seeing any attention? I still have a bug from 2013 sitting there. Apple doesn't care.
-
It’s easier if your provide proof of this. Then everyone would be on your side.
End of conversation
New conversation -
-
-
I would like to clarify my point here. I should've just stuck to the fact that this is "unethical". Apologies about that point.
- 1 more reply
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Perhaps you should call yourself "Apple fanboy" who clearly doesn't understand how reporting security bugs works. Blaming a good Samaritan who is trying to help. Nice.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Can you imagine the chilling effects your stance would have for disclosing any flaws at all?
-
If not disclosing in the correct way can result in a lawsuit, this would essentially a gag-order for all who are no security professionals. It would also create incentives to make disclosure harder in an attempt to keep out the competition.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.