Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as "root" with empty password after clicking on login button several times. Are you aware of it @Apple?
-
-
-
This bug was epic for sure. :D
-
-
I wonder how this issue was discovered. I imagine it like someone spilled the coffee on the laptop and hit Enter by mistake. :)
-
Probably not because they would have had to enter “root” in the userID field as well before that, if the root-user was already enabled the hack wouldn’t work as well
-
yeah, well. i was trying to imagine the funny part of this LOL
-
Haha, well it could have been simply something like: let’s see what happens now, hey I’ve got acccess type of accidental discoveries either
End of conversation
New conversation -
-
-
No need to try it several times. Just type in `root` and press enter.pic.twitter.com/1s7xwBV8An
-
What's the cut/copy/paste contextual menu you're running?
End of conversation
New conversation -
-
-
Ghvvvv tt t. Tg venne n
Thanks. Twitter will use this to make your timeline better. Undo
-
-
-
it works weird for me, seems more like a UI issue. After such login, I can't add new users, can't change settings, etc...
-
oh, no. I can actually login to the system (not only unlock some settings) with `root` & empty password
End of conversation
New conversation -
-
-
@lemiorhan how can you change the root password? -
We'd like to take a closer look at what's happening on your device model. Please DM us more details here:https://twitter.com/messages/compose?recipient_id=3309375033 …
End of conversation
New conversation -
-
-
Terrible bug, maybe the worst ever on macOS. This was a highly irresponsible way to report such a security issue however & now puts more people at risk. In the mean time ensure FileVault is enabled & shutdown after work.
-
Also, setting a password on the root account prevents it
End of conversation
New conversation -
-
-
Looks like this is only a local issue that requires physical access to a macOS system? or is there any remote (RCE) risk?
-
That's what matters the most.
End of conversation
New conversation -
-
-
WTH indeed works here hope apple gives you a big reward
-
Not yet upgraded...
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.