Wow....that is surprising. Most user will never login as root on their MAC.
But why would it have ever been set to blank?
most of the users will never login as `KdParker` - let's disable that one as well.
Wow....that is surprising. Most user will never login as root on their MAC.
But why would it have ever been set to blank?
Given how easy to exploit this bug is, it sure needed to be...That was quick
Beta won't be fixed until the next beta release. Same thing happened with the FileVault password becoming hint issue in High Sierra's 10.13.0 release.Nothing for me on the 10.13.2 beta.
That was quick
How embarrassing...
I wish Apple did a better job testing their releases. We used to enjoy such high quality when it came to software updates and releases.
It’s a good thing this isn’t happening on windows then.Amazing that this bug existed in the first place, however equally amazing response from Apple in terms of how quickly they released a fix.
As embarassed as I am for Apple for this bug popping up, I’m quite certain that Windows would not have benefited from such a quick correction.
This is actually an argument in favor of public disclosure of vulnerabilities. Lemi Orhan Ergin was catching a lot of criticism yesterday for posting it on twitter, but if this bug had been reported privately, it would have taken much longer to fix, while malicious actors would be able to exploit it all along.
Why would that have anything to do with Samsung TVs?
Wow....that is surprising. Most user will never login as root on their MAC.
But why would it have ever been set to blank?
macos 10.13 bug isn't limited to root in all circumstances; via ARD, you can log in as any existing user (e.g. _applepay) and share the screen of the logged-in user. also _uucp is allowed to log in
True, sometimes it's necessary to go public so they'd have no choice but to patch it immediately. But I would still give Apple a couple weeks on something like this, unless there is any sort of evidence that it's already being exploited maliciously.This is actually an argument in favor of public disclosure of vulnerabilities. Lemi Orhan Ergin was catching a lot of criticism yesterday for posting it on twitter, but if this bug had been reported privately, it would have taken much longer to fix, while malicious actors would be able to exploit it all along.
Android is a mobile operating system and you are also forgetting the fact that Google supports it's own devices for at least as long as Apple does.This would have been a very different story on Android. The majority of Android devices are still vulnerable to KRACK let alone any other issue that will never get fixed (except on Nexus devices).
I think the bug was reported two weeks ago: https://forums.developer.apple.com/thread/79235#277225
So Apple had enough time (over Thanksgiving) to solve the vulnerability. It became public as late as yesterday. I'm curious whether the problem persisted/persits with the current macOS beta.
It's been in there for a few years now, IIRC.Until now, I didn't even know MacOS has a restartless mechanism for quick security updates. Clearly Apple anticipated a fix like this being necessary in advance![]()
Does Craig loose some stock options for this and other software bugs that seem to become more prevalent with Apple software?
I respectfully disagree. Lemi could have very easily given Apple 24 hours notice to fix or go public. By not doing so, they left a lot of computers vulnerable.This is actually an argument in favor of public disclosure of vulnerabilities. Lemi Orhan Ergin was catching a lot of criticism yesterday for posting it on twitter, but if this bug had been reported privately, it would have taken much longer to fix, while malicious actors would be able to exploit it all along.
Given how easy to exploit this bug is, it sure needed to be...
Until now, I didn't even know MacOS has a restartless mechanism for quick security updates. Clearly Apple anticipated a fix like this being necessary in advance![]()
You ever heard of Windows? Perhaps you should read up on that OS if you haven't.
Also, give me a break. Nobody finds everything, not even "Apple". Patched quickly and painlessly. Move along.