Tim Cook has gradually reduced the testing and Q&A at Apple since taking over. I guess emojis and wearing halos are more important.
Do you know this? Extraordinary if true.
This is such a fundamental and major security flaw, it's mind-blowing how it managed to get through Apple's QA
A critical vulnerability that allows root access to all macs with a single click. We'd be laughing at Microsoft if this had occurred with Windows
Laptop? How about all the schools and Universities that use iMacs with admin accounts? This is a HUGE flaw and shouldn’t be downplayed.
Steve’s Apple deleted all your user data when you logged into the guest account (OS X 10.6.2 bug)Unbelievable. This is not Steve’s Apple.
Most schools and universities keep older OS until the newer ones are finished development. As of now, they’re probably using macOS El Captain and Windows 7 still.Laptop? How about all the schools and Universities that use iMacs with admin accounts? This is a HUGE flaw and shouldn’t be downplayed.
That’s your excuse, really?Heck No!!! This needs to be fixed next beta
Steve’s Apple deleted all your user data when you logged into the guest account (OS X 10.6.2 bug)
[doublepost=1511914942][/doublepost]
Most schools and universities keep older OS until the newer ones are finished development. As of now, they’re probably using macOS El Captain and Windows 7 still.
Oh cool, well too bad for the rest of the world then. Right?! WRONGThat's why most schools, universities and workplaces don't upgrade software until its been out for a year or so
Heck No!!! This needs to be fixed next beta
Steve’s Apple deleted all your user data when you logged into the guest account (OS X 10.6.2 bug)
[doublepost=1511914942][/doublepost]
Most schools and universities keep older OS until the newer ones are finished development. As of now, they’re probably using macOS El Captain and Windows 7 still.[/
Source?That's why most schools, universities and workplaces don't upgrade software until its been out for a year or so
Btw, this is a horrible excuse and doesn’t make anything better.
I made no excuse. I just corrected you on inaccurate information.That’s your excuse, really?
Oh cool, well too bad for the rest of the world then. Right?! WRONG
[doublepost=1511917162][/doublepost]
Or, you know, don't leave your laptop sitting around unlocked. As more or less 100% of your critical info is under your user account anyway, probably even in the easy to find Documents folder, it's almost useless to spend time (as a theif) monkeying with root accounts. Just yoink what you need directly. Creating a root password (as a theif) presumes future access to the Mac, in which case it's been lifted already, and there are ways to get at your info, anyway, if it's unencrypted, as most Macs are.
Pretty dumb flaw, yes, but you deserve what you get if you leave your unattended, unlocked laptop lying around where people can physically get at it in the first place.
Is this related to the rogue guest account on my login screen?
I'm pretty sure you could take advantage of this bug remotely via SSH as well.Or, you know, don't leave your laptop sitting around unlocked. As more or less 100% of your critical info is under your user account anyway, probably even in the easy to find Documents folder, it's almost useless to spend time (as a theif) monkeying with root accounts. Just yoink what you need directly. Creating a root password (as a theif) presumes future access to the Mac, in which case it's been lifted already, and there are ways to get at your info, anyway, if it's unencrypted, as most Macs are.
Pretty dumb flaw, yes, but you deserve what you get if you leave your unattended, unlocked laptop lying around where people can physically get at it in the first place.
dscl . passwd /users/root "$(env LC_CTYPE=C tr -dc 'A-Za-z0-9_\ \!\@\#\$\%\^\&\*\(\)-+=' < /dev/urandom | head -c 32)"You mean this exact bug or a privilege escalation bug?Linus would never let this happen.
That is wild. The bug was described in developer notes in Apple's posesson. But who cares, iPhones are selling very well.This bug was apparently known a couple of weeks ago
https://forums.developer.apple.com/thread/79235
Look for:
“Enter username: root and leave the password empty.”
The guy answering the question thought it was a feature!
A critical vulnerability that allows root access to all macs with a single click. We'd be laughing at Microsoft if this had occurred with Windows